This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Freezing on start up. Firefox nonresponsive [Solved]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, Chrome worked better. I reinstalled Firefox. It is working now, but I've had slow running and a few identity thefts. I'd like someone to check my scans. thanks

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-08-11 15:52:58
—————————–
15:52:58.233    OS Version: Windows x64 6.1.7601 Service Pack 1
15:52:58.233    Number of processors: 4 586 0x100
15:52:58.233    ComputerName: LLANO2012  UserName: JBH
15:53:00.433    Initialize success
15:53:00.449    VM: initialized successfully
15:53:00.449    VM: Amd CPU supported virtualized
15:54:39.242    AVAST engine defs: 16081106
15:54:56.511    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000006b
15:54:56.511    Disk 0 Vendor: ST950032 0011 Size: 476940MB BusType: 11
15:54:56.745    Disk 0 MBR read successfully
15:54:56.745    Disk 0 MBR scan
15:54:56.761    Disk 0 Windows 7 default MBR code
15:54:56.792    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          200 MB offset 2048
15:54:56.792    Disk 0 Boot: NTFS     code=1
15:54:56.808    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       431938 MB offset 411648
15:54:56.823    Disk 0 Partition - 00     0F Extended LBA             29692 MB offset 885020672
15:54:56.870    Disk 0 Partition 3 00     12  Compaq diag NTFS        15109 MB offset 945829888
15:54:56.933    Disk 0 Partition 4 00     07    HPFS/NTFS NTFS        29691 MB offset 885022720
15:54:57.354    Disk 0 scanning C:\windows\system32\drivers
15:55:20.834    Service scanning
15:56:01.127    Modules scanning
15:56:01.127    Disk 0 trace - called modules:
15:56:01.158    ntoskrnl.exe CLASSPNP.SYS disk.sys amdxata.sys storport.sys hal.dll amdsata.sys
15:56:01.174    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8005abf060]
15:56:01.174    3 CLASSPNP.SYS[fffff8800190643f] -> nt!IofCallDriver -> [0xfffffa80051dfb80]
15:56:01.174    5 amdxata.sys[fffff880010b47a8] -> nt!IofCallDriver -> \Device\0000006b[0xfffffa80054d9730]
15:56:03.108    AVAST engine scan C:\windows
15:56:09.274    AVAST engine scan C:\windows\system32
16:02:46.654    AVAST engine scan C:\windows\system32\drivers
16:03:34.513    AVAST engine scan C:\Users\JBH
18:44:40.840    AVAST engine scan C:\ProgramData
19:22:18.277    Disk 0 statistics 5942259/0/0 @ 0.27 MB/s
19:22:18.308    Scan finished successfully
19:26:28.924    Disk 0 MBR has been saved successfully to "C:\Users\JBH\Desktop\Whatthetech\MBR.dat"
19:26:28.940    The log file has been saved successfully to "C:\Users\JBH\Desktop\Whatthetech\aswMBR.txt"

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2016 01
Ran by [removed] (2016-08-11 19:29:55)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2012-04-19 03:36:53)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3722793996-1674335959-776591757-500 - Administrator - Disabled)
Guest (S-1-5-21-3722793996-1674335959-776591757-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3722793996-1674335959-776591757-1003 - Limited - Enabled)
JBH (S-1-5-21-3722793996-1674335959-776591757-1001 - Administrator - Enabled) => C:\Users\JBH

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acoustica Effects Pack (HKLM-x32\…\Acoustica Effects Pack) (Version: 1.0 - Acoustica, Inc)
Acoustica Mixcraft (HKLM-x32\…\Acoustica Mixcraft) (Version:  - Acoustica)
Acoustica Mixcraft 6 (HKLM-x32\…\Acoustica Mixcraft 6) (Version: b216 - Acoustica)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 15.0.0.356 - Adobe Systems Incorporated)
Adobe Flash Player 22 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 22.0.0.209 - Adobe Systems Incorporated)
Adobe Flash Player 22 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Akamai) (Version:  - Akamai Technologies, Inc)
AMD Catalyst Install Manager (HKLM\…\{F37078EA-4B6A-1D6F-6FED-3EDF2117B42C}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
AMD Quick Stream (HKLM\…\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 4.0.0.0 - AppEx Networks)
Apple Application Support (32-bit) (HKLM-x32\…\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Audacity 2.0 (HKLM-x32\…\Audacity_is1) (Version:  - Audacity Team)
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 12.2.2276 - AVAST Software)
AVG Web TuneUp (HKLM-x32\…\AVG Web TuneUp) (Version: 4.3.2.18 - AVG Technologies)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden
Canvas 12 (HKLM-x32\…\{D6160AAA-9E9A-4255-8E41-969129D31094}) (Version: 12.00.1398 - ACD Systems of America Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 5.20 - Piriform)
ConvertHelper 3.2 (HKLM\…\{27CC6AB1-E72B-4179-AF1A-EAE507EBAF52}}_is1) (Version:  - DownloadHelper)
CopyTrans Suite Remove Only (HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\CopyTrans Suite) (Version: 2.36 - WindSolutions)
CyberGhost 5 (HKLM\…\CyberGhost 5_is1) (Version:  - CyberGhost S.R.L.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Defraggler (HKLM\…\Defraggler) (Version: 2.19 - Piriform)
Digital Voice Editor 3 (HKLM-x32\…\{6CCC133E-9A2F-4CAA-8866-75D029CD3AB3}) (Version: 3.3.01.11240 - Sony Corporation)
DriverToolkit version 8.4.0.0 (HKLM-x32\…\{D66BF89F-B0A2-48F5-A2E4-242EB645AB76}_is1) (Version: 8.4.0.0 - Megaify Software)
Duplicate Cleaner Free 3.2.4 (HKLM-x32\…\Duplicate Cleaner Free) (Version: 3.2.4 - DigitalVolcano Software Ltd) <==== ATTENTION
EaseUS Todo Backup Free 8.0  (HKLM-x32\…\EaseUS Todo Backup_is1) (Version: 8.0 - CHENGDU YIWO Tech Development Co., Ltd)
Energy Management (HKLM-x32\…\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.1 - Lenovo)
Energy Management (x32 Version: 6.0.2.1 - Lenovo) Hidden
erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
Express Scribe Transcription Software (HKLM-x32\…\Scribe) (Version: 5.85 - NCH Software)
FastStone Image Viewer 5.3 (HKLM-x32\…\FastStone Image Viewer) (Version: 5.3 - FastStone Soft)
Foxit PhantomPDF (HKLM-x32\…\{356E39DB-F4F8-4EF7-BFA7-9ABA11E27731}) (Version: 5.5.6.218 - Foxit Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
HijackThis 2.0.2 (HKLM-x32\…\HijackThis) (Version: 2.0.2 - TrendMicro)
iCloud (HKLM\…\{724A887F-2B55-4306-B6F9-8F0E7A04B1B5}) (Version: 5.2.2.87 - Apple Inc.)
IDrive Version - 6.0 (HKLM-x32\…\IDrive_is1) (Version: 6.0 - Pro Softnet Corp)
iTunes (HKLM\…\{955524E7-79EB-4CA9-BA4D-FD2DF587651B}) (Version: 12.4.3.1 - Apple Inc.)
Java 8 Update 91 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\…\LAME_is1) (Version:  - )
LastPass (uninstall only) (HKLM-x32\…\LastPass) (Version:  - LastPass)
Lenovo EasyCamera (HKLM-x32\…\{FC9B811E-39BC-4813-9E29-B83CCF700010}) (Version: 2.16.23.3 - Alcor)
Lenovo EE Boot Optimizer (HKLM\…\Lenovo EE Boot Optimizer) (Version: 0.0.1.9 - Lenovo)
Lenovo Games Console (HKLM-x32\…\Lenovo Games Console) (Version: 1.2.6.436 - Oberon Media Inc.)
Lenovo OneKey Recovery (HKLM-x32\…\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.0.2525 - CyberLink Corp.)
Lenovo OneKey Recovery (Version: 7.0.0.2525 - CyberLink Corp.) Hidden
Logitech Webcam Software (HKLM-x32\…\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)
MagicDisc 2.7.106 (HKLM-x32\…\MagicDisc 2.7.106) (Version:  - )
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Market Samurai (HKLM-x32\…\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1) (Version: 0.93.42 - Alliance Software Pty Ltd)
Market Samurai (x32 Version: 0.93.42 - Alliance Software Pty Ltd) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\…\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Mozilla Firefox 48.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 48.0 (x86 en-US)) (Version: 48.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 48.0.0.6051 - Mozilla)
Mozilla Thunderbird 24.6.0 (x86 en-US) (HKLM-x32\…\Mozilla Thunderbird 24.6.0 (x86 en-US)) (Version: 24.6.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NaturalReaderFree (HKLM-x32\…\{C5E7BF75-007E-44AD-8962-627ED44CB63B}) (Version: 11.9 - NaturalSoft)
Newnovelist 3 (HKLM-x32\…\{5E0548D2-AA3E-44F9-9BD6-8E6E1337266D}) (Version: 1.1.2 - Lifestyle Toolbox)
NLP Coach (HKLM-x32\…\{0DFF2C14-7EDF-407E-B506-DAF24880B104}) (Version: 3.5.3 - Evolve Developmental Software)
OpenOffice.org 3.3 (HKLM-x32\…\{3E171899-0175-47CC-84C4-562ACDD4C021}) (Version: 3.3.9567 - OpenOffice.org)
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Ralink RT2860 Wireless LAN Card (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}) (Version: 1.2.0.36 - Ralink)
Raptr (HKLM-x32\…\Raptr) (Version:  - )
Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.21.531.2010 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6358 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Reader Driver (HKLM-x32\…\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10008 - Realtek Semiconductor Corp.)
RiyazStudio (HKLM-x32\…\RiyazStudio) (Version: 1.44c - RiyazStudio)
SafeZone Stable 1.51.2220.47 (x32 Version: 1.51.2220.47 - Avast Software) Hidden
ScanMaster-ELM 2.0.101.650 DEMO (HKLM-x32\…\ScanMaster-ELM - DEMO_is1) (Version: 2.0.101.650 - WGSoft.de)
ScanXL Professional (HKLM-x32\…\{2BE87846-415C-4098-A6AE-226931D1C01A}) (Version: 3.5.0 - Palmer Performance Engineering)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
Skype™ 7.13 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.13.101 - Skype Technologies S.A.)
Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
SRS Control Panel (HKLM\…\{F3C66EC8-2F33-452D-9CFF-E8C886B3ECC4}) (Version: 1.11.0900 - SRS Labs, Inc.)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 16.2.9.3 - Synaptics Incorporated)
TAP-Windows 9.9.2 (HKLM\…\TAP-Windows) (Version: 9.9.2 - )
TaxACT 2012 - 1040 Edition (HKLM-x32\…\TaxACT 2012 - 1040 Edition) (Version:  - 2nd Story Software, Inc.)
TaxACT 2012 Pennsylvania (HKLM-x32\…\TaxACT 2012 Pennsylvania) (Version:  - 2nd Story Software, Inc.)
TaxACT 2013 - 1040 Edition (HKLM-x32\…\TaxACT 2013 - 1040 Edition) (Version:  - TaxACT, Inc.)
TaxACT 2013 Pennsylvania (HKLM-x32\…\TaxACT 2013 Pennsylvania) (Version:  - TaxACT, Inc.)
TaxACT 2014 - 1040 Edition (HKLM-x32\…\TaxACT 2014 - 1040 Edition) (Version: 1.02 - TaxACT, Inc.)
TaxACT 2014 Pennsylvania (HKLM-x32\…\TaxACT 2014 Pennsylvania) (Version: 1.01 - TaxACT, Inc.)
TaxAct 2015 1040 Edition (HKLM-x32\…\TaxAct 2015 1040 Edition) (Version: 1.05 - TaxAct, Inc.)
TaxAct 2015 Pennsylvania (HKLM-x32\…\TaxAct 2015 Pennsylvania) (Version: 1.03 - TaxAct, Inc.)
TextPad 7 (HKLM-x32\…\{9F53AC20-2D32-4341-9DA1-29DD40E2199E}) (Version: 7.0.9 - Helios)
Un-Rar for Windows 9.22beta (HKLM-x32\…\Un-Rar for Windows) (Version:  - )
UserGuide (HKLM-x32\…\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.6 - Lenovo)
UserGuide (x32 Version: 1.0.0.6 - Lenovo) Hidden
Vegas Movie Studio HD 11.0 (HKLM-x32\…\{6DC79411-858B-11E1-8E7A-F04DA23A5C58}) (Version: 11.0.75 - Sony)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
VueScan (HKLM\…\VueScan) (Version:  - )
Winamp (HKLM-x32\…\Winamp) (Version: 5.666  - Nullsoft, Inc)
WinDirStat 1.1.2 (HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\WinDirStat) (Version:  - )
Windows Driver Package - Lenovo (ACPIVPC) System  (12/02/2010 6.1.0.1) (HKLM\…\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
WinPatrol (HKLM\…\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 32.0.2014.5 - Ruiware)
WinRAR 4.20 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinRAR 5.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
Yahoo! Messenger (HKLM-x32\…\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
yWriter5 (HKLM-x32\…\yWriter5_is1) (Version:  - Spacejock Software)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3722793996-1674335959-776591757-1001_Classes\CLSID\{8A791F0C-C63C-4EC5-B97F-FBCE74EDBC54}\InprocServer32 -> C:\Program Files (x86)\TextPad 7\System\shellext64.dll (Helios Software Solutions)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {28B0DBB8-2298-49CB-B4BF-0E5BBCDFC8FE} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-11] (AVAST Software)
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {2F584210-A17E-40D2-8649-11B20458034B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2016-03-21] (Safer-Networking Ltd.)
Task: {404A038E-5FDD-4B5A-B1C0-C22EA252811F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate [Argument = -crl -hms -pscn 15]
Task: {4ACEE298-DFFC-49BE-8D9B-37FECA1673C5} - System32\Tasks\AVG_SYS_TASK_1015av => C:\ProgramData\Avg_Update_1015av\AVG-Secure-Search-Update_1015av.exe [2015-10-11] ()
Task: {6CC623E8-79B5-450A-A868-AF92110F7E01} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-15] (Adobe Systems Incorporated)
Task: {70930575-75B5-4BF8-9717-737C37468E7F} - System32\Tasks\{AFBD4291-3D70-42EC-95E2-625DB45BBCF8} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{D4B060B9-AD4A-4152-9D99-28B93C615AFE}\setup.exe" -c -runfromtemp -l0x0409 -removeonly
Task: {7FC1E325-D3ED-473B-AE6B-F13B04524D59} - System32\Tasks\0116avUpdateInfo => C:\ProgramData\Avg_Update_0116av\0116av_AVG-Secure-Search-Update.exe [2016-01-10] ()
Task: {827C6B65-F88A-4189-9364-ECFDA8E67D59} - System32\Tasks\{E2A38420-063F-4D2F-A228-4F590ABDA44B} => C:\Program Files (x86)\Freecorder\Freecorder.exe [2005-04-29] (Applian Technologies Inc.)
Task: {882A9DB8-A46A-4D54-9A82-3D3F3C38C5DD} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec [Argument = /RestartRecording]
Task: {9167BFC6-17FA-45E5-B979-3DDAC8003DD3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-19] (Google Inc.)
Task: {95E25DE0-CF3C-4D67-ACE0-DCC0686C1D61} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {A455474A-70F7-4506-A14B-61B79719F432} - System32\Tasks\avastBCLRestartS-1-5-21-3722793996-1674335959-776591757-1001 => Firefox.exe
Task: {A6152442-DB26-4D54-B335-A9AFC494F969} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {AB46880A-A022-43D8-A5AE-FBB70E7B6EBA} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate [Argument = $(Arg0)]
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {B73A016B-7321-4FDF-83A6-E1918528ED8D} - System32\Tasks\DSite => C:\Users\JBH\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE [Argument = /Check] <==== ATTENTION
Task: {B7996D3E-60B3-4E43-8C23-C13DB7C70F59} - System32\Tasks\SafeZone scheduled Autoupdate 1470944520 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-07-25] (Avast Software)
Task: {BB98D59B-C62C-479F-A7C9-077AF9720B09} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {C28909AF-4662-49A4-921C-C30C7593DE8A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-19] (Google Inc.)
Task: {CBBC4101-246C-4C74-8347-A9FE079AEC52} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {E1BA3EBA-7F51-45DE-BC73-4D6D1BE28623} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
Task: {E343F98A-BF87-4236-ADA8-1BD0FE3E5640} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2016-03-21] (Safer-Networking Ltd.)
Task: {E401B40E-20D2-4F14-A3AF-C627A0A71954} - System32\Tasks\AVG_SYS_TASK_0316av_DELETE => C:\ProgramData\Avg_Update_0316av\AVG-Secure-Search-Update_0316av.exe
Task: {E5A28074-9D12-4D0E-9544-CC7EC6AAD40E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-07-13] (Piriform Ltd)
Task: {F1B761A0-F4F4-4EA3-8D8B-2566D3611D13} - System32\Tasks\{CD6C5541-4C51-465F-9199-9016A7FFEE8C} => C:\Program Files (x86)\Freecorder\Freecorder.exe [2005-04-29] (Applian Technologies Inc.)
Task: {F20A17C6-400B-48BB-8B01-94FE27715747} - System32\Tasks\AVG_SYS_TASK_0316av => C:\ProgramData\Avg_Update_0316av\AVG-Secure-Search-Update_0316av.exe
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
Task: {FF2541C2-9E0F-401A-9F3C-8C5401EF27B5} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec [Argument = /StartRecording]

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\windows\Tasks\0116avUpdateInfo.job => C:\ProgramData\Avg_Update_0116av\0116av_AVG-Secure-Search-Update.exe
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\AVG_SYS_TASK_0316av.job => C:\ProgramData\Avg_Update_0316av\AVG-Secure-Search-Update_0316av.exe
Task: C:\windows\Tasks\AVG_SYS_TASK_0316av_DELETE.job => C:\ProgramData\Avg_Update_0316av\AVG-Secure-Search-Update_0316av.exe
Task: C:\windows\Tasks\AVG_SYS_TASK_1015av.job => C:\ProgramData\Avg_Update_1015av\AVG-Secure-Search-Update_1015av.exe
Task: C:\windows\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\JBH\Favorites\NCH Software Download Site.lnk -> hxxp://www.nch.com.au/index.html

==================== Loaded Modules (Whitelisted) ==============

2016-06-08 14:39 - 2016-07-21 22:53 - 00976456 _____ () C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
2015-07-28 22:45 - 2015-07-28 22:45 - 00214528 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Container.PerformanceTuning.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 00817152 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Device.dll
2014-02-11 07:08 - 2014-02-11 07:08 - 03650560 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Platform.dll
2015-07-28 22:45 - 2015-07-28 22:45 - 00127488 _____ () C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2016-04-22 01:07 - 2016-04-22 01:07 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-07-05 15:23 - 2016-07-05 15:23 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2012-03-25 03:56 - 2010-05-19 06:43 - 00454656 _____ () C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe
2015-01-01 20:40 - 2014-12-15 02:03 - 00241704 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
2015-01-01 20:41 - 2014-12-15 02:04 - 00253992 _____ () C:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe
2016-01-26 18:40 - 2016-01-21 19:15 - 00013312 _____ () C:\Program Files (x86)\IDriveWindows\SqliteWrapper.dll
2016-01-26 18:40 - 2015-11-25 14:03 - 00834048 _____ () C:\Program Files (x86)\IDriveWindows\sqlite3.dll
2016-01-26 18:40 - 2015-11-25 14:03 - 00412672 _____ () C:\Program Files (x86)\IDriveWindows\Sync.dll
2016-06-08 14:39 - 2016-07-21 22:53 - 02162760 _____ () C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
2016-01-26 18:40 - 2016-01-21 19:15 - 00043520 _____ () C:\Program Files (x86)\IDriveWindows\RemoteManagement.dll
2016-01-26 18:40 - 2015-11-25 14:03 - 02466184 _____ () C:\Program Files (x86)\IDriveWindows\cmd_util\idwutil_600.exe
2015-01-01 20:40 - 2014-12-15 01:53 - 00098856 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CodeLog.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00031272 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CheckTool.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 01296424 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\libxml2.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00060968 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\zlib1.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00017448 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CompressFile.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00088616 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBGetRemoteNetInfo.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00107560 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActivationOnline.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00077864 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\logsys.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00030248 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DiskSearchImg.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00068136 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\MountImg.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00158248 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ImgFile.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00280104 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\DsImgFile.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00072232 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CheckImg.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00139816 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\vhdvmdk.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00037416 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\BootDriver.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00754728 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ExImage.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00193064 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBackupSize.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00407080 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidImage.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00148008 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumDisk.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00076840 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\FatLib.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00207912 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NTFSLib.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00024616 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\GetDriverInfo.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00020520 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CorrectMbr.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00032296 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EnumTapeDevice.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00034856 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbTapeBrowse.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00064040 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\RegLib.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00022568 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AccountManager.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00115752 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\NasOperator.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00194088 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\EmailBrowser.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00077864 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\CloudOperator.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00037928 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\ActiveOnline.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00135720 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\VMConfig.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00020008 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\AndroidDeviceManager.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00043048 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbDataSwap.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00096808 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBFireWall.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00223784 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\SmartBackup.dll
2015-01-01 20:40 - 2014-12-15 01:53 - 00077864 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\LogSys.dll
2015-01-01 20:41 - 2014-07-22 18:45 - 00243344 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\uexper.dll
2015-01-01 20:41 - 2014-06-17 12:13 - 00163914 _____ () C:\Program Files (x86)\EaseUS\Todo Backup\bin\libssh2.dll
2015-11-30 08:06 - 2014-05-13 13:04 - 00109400 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2015-11-30 08:06 - 2014-05-13 13:04 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2015-11-30 08:06 - 2014-05-13 13:04 - 00167768 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2015-11-30 08:06 - 2012-08-23 11:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2015-11-30 08:06 - 2012-04-03 18:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2016-07-05 15:23 - 2016-07-05 15:23 - 01041208 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2016-04-22 01:08 - 2016-04-22 01:08 - 00080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2016-07-05 15:23 - 2016-07-05 15:23 - 00244536 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll
2015-01-01 20:41 - 2014-12-15 02:04 - 00223272 _____ () C:\Program Files (x86)\EaseUS\TrayPopup\traynet.dll
2015-01-01 20:41 - 2014-12-15 02:04 - 00275496 _____ () C:\Program Files (x86)\EaseUS\TrayPopup\libcurl.dll
2015-01-01 20:41 - 2014-12-15 02:04 - 00118328 _____ () C:\Program Files (x86)\EaseUS\TrayPopup\zlib1.dll
2015-01-01 20:41 - 2014-12-15 02:04 - 00249896 _____ () C:\Program Files (x86)\EaseUS\TrayPopup\uexper.dll
2016-08-11 15:39 - 2016-08-11 15:39 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2016-08-11 15:39 - 2016-08-11 15:39 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-08-11 15:39 - 2016-08-11 15:39 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-01-26 18:40 - 2015-11-25 14:03 - 00022528 _____ () C:\Program Files (x86)\IDriveWindows\cmd_util\cygpopt-0.dll
2016-01-26 18:40 - 2015-11-25 14:03 - 00046094 _____ () C:\Program Files (x86)\IDriveWindows\cmd_util\cyggcc_s-1.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com

There are 7867 more sites.

IE trusted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\northwestsavingsbank.com -> hxxps://www.northwestsavingsbank.com
IE trusted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\wikimedia.org -> hxxps://commons.wikimedia.org
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\123simsen.com -> www.123simsen.com

There are 7867 more sites.


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2012-08-13 23:13 - 2015-11-30 09:01 - 00450028 ___RA C:\windows\system32\Drivers\etc\hosts

127.0.0.1    localhost127.0.0.1    www.007guard.com
127.0.0.1    007guard.com
127.0.0.1    008i.com
127.0.0.1    www.008k.com
127.0.0.1    008k.com
127.0.0.1    www.00hq.com
127.0.0.1    00hq.com
127.0.0.1    010402.com
127.0.0.1    www.032439.com
127.0.0.1    032439.com
127.0.0.1    www.0scan.com
127.0.0.1    0scan.com
127.0.0.1    1000gratisproben.com
127.0.0.1    www.1000gratisproben.com
127.0.0.1    1001namen.com
127.0.0.1    www.1001namen.com
127.0.0.1    100888290cs.com
127.0.0.1    www.100888290cs.com
127.0.0.1    www.100sexlinks.com
127.0.0.1    100sexlinks.com
127.0.0.1    10sek.com
127.0.0.1    www.10sek.com
127.0.0.1    www.1-2005-search.com
127.0.0.1    1-2005-search.com
127.0.0.1    123fporn.info
127.0.0.1    www.123fporn.info
127.0.0.1    123haustiereundmehr.com
127.0.0.1    www.123haustiereundmehr.com
127.0.0.1    123moviedownload.com
127.0.0.1    www.123moviedownload.com

There are 15464 more lines.


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3722793996-1674335959-776591757-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\JBH\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.76.76 - 75.75.75.75
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Install LastPass FF RunOnce.lnk => C:\windows\pss\Install LastPass FF RunOnce.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Install LastPass IE RunOnce.lnk => C:\windows\pss\Install LastPass IE RunOnce.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^JBH^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^JBH^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk => C:\windows\pss\Logitech . Product Registration.lnk.Startup
MSCONFIG\startupfolder: C:^Users^JBH^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk => C:\windows\pss\MagicDisc.lnk.Startup
MSCONFIG\startupfolder: C:^Users^JBH^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk => C:\windows\pss\OpenOffice.org 3.3.lnk.Startup
MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: ArcSoft MediaImpression Monitor => C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe
MSCONFIG\startupreg: CCleaner => "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
MSCONFIG\startupreg: Clownfish => "C:\Program Files (x86)\Clownfish\Clownfish.exe"
MSCONFIG\startupreg: com.apple.dav.bookmarks.daemon => C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
MSCONFIG\startupreg: CyberGhost => "C:\Program Files\CyberGhost 5\CyberGhost.exe" /autostart /min
MSCONFIG\startupreg: Energy Management => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
MSCONFIG\startupreg: EnergyUtility => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe
MSCONFIG\startupreg: Eraser => "C:\Program Files\Eraser\Eraser.exe" -atRestart
MSCONFIG\startupreg: iCloudDrive => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
MSCONFIG\startupreg: iCloudServices => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
MSCONFIG\startupreg: IDrive Background process => "C:\Program Files (x86)\IDriveWindows\id_bglaunch.exe" min
MSCONFIG\startupreg: IDrive Tray => "C:\Program Files (x86)\IDriveWindows\id_tray.exe" min
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Raptr => C:\PROGRA~2\Raptr\raptrstub.exe –startup
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Spybot-S&D; Cleaning => C:\PROGRAM FILES (X86)\QUICKTIME\QTTask.exe
MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
MSCONFIG\startupreg: uTorrent => "C:\Users\JBH\AppData\Roaming\uTorrent\uTorrent.exe"
MSCONFIG\startupreg: VeriFaceManager => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
MSCONFIG\startupreg: YouCam Mirage => "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
MSCONFIG\startupreg: YouCam Tray => "C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe" /s

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{A053D0E1-7046-4489-A294-C886C9AB9532}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{083A73F3-CBA8-4ECA-9EC1-553AD9F7DAFE}] => (Allow) LPort=2869
FirewallRules: [{0E2EFACB-2346-4E55-BB79-C6CB7BBD3219}] => (Allow) LPort=1900
FirewallRules: [{8D43DF4D-7D76-487B-95E8-A910C58DBFA5}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{6434D98F-384B-43A4-99CD-7B12725006D5}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{569A95D6-68E8-458C-BBB0-F0BBF58E70F8}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{937D7EB7-B2CB-4ED1-ABFB-4899DF4F25E5}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{E97A25D1-FC5D-4069-93C1-95A112367EB8}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
FirewallRules: [{838ECADB-B1F9-43DB-8301-40DD7393E6C8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A9111FA8-AE9C-4441-A64E-825AF3626D3F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{E4D7D1DC-0C85-4ECB-B448-DD636E23F5D7}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82DFEE54-0D7B-4327-966E-F47B154C59DC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{E8B4A249-CAD4-484D-B791-8AB19795B1F8}C:\users\jbh\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jbh\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{85251B5F-2E9A-4F6B-A1FC-7995FB88FAD4}C:\users\jbh\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jbh\appdata\local\akamai\netsession_win.exe
FirewallRules: [TCP Query User{424D26BF-BD8B-40FE-BB57-1DAFC0CE8DDA}C:\users\jbh\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jbh\appdata\local\akamai\netsession_win.exe
FirewallRules: [UDP Query User{6FD5BFB3-4A8D-4DA5-ABB3-4831479D92C5}C:\users\jbh\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jbh\appdata\local\akamai\netsession_win.exe
FirewallRules: [{94D8153C-68DE-4B63-BB56-CCD7199EA7F5}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
FirewallRules: [{6DB6ECD6-4AAC-432A-9BE3-2559420ADDA6}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
FirewallRules: [{854D6B02-CCBA-4640-A6CC-252F1350A5D3}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
FirewallRules: [{66FEF005-8F76-4C1D-ADEA-807A6E2D8110}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
FirewallRules: [{C8CD50C2-BBEC-43D8-A896-55FE19092DD8}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{7E3A66EE-D105-4208-8A1D-47B163145F79}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{54A43FA6-302A-4B10-9E20-0F686EA03A00}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
FirewallRules: [{CCBBC23D-7DDC-4FCA-B5EA-EE2D86BF7827}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{7C10F1C6-692E-4E68-B3EB-467E2ED03D18}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{F76A248A-D8C8-4458-8ECB-341B984FDFAF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{4F8EE475-C3AE-4103-945F-CE56C867A40A}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{1908B42E-218C-4F34-B0F7-7BA008E4E086}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
FirewallRules: [{7B304B08-118E-4606-ACF7-B5F04F121F91}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{31D62256-D2E6-4FD2-B3B0-B5CB646EB6D8}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{0B643850-FBBC-4513-A2A8-5FDF636696C3}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{80B38FBC-B11E-43E5-BF84-9320A0185CE3}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{5342FBDA-59DA-436F-843B-BA9EA21385B1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3482C044-C065-4446-B3A1-0966A9D59E55}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{15622C57-4165-4EEE-BF48-5F14AE39DBCC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{EDFD4F25-5064-4C1A-95CB-6184FEB84D85}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8CB17C54-99B4-4751-973C-1BB88CE0E2D1}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{3D91E4A5-C6CA-4E47-BC51-56C066663FB7}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
FirewallRules: [{E548BFE3-BA0D-4FC4-AA02-CCDE0D3099F7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2ACBBB57-BCE0-4FDB-99E2-A51271342B7B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{80880676-33B5-4656-BA9D-2C900300FBC9}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{007A258D-CD4D-43A3-997D-8DF758803494}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service

==================== Restore Points =========================

29-07-2016 15:39:28 Scheduled Checkpoint
07-08-2016 11:37:10 Scheduled Checkpoint
10-08-2016 22:20:38 Windows Update

==================== Faulty Device Manager Devices =============

Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (08/11/2016 03:07:52 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (08/11/2016 03:07:52 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (08/11/2016 03:01:22 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/11/2016 02:45:30 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (08/11/2016 02:45:30 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (08/11/2016 02:41:44 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/11/2016 02:37:29 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

Error: (08/11/2016 02:37:29 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

Error: (08/11/2016 02:31:00 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (08/11/2016 02:22:08 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\windows\system32\msiexec.exe /V; Description = Removed AVG 2016; Error = 0x8007043c).


System errors:
=============
Error: (08/11/2016 03:08:58 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Update service hung on starting.

Error: (08/11/2016 03:05:31 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The IDriveService service failed to start due to the following error:
%%1053 = The service did not respond to the start or control request in a timely fashion.

Error: (08/11/2016 03:05:31 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the IDriveService service to connect.

Error: (08/11/2016 03:01:44 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The CyberGhost 5 Client Service service failed to start due to the following error:
%%1053 = The service did not respond to the start or control request in a timely fashion.

Error: (08/11/2016 03:01:44 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the CyberGhost 5 Client Service service to connect.

Error: (08/11/2016 03:01:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Spybot-S&D; 2 Scanner Service service failed to start due to the following error:
%%1053 = The service did not respond to the start or control request in a timely fashion.

Error: (08/11/2016 03:01:02 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Spybot-S&D; 2 Scanner Service service to connect.

Error: (08/11/2016 02:58:24 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068 = The dependency service or group failed to start.

Error: (08/11/2016 02:58:24 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068 = The dependency service or group failed to start.

Error: (08/11/2016 02:58:23 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
%%1068 = The dependency service or group failed to start.


CodeIntegrity:
===================================
  Date: 2016-03-30 23:06:10.846
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_64.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-03-30 23:05:38.741
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_64.dll because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: AMD A6-3420M APU with Radeon™ HD Graphics
Percentage of memory in use: 40%
Total physical RAM: 5606.11 MB
Available physical RAM: 3341.32 MB
Total Virtual: 11210.4 MB
Available Virtual: 8885.35 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:421.81 GB) (Free:57.52 GB) NTFS
Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:5.51 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 5DD3F739)
Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=421.8 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended)
Partition 4: (Not Active) - (Size=14.8 GB) - (Type=12)

==================== End of Addition.txt ============================

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 11-08-2016 01
Ran by [removed] (administrator) on LLANO2012 (11-08-2016 19:27:08)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

() C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe
(AMD) C:\windows\System32\atiesrxx.exe
(Logitech Inc.) C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe
(AMD) C:\windows\System32\atieclxx.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Advanced Micro Devices, Inc.) C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(CHENGDU YIWO Tech Development Co., Ltd) C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
() C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe
() C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.2\ToolbarUpdater.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Microsoft Corporation) C:\windows\System32\vds.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Akamai Technologies, Inc.) C:\Users\JBH\AppData\Local\Akamai\netsession_win.exe
(Ruiware LLC) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(AppEx Networks Corporation) C:\Program Files\AMD Quick Stream\AMDQuickStream.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Akamai Technologies, Inc.) C:\Users\JBH\AppData\Local\Akamai\netsession_win.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
() C:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Prosoftnet) C:\Program Files (x86)\IDriveWindows\id_bglaunch.exe
(Prosoftnet) C:\Program Files (x86)\IDriveWindows\id_tray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
() C:\Program Files (x86)\AVG Web TuneUp\vprot.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\MOM.exe
(Prosoftnet) C:\Program Files (x86)\IDriveWindows\id_service.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\CCC.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(CyberGhost S.R.L) C:\Program Files\CyberGhost 5\Service.exe
(Microsoft Corporation) C:\windows\System32\dllhost.exe
() C:\Program Files (x86)\IDriveWindows\cmd_util\idwutil_600.exe
() C:\Program Files (x86)\IDriveWindows\cmd_util\idwutil_600.exe


==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11831400 2011-04-21] (Realtek Semiconductor)
HKLM\…\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-03-25] (Lenovo)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-07-26] (Apple Inc.)
HKLM-x32\…\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\…\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
HKLM-x32\…\Run: [EaseUS TB Tray Agent] => C:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe [253992 2014-12-15] ()
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-07-28] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
HKLM-x32\…\Run: [IDrive Background process] => C:\Program Files (x86)\IDriveWindows\id_bglaunch.exe [72936 2016-01-21] (Prosoftnet)
HKLM-x32\…\Run: [IDrive Tray] => C:\Program Files (x86)\IDriveWindows\id_tray.exe [1985256 2016-01-21] (Prosoftnet)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595992 2016-05-20] (Oracle Corporation)
HKLM-x32\…\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [2162760 2016-07-21] ()
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9071752 2016-08-11] (AVAST Software)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE ->
HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [Akamai NetSession Interface] => C:\Users\JBH\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [SetupWizard] => F:\SetupWizard.exe reboot
HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1154112 2014-07-20] (Ruiware LLC)
HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-07-08] (Apple Inc.)
HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [AppEx Accelerator UI] => C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [488640 2015-04-06] (AppEx Networks Corporation)
HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8891608 2016-07-13] (Piriform Ltd)
HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [Spybot-S&D; Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [5915776 2016-03-21] (Safer-Networking Ltd.)
HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2016-07-08] (Apple Inc.)
HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Policies\Explorer: [NoLowDiskSpaceChecks] True
HKU\S-1-5-18\…\RunOnce: [iCloud] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloud.exe [67384 2016-07-08] (Apple Inc.)
HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
ShellIconOverlayIdentifiers: [  0001IDSIcon1] -> {0FA6DCC0-CF0B-427D-A8AF-97C466AB5769} => C:\Program Files (x86)\IDriveWindows\IDSyncIntIcon64.dll [2015-11-25] (Pro-Softnet Corporation, U.S.A)
ShellIconOverlayIdentifiers: [  0001IDSIcon2] -> {66357BBE-D2E5-453C-95FF-8102EB32419D} => C:\Program Files (x86)\IDriveWindows\IDSyncIntIcon64.dll [2015-11-25] (Pro-Softnet Corporation, U.S.A)
ShellIconOverlayIdentifiers: [  0001IDSIcon3] -> {904E6336-8B13-43FA-B4C3-5B62C1C91971} => C:\Program Files (x86)\IDriveWindows\IDSyncIntIcon64.dll [2015-11-25] (Pro-Softnet Corporation, U.S.A)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-11] (AVAST Software)
ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
BootExecute: autocheck autochk * sdnclean64.exe
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75
Tcpip\..\Interfaces\{6156732B-ABFC-41D3-9628-1A5665D65B9E}: [DhcpNameServer] 75.75.76.76 75.75.75.75
Tcpip\..\Interfaces\{71F7E020-02AC-4FF3-B21A-4091DF5B4B44}: [NameServer] 95.169.183.219,89.41.60.38
Tcpip\..\Interfaces\{C1276BC5-982C-4EE7-84C0-6DB1958E06AB}: [DhcpNameServer] 75.75.76.76 75.75.75.75

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-3722793996-1674335959-776591757-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-3722793996-1674335959-776591757-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={27DA12F0-F8DD-4EF9-B9E6-24B7D0F10108}∣=f4cb15fd776347cdae952197b704771a-55b295471c69335542e9e8eb1ad090025cf084ef⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=0616av≺=fr&d;=2016-06-08 14:39:58&v;=4.3.1.831&pid;=wtu&sg;=&sap;=hp
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=LENDF8&pc;=MALN&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=LENDF8&pc;=MALN&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-3722793996-1674335959-776591757-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-3722793996-1674335959-776591757-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={27DA12F0-F8DD-4EF9-B9E6-24B7D0F10108}∣=f4cb15fd776347cdae952197b704771a-55b295471c69335542e9e8eb1ad090025cf084ef⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=0616av≺=fr&d;=2016-06-08 14:39:58&v;=4.3.1.831&pid;=wtu&sg;=&sap;=dsp&q;={searchTerms}
BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-07] (Advanced Micro Devices)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-08-11] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-11-19] (LastPass)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-05-27] (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-08-11] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.3.2.18\AVG Web TuneUp.dll [2016-07-21] (AVG)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-11-19] (LastPass)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-27] (Oracle Corporation)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2015-11-19] (LastPass)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2015-11-19] (LastPass)
Toolbar: HKU\S-1-5-21-3722793996-1674335959-776591757-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)

FireFox:
========
FF ProfilePath: C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default
FF DefaultSearchEngine: AVG Secure Search
FF DefaultSearchEngine.US: Google
FF SelectedSearchEngine: Google
FF Homepage: hxxps://google.com/
FF Keyword.URL: hxxp://us.search.yahoo.com/search?fr=ytff-comodo&p;=
FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-15] ()
FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\windows\system32\npDeployJava1.dll [2013-07-04] (Oracle Corporation)
FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-11-19] (LastPass)
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-15] ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.2\\npsitesafety.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2013-01-21] (Foxit Corporation)
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-27] (Oracle Corporation)
FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2015-11-19] (LastPass)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll [No File]
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
FF SearchPlugin: C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\searchplugins\avg-secure-search.xml [2016-06-08]
FF Extension: Text to Voice - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\extensions\[removed] [2016-01-26]
FF Extension: LastPass - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\extensions\[removed] [2016-03-09]
FF Extension: Zotero - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\extensions\[removed] [2016-07-28]
FF Extension: Facebook Translate - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\[removed] [2015-05-28]
FF Extension: Gmelius - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\[removed] [2014-04-25] [not signed]
FF Extension: NoSquint - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\[removed] [2016-04-27]
FF Extension: New Tab Homepage - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}.xpi [2016-02-12]
FF Extension: Video DownloadHelper - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}.xpi [2016-08-10]
FF Extension: Adblock Plus - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28]
FF Extension: Textise Add-On v3.0 - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\{d358dc61-498f-3de1-4d99-deacebaa276f}.xpi [2016-04-27]
FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-05-25]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: Avast SafePrice - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-08-11]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-08-11]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF

Chrome:
=======
CHR DefaultSearchKeyword: Default -> lp
CHR Profile: C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-07]
CHR Extension: (Google Drive) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-07]
CHR Extension: (YouTube) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-07]
CHR Extension: (Avast SafePrice) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-08-11]
CHR Extension: (Google Sheets) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-07-07]
CHR Extension: (Google Docs Offline) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-07]
CHR Extension: (Avast Online Security) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2016-08-11]
CHR Extension: (Skype) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-07-07]
CHR Extension: (Chrome Web Store Payments) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-07-07]
CHR Extension: (Gmail) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-07]
CHR Extension: (Chrome Media Router) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-11]
CHR HKLM\…\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-07-28] (Advanced Micro Devices, Inc.) [File not signed]
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197640 2016-08-11] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
R2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [65128 2016-01-11] (CyberGhost S.R.L)
S3 CVShell Service; C:\Program Files (x86)\ACD Systems\Canvas 12\CVShellSrv.exe [257400 2010-12-23] (ACD Systems of America Inc.)
R2 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [37416 2014-12-15] (CHENGDU YIWO Tech Development Co., Ltd)
R2 IDriveService; C:\Program Files (x86)\IDriveWindows\id_service.exe [154856 2016-01-21] (Prosoftnet)
R2 RaMediaServer; C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe [454656 2010-05-19] () [File not signed]
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
R2 vToolbarUpdater40.3.2; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.2\ToolbarUpdater.exe [1309768 2016-07-21] (AVG Secure Search)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
R2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [976456 2016-07-21] ()

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
R2 APXACC; C:\Windows\System32\DRIVERS\appexDrv.sys [229056 2015-04-03] (AppEx Networks Corporation)
R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-11] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-11] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-11] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-08-11] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-11] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [968536 2016-08-11] (AVAST Software)
S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513496 2016-08-11] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-08-11] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [292704 2016-08-11] (AVAST Software)
S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [48168 2014-12-15] ()
R3 S6000KNT; C:\Windows\System32\Drivers\S6000KNT.sys [3293272 2010-12-23] (Windows (R) Win 7 DDK provider)
S3 visctap0901; C:\Windows\System32\DRIVERS\visctap0901.sys [39048 2014-06-06] (The OpenVPN Project)
U3 BcmSqlStartupSvc; no ImagePath
U2 CLKMSVC10_3A60B698; no ImagePath
U2 CLKMSVC10_C3B3B687; no ImagePath
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
U2 DriverService; no ImagePath
U2 IAStorDataMgrSvc; no ImagePath
U2 iATAgentService; no ImagePath
U2 idealife Update Service; no ImagePath
U3 IGRS; no ImagePath
U2 IviRegMgr; no ImagePath
U2 nvUpdatusService; no ImagePath
U2 Oasis2Service; no ImagePath
U2 PCCarerService; no ImagePath
U2 ReadyComm.DirectRouter; no ImagePath
U2 RichVideo; no ImagePath
U2 RtLedService; no ImagePath
U2 SeaPort; no ImagePath
U2 SoftwareService; no ImagePath
U3 SQLWriter; no ImagePath
U3 aswMBR; \??\C:\Users\JBH\AppData\Local\Temp\aswMBR.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-11 19:27 - 2016-08-11 19:29 - 00029416 _____ C:\Users\JBH\Desktop\FRST.txt
2016-08-11 15:45 - 2016-08-11 15:41 - 00292704 _____ (AVAST Software) C:\windows\system32\Drivers\asw7DB7.tmp
2016-08-11 15:45 - 2016-08-11 15:39 - 00968536 _____ (AVAST Software) C:\windows\system32\Drivers\asw67EF.tmp
2016-08-11 15:45 - 2016-08-11 15:39 - 00513496 _____ (AVAST Software) C:\windows\system32\Drivers\asw7BA3.tmp
2016-08-11 15:45 - 2016-08-11 15:39 - 00391496 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2016-08-11 15:45 - 2016-08-11 15:39 - 00163416 _____ (AVAST Software) C:\windows\system32\Drivers\asw7FBA.tmp
2016-08-11 15:45 - 2016-08-11 15:39 - 00108816 _____ (AVAST Software) C:\windows\system32\Drivers\asw7644.tmp
2016-08-11 15:45 - 2016-08-11 15:39 - 00103064 _____ (AVAST Software) C:\windows\system32\Drivers\asw6FAE.tmp
2016-08-11 15:45 - 2016-08-11 15:39 - 00074544 _____ (AVAST Software) C:\windows\system32\Drivers\asw7932.tmp
2016-08-11 15:45 - 2016-08-11 15:39 - 00037656 _____ (AVAST Software) C:\windows\system32\Drivers\asw724D.tmp
2016-08-11 15:45 - 2016-08-11 15:39 - 00037144 _____ (AVAST Software) C:\windows\system32\Drivers\asw63AA.tmp
2016-08-11 15:44 - 2016-08-11 15:46 - 00000000 _____ C:\windows\SysWOW64\last.dump
2016-08-11 15:43 - 2016-08-11 15:43 - 00000000 ____D C:\Users\JBH\AppData\Roaming\AVAST Software
2016-08-11 15:43 - 2016-08-11 15:41 - 00292704 _____ (AVAST Software) C:\windows\system32\Drivers\aswEA8C.tmp
2016-08-11 15:43 - 2016-08-11 15:39 - 00513496 _____ (AVAST Software) C:\windows\system32\Drivers\aswE81B.tmp
2016-08-11 15:43 - 2016-08-11 15:39 - 00163416 _____ (AVAST Software) C:\windows\system32\Drivers\aswEEC2.tmp
2016-08-11 15:43 - 2016-08-11 15:39 - 00108816 _____ (AVAST Software) C:\windows\system32\Drivers\aswE0F8.tmp
2016-08-11 15:43 - 2016-08-11 15:39 - 00103064 _____ (AVAST Software) C:\windows\system32\Drivers\aswD504.tmp
2016-08-11 15:43 - 2016-08-11 15:39 - 00074544 _____ (AVAST Software) C:\windows\system32\Drivers\aswE3D6.tmp
2016-08-11 15:43 - 2016-08-11 15:39 - 00037656 _____ (AVAST Software) C:\windows\system32\Drivers\aswDE39.tmp
2016-08-11 15:43 - 2016-08-11 15:39 - 00037144 _____ (AVAST Software) C:\windows\system32\Drivers\aswB1BA.tmp
2016-08-11 15:42 - 2016-08-11 15:46 - 00001922 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2016-08-11 15:42 - 2016-08-11 15:45 - 00003892 _____ C:\windows\System32\Tasks\SafeZone scheduled Autoupdate 1470944520
2016-08-11 15:42 - 2016-08-11 15:42 - 00001043 _____ C:\Users\Public\Desktop\Avast SafeZone Browser.lnk
2016-08-11 15:42 - 2016-08-11 15:42 - 00001043 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2016-08-11 15:42 - 2016-08-11 15:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-08-11 15:41 - 2016-08-11 15:41 - 00292704 _____ (AVAST Software) C:\windows\system32\Drivers\aswvmm.sys.147094449846705
2016-08-11 15:41 - 2016-08-11 15:41 - 00292704 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
2016-08-11 15:41 - 2016-08-11 15:39 - 00968536 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2016-08-11 15:41 - 2016-08-11 15:39 - 00513496 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2016-08-11 15:41 - 2016-08-11 15:39 - 00292704 _____ (AVAST Software) C:\windows\system32\Drivers\aswvmm.sys.147094449729704
2016-08-11 15:41 - 2016-08-11 15:39 - 00163416 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2016-08-11 15:41 - 2016-08-11 15:39 - 00108816 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2016-08-11 15:41 - 2016-08-11 15:39 - 00103064 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2016-08-11 15:41 - 2016-08-11 15:39 - 00074544 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
2016-08-11 15:41 - 2016-08-11 15:39 - 00037656 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
2016-08-11 15:41 - 2016-08-11 15:39 - 00037144 _____ (AVAST Software) C:\windows\system32\Drivers\aswKbd.sys
2016-08-11 15:39 - 2016-08-11 15:39 - 00053208 _____ (AVAST Software) C:\windows\avastSS.scr
2016-08-11 15:39 - 2016-08-11 15:39 - 00000000 ____D C:\Program Files\AVAST Software
2016-08-11 15:11 - 2016-08-11 15:11 - 00513496 _____ (AVAST Software) C:\windows\system32\Drivers\rxqslwqh.sys
2016-08-11 15:09 - 2016-08-11 15:11 - 230102040 _____ (AVAST Software) C:\Users\JBH\Downloads\avast_free_antivirus_setup_offline.exe
2016-08-11 14:49 - 2016-08-11 14:49 - 00000000 ____D C:\Users\JBH\AppData\Local\CEF
2016-08-11 14:45 - 2016-08-11 14:46 - 06253640 _____ (AVAST Software) C:\Users\JBH\Downloads\avast_free_antivirus_setup_online_cnet_2.exe
2016-08-11 14:14 - 2016-08-11 19:26 - 00000000 ____D C:\Users\JBH\Desktop\Whatthetech
2016-08-11 14:12 - 2016-08-11 14:12 - 02393600 _____ (Farbar) C:\Users\JBH\Desktop\FRST64.exe
2016-08-11 14:10 - 2016-08-11 14:10 - 05198336 _____ (AVAST Software) C:\Users\JBH\Desktop\aswMBR.exe
2016-08-11 13:02 - 2016-08-11 13:02 - 00001159 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2016-08-11 13:02 - 2016-08-11 13:02 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2016-08-11 13:01 - 2016-08-11 13:01 - 00242192 _____ C:\Users\JBH\Downloads\Firefox Setup Stub 48.0.exe
2016-08-11 11:12 - 2016-08-11 11:12 - 00739904 _____ (Oracle Corporation) C:\Users\JBH\Downloads\jxpiinstall.exe
2016-08-11 11:06 - 2016-08-11 13:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-08-10 12:15 - 2016-08-10 12:16 - 00000000 ____D C:\Users\JBH\dwhelper
2016-08-10 12:14 - 2016-08-10 12:15 - 00000000 ____D C:\Program Files\ConvertHelper3
2016-08-10 12:13 - 2016-08-10 12:14 - 45936050 _____ (DownloadHelper ) C:\Users\JBH\Downloads\ConvertHelperSetup-3.2.exe
2016-08-10 11:43 - 2016-08-10 11:43 - 00024919 _____ C:\Users\JBH\Downloads\RECEIPT(3).pdf
2016-08-10 10:46 - 2016-08-10 10:47 - 00094825 _____ C:\Users\JBH\Downloads\FAQ-INS.pdf
2016-08-10 06:17 - 2016-07-08 11:37 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2016-08-10 06:17 - 2016-07-08 11:37 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2016-08-10 06:17 - 2016-07-08 11:32 - 01464320 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00343552 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00316416 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2016-08-10 06:17 - 2016-07-08 11:32 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2016-08-10 06:17 - 2016-07-08 11:17 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2016-08-10 06:17 - 2016-07-08 11:17 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00260608 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00251392 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2016-08-10 06:17 - 2016-07-08 11:16 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2016-08-10 06:17 - 2016-07-08 11:03 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2016-08-10 06:17 - 2016-07-08 10:57 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2016-08-10 06:17 - 2016-07-08 10:56 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2016-08-10 06:17 - 2016-07-08 10:56 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2016-08-10 06:17 - 2016-07-08 10:55 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2016-08-10 06:17 - 2016-07-08 10:55 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2016-08-10 06:17 - 2016-07-08 10:50 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2016-08-10 06:16 - 2016-08-02 10:54 - 00394440 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2016-08-10 06:16 - 2016-08-02 10:08 - 00346312 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2016-08-10 06:16 - 2016-08-02 02:54 - 25808384 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2016-08-10 06:16 - 2016-08-02 02:47 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2016-08-10 06:16 - 2016-08-02 02:47 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2016-08-10 06:16 - 2016-08-02 02:32 - 02894336 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2016-08-10 06:16 - 2016-08-02 02:32 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2016-08-10 06:16 - 2016-08-02 02:31 - 00572416 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2016-08-10 06:16 - 2016-08-02 02:31 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2016-08-10 06:16 - 2016-08-02 02:31 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2016-08-10 06:16 - 2016-08-02 02:31 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2016-08-10 06:16 - 2016-08-02 02:24 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2016-08-10 06:16 - 2016-08-02 02:23 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2016-08-10 06:16 - 2016-08-02 02:20 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2016-08-10 06:16 - 2016-08-02 02:19 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2016-08-10 06:16 - 2016-08-02 02:19 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2016-08-10 06:16 - 2016-08-02 02:18 - 06047744 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2016-08-10 06:16 - 2016-08-02 02:18 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2016-08-10 06:16 - 2016-08-02 02:18 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2016-08-10 06:16 - 2016-08-02 02:11 - 00969216 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2016-08-10 06:16 - 2016-08-02 02:08 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2016-08-10 06:16 - 2016-08-02 02:03 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2016-08-10 06:16 - 2016-08-02 02:00 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2016-08-10 06:16 - 2016-08-02 01:59 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2016-08-10 06:16 - 2016-08-02 01:56 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2016-08-10 06:16 - 2016-08-02 01:55 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2016-08-10 06:16 - 2016-08-02 01:54 - 20343808 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2016-08-10 06:16 - 2016-08-02 01:53 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2016-08-10 06:16 - 2016-08-02 01:51 - 00497664 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2016-08-10 06:16 - 2016-08-02 01:51 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2016-08-10 06:16 - 2016-08-02 01:51 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2016-08-10 06:16 - 2016-08-02 01:51 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2016-08-10 06:16 - 2016-08-02 01:51 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2016-08-10 06:16 - 2016-08-02 01:50 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2016-08-10 06:16 - 2016-08-02 01:47 - 02286592 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2016-08-10 06:16 - 2016-08-02 01:45 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2016-08-10 06:16 - 2016-08-02 01:44 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2016-08-10 06:16 - 2016-08-02 01:42 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2016-08-10 06:16 - 2016-08-02 01:41 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2016-08-10 06:16 - 2016-08-02 01:41 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2016-08-10 06:16 - 2016-08-02 01:41 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2016-08-10 06:16 - 2016-08-02 01:40 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2016-08-10 06:16 - 2016-08-02 01:38 - 00806400 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2016-08-10 06:16 - 2016-08-02 01:38 - 00724992 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2016-08-10 06:16 - 2016-08-02 01:37 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2016-08-10 06:16 - 2016-08-02 01:36 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2016-08-10 06:16 - 2016-08-02 01:33 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2016-08-10 06:16 - 2016-08-02 01:29 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-08-10 06:16 - 2016-08-02 01:28 - 15412224 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2016-08-10 06:16 - 2016-08-02 01:28 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2016-08-10 06:16 - 2016-08-02 01:26 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2016-08-10 06:16 - 2016-08-02 01:25 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2016-08-10 06:16 - 2016-08-02 01:24 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2016-08-10 06:16 - 2016-08-02 01:23 - 02868224 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2016-08-10 06:16 - 2016-08-02 01:22 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2016-08-10 06:16 - 2016-08-02 01:21 - 04608000 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2016-08-10 06:16 - 2016-08-02 01:16 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2016-08-10 06:16 - 2016-08-02 01:15 - 00692736 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2016-08-10 06:16 - 2016-08-02 01:14 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2016-08-10 06:16 - 2016-08-02 01:14 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2016-08-10 06:16 - 2016-08-02 01:11 - 13808128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2016-08-10 06:16 - 2016-08-02 01:10 - 01550848 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2016-08-10 06:16 - 2016-08-02 00:59 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2016-08-10 06:16 - 2016-08-02 00:56 - 02393088 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2016-08-10 06:16 - 2016-08-02 00:53 - 01316352 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2016-08-10 06:16 - 2016-08-02 00:51 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2016-08-10 06:16 - 2016-07-08 11:01 - 03218944 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2016-08-09 17:12 - 2016-08-09 17:12 - 00000000 ____D C:\Users\Public\Documents\Olive Juice
2016-08-07 09:23 - 2016-08-07 09:23 - 03220004 _____ C:\Users\JBH\Downloads\ddr30e.pdf
2016-08-05 22:35 - 2016-08-05 22:35 - 00000044 _____ C:\Users\JBH\Documents\Parvez Pilu c sharp.avi.sfl
2016-08-05 20:14 - 2016-08-05 21:18 - 00000000 ____D C:\Users\JBH\Downloads\Noam Chomsky
2016-08-03 10:36 - 2016-08-03 23:08 - 00000000 ____D C:\Users\JBH\Desktop\Alastair Reynolds (All Chaptered)
2016-08-03 10:20 - 2016-08-03 23:20 - 00000000 ____D C:\Users\JBH\Downloads\Klaus Schulze & Pete Namlook - Dark Side Of The Moog 11CD
2016-08-03 10:16 - 2016-08-03 23:33 - 00000000 ____D C:\Users\JBH\Downloads\Ambient Torrent 2
2016-08-03 10:15 - 2016-08-03 10:36 - 00000000 ____D C:\Users\JBH\Downloads\Ambient
2016-08-03 10:12 - 2016-08-03 10:12 - 00000000 ____D C:\Users\JBH\Downloads\Various Artists - Ambient Spheres (CHMO 090)-WEB-2016-iHR
2016-08-02 09:45 - 2016-08-02 09:45 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2016-08-02 09:45 - 2016-08-02 09:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-08-02 09:44 - 2016-08-02 09:45 - 00000000 ____D C:\Program Files\iTunes
2016-08-01 07:42 - 2016-08-01 07:43 - 00000000 ____D C:\Users\JBH\Desktop\iPhone Photos
2016-07-31 14:04 - 2016-07-31 14:04 - 00000000 ____D C:\Users\JBH\AppData\Roaming\Sony Creative Software Inc
2016-07-29 18:16 - 2016-07-29 18:16 - 08136664 _____ (Piriform Ltd) C:\Users\JBH\Downloads\ccsetup520.exe
2016-07-21 15:18 - 2016-07-21 15:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
2016-07-15 23:28 - 2016-08-06 19:23 - 00000000 ____D C:\Users\JBH\Desktop\PILU
2016-07-15 07:21 - 2016-07-15 07:21 - 00000000 ____D C:\Users\JBH\Documents\ProcAlyzer Dumps
2016-07-14 18:49 - 2016-07-14 20:35 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2016-07-14 17:06 - 2016-07-14 17:07 - 16563352 _____ (Malwarebytes Corp.) C:\Users\JBH\Downloads\mbar-1.09.3.1001.exe
2016-07-13 08:20 - 2016-06-25 20:35 - 00041704 _____ (Microsoft Corporation) C:\windows\system32\CompatTelRunner.exe
2016-07-13 08:20 - 2016-06-25 20:27 - 01208320 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll
2016-07-13 08:20 - 2016-06-25 20:27 - 00970240 _____ (Microsoft Corporation) C:\windows\system32\localspl.dll
2016-07-13 08:20 - 2016-06-25 20:27 - 00756736 _____ (Microsoft Corporation) C:\windows\system32\win32spl.dll
2016-07-13 08:20 - 2016-06-25 20:27 - 00344576 _____ (Microsoft Corporation) C:\windows\system32\ntprint.dll
2016-07-13 08:20 - 2016-06-25 20:27 - 00166400 _____ (Microsoft Corporation) C:\windows\system32\inetpp.dll
2016-07-13 08:20 - 2016-06-25 20:27 - 00022528 _____ (Microsoft Corporation) C:\windows\system32\inetppui.dll
2016-07-13 08:20 - 2016-06-25 15:54 - 00497152 _____ (Microsoft Corporation) C:\windows\SysWOW64\win32spl.dll
2016-07-13 08:20 - 2016-06-25 15:53 - 00297472 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.dll
2016-07-13 08:20 - 2016-06-25 15:53 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\ntprint.exe
2016-07-13 08:20 - 2016-06-25 15:53 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\wpnpinst.exe
2016-07-13 08:20 - 2016-06-25 15:41 - 00061952 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntprint.exe
2016-07-13 08:20 - 2016-06-22 09:06 - 00268800 _____ (Microsoft Corporation) C:\windows\system32\centel.dll
2016-07-13 08:20 - 2016-06-17 14:24 - 01490432 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll
2016-07-13 08:20 - 2016-06-17 14:24 - 00571904 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll
2016-07-13 08:20 - 2016-06-17 14:24 - 00544256 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll
2016-07-13 08:20 - 2016-06-17 14:24 - 00294912 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll
2016-07-13 08:20 - 2016-06-17 14:24 - 00219136 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll
2016-07-13 08:20 - 2016-06-17 14:24 - 00076800 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll
2016-07-12 13:08 - 2016-07-12 13:08 - 19525824 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerInstaller.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-08-11 19:27 - 2014-12-02 19:23 - 00000000 ____D C:\FRST
2016-08-11 19:25 - 2012-05-05 20:41 - 00000000 ____D C:\Users\JBH\AppData\LocalLow\Temp
2016-08-11 19:16 - 2015-11-19 20:27 - 00000000 ____D C:\Users\JBH\AppData\LocalLow\LastPass
2016-08-11 18:50 - 2012-04-28 21:27 - 00000000 ____D C:\Users\JBH\AppData\Roaming\vlc
2016-08-11 18:38 - 2016-06-19 06:18 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-08-11 17:44 - 2015-09-23 10:54 - 00000000 ____D C:\ProgramData\IDrive
2016-08-11 17:37 - 2016-06-19 06:18 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-08-11 15:45 - 2015-02-22 07:58 - 00003922 _____ C:\windows\System32\Tasks\avast! Emergency Update
2016-08-11 15:39 - 2012-04-18 23:54 - 00000000 ____D C:\ProgramData\AVAST Software
2016-08-11 15:15 - 2009-07-14 00:45 - 00028928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-08-11 15:15 - 2009-07-14 00:45 - 00028928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-08-11 15:07 - 2009-07-14 01:13 - 00006214 _____ C:\windows\system32\PerfStringBackup.INI
2016-08-11 15:04 - 2012-03-25 04:14 - 00164770 _____ C:\windows\system32\fastboot.set
2016-08-11 15:03 - 2016-03-17 23:55 - 00000572 _____ C:\windows\Tasks\AVG_SYS_TASK_0316av.job
2016-08-11 15:03 - 2016-03-17 23:54 - 00000426 _____ C:\windows\Tasks\AVG_SYS_TASK_0316av_DELETE.job
2016-08-11 15:03 - 2015-10-31 17:25 - 00000542 _____ C:\windows\Tasks\AVG_SYS_TASK_1015av.job
2016-08-11 15:00 - 2009-07-14 01:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
2016-08-11 14:48 - 2015-08-12 22:18 - 00000000 ____D C:\Program Files\Common Files\AV
2016-08-11 14:28 - 2015-09-17 09:46 - 00000000 ____D C:\Users\JBH\AppData\Local\Avg
2016-08-11 14:28 - 2015-08-12 22:11 - 00000000 ____D C:\ProgramData\MFAData
2016-08-11 14:24 - 2015-08-12 22:15 - 00000000 ____D C:\Program Files (x86)\AVG
2016-08-11 14:22 - 2015-10-23 08:59 - 00000000 ____D C:\Users\JBH\AppData\Local\AvgSetupLog
2016-08-11 11:54 - 2012-04-22 09:32 - 00000000 ____D C:\Users\JBH\Documents\cc backups
2016-08-11 11:15 - 2012-05-29 18:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-08-11 08:35 - 2012-06-18 23:15 - 00000000 ____D C:\Users\JBH\AppData\Roaming\Skype
2016-08-11 07:07 - 2009-07-14 00:45 - 00289984 _____ C:\windows\system32\FNTCACHE.DAT
2016-08-10 23:01 - 2013-07-25 03:41 - 00000000 ____D C:\windows\system32\MRT
2016-08-10 22:23 - 2012-04-22 22:46 - 147640136 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2016-08-10 17:24 - 2014-08-09 10:32 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2016-08-10 12:15 - 2012-04-18 23:36 - 00000000 ____D C:\Users\JBH
2016-08-08 17:42 - 2016-07-07 01:49 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-06 18:52 - 2012-06-28 22:40 - 00000000 ____D C:\Users\JBH\Documents\Vegas Movie Studio HD 11.0 Projects
2016-08-05 22:08 - 2012-05-05 21:07 - 00000000 ____D C:\Users\JBH\AppData\Roaming\Audacity
2016-08-02 09:44 - 2014-10-27 18:59 - 00000000 ____D C:\Program Files\iPod
2016-08-02 09:44 - 2014-10-27 18:59 - 00000000 ____D C:\Program Files (x86)\iTunes
2016-08-02 09:44 - 2012-07-04 09:16 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-08-02 05:51 - 2009-07-13 23:20 - 00000000 ____D C:\windows\system32\NDF
2016-07-30 16:35 - 2012-05-29 15:35 - 00000000 ____D C:\Users\JBH\Desktop\Pillow Project
2016-07-29 18:16 - 2016-02-21 15:33 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-07-28 17:32 - 2016-06-19 06:18 - 00003894 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
2016-07-28 17:32 - 2016-06-19 06:18 - 00003642 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
2016-07-28 12:08 - 2015-06-17 20:00 - 00000000 ____D C:\Users\JBH\Downloads\Sitar
2016-07-24 07:44 - 2014-06-12 13:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2016-07-22 07:58 - 2015-05-26 09:33 - 00000000 ____D C:\Users\JBH\Desktop\To Staples
2016-07-21 22:54 - 2016-06-08 14:39 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
2016-07-21 22:53 - 2016-06-08 14:39 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
2016-07-21 15:21 - 2014-09-24 09:10 - 00000000 ____D C:\Users\JBH\AppData\Local\Apple Inc
2016-07-20 03:01 - 2016-03-24 07:30 - 00000000 ___SD C:\windows\SysWOW64\GWX
2016-07-20 03:01 - 2016-03-24 07:30 - 00000000 ___SD C:\windows\system32\GWX
2016-07-15 23:55 - 2009-07-13 23:20 - 00000000 ____D C:\windows\inf
2016-07-15 23:15 - 2014-08-09 10:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
2016-07-15 17:01 - 2014-06-24 09:31 - 00000000 ____D C:\Users\JBH\AppData\Local\Adobe
2016-07-15 17:00 - 2013-07-23 16:28 - 00796352 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2016-07-15 17:00 - 2013-07-23 16:28 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-07-14 17:25 - 2014-08-09 10:32 - 00109272 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
2016-07-14 09:30 - 2014-12-03 10:39 - 00000000 ____D C:\Users\JBH\AppData\Local\ElevatedDiagnostics
2016-07-14 05:05 - 2009-07-13 23:20 - 00000000 ____D C:\windows\rescache
2016-07-14 04:01 - 2014-12-10 04:41 - 00000000 ____D C:\windows\system32\appraiser
2016-07-14 04:01 - 2011-09-28 23:37 - 00000000 ____D C:\Program Files\Windows Journal
2016-07-12 13:08 - 2012-06-23 20:11 - 00000000 ____D C:\windows\system32\Macromed
2016-07-12 13:08 - 2012-03-25 04:14 - 00000000 ____D C:\windows\SysWOW64\Macromed

==================== Files in the root of some directories =======

2015-11-19 20:27 - 2015-11-19 20:27 - 20320792 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2013-10-12 14:57 - 2014-02-26 23:46 - 0008704 _____ () C:\Users\JBH\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2015-05-06 13:42 - 2015-05-06 13:42 - 0628688 _____ (CMI Limited) C:\Users\JBH\AppData\Local\nsvF958.tmp
2014-07-14 13:33 - 2014-07-14 13:33 - 0007612 _____ () C:\Users\JBH\AppData\Local\Resmon.ResmonCfg
2015-03-20 21:43 - 2015-03-20 21:43 - 0000000 _____ () C:\Users\JBH\AppData\Local\{8E968032-81FE-463E-831D-83385A08D0CB}
2014-07-24 19:26 - 2014-07-25 19:03 - 0123904 _____ () C:\ProgramData\ppe_fleetdb.vdb
2014-07-25 03:18 - 2014-07-25 10:15 - 0001837 _____ () C:\ProgramData\scantool.tr

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2016-08-07 09:20

==================== End of FRST.txt ============================

.

 

 

:welcome:

 

You mentioned Identity Theft, what i would do first is use a known clean computer and change all your passwords for sites you access, especially if you do any online banking or purchase from websites using a credit card.

 

Your logs actually dont look to bad, I see a lot of things starting up when you start your computer, this may be part of the slowness issue. You have Avast Anti Virus thats fine, just one is recommended, more than one AV can hamper system performance. 

 

I am also looking at WinPatrol and Spybot, both nice programs but having them both can be adding to your slowness. Trying uninstallilng them and see if things get better

 

 

 

All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
     
     
    [external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
    • Download the one from Bleeping Computer
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
      Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
      •  
        [external image: MBAM221%201043_zpsdtasp5xe.jpg]
         
        • On the Dashboard click on Update Now
        • Go to the Setting Tab
        • Under Setting go to Detection and Protection
        • Under PUP and PUM make sure both are set to show Treat Detections as Malware
        • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
        • Then on the Dashboard click on Scan
        • Make sure to select THREAT SCAN
        • Then click on Scan
        • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
        • Please paste the log back into this thread for review
        • Exit Malwarebytes
        • See logs below. Still freezes upon normal start up. I'm in safe mode now.

           

          Malwarebytes Anti-Malware
          www.malwarebytes.org

          Scan Date: 8/14/2016
          Scan Time: 11:24 AM
          Logfile: Malwarebytes scan results 08142016.txt
          Administrator: Yes

          Version: 2.2.1.1043
          Malware Database: v2016.08.14.05
          Rootkit Database: v2016.08.09.01
          License: Free
          Malware Protection: Disabled
          Malicious Website Protection: Disabled
          Self-protection: Disabled

          OS: Windows 7 Service Pack 1
          CPU: x64
          File System: NTFS
          User: JBH

          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 335762
          Time Elapsed: 52 min, 56 sec

          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Enabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled

          Processes: 0
          (No malicious items detected)

          Modules: 0
          (No malicious items detected)

          Registry Keys: 0
          (No malicious items detected)

          Registry Values: 0
          (No malicious items detected)

          Registry Data: 0
          (No malicious items detected)

          Folders: 0
          (No malicious items detected)

          Files: 0
          (No malicious items detected)

          Physical Sectors: 0
          (No malicious items detected)


          (end)

           

          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Malwarebytes
          Version: 8.0.7 (07.03.2016)
          Operating System: Windows 7 Home Premium x64
          Ran by [removed] (Limited) on Sun 08/14/2016 at 10:52:19.20
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




          File System: 324

          Successfully deleted: C:\Users\JBH\AppData\Local\{1A928CDE-9D76-4B63-B21C-8B2D2C94FCCD} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{221C67E4-9827-4265-AEE9-F04CFF834D8A} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{2A07F840-2450-4999-B6B3-0DDBFDE5B8AF} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{302BA395-DDBE-42FD-9232-574BE3DD5DE7} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{492121E1-8E5D-41CC-97B2-BEC649165064} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{57D2DFEA-A16D-4AAB-B003-95CF12582CA9} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{5A70431C-7569-45BC-8674-979055D86E38} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{63AF4ECA-7183-48B4-8211-939D33BCEB65} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{71DE64AC-48EE-4BBF-99C5-326D34D56F9E} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{BDCC5BF0-5EC0-4684-91D7-2545336E9898} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{C911C347-7660-4F83-8041-21AB79F6C6A4} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{D0732167-734C-4634-9798-D4813B45E09A} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{E44BD8D2-62C4-49C6-8BF1-D87A86C5DBB1} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{F266BEB9-2B8F-45AA-822E-4D5B41EE5AB2} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{F5A5AF05-0F0C-43A6-A6F9-35706B5756F1} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\{F81E670C-386A-418C-A7C5-DC3D2519066D} (Empty Folder)
          Successfully deleted: C:\Users\JBH\AppData\Roaming\MarketSamurai (Folder)
          Successfully deleted: C:\Users\JBH\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1 (Folder)
          Successfully deleted: C:\windows\system32\Tasks\0116avUpdateInfo (Task)
          Successfully deleted: C:\windows\Tasks\0116avUpdateInfo.job (Task)
          Successfully deleted: C:\windows\wininit.ini (File)
          Successfully deleted: C:\Program Files\waien (Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\06CSM09D (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0ABE45KJ (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0NQM274J (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0P1BIEW1 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0YC7UM07 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\11R3ANAI (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1761YWLJ (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1B34LD7S (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1C6HIDYJ (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PYX05A6 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1XINYCJD (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\22NYUE3D (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\24OG2C0T (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\29PA7BUK (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2KQT8W4S (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2O1LYDQY (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2PAMUS4M (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2PO9GMKW (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2QX6YH1D (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2TWCKX95 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\36KGEIAP (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3M58URNQ (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3TWLVDU9 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\42R2YIDZ (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NDK9V30 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5090FCZ9 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\515Q0UUN (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\51M9MQU6 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\586NZM8O (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5K1ZCGPM (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5P7RA4PV (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5S4ZKBTX (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5UIF9955 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5XA93PLC (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\67VY20FP (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6SMWNF8S (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6T3JZUQS (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6YQYO4A2 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6YS6LF3M (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\73Q9J9SV (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\75X8JUOA (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\79KDOR9U (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7BIOAGMI (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7OLR7G3F (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\88XZ2O8T (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8AHOSF35 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8DBDPI1A (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8FXQ2IT0 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8L3AIHF6 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PVDX3O7 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\90UEYQPH (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\920B2T1F (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\97ZI4IBS (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\98AN09Y1 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9C9EGR9H (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9UCXU136 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A2MQKSKE (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A3223626 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ALP071SA (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ATHIPNYQ (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BP0WD9KA (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYE668GT (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C5OXVD5N (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CDIUZ1IU (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CI3R8HQ2 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CRMSG6ST (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D1TCIWSI (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D5R2I4JX (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DALLGBRU (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DBUDP6IT (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DFDE69P5 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EKGMUA6I (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F0A9ZBEN (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F24A62N1 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F3TS0YO5 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FA3PUO3Z (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FKNSRRIY (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FRA3DXRS (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FW8TGYWE (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G5Q5C1VO (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GSY1FME1 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZN0DWTX (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H4RF9UO7 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HB46ZL64 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J9BKZQFE (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ5O7URX (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K4Y0F7ZE (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L6PPHKK2 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L71WO57Z (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LKVR8IS1 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LL8OGLTM (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LSGCC8AF (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LY4PXVU5 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M7ZWHCYY (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MWIEAQNT (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NJ2S9O62 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NVPMAHSJ (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O0BFZBV7 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O79U89MS (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OHAQRA6H (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P31A5NWT (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P6KY13Q4 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PEU1YY6M (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PF200GSJ (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PG2Y43AB (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PN40PG8P (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PUWF2WVW (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PYM35OA6 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHIJX5W3 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QKJRGCQL (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QT9WIPTI (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QV2ITLHU (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R2IQPNQJ (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R5I8JBXG (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RC216SXF (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RJJO7TD9 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYK3V2PR (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYNYWTHQ (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S3Y5KB4M (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S45ZLMGN (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S68JLUG3 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SFVLC0EY (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SYXQP796 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T01CZMS1 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T3IK87C8 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TF3FGKZS (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TRS9Q983 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U7UXFSXB (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U9BO7J8F (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UBMIPYHO (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UCOOOUX8 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V0C8JQGO (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V78WS10W (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V7R9ZPR4 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VF0QZW3Y (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKSY37J8 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBEM35PK (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WE6QVN3H (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WEDK94DK (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WXRQGRM7 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2QNSVZ0 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3M29J4O (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNWB7WGA (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XO07R1SA (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU2G4QUF (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YG4ZZMUP (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YSU14YQ9 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z2N0KZ9V (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z5OCEDO9 (Temporary Internet Files Folder)
          Successfully deleted: C:\Users\JBH\AppData\Local\nsvF958.tmp (File)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\06CSM09D (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0ABE45KJ (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0NQM274J (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0P1BIEW1 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0YC7UM07 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\11R3ANAI (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1761YWLJ (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1B34LD7S (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1C6HIDYJ (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1PYX05A6 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1XINYCJD (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\22NYUE3D (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\24OG2C0T (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\29PA7BUK (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2KQT8W4S (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2O1LYDQY (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2PAMUS4M (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2PO9GMKW (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2QX6YH1D (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2TWCKX95 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\36KGEIAP (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3M58URNQ (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\3TWLVDU9 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\42R2YIDZ (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4NDK9V30 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5090FCZ9 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\515Q0UUN (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\51M9MQU6 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\586NZM8O (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5K1ZCGPM (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5P7RA4PV (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5S4ZKBTX (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5UIF9955 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\5XA93PLC (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\67VY20FP (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6SMWNF8S (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6T3JZUQS (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6YQYO4A2 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6YS6LF3M (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\73Q9J9SV (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\75X8JUOA (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\79KDOR9U (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7BIOAGMI (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\7OLR7G3F (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\88XZ2O8T (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8AHOSF35 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8DBDPI1A (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8FXQ2IT0 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8L3AIHF6 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PVDX3O7 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\90UEYQPH (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\920B2T1F (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\97ZI4IBS (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\98AN09Y1 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9C9EGR9H (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9UCXU136 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A2MQKSKE (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\A3223626 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ALP071SA (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ATHIPNYQ (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BP0WD9KA (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BYE668GT (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\C5OXVD5N (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CDIUZ1IU (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CI3R8HQ2 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CRMSG6ST (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D1TCIWSI (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\D5R2I4JX (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DALLGBRU (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DBUDP6IT (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DFDE69P5 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EKGMUA6I (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F0A9ZBEN (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F24A62N1 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F3TS0YO5 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FA3PUO3Z (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FKNSRRIY (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FRA3DXRS (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FW8TGYWE (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\G5Q5C1VO (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GSY1FME1 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GZN0DWTX (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H4RF9UO7 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HB46ZL64 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\J9BKZQFE (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\JZ5O7URX (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K4Y0F7ZE (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L6PPHKK2 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\L71WO57Z (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LKVR8IS1 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LL8OGLTM (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LSGCC8AF (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LY4PXVU5 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\M7ZWHCYY (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MWIEAQNT (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NJ2S9O62 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NVPMAHSJ (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O0BFZBV7 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\O79U89MS (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OHAQRA6H (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P31A5NWT (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\P6KY13Q4 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PEU1YY6M (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PF200GSJ (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PG2Y43AB (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PN40PG8P (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PUWF2WVW (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PYM35OA6 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QHIJX5W3 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QKJRGCQL (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QT9WIPTI (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QV2ITLHU (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R2IQPNQJ (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\R5I8JBXG (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RC216SXF (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RJJO7TD9 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYK3V2PR (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\RYNYWTHQ (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S3Y5KB4M (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S45ZLMGN (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\S68JLUG3 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SFVLC0EY (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SYXQP796 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T01CZMS1 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T3IK87C8 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TF3FGKZS (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TRS9Q983 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U7UXFSXB (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\U9BO7J8F (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UBMIPYHO (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\UCOOOUX8 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V0C8JQGO (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V78WS10W (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\V7R9ZPR4 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VF0QZW3Y (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\VKSY37J8 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WBEM35PK (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WE6QVN3H (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WEDK94DK (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WXRQGRM7 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X2QNSVZ0 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\X3M29J4O (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNWB7WGA (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XO07R1SA (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XU2G4QUF (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YG4ZZMUP (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YSU14YQ9 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z2N0KZ9V (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z5OCEDO9 (Temporary Internet Files Folder)
          Successfully deleted: C:\windows\SysWOW64\FAP6B04.tmp (File)



          Registry: 1

          Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value)

          # AdwCleaner v6.000 - Logfile created 14/08/2016 at 10:20:44
          # Updated on 12/08/2016 by ToolsLib
          # Database : 2016-08-13.3 [Server]
          # Operating System : Windows 7 Home Premium Service Pack 1 (X64)
          # Username : JBH - LLANO2012
          # Running from : C:\Users\JBH\Desktop\AdwCleaner.exe
          # Mode: Clean
          # Support : https://toolslib.net/forum



          ***** [ Services ] *****

          [-] Service deleted: vToolbarUpdater40.3.2
          [-] Service deleted: WtuSystemSupport


          ***** [ Folders ] *****

          [-] Folder deleted: C:\ProgramData\Avg_Update_0116av
          [-] Folder deleted: C:\ProgramData\Avg_Update_1015av
          [-] Folder deleted: C:\Users\JBH\AppData\Local\E01209E9-1430915430-E111-980D-94EC8750FC18
          [-] Folder deleted: C:\Users\JBH\AppData\Local\DriverToolkit
          [-] Folder deleted: C:\Users\JBH\AppData\Local\avg web tuneup
          [-] Folder deleted: C:\Users\JBH\AppData\Roaming\DSite
          [-] Folder deleted: C:\Users\JBH\AppData\Roaming\Maxiget
          [-] Folder deleted: C:\Users\JBH\AppData\Roaming\mipony
          [-] Folder deleted: C:\Users\JBH\Documents\uc
          [-] Folder deleted: C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Smartbar
          [-] Folder deleted: C:\Program Files\Common Files\AVG Secure Search
          [-] Folder deleted: C:\ProgramData\apn
          [-] Folder deleted: C:\ProgramData\Partner
          [-] Folder deleted: C:\ProgramData\ZombieNews
          [-] Folder deleted: C:\ProgramData\avg web tuneup
          [#] Folder deleted on reboot: C:\ProgramData\Application Data\apn
          [#] Folder deleted on reboot: C:\ProgramData\Application Data\Partner
          [#] Folder deleted on reboot: C:\ProgramData\Application Data\ZombieNews
          [#] Folder deleted on reboot: C:\ProgramData\Application Data\avg web tuneup
          [-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverToolkit
          [-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\mipony
          [-] Folder deleted: C:\Program Files (x86)\1ClickDownload
          [-] Folder deleted: C:\Program Files (x86)\Conduit
          [-] Folder deleted: C:\Program Files (x86)\DriverToolkit
          [-] Folder deleted: C:\Program Files (x86)\XTab
          [-] Folder deleted: C:\Program Files (x86)\avg web tuneup
          [-] Folder deleted: C:\Program Files (x86)\Common Files\AVG Secure Search
          [-] Folder deleted: C:\Users\JBH\AppData\Local\Geckofx
          [#] Folder deleted on reboot: C:\Users\JBH\Documents\uc


          ***** [ Files ] *****



          ***** [ DLL ] *****



          ***** [ WMI ] *****



          ***** [ Shortcuts ] *****



          ***** [ Scheduled Tasks ] *****

          [-] Task deleted: DSite
          [-] Task deleted: DRIVERTOOLKIT AUTORUN


          ***** [ Registry ] *****

          [-] Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd
          [-] Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.GenericWnd.1
          [-] Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi
          [-] Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.NativeApi.1
          [-] Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
          [-] Key deleted: HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
          [-] Key deleted: HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj
          [-] Key deleted: HKLM\SOFTWARE\Classes\WtuServer.WtuServerObj.1
          [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
          [-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
          [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
          [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
          [-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
          [-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
          [-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
          [-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
          [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
          [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
          [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
          [-] Key deleted: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\Software\Ask&Record
          [-] Key deleted: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\Software\DriverToolkit
          [-] Key deleted: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\Software\AppDataLow\Software\Conduit
          [#] Key deleted on reboot: HKCU\Software\Ask&Record
          [#] Key deleted on reboot: HKCU\Software\DriverToolkit
          [#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\Conduit
          [-] Key deleted: HKLM\SOFTWARE\Conduit
          [-] Key deleted: HKLM\SOFTWARE\AVG Tuneup
          [-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{D66BF89F-B0A2-48F5-A2E4-242EB645AB76}_is1
          [-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0C776EBEBCBCFBE408892EE7B12517FC
          [-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\0C776EBEBCBCFBE408892EE7B12517FC
          [-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Installer\Products\0C776EBEBCBCFBE408892EE7B12517FC
          [-] Key deleted: HKLM\SOFTWARE\Classes\Installer\Features\0C776EBEBCBCFBE408892EE7B12517FC
          [#] Key deleted on reboot: HKLM\SOFTWARE\Classes\Installer\Products\0C776EBEBCBCFBE408892EE7B12517FC
          [-] Data restored: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\Software\Microsoft\Internet Explorer\Main [Start Page]
          [-] Data restored: HKCU\Software\Microsoft\Internet Explorer\Main [Start Page]
          [-] Key deleted: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [#] Key deleted on reboot: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}
          [-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Shared Tools\MsConfig\StartupReg\vProt
          [-] Key deleted: HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
          [-] Key deleted: HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin


          ***** [ Web browsers ] *****

          [-] Chrome preferences cleaned: "CT3019965.navigationAliasesJson" -  "{\"EB_MAIN_FRAME_URL\":\"hxxp%3A%2F%2Fwww.anat.stonybrook.edu%2FHBA531%2FEGA%2FEGA_2003_12.pdf\",\"EB_MAIN_FRAME_TITLE\":\"EGA_2003_12.pdf%20(application%2Fpdf%20Object)\",\"EB_SEARCH_TERM\":\"\",\"EB_TOOLBAR_SUB_DOMAIN\":\"hxxp://FreeMediaRecorder.Media-Toolbar.com/\",\"EB_TOOLBAR_ID\":\"CT3019965\",\"EB_TOOLBAR_VERSION\":\"10.10.27.6\",\"EB_ORIGINAL_CTID\":\"CT3019965\",\"EB_DOWNLOAD_PAGE\":\"hxxp://FreeMediaRecorder.Media-Toolbar.com/\",\"EB_TOOLBAR_NAME\":\"Free Media Recorder\"}"
          [-] Chrome preferences cleaned: "CT3019965.serviceLayer_service_toolbarGrouping_activeCTID" -  "{\"dataType\":\"string\",\"data\":\"CT3019965\"}"
          [-] Chrome preferences cleaned: "CT3019965.smartbar.CTID" -  "CT3019965"
          [-] [aol.com] [Search Provider] Deleted: aol.com
          [-] [ask.com] [Search Provider] Deleted: ask.com


          *************************

          :: "Tracing" keys deleted
          :: Winsock settings cleared

          *************************

          C:\AdwCleaner\AdwCleaner[C0].txt - [7662 Bytes] - [14/08/2016 10:20:44]
          C:\AdwCleaner\AdwCleaner[S0].txt - [8190 Bytes] - [14/08/2016 10:16:58]

          ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [7808 Bytes] ##########




          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Sun 08/14/2016 at 10:55:44.91
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           

          Thanks for the logs

           

          Open FRST64 by right clicking on the icon and selecting RUN AS ADMINISTRATOR, when the program loads besure to checkmark ADDITIONS, leave everything else as is, click on SCAN and post both new FRST and Additions logs please

          Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 14-08-2016
          Ran by [removed] (administrator) on LLANO2012 (14-08-2016 20:35:24)
          Running from C:\Users\[removed]\Desktop
          [removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
          Internet Explorer Version 11 (Default browser: FF)
          Boot Mode: Safe Mode (with Networking)
          Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

          ==================== Processes (Whitelisted) =================

          (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

          (Microsoft Corporation) C:\windows\System32\dllhost.exe
          (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
          (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


          ==================== Registry (Whitelisted) ===========================

          (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

          HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11831400 2011-04-21] (Realtek Semiconductor)
          HKLM\…\Run: [Lenovo EE Boot Optimizer] => C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe [206176 2012-03-25] (Lenovo)
          HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-07-26] (Apple Inc.)
          HKLM-x32\…\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
          HKLM-x32\…\Run: [UpdatePRCShortCut] => C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe [222504 2009-05-13] (CyberLink Corp.)
          HKLM-x32\…\Run: [EaseUS TB Tray Agent] => C:\Program Files (x86)\EaseUS\TrayPopup\TrayTipAgent.exe [253992 2014-12-15] ()
          HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-07-28] (Advanced Micro Devices, Inc.)
          HKLM-x32\…\Run: [SDTray] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [4101576 2014-06-24] (Safer-Networking Ltd.)
          HKLM-x32\…\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [6723856 2016-07-22] (AVG Technologies CZ, s.r.o.)
          HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirnx.exe [186640 2016-07-20] (AVG Technologies CZ, s.r.o.)
          HKLM-x32\…\Run: [IDrive Background process] => C:\Program Files (x86)\IDriveWindows\id_bglaunch.exe [72936 2016-01-21] (Prosoftnet)
          HKLM-x32\…\Run: [IDrive Tray] => C:\Program Files (x86)\IDriveWindows\id_tray.exe [1985256 2016-01-21] (Prosoftnet)
          HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595992 2016-05-20] (Oracle Corporation)
          HKLM-x32\…\Run: [vProt] => C:\Program Files (x86)\AVG Web TuneUp\vprot.exe [2162760 2016-07-21] ()
          Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
          HKU\S-1-5-19\Control Panel\Desktop\\SCRNSAVE.EXE ->
          HKU\S-1-5-20\Control Panel\Desktop\\SCRNSAVE.EXE ->
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [Akamai NetSession Interface] => C:\Users\JBH\AppData\Local\Akamai\netsession_win.exe [4691384 2015-09-10] (Akamai Technologies, Inc.)
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [SetupWizard] => F:\SetupWizard.exe reboot
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1154112 2014-07-20] (Ruiware LLC)
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-07-08] (Apple Inc.)
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [AppEx Accelerator UI] => C:\Program Files\AMD Quick Stream\AMDQuickStream.exe [488640 2015-04-06] (AppEx Networks Corporation)
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8891608 2016-07-13] (Piriform Ltd)
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [Spybot-S&D; Cleaning] => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [5915776 2016-03-21] (Safer-Networking Ltd.)
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [67896 2016-07-08] (Apple Inc.)
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Policies\Explorer: [NoLowDiskSpaceChecks] True
          HKU\S-1-5-18\…\RunOnce: [iCloud] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloud.exe [67384 2016-07-08] (Apple Inc.)
          HKU\S-1-5-18\Control Panel\Desktop\\SCRNSAVE.EXE ->
          ShellIconOverlayIdentifiers: [  0001IDSIcon1] -> {0FA6DCC0-CF0B-427D-A8AF-97C466AB5769} => C:\Program Files (x86)\IDriveWindows\IDSyncIntIcon64.dll [2015-11-25] (Pro-Softnet Corporation, U.S.A)
          ShellIconOverlayIdentifiers: [  0001IDSIcon2] -> {66357BBE-D2E5-453C-95FF-8102EB32419D} => C:\Program Files (x86)\IDriveWindows\IDSyncIntIcon64.dll [2015-11-25] (Pro-Softnet Corporation, U.S.A)
          ShellIconOverlayIdentifiers: [  0001IDSIcon3] -> {904E6336-8B13-43FA-B4C3-5B62C1C91971} => C:\Program Files (x86)\IDriveWindows\IDSyncIntIcon64.dll [2015-11-25] (Pro-Softnet Corporation, U.S.A)
          ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  No File
          ShellIconOverlayIdentifiers: [GDriveSharedOverlay] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D44} =>  No File
          Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass FF RunOnce.lnk [2016-08-14]
          ShortcutTarget: Install LastPass FF RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
          Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Install LastPass IE RunOnce.lnk [2016-08-14]
          ShortcutTarget: Install LastPass IE RunOnce.lnk -> C:\Program Files (x86)\Common Files\lpuninstall.exe (LastPass)
          BootExecute: autocheck autochk * sdnclean64.exe
          CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

          ==================== Internet (Whitelisted) ====================

          (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

          Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
          Tcpip\Parameters: [DhcpNameServer] 75.75.76.76 75.75.75.75
          Tcpip\..\Interfaces\{6156732B-ABFC-41D3-9628-1A5665D65B9E}: [DhcpNameServer] 75.75.76.76 75.75.75.75
          Tcpip\..\Interfaces\{71F7E020-02AC-4FF3-B21A-4091DF5B4B44}: [NameServer] 95.169.183.219,89.41.60.38

          Internet Explorer:
          ==================
          HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
          HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
          HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={27DA12F0-F8DD-4EF9-B9E6-24B7D0F10108}∣=f4cb15fd776347cdae952197b704771a-55b295471c69335542e9e8eb1ad090025cf084ef⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=0616av≺=fr&d;=2016-06-08 14:39:58&v;=4.3.1.831&pid;=wtu&sg;=&sap;=hp
          SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=LENDF8&pc;=MALN&src;=IE-SearchBox
          SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=LENDF8&pc;=MALN&src;=IE-SearchBox
          SearchScopes: HKU\S-1-5-21-3722793996-1674335959-776591757-1001 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxps://www.google.com/search?q={searchTerms}
          SearchScopes: HKU\S-1-5-21-3722793996-1674335959-776591757-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={27DA12F0-F8DD-4EF9-B9E6-24B7D0F10108}∣=f4cb15fd776347cdae952197b704771a-55b295471c69335542e9e8eb1ad090025cf084ef⟨=en&ds;=AVG&coid;=avgtbavg&cmpid;=0616av≺=fr&d;=2016-06-08 14:39:58&v;=4.3.1.831&pid;=wtu&sg;=&sap;=dsp&q;={searchTerms}
          BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-07] (Advanced Micro Devices)
          BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
          BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-08-14] (LastPass)
          BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
          BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2012-02-14] (Advanced Micro Devices)
          BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-05-27] (Oracle Corporation)
          BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
          BHO-x32: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Web TuneUp\4.3.2.18\AVG Web TuneUp.dll [2016-07-21] (AVG)
          BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-08-14] (LastPass)
          BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
          BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-27] (Oracle Corporation)
          Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} -  No File
          Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
          Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-08-14] (LastPass)
          Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-08-14] (LastPass)
          Toolbar: HKU\S-1-5-21-3722793996-1674335959-776591757-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
          DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
          Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2014-05-02] (Skype Technologies)
          Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2016-05-25] (Microsoft Corporation)
          Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2016-05-25] (Microsoft Corporation)
          Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
          Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
          Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-07] (Advanced Micro Devices)
          Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)

          FireFox:
          ========
          FF ProfilePath: C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default
          FF DefaultSearchEngine: AVG Secure Search
          FF DefaultSearchEngine.US: Google
          FF SelectedSearchEngine: Google
          FF Homepage: hxxps://google.com/
          FF Keyword.URL: hxxp://us.search.yahoo.com/search?fr=ytff-comodo&p;=
          FF Plugin: @adobe.com/FlashPlayer -> C:\windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-07-15] ()
          FF Plugin: @java.com/DTPlugin,version=10.25.2 -> C:\windows\system32\npDeployJava1.dll [2013-07-04] (Oracle Corporation)
          FF Plugin: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-08-14] (LastPass)
          FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
          FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll [2014-12-11] ( Microsoft Corporation)
          FF Plugin-x32: @adobe.com/FlashPlayer -> C:\windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-07-15] ()
          FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] ()
          FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.2\\npsitesafety.dll [No File]
          FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/pdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [2013-01-21] (Foxit Corporation)
          FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
          FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
          FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
          FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-27] (Oracle Corporation)
          FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-27] (Oracle Corporation)
          FF Plugin-x32: @lastpass.com/NPLastPass -> C:\Program Files (x86)\LastPass\nplastpass64.dll [2016-08-14] (LastPass)
          FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-05-25] (Yahoo! Inc.)
          FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
          FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.31211.0\npctrl.dll [No File]
          FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
          FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
          FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation)
          FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
          FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
          FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
          FF Plugin-x32: @videolan.org/vlc,version=2.1.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
          FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
          FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
          FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-04-13] (VideoLAN)
          FF Extension: Text to Voice - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\extensions\[removed] [2016-01-26]
          FF Extension: Zotero - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\extensions\[removed] [2016-08-14]
          FF Extension: Facebook Translate - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\[removed] [2015-05-28]
          FF Extension: Gmelius - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\[removed] [2014-04-25] [not signed]
          FF Extension: NoSquint - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\[removed] [2016-04-27]
          FF Extension: LastPass - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\[removed] [2016-08-14]
          FF Extension: New Tab Homepage - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\{66E978CD-981F-47DF-AC42-E3CF417C1467}.xpi [2016-02-12]
          FF Extension: Adblock Plus - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-04-28]
          FF Extension: Textise Add-On v3.0 - C:\Users\JBH\AppData\Roaming\Mozilla\Firefox\Profiles\luee5eq8.default\Extensions\{d358dc61-498f-3de1-4d99-deacebaa276f}.xpi [2016-04-27]
          FF Extension: Skype - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-05-25]

          Chrome:
          =======
          CHR DefaultSearchKeyword: Default -> lp
          CHR Profile: C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default
          CHR Extension: (Google Docs) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-07]
          CHR Extension: (Google Drive) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-07]
          CHR Extension: (YouTube) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-07]
          CHR Extension: (Google Sheets) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-07-07]
          CHR Extension: (Google Docs Offline) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-07]
          CHR Extension: (Skype) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2016-07-07]
          CHR Extension: (Chrome Web Store Payments) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-07-07]
          CHR Extension: (Gmail) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-07]
          CHR Extension: (Chrome Media Router) - C:\Users\JBH\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-08-14]
          CHR HKLM\…\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
          CHR HKLM-x32\…\Chrome\Extension: [hdokiejnpimakedhajhdlcegeplioahd] - hxxp://clients2.google.com/service/update2/crx
          CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2016-05-25]

          ==================== Services (Whitelisted) ========================

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

          S2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
          S2 AMD FUEL Service; C:\Program Files\AMD\ATI.ACE\Fuel\Fuel.Service.exe [344064 2015-07-28] (Advanced Micro Devices, Inc.) [File not signed]
          S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.)
          S3 AvgAMPS; C:\Program Files (x86)\AVG\Av\avgamps.exe [637944 2016-07-22] (AVG Technologies CZ, s.r.o.)
          S2 AVGIDSAgent; C:\Program Files (x86)\AVG\Av\avgidsagenta.exe [5251808 2016-07-22] (AVG Technologies CZ, s.r.o.)
          S2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1097488 2016-07-20] (AVG Technologies CZ, s.r.o.)
          S2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [712792 2016-07-22] (AVG Technologies CZ, s.r.o.)
          S2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1364096 2016-05-25] (Microsoft Corporation)
          S2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1687680 2016-05-25] (Microsoft Corporation)
          S2 CGVPNCliService; C:\Program Files\CyberGhost 5\Service.exe [65128 2016-01-11] (CyberGhost S.R.L)
          S3 CVShell Service; C:\Program Files (x86)\ACD Systems\Canvas 12\CVShellSrv.exe [257400 2010-12-23] (ACD Systems of America Inc.)
          S2 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [37416 2014-12-15] (CHENGDU YIWO Tech Development Co., Ltd)
          S2 IDriveService; C:\Program Files (x86)\IDriveWindows\id_service.exe [154856 2016-01-21] (Prosoftnet)
          S2 RaMediaServer; C:\Program Files (x86)\Ralink\RT2860 Wireless LAN Card\ExtraFiles\RaMediaServer.exe [454656 2010-05-19] () [File not signed]
          S2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1738168 2014-06-24] (Safer-Networking Ltd.)
          S2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [2088408 2014-06-27] (Safer-Networking Ltd.)
          S2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2014-04-25] (Safer-Networking Ltd.)
          S2 vToolbarUpdater40.3.2; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\40.3.2\ToolbarUpdater.exe [1309768 2016-07-21] (AVG Secure Search)
          S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
          S2 WtuSystemSupport; C:\Program Files (x86)\AVG Web TuneUp\WtuSystemSupport.exe [976456 2016-07-21] ()

          ===================== Drivers (Whitelisted) ==========================

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

          S2 AODDriver4.3; C:\Program Files\AMD\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
          U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation)
          S2 APXACC; C:\Windows\System32\DRIVERS\appexDrv.sys [229056 2015-04-03] (AppEx Networks Corporation)
          S1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [163072 2016-05-13] (AVG Technologies CZ, s.r.o.)
          S1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [310016 2016-06-09] (AVG Technologies CZ, s.r.o.)
          R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [261376 2016-06-01] (AVG Technologies CZ, s.r.o.)
          S1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [260352 2016-06-01] (AVG Technologies CZ, s.r.o.)
          S0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [360736 2016-02-16] (AVG Technologies CZ, s.r.o.)
          R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [249088 2016-06-02] (AVG Technologies CZ, s.r.o.)
          R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [52992 2016-06-01] (AVG Technologies CZ, s.r.o.)
          S0 Avguniva; C:\Windows\System32\DRIVERS\avguniva.sys [76544 2016-06-01] (AVG Technologies CZ, s.r.o.)
          S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
          R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [48168 2014-12-15] ()
          S3 S6000KNT; C:\Windows\System32\Drivers\S6000KNT.sys [3293272 2010-12-23] (Windows (R) Win 7 DDK provider)
          S3 visctap0901; C:\Windows\System32\DRIVERS\visctap0901.sys [39048 2014-06-06] (The OpenVPN Project)
          U3 BcmSqlStartupSvc; no ImagePath
          U2 CLKMSVC10_3A60B698; no ImagePath
          U2 CLKMSVC10_C3B3B687; no ImagePath
          S3 clwvd; system32\DRIVERS\clwvd.sys [X]
          U2 DriverService; no ImagePath
          U2 IAStorDataMgrSvc; no ImagePath
          U2 iATAgentService; no ImagePath
          U2 idealife Update Service; no ImagePath
          U3 IGRS; no ImagePath
          U2 IviRegMgr; no ImagePath
          U2 nvUpdatusService; no ImagePath
          U2 Oasis2Service; no ImagePath
          U2 PCCarerService; no ImagePath
          U2 ReadyComm.DirectRouter; no ImagePath
          U2 RichVideo; no ImagePath
          U2 RtLedService; no ImagePath
          U2 SeaPort; no ImagePath
          U2 SoftwareService; no ImagePath
          U3 SQLWriter; no ImagePath

          ==================== NetSvcs (Whitelisted) ===================

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


          ==================== One Month Created files and folders ========

          (If an entry is included in the fixlist, the file/folder will be moved.)

          2016-08-14 20:35 - 2016-08-14 20:37 - 00025133 _____ C:\Users\JBH\Desktop\FRST.txt
          2016-08-14 20:32 - 2016-08-14 20:32 - 02394624 _____ (Farbar) C:\Users\JBH\Desktop\FRST64.exe
          2016-08-14 18:00 - 2016-08-14 18:01 - 00094674 _____ C:\windows\ntbtlog.txt
          2016-08-14 17:29 - 2016-08-14 17:29 - 00001192 _____ C:\Users\Public\Desktop\My LastPass Vault.lnk
          2016-08-14 17:12 - 2016-08-14 17:12 - 21874200 _____ (LastPass) C:\Users\JBH\Downloads\lastpass_x64 (2).exe
          2016-08-14 16:43 - 2016-08-14 16:44 - 21874200 _____ (LastPass) C:\Users\JBH\Downloads\lastpass_x64 (1).exe
          2016-08-14 10:15 - 2016-08-14 13:50 - 00000000 ____D C:\AdwCleaner
          2016-08-14 09:48 - 2016-08-14 09:50 - 00000000 ____D C:\Users\JBH\Documents\Video
          2016-08-12 07:29 - 2016-08-12 07:29 - 00291891 _____ C:\unp305368443198773224.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00291811 _____ C:\unp305368443200957228.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00291355 _____ C:\unp305368443201737230.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00290925 _____ C:\unp305368443197837223.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00290690 _____ C:\unp305368443199553226.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00289707 _____ C:\unp305368443196121220.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00289625 _____ C:\unp305368443190661210.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00289191 _____ C:\unp305368443184733200.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00289081 _____ C:\unp305368443195185218.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00288421 _____ C:\unp305368443196901221.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00288349 _____ C:\unp305368443188945207.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00288271 _____ C:\unp305368443185513201.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00288201 _____ C:\unp305368443187229204.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00288099 _____ C:\unp305368443186449203.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00288087 _____ C:\unp305368443194249216.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00287637 _____ C:\unp305368443192377213.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00287305 _____ C:\unp305368443193469215.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00287199 _____ C:\unp305368443191597212.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00286127 _____ C:\unp305368443188165206.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00285987 _____ C:\unp305368443189881209.mdmp
          2016-08-12 07:29 - 2016-08-12 07:29 - 00279524 _____ C:\unp305368443177713188.mdmp
          2016-08-11 14:49 - 2016-08-11 14:49 - 00000000 ____D C:\Users\JBH\AppData\Local\CEF
          2016-08-11 14:14 - 2016-08-14 12:20 - 00000000 ____D C:\Users\JBH\Desktop\Whatthetech
          2016-08-10 12:15 - 2016-08-10 12:16 - 00000000 ____D C:\Users\JBH\dwhelper
          2016-08-10 12:14 - 2016-08-12 09:57 - 00000000 ____D C:\Program Files\ConvertHelper3
          2016-08-10 11:43 - 2016-08-10 11:43 - 00024919 _____ C:\Users\JBH\Downloads\RECEIPT(3).pdf
          2016-08-10 10:46 - 2016-08-10 10:47 - 00094825 _____ C:\Users\JBH\Downloads\FAQ-INS.pdf
          2016-08-09 17:12 - 2016-08-09 17:12 - 00000000 ____D C:\Users\Public\Documents\Olive Juice
          2016-08-07 09:23 - 2016-08-07 09:23 - 03220004 _____ C:\Users\JBH\Downloads\ddr30e.pdf
          2016-08-05 22:35 - 2016-08-05 22:35 - 00000044 _____ C:\Users\JBH\Documents\Parvez Pilu c sharp.avi.sfl
          2016-08-05 20:14 - 2016-08-14 13:44 - 00000000 ____D C:\Users\JBH\Downloads\Noam Chomsky
          2016-08-03 10:36 - 2016-08-03 23:08 - 00000000 ____D C:\Users\JBH\Desktop\Alastair Reynolds (All Chaptered)
          2016-08-03 10:20 - 2016-08-03 23:20 - 00000000 ____D C:\Users\JBH\Downloads\Klaus Schulze & Pete Namlook - Dark Side Of The Moog 11CD
          2016-08-03 10:16 - 2016-08-14 13:44 - 00000000 ____D C:\Users\JBH\Downloads\Ambient Torrent 2
          2016-08-03 10:15 - 2016-08-14 13:50 - 00000000 ____D C:\Users\JBH\Downloads\Ambient
          2016-08-03 10:12 - 2016-08-03 10:12 - 00000000 ____D C:\Users\JBH\Downloads\Various Artists - Ambient Spheres (CHMO 090)-WEB-2016-iHR
          2016-08-02 09:45 - 2016-08-14 13:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
          2016-08-02 09:45 - 2016-08-02 09:45 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
          2016-08-02 09:44 - 2016-08-14 15:21 - 00000000 ____D C:\Program Files\iTunes
          2016-07-31 14:04 - 2016-07-31 14:04 - 00000000 ____D C:\Users\JBH\AppData\Roaming\Sony Creative Software Inc
          2016-07-29 18:16 - 2016-07-29 18:16 - 08136664 _____ (Piriform Ltd) C:\Users\JBH\Downloads\ccsetup520.exe
          2016-07-21 15:18 - 2016-07-21 15:18 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iCloud
          2016-07-15 23:28 - 2016-08-06 19:23 - 00000000 ____D C:\Users\JBH\Desktop\PILU
          2016-07-15 07:21 - 2016-07-15 07:21 - 00000000 ____D C:\Users\JBH\Documents\ProcAlyzer Dumps

          ==================== One Month Modified files and folders ========

          (If an entry is included in the fixlist, the file/folder will be moved.)

          2016-08-14 20:35 - 2014-12-02 19:23 - 00000000 ____D C:\FRST
          2016-08-14 20:32 - 2012-05-05 20:41 - 00000000 ____D C:\Users\JBH\AppData\LocalLow\Temp
          2016-08-14 20:23 - 2016-06-15 17:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
          2016-08-14 18:05 - 2009-07-14 01:13 - 00006214 _____ C:\windows\system32\PerfStringBackup.INI
          2016-08-14 18:03 - 2012-03-25 04:14 - 00724860 _____ C:\windows\system32\fastboot.set
          2016-08-14 17:58 - 2009-07-14 00:45 - 00028928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
          2016-08-14 17:58 - 2009-07-14 00:45 - 00028928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
          2016-08-14 17:48 - 2016-06-19 06:18 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
          2016-08-14 17:47 - 2016-03-17 23:55 - 00000572 _____ C:\windows\Tasks\AVG_SYS_TASK_0316av.job
          2016-08-14 17:47 - 2016-03-17 23:54 - 00000426 _____ C:\windows\Tasks\AVG_SYS_TASK_0316av_DELETE.job
          2016-08-14 17:47 - 2015-10-31 17:25 - 00000542 _____ C:\windows\Tasks\AVG_SYS_TASK_1015av.job
          2016-08-14 17:46 - 2009-07-14 01:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
          2016-08-14 17:42 - 2012-06-18 23:15 - 00000000 ____D C:\Users\JBH\AppData\Roaming\Skype
          2016-08-14 17:39 - 2015-11-19 20:27 - 00000000 ____D C:\Users\JBH\AppData\LocalLow\LastPass
          2016-08-14 17:37 - 2016-06-19 06:18 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA.job
          2016-08-14 17:30 - 2015-11-19 20:27 - 00000000 ____D C:\Program Files (x86)\LastPass
          2016-08-14 17:29 - 2015-11-19 20:27 - 00000000 ____D C:\Users\JBH\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LastPass
          2016-08-14 17:29 - 2015-11-19 20:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LastPass
          2016-08-14 15:23 - 2012-04-18 23:36 - 00000000 ____D C:\Users\JBH
          2016-08-14 15:21 - 2014-12-04 19:40 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol
          2016-08-14 15:21 - 2014-09-07 09:00 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
          2016-08-14 15:21 - 2009-07-13 23:20 - 00000000 ____D C:\windows\PolicyDefinitions
          2016-08-14 13:51 - 2016-03-24 07:30 - 00000000 ___SD C:\windows\system32\GWX
          2016-08-14 13:51 - 2016-02-21 15:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
          2016-08-14 13:51 - 2009-07-13 23:20 - 00000000 ____D C:\windows\system32\NDF
          2016-08-14 13:50 - 2016-06-08 14:40 - 00000000 ____D C:\Users\JBH\AppData\Local\AVG Web TuneUp
          2016-08-14 13:50 - 2016-06-08 14:39 - 00000000 ____D C:\ProgramData\AVG Web TuneUp
          2016-08-14 13:50 - 2016-06-08 14:39 - 00000000 ____D C:\Program Files\Common Files\AVG Secure Search
          2016-08-14 13:50 - 2016-06-08 14:39 - 00000000 ____D C:\Program Files (x86)\AVG Web TuneUp
          2016-08-14 13:50 - 2016-05-13 19:20 - 00000000 ____D C:\Users\JBH\Desktop\HB
          2016-08-14 13:50 - 2016-01-26 23:15 - 00000000 ____D C:\ProgramData\Avg_Update_0116av
          2016-08-14 13:50 - 2015-11-30 08:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
          2016-08-14 13:50 - 2015-10-31 17:24 - 00000000 ____D C:\ProgramData\Avg_Update_1015av
          2016-08-14 13:50 - 2015-10-23 09:07 - 00000000 ____D C:\ProgramData\Avg
          2016-08-14 13:50 - 2015-10-02 11:17 - 00000000 ____D C:\Program Files (x86)\1ClickDownload
          2016-08-14 13:50 - 2015-08-12 22:18 - 00000000 ____D C:\Program Files\Common Files\AV
          2016-08-14 13:50 - 2015-08-12 22:15 - 00000000 ____D C:\Program Files (x86)\AVG
          2016-08-14 13:50 - 2015-08-12 22:11 - 00000000 ____D C:\ProgramData\MFAData
          2016-08-14 13:50 - 2014-12-04 19:40 - 00000000 ____D C:\ProgramData\InstallMate
          2016-08-14 13:50 - 2014-12-04 19:40 - 00000000 ____D C:\Program Files (x86)\Ruiware
          2016-08-14 13:50 - 2014-12-03 22:53 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DriverToolkit
          2016-08-14 13:50 - 2014-12-03 22:53 - 00000000 ____D C:\Program Files (x86)\DriverToolkit
          2016-08-14 13:50 - 2014-09-05 23:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
          2016-08-14 13:50 - 2014-08-19 15:37 - 00000000 ____D C:\Users\JBH\AppData\Roaming\uTorrent
          2016-08-14 13:50 - 2014-08-09 10:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
          2016-08-14 13:50 - 2014-08-09 10:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
          2016-08-14 13:50 - 2014-06-12 13:26 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
          2016-08-14 13:50 - 2013-12-09 11:17 - 00000000 ____D C:\ProgramData\Oracle
          2016-08-14 13:50 - 2013-10-12 07:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
          2016-08-14 13:50 - 2013-03-05 22:31 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiPony
          2016-08-14 13:50 - 2013-02-26 23:46 - 00000000 ____D C:\Users\JBH\AppData\Local\Akamai
          2016-08-14 13:50 - 2012-07-04 09:16 - 00000000 ____D C:\Program Files\Common Files\Apple
          2016-08-14 13:50 - 2012-05-29 18:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
          2016-08-14 13:50 - 2012-05-05 21:07 - 00000000 ____D C:\Users\JBH\AppData\Roaming\Audacity
          2016-08-14 13:50 - 2012-04-28 21:27 - 00000000 ____D C:\Users\JBH\AppData\Roaming\vlc
          2016-08-14 13:50 - 2012-04-22 09:32 - 00000000 ____D C:\Users\JBH\Documents\cc backups
          2016-08-14 13:50 - 2012-04-22 09:30 - 00000000 ____D C:\Program Files\CCleaner
          2016-08-14 13:50 - 2012-04-22 07:21 - 00000000 ____D C:\Program Files (x86)\Java
          2016-08-14 13:50 - 2012-04-20 23:21 - 00000000 ____D C:\Users\JBH\AppData\Roaming\ArcSoft
          2016-08-14 13:50 - 2012-03-25 04:25 - 00000000 ____D C:\Program Files (x86)\Google
          2016-08-14 13:50 - 2009-07-13 23:20 - 00000000 ____D C:\windows\inf
          2016-08-14 13:50 - 2009-07-13 23:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
          2016-08-14 13:49 - 2009-07-13 23:20 - 00000000 ____D C:\windows\registration
          2016-08-14 13:47 - 2014-09-07 09:01 - 00000000 ____D C:\windows\System32\Tasks\Safer-Networking
          2016-08-14 13:43 - 2015-09-23 10:54 - 00000000 ____D C:\ProgramData\IDrive
          2016-08-14 13:43 - 2013-05-12 23:58 - 00000000 ____D C:\Users\JBH\Documents\Broom making
          2016-08-14 13:43 - 2012-04-18 23:50 - 00000000 ____D C:\Users\JBH\AppData\Local\Google
          2016-08-14 13:42 - 2014-10-27 18:59 - 00000000 ____D C:\Program Files\iPod
          2016-08-14 13:41 - 2014-10-27 18:59 - 00000000 ____D C:\Program Files (x86)\iTunes
          2016-08-14 09:44 - 2012-05-29 16:16 - 00000000 ____D C:\Users\JBH\Documents\Pdfs
          2016-08-14 09:42 - 2012-05-29 15:53 - 00000000 ____D C:\Users\JBH\Documents\images
          2016-08-14 09:36 - 2013-02-09 11:08 - 00000000 ____D C:\Users\JBH\Documents\Self Care
          2016-08-14 08:32 - 2012-04-21 23:06 - 00000000 ____D C:\Users\JBH\AppData\Local\Thunderbird
          2016-08-12 09:11 - 2012-04-18 23:54 - 00000000 ____D C:\ProgramData\AVAST Software
          2016-08-11 19:57 - 2015-09-30 08:28 - 00000000 ____D C:\Users\JBH\.oracle_jre_usage
          2016-08-11 14:28 - 2015-09-17 09:46 - 00000000 ____D C:\Users\JBH\AppData\Local\Avg
          2016-08-11 14:22 - 2015-10-23 08:59 - 00000000 ____D C:\Users\JBH\AppData\Local\AvgSetupLog
          2016-08-06 18:52 - 2012-06-28 22:40 - 00000000 ____D C:\Users\JBH\Documents\Vegas Movie Studio HD 11.0 Projects
          2016-07-30 16:35 - 2012-05-29 15:35 - 00000000 ____D C:\Users\JBH\Desktop\Pillow Project
          2016-07-29 18:16 - 2016-02-21 15:33 - 00000822 _____ C:\Users\Public\Desktop\CCleaner.lnk
          2016-07-28 17:32 - 2016-06-19 06:18 - 00003894 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineUA
          2016-07-28 17:32 - 2016-06-19 06:18 - 00003642 _____ C:\windows\System32\Tasks\GoogleUpdateTaskMachineCore
          2016-07-28 12:08 - 2015-06-17 20:00 - 00000000 ____D C:\Users\JBH\Downloads\Sitar
          2016-07-26 07:46 - 2015-10-23 09:13 - 00000936 _____ C:\Users\Public\Desktop\AVG Protection.lnk
          2016-07-21 15:21 - 2014-09-24 09:10 - 00000000 ____D C:\Users\JBH\AppData\Local\Apple Inc
          2016-07-20 03:01 - 2016-03-24 07:30 - 00000000 ___SD C:\windows\SysWOW64\GWX
          2016-07-16 13:36 - 2014-08-09 10:32 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
          2016-07-15 17:01 - 2014-06-24 09:31 - 00000000 ____D C:\Users\JBH\AppData\Local\Adobe
          2016-07-15 17:00 - 2013-07-23 16:28 - 00796352 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
          2016-07-15 17:00 - 2013-07-23 16:28 - 00142528 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl

          ==================== Files in the root of some directories =======

          2015-11-19 20:27 - 2016-08-14 17:30 - 21874200 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
          2013-10-12 14:57 - 2014-02-26 23:46 - 0008704 _____ () C:\Users\JBH\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
          2014-07-14 13:33 - 2014-07-14 13:33 - 0007612 _____ () C:\Users\JBH\AppData\Local\Resmon.ResmonCfg
          2015-03-20 21:43 - 2015-03-20 21:43 - 0000000 _____ () C:\Users\JBH\AppData\Local\{8E968032-81FE-463E-831D-83385A08D0CB}
          2014-07-24 19:26 - 2014-07-25 19:03 - 0123904 _____ () C:\ProgramData\ppe_fleetdb.vdb
          2014-07-25 03:18 - 2014-07-25 10:15 - 0001837 _____ () C:\ProgramData\scantool.tr

          ==================== Bamital & volsnap =================

          (There is no automatic fix for files that do not pass verification.)

          C:\windows\system32\winlogon.exe => File is digitally signed
          C:\windows\system32\wininit.exe => File is digitally signed
          C:\windows\SysWOW64\wininit.exe => File is digitally signed
          C:\windows\explorer.exe => File is digitally signed
          C:\windows\SysWOW64\explorer.exe => File is digitally signed
          C:\windows\system32\svchost.exe => File is digitally signed
          C:\windows\SysWOW64\svchost.exe => File is digitally signed
          C:\windows\system32\services.exe => File is digitally signed
          C:\windows\system32\User32.dll => File is digitally signed
          C:\windows\SysWOW64\User32.dll => File is digitally signed
          C:\windows\system32\userinit.exe => File is digitally signed
          C:\windows\SysWOW64\userinit.exe => File is digitally signed
          C:\windows\system32\rpcss.dll => File is digitally signed
          C:\windows\system32\dnsapi.dll => File is digitally signed
          C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
          C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


          LastRegBack: 2016-08-07 09:20

          ==================== End of FRST.txt ============================

           

          Additional scan result of Farbar Recovery Scan Tool (x64) Version: 14-08-2016
          Ran by [removed] (14-08-2016 20:38:24)
          Running from C:\Users\[removed]\Desktop
          Windows 7 Home Premium Service Pack 1 (X64) (2012-04-19 03:36:53)
          Boot Mode: Safe Mode (with Networking)
          ==========================================================


          ==================== Accounts: =============================

          Administrator (S-1-5-21-3722793996-1674335959-776591757-500 - Administrator - Disabled)
          Guest (S-1-5-21-3722793996-1674335959-776591757-501 - Limited - Disabled)
          HomeGroupUser$ (S-1-5-21-3722793996-1674335959-776591757-1003 - Limited - Enabled)
          JBH (S-1-5-21-3722793996-1674335959-776591757-1001 - Administrator - Enabled) => C:\Users\JBH

          ==================== Security Center ========================

          (If an entry is included in the fixlist, it will be removed.)

          AV: Spybot - Search and Destroy (Disabled - Up to date) {20A26C15-1AF0-7CA3-9380-FAB824A7EE0D}
          AV: AVG AntiVirus Free Edition (Disabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
          AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          AS: Spybot - Search and Destroy (Disabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
          AS: AVG AntiVirus Free Edition (Disabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

          ==================== Installed Programs ======================

          (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

          µTorrent (HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\uTorrent) (Version: 3.4.2.37248 - BitTorrent Inc.)
          Acoustica Effects Pack (HKLM-x32\…\Acoustica Effects Pack) (Version: 1.0 - Acoustica, Inc)
          Acoustica Mixcraft (HKLM-x32\…\Acoustica Mixcraft) (Version:  - Acoustica)
          Acoustica Mixcraft 6 (HKLM-x32\…\Acoustica Mixcraft 6) (Version: b216 - Acoustica)
          Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 15.0.0.356 - Adobe Systems Incorporated)
          Adobe Flash Player 22 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 22.0.0.209 - Adobe Systems Incorporated)
          Adobe Flash Player 22 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
          Akamai NetSession Interface (HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\Akamai) (Version:  - Akamai Technologies, Inc)
          AMD Catalyst Install Manager (HKLM\…\{F37078EA-4B6A-1D6F-6FED-3EDF2117B42C}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
          AMD Quick Stream (HKLM\…\{E9EED4AE-682B-4501-9574-D09A21717599}_is1) (Version: 4.0.0.0 - AppEx Networks)
          Apple Application Support (32-bit) (HKLM-x32\…\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.)
          Apple Application Support (64-bit) (HKLM\…\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.)
          Apple Mobile Device Support (HKLM\…\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
          Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
          Audacity 2.0 (HKLM-x32\…\Audacity_is1) (Version:  - Audacity Team)
          AVG (Version: 16.91.7690 - AVG Technologies) Hidden
          AVG 2016 (Version: 16.0.4627 - AVG Technologies) Hidden
          AVG Protection (HKLM\…\AVG) (Version: 2016.91.7690 - AVG Technologies)
          AVG Web TuneUp (HKLM-x32\…\AVG Web TuneUp) (Version: 4.3.2.18 - AVG Technologies)
          Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
          CameraHelperMsi (x32 Version: 13.51.815.0 - Logitech) Hidden
          Canvas 12 (HKLM-x32\…\{D6160AAA-9E9A-4255-8E41-969129D31094}) (Version: 12.00.1398 - ACD Systems of America Inc.)
          CCleaner (HKLM\…\CCleaner) (Version: 5.20 - Piriform)
          CopyTrans Suite Remove Only (HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\CopyTrans Suite) (Version: 2.36 - WindSolutions)
          CyberGhost 5 (HKLM\…\CyberGhost 5_is1) (Version:  - CyberGhost S.R.L.)
          D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
          Defraggler (HKLM\…\Defraggler) (Version: 2.19 - Piriform)
          Digital Voice Editor 3 (HKLM-x32\…\{6CCC133E-9A2F-4CAA-8866-75D029CD3AB3}) (Version: 3.3.01.11240 - Sony Corporation)
          DriverToolkit version 8.4.0.0 (HKLM-x32\…\{D66BF89F-B0A2-48F5-A2E4-242EB645AB76}_is1) (Version: 8.4.0.0 - Megaify Software)
          Duplicate Cleaner Free 3.2.4 (HKLM-x32\…\Duplicate Cleaner Free) (Version: 3.2.4 - DigitalVolcano Software Ltd) <==== ATTENTION
          EaseUS Todo Backup Free 8.0  (HKLM-x32\…\EaseUS Todo Backup_is1) (Version: 8.0 - CHENGDU YIWO Tech Development Co., Ltd)
          Energy Management (HKLM-x32\…\InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}) (Version: 6.0.2.1 - Lenovo)
          Energy Management (x32 Version: 6.0.2.1 - Lenovo) Hidden
          erLT (x32 Version: 1.20.138.34 - Logitech, Inc.) Hidden
          Express Scribe Transcription Software (HKLM-x32\…\Scribe) (Version: 5.85 - NCH Software)
          FastStone Image Viewer 5.3 (HKLM-x32\…\FastStone Image Viewer) (Version: 5.3 - FastStone Soft)
          FMW 1 (Version: 1.112.3 - AVG Technologies) Hidden
          Foxit PhantomPDF (HKLM-x32\…\{356E39DB-F4F8-4EF7-BFA7-9ABA11E27731}) (Version: 5.5.6.218 - Foxit Corporation)
          Google Chrome (HKLM-x32\…\Google Chrome) (Version: 51.0.2704.106 - Google Inc.)
          Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
          Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
          Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
          HijackThis 2.0.2 (HKLM-x32\…\HijackThis) (Version: 2.0.2 - TrendMicro)
          iCloud (HKLM\…\{724A887F-2B55-4306-B6F9-8F0E7A04B1B5}) (Version: 5.2.2.87 - Apple Inc.)
          IDrive Version - 6.0 (HKLM-x32\…\IDrive_is1) (Version: 6.0 - Pro Softnet Corp)
          iTunes (HKLM\…\{955524E7-79EB-4CA9-BA4D-FD2DF587651B}) (Version: 12.4.3.1 - Apple Inc.)
          Java 8 Update 91 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation)
          Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
          LAME v3.99.3 (for Windows) (HKLM-x32\…\LAME_is1) (Version:  - )
          LastPass (uninstall only) (HKLM-x32\…\LastPass) (Version:  - LastPass)
          Lenovo EasyCamera (HKLM-x32\…\{FC9B811E-39BC-4813-9E29-B83CCF700010}) (Version: 2.16.23.3 - Alcor)
          Lenovo EE Boot Optimizer (HKLM\…\Lenovo EE Boot Optimizer) (Version: 0.0.1.9 - Lenovo)
          Lenovo Games Console (HKLM-x32\…\Lenovo Games Console) (Version: 1.2.6.436 - Oberon Media Inc.)
          Lenovo OneKey Recovery (HKLM-x32\…\InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}) (Version: 7.0.0.2525 - CyberLink Corp.)
          Lenovo OneKey Recovery (Version: 7.0.0.2525 - CyberLink Corp.) Hidden
          Logitech Webcam Software (HKLM-x32\…\{D40EB009-0499-459c-A8AF-C9C110766215}) (Version: 2.51 - Logitech Inc.)
          MagicDisc 2.7.106 (HKLM-x32\…\MagicDisc 2.7.106) (Version:  - )
          Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
          Market Samurai (HKLM-x32\…\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1) (Version: 0.93.42 - Alliance Software Pty Ltd)
          Market Samurai (x32 Version: 0.93.42 - Alliance Software Pty Ltd) Hidden
          Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
          Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
          Microsoft Office 2010 (HKLM-x32\…\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
          Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation)
          Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
          Microsoft SQL Server Compact 3.5 SP2 ENU (HKLM-x32\…\{3A9FC03D-C685-4831-94CF-4EDFD3749497}) (Version: 3.5.8080.0 - Microsoft Corporation)
          Microsoft SQL Server Compact 3.5 SP2 x64 ENU (HKLM\…\{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}) (Version: 3.5.8080.0 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
          Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
          Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
          Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
          Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
          Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
          Mozilla Firefox 47.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 47.0 (x86 en-US)) (Version: 47.0 - Mozilla)
          Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 47.0.0.5999 - Mozilla)
          Mozilla Thunderbird 24.6.0 (x86 en-US) (HKLM-x32\…\Mozilla Thunderbird 24.6.0 (x86 en-US)) (Version: 24.6.0 - Mozilla)
          MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
          MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
          NaturalReaderFree (HKLM-x32\…\{C5E7BF75-007E-44AD-8962-627ED44CB63B}) (Version: 11.9 - NaturalSoft)
          Newnovelist 3 (HKLM-x32\…\{5E0548D2-AA3E-44F9-9BD6-8E6E1337266D}) (Version: 1.1.2 - Lifestyle Toolbox)
          NLP Coach (HKLM-x32\…\{0DFF2C14-7EDF-407E-B506-DAF24880B104}) (Version: 3.5.3 - Evolve Developmental Software)
          OpenOffice.org 3.3 (HKLM-x32\…\{3E171899-0175-47CC-84C4-562ACDD4C021}) (Version: 3.3.9567 - OpenOffice.org)
          Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
          QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
          Ralink RT2860 Wireless LAN Card (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309B0}) (Version: 1.2.0.36 - Ralink)
          Raptr (HKLM-x32\…\Raptr) (Version:  - )
          Realtek Ethernet Controller Driver For Windows 7 (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.21.531.2010 - Realtek)
          Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6358 - Realtek Semiconductor Corp.)
          Realtek USB 2.0 Reader Driver (HKLM-x32\…\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10008 - Realtek Semiconductor Corp.)
          RiyazStudio (HKLM-x32\…\RiyazStudio) (Version: 1.44c - RiyazStudio)
          ScanMaster-ELM 2.0.101.650 DEMO (HKLM-x32\…\ScanMaster-ELM - DEMO_is1) (Version: 2.0.101.650 - WGSoft.de)
          ScanXL Professional (HKLM-x32\…\{2BE87846-415C-4098-A6AE-226931D1C01A}) (Version: 3.5.0 - Palmer Performance Engineering)
          Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
          Skype™ 7.13 (HKLM-x32\…\{6A0549A9-1B96-498C-ACBC-3943001FEB19}) (Version: 7.13.101 - Skype Technologies S.A.)
          Spybot - Search & Destroy (HKLM-x32\…\{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1) (Version: 2.4.40 - Safer-Networking Ltd.)
          SRS Control Panel (HKLM\…\{F3C66EC8-2F33-452D-9CFF-E8C886B3ECC4}) (Version: 1.11.0900 - SRS Labs, Inc.)
          Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 16.2.9.3 - Synaptics Incorporated)
          TAP-Windows 9.9.2 (HKLM\…\TAP-Windows) (Version: 9.9.2 - )
          TaxACT 2012 - 1040 Edition (HKLM-x32\…\TaxACT 2012 - 1040 Edition) (Version:  - 2nd Story Software, Inc.)
          TaxACT 2012 Pennsylvania (HKLM-x32\…\TaxACT 2012 Pennsylvania) (Version:  - 2nd Story Software, Inc.)
          TaxACT 2013 - 1040 Edition (HKLM-x32\…\TaxACT 2013 - 1040 Edition) (Version:  - TaxACT, Inc.)
          TaxACT 2013 Pennsylvania (HKLM-x32\…\TaxACT 2013 Pennsylvania) (Version:  - TaxACT, Inc.)
          TaxACT 2014 - 1040 Edition (HKLM-x32\…\TaxACT 2014 - 1040 Edition) (Version: 1.02 - TaxACT, Inc.)
          TaxACT 2014 Pennsylvania (HKLM-x32\…\TaxACT 2014 Pennsylvania) (Version: 1.01 - TaxACT, Inc.)
          TaxAct 2015 1040 Edition (HKLM-x32\…\TaxAct 2015 1040 Edition) (Version: 1.05 - TaxAct, Inc.)
          TaxAct 2015 Pennsylvania (HKLM-x32\…\TaxAct 2015 Pennsylvania) (Version: 1.03 - TaxAct, Inc.)
          TextPad 7 (HKLM-x32\…\{9F53AC20-2D32-4341-9DA1-29DD40E2199E}) (Version: 7.0.9 - Helios)
          Un-Rar for Windows 9.22beta (HKLM-x32\…\Un-Rar for Windows) (Version:  - )
          UserGuide (HKLM-x32\…\InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}) (Version: 1.0.0.6 - Lenovo)
          UserGuide (x32 Version: 1.0.0.6 - Lenovo) Hidden
          Vegas Movie Studio HD 11.0 (HKLM-x32\…\{6DC79411-858B-11E1-8E7A-F04DA23A5C58}) (Version: 11.0.75 - Sony)
          Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
          Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
          VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.1 - VideoLAN)
          VueScan (HKLM\…\VueScan) (Version:  - )
          Winamp (HKLM-x32\…\Winamp) (Version: 5.666  - Nullsoft, Inc)
          WinDirStat 1.1.2 (HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\WinDirStat) (Version:  - )
          Windows Driver Package - Lenovo (ACPIVPC) System  (12/02/2010 6.1.0.1) (HKLM\…\EA12B1FB53CE4E387C31A85236C41EF559B5E392) (Version: 12/02/2010 6.1.0.1 - Lenovo)
          Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
          Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\…\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
          WinPatrol (HKLM\…\{6A206A04-6BC1-411B-AA04-4E52EDEEADF2}) (Version: 32.0.2014.5 - Ruiware)
          WinRAR 4.20 (32-bit) (HKLM-x32\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
          WinRAR 5.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.20.0 - win.rar GmbH)
          Yahoo! Messenger (HKLM-x32\…\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
          yWriter5 (HKLM-x32\…\yWriter5_is1) (Version:  - Spacejock Software)

          ==================== Custom CLSID (Whitelisted): ==========================

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

          CustomCLSID: HKU\S-1-5-21-3722793996-1674335959-776591757-1001_Classes\CLSID\{8A791F0C-C63C-4EC5-B97F-FBCE74EDBC54}\InprocServer32 -> C:\Program Files (x86)\TextPad 7\System\shellext64.dll (Helios Software Solutions)

          ==================== Scheduled Tasks (Whitelisted) =============

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

          Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
          Task: {2F584210-A17E-40D2-8649-11B20458034B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2016-03-21] (Safer-Networking Ltd.)
          Task: {404A038E-5FDD-4B5A-B1C0-C22EA252811F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate [Argument = -crl -hms -pscn 15]
          Task: {4ACEE298-DFFC-49BE-8D9B-37FECA1673C5} - System32\Tasks\AVG_SYS_TASK_1015av => C:\ProgramData\Avg_Update_1015av\AVG-Secure-Search-Update_1015av.exe [2015-10-11] ()
          Task: {4BB6AAB8-90FC-4817-8601-BD0DE259F9D1} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
          Task: {6CC623E8-79B5-450A-A868-AF92110F7E01} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-15] (Adobe Systems Incorporated)
          Task: {70930575-75B5-4BF8-9717-737C37468E7F} - System32\Tasks\{AFBD4291-3D70-42EC-95E2-625DB45BBCF8} => pcalua.exe -a "C:\Program Files (x86)\InstallShield Installation Information\{D4B060B9-AD4A-4152-9D99-28B93C615AFE}\setup.exe" -c -runfromtemp -l0x0409 -removeonly
          Task: {7FC1E325-D3ED-473B-AE6B-F13B04524D59} - System32\Tasks\0116avUpdateInfo => C:\ProgramData\Avg_Update_0116av\0116av_AVG-Secure-Search-Update.exe [2016-01-10] ()
          Task: {827C6B65-F88A-4189-9364-ECFDA8E67D59} - System32\Tasks\{E2A38420-063F-4D2F-A228-4F590ABDA44B} => C:\Program Files (x86)\Freecorder\Freecorder.exe [2005-04-29] (Applian Technologies Inc.)
          Task: {882A9DB8-A46A-4D54-9A82-3D3F3C38C5DD} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec [Argument = /RestartRecording]
          Task: {9167BFC6-17FA-45E5-B979-3DDAC8003DD3} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-19] (Google Inc.)
          Task: {95E25DE0-CF3C-4D67-ACE0-DCC0686C1D61} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
          Task: {A455474A-70F7-4506-A14B-61B79719F432} - System32\Tasks\avastBCLRestartS-1-5-21-3722793996-1674335959-776591757-1001 => Firefox.exe
          Task: {A6152442-DB26-4D54-B335-A9AFC494F969} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
          Task: {AB46880A-A022-43D8-A5AE-FBB70E7B6EBA} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate [Argument = $(Arg0)]
          Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
          Task: {B73A016B-7321-4FDF-83A6-E1918528ED8D} - System32\Tasks\DSite => C:\Users\JBH\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE [Argument = /Check] <==== ATTENTION
          Task: {BB98D59B-C62C-479F-A7C9-077AF9720B09} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
          Task: {C28909AF-4662-49A4-921C-C30C7593DE8A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-06-19] (Google Inc.)
          Task: {CBBC4101-246C-4C74-8347-A9FE079AEC52} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks
          Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
          Task: {E1BA3EBA-7F51-45DE-BC73-4D6D1BE28623} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
          Task: {E343F98A-BF87-4236-ADA8-1BD0FE3E5640} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2016-03-21] (Safer-Networking Ltd.)
          Task: {E401B40E-20D2-4F14-A3AF-C627A0A71954} - System32\Tasks\AVG_SYS_TASK_0316av_DELETE => C:\ProgramData\Avg_Update_0316av\AVG-Secure-Search-Update_0316av.exe
          Task: {E5A28074-9D12-4D0E-9544-CC7EC6AAD40E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-07-13] (Piriform Ltd)
          Task: {F1B761A0-F4F4-4EA3-8D8B-2566D3611D13} - System32\Tasks\{CD6C5541-4C51-465F-9199-9016A7FFEE8C} => C:\Program Files (x86)\Freecorder\Freecorder.exe [2005-04-29] (Applian Technologies Inc.)
          Task: {F20A17C6-400B-48BB-8B01-94FE27715747} - System32\Tasks\AVG_SYS_TASK_0316av => C:\ProgramData\Avg_Update_0316av\AVG-Secure-Search-Update_0316av.exe
          Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
          Task: {FF2541C2-9E0F-401A-9F3C-8C5401EF27B5} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec [Argument = /StartRecording]

          (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

          Task: C:\windows\Tasks\0116avUpdateInfo.job => C:\ProgramData\Avg_Update_0116av\0116av_AVG-Secure-Search-Update.exe
          Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
          Task: C:\windows\Tasks\AVG_SYS_TASK_0316av.job => C:\ProgramData\Avg_Update_0316av\AVG-Secure-Search-Update_0316av.exe
          Task: C:\windows\Tasks\AVG_SYS_TASK_0316av_DELETE.job => C:\ProgramData\Avg_Update_0316av\AVG-Secure-Search-Update_0316av.exe
          Task: C:\windows\Tasks\AVG_SYS_TASK_1015av.job => C:\ProgramData\Avg_Update_1015av\AVG-Secure-Search-Update_1015av.exe
          Task: C:\windows\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
          Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
          Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

          ==================== Shortcuts =============================

          (The entries could be listed to be restored or removed.)

          Shortcut: C:\Users\JBH\Favorites\NCH Software Download Site.lnk -> hxxp://www.nch.com.au/index.html

          ==================== Loaded Modules (Whitelisted) ==============

          2016-01-26 18:40 - 2015-11-25 14:03 - 00601600 _____ () C:\Program Files (x86)\IDriveWindows\IDContextMenu.dll
          2016-07-15 17:00 - 2016-07-15 17:00 - 19483328 _____ () C:\windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll

          ==================== Alternate Data Streams (Whitelisted) =========

          (If an entry is included in the fixlist, only the ADS will be removed.)


          ==================== Safe Mode (Whitelisted) ===================

          (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"

          ==================== Association (Whitelisted) ===============

          (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


          ==================== Internet Explorer trusted/restricted ===============

          (If an entry is included in the fixlist, it will be removed from the registry.)

          IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
          IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
          IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
          IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
          IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
          IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
          IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
          IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
          IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
          IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
          IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
          IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
          IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
          IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
          IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
          IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
          IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
          IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
          IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
          IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com

          There are 7867 more sites.

          IE trusted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\northwestsavingsbank.com -> hxxps://www.northwestsavingsbank.com
          IE trusted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\wikimedia.org -> hxxps://commons.wikimedia.org
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\007guard.com -> install.007guard.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\008i.com -> 008i.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\008k.com -> www.008k.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\00hq.com -> www.00hq.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\010402.com -> 010402.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\0scan.com -> www.0scan.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\1-2005-search.com -> www.1-2005-search.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\1-domains-registrations.com -> www.1-domains-registrations.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\1000gratisproben.com -> www.1000gratisproben.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\1001namen.com -> www.1001namen.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\100888290cs.com -> mir.100888290cs.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\100sexlinks.com -> www.100sexlinks.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\10sek.com -> www.10sek.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\12-26.net -> user1.12-26.net
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\12-27.net -> user1.12-27.net
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\123fporn.info -> www.123fporn.info
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\123moviedownload.com -> www.123moviedownload.com
          IE restricted site: HKU\S-1-5-21-3722793996-1674335959-776591757-1001\…\123simsen.com -> www.123simsen.com

          There are 7867 more sites.


          ==================== Hosts content: ==========================

          (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

          2012-08-13 23:13 - 2015-11-30 09:01 - 00450028 ___RA C:\windows\system32\Drivers\etc\hosts

          127.0.0.1    localhost127.0.0.1    www.007guard.com
          127.0.0.1    007guard.com
          127.0.0.1    008i.com
          127.0.0.1    www.008k.com
          127.0.0.1    008k.com
          127.0.0.1    www.00hq.com
          127.0.0.1    00hq.com
          127.0.0.1    010402.com
          127.0.0.1    www.032439.com
          127.0.0.1    032439.com
          127.0.0.1    www.0scan.com
          127.0.0.1    0scan.com
          127.0.0.1    1000gratisproben.com
          127.0.0.1    www.1000gratisproben.com
          127.0.0.1    1001namen.com
          127.0.0.1    www.1001namen.com
          127.0.0.1    100888290cs.com
          127.0.0.1    www.100888290cs.com
          127.0.0.1    www.100sexlinks.com
          127.0.0.1    100sexlinks.com
          127.0.0.1    10sek.com
          127.0.0.1    www.10sek.com
          127.0.0.1    www.1-2005-search.com
          127.0.0.1    1-2005-search.com
          127.0.0.1    123fporn.info
          127.0.0.1    www.123fporn.info
          127.0.0.1    123haustiereundmehr.com
          127.0.0.1    www.123haustiereundmehr.com
          127.0.0.1    123moviedownload.com
          127.0.0.1    www.123moviedownload.com

          There are 15464 more lines.


          ==================== Other Areas ============================

          (Currently there is no automatic fix for this section.)

          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\JBH\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
          DNS Servers: [removed] - [removed]
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 0)
          Windows Firewall is enabled.

          ==================== MSCONFIG/TASK MANAGER disabled items ==

          (Currently there is no automatic fix for this section.)

          MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Install LastPass FF RunOnce.lnk => C:\windows\pss\Install LastPass FF RunOnce.lnk.CommonStartup
          MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Install LastPass IE RunOnce.lnk => C:\windows\pss\Install LastPass IE RunOnce.lnk.CommonStartup
          MSCONFIG\startupfolder: C:^Users^JBH^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\windows\pss\Dropbox.lnk.Startup
          MSCONFIG\startupfolder: C:^Users^JBH^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Logitech . Product Registration.lnk => C:\windows\pss\Logitech . Product Registration.lnk.Startup
          MSCONFIG\startupfolder: C:^Users^JBH^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^MagicDisc.lnk => C:\windows\pss\MagicDisc.lnk.Startup
          MSCONFIG\startupfolder: C:^Users^JBH^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OpenOffice.org 3.3.lnk => C:\windows\pss\OpenOffice.org 3.3.lnk.Startup
          MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
          MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
          MSCONFIG\startupreg: ArcSoft MediaImpression Monitor => C:\Program Files (x86)\Kodak\MediaImpression\ArcMonitor.exe
          MSCONFIG\startupreg: CCleaner => "C:\Program Files\CCleaner\CCleaner64.exe" /AUTO
          MSCONFIG\startupreg: Clownfish => "C:\Program Files (x86)\Clownfish\Clownfish.exe"
          MSCONFIG\startupreg: com.apple.dav.bookmarks.daemon => C:\Program Files (x86)\Common Files\Apple\Internet Services\BookmarkDAV_client.exe
          MSCONFIG\startupreg: CyberGhost => "C:\Program Files\CyberGhost 5\CyberGhost.exe" /autostart /min
          MSCONFIG\startupreg: Energy Management => C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe
          MSCONFIG\startupreg: EnergyUtility => C:\Program Files (x86)\Lenovo\Energy Management\Utility.exe
          MSCONFIG\startupreg: Eraser => "C:\Program Files\Eraser\Eraser.exe" -atRestart
          MSCONFIG\startupreg: iCloudDrive => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
          MSCONFIG\startupreg: iCloudServices => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
          MSCONFIG\startupreg: IDrive Background process => "C:\Program Files (x86)\IDriveWindows\id_bglaunch.exe" min
          MSCONFIG\startupreg: IDrive Tray => "C:\Program Files (x86)\IDriveWindows\id_tray.exe" min
          MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
          MSCONFIG\startupreg: LWS => C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe -hide
          MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
          MSCONFIG\startupreg: Raptr => C:\PROGRA~2\Raptr\raptrstub.exe –startup
          MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
          MSCONFIG\startupreg: Spybot-S&D; Cleaning => C:\PROGRAM FILES (X86)\QUICKTIME\QTTask.exe
          MSCONFIG\startupreg: StartCCC => "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
          MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
          MSCONFIG\startupreg: SynTPEnh => %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
          MSCONFIG\startupreg: uTorrent => "C:\Users\JBH\AppData\Roaming\uTorrent\uTorrent.exe"
          MSCONFIG\startupreg: VeriFaceManager => C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
          MSCONFIG\startupreg: YouCam Mirage => "C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe"
          MSCONFIG\startupreg: YouCam Tray => "C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe" /s

          ==================== FirewallRules (Whitelisted) ===============

          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

          FirewallRules: [{A053D0E1-7046-4489-A294-C886C9AB9532}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
          FirewallRules: [{083A73F3-CBA8-4ECA-9EC1-553AD9F7DAFE}] => (Allow) LPort=2869
          FirewallRules: [{0E2EFACB-2346-4E55-BB79-C6CB7BBD3219}] => (Allow) LPort=1900
          FirewallRules: [{8D43DF4D-7D76-487B-95E8-A910C58DBFA5}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
          FirewallRules: [{6434D98F-384B-43A4-99CD-7B12725006D5}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
          FirewallRules: [{569A95D6-68E8-458C-BBB0-F0BBF58E70F8}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
          FirewallRules: [{937D7EB7-B2CB-4ED1-ABFB-4899DF4F25E5}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
          FirewallRules: [{E97A25D1-FC5D-4069-93C1-95A112367EB8}] => (Allow) C:\Program Files (x86)\Yahoo!\Messenger\YahooMessenger.exe
          FirewallRules: [{838ECADB-B1F9-43DB-8301-40DD7393E6C8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{A9111FA8-AE9C-4441-A64E-825AF3626D3F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{E4D7D1DC-0C85-4ECB-B448-DD636E23F5D7}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
          FirewallRules: [{82DFEE54-0D7B-4327-966E-F47B154C59DC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
          FirewallRules: [TCP Query User{E8B4A249-CAD4-484D-B791-8AB19795B1F8}C:\users\jbh\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jbh\appdata\local\akamai\netsession_win.exe
          FirewallRules: [UDP Query User{85251B5F-2E9A-4F6B-A1FC-7995FB88FAD4}C:\users\jbh\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jbh\appdata\local\akamai\netsession_win.exe
          FirewallRules: [TCP Query User{424D26BF-BD8B-40FE-BB57-1DAFC0CE8DDA}C:\users\jbh\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jbh\appdata\local\akamai\netsession_win.exe
          FirewallRules: [UDP Query User{6FD5BFB3-4A8D-4DA5-ABB3-4831479D92C5}C:\users\jbh\appdata\local\akamai\netsession_win.exe] => (Allow) C:\users\jbh\appdata\local\akamai\netsession_win.exe
          FirewallRules: [{94D8153C-68DE-4B63-BB56-CCD7199EA7F5}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
          FirewallRules: [{6DB6ECD6-4AAC-432A-9BE3-2559420ADDA6}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
          FirewallRules: [{854D6B02-CCBA-4640-A6CC-252F1350A5D3}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
          FirewallRules: [{66FEF005-8F76-4C1D-ADEA-807A6E2D8110}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
          FirewallRules: [{C8CD50C2-BBEC-43D8-A896-55FE19092DD8}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
          FirewallRules: [{7E3A66EE-D105-4208-8A1D-47B163145F79}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
          FirewallRules: [{54A43FA6-302A-4B10-9E20-0F686EA03A00}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe
          FirewallRules: [{CCBBC23D-7DDC-4FCA-B5EA-EE2D86BF7827}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
          FirewallRules: [{7C10F1C6-692E-4E68-B3EB-467E2ED03D18}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
          FirewallRules: [{F76A248A-D8C8-4458-8ECB-341B984FDFAF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
          FirewallRules: [{4FE25D26-6BDD-4714-AF2D-F3760C65C67C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
          FirewallRules: [{4F8EE475-C3AE-4103-945F-CE56C867A40A}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
          FirewallRules: [{1908B42E-218C-4F34-B0F7-7BA008E4E086}] => (Allow) C:\Program Files (x86)\Winamp\winamp.exe
          FirewallRules: [{7B304B08-118E-4606-ACF7-B5F04F121F91}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
          FirewallRules: [{31D62256-D2E6-4FD2-B3B0-B5CB646EB6D8}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
          FirewallRules: [{0B643850-FBBC-4513-A2A8-5FDF636696C3}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
          FirewallRules: [{80B38FBC-B11E-43E5-BF84-9320A0185CE3}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
          FirewallRules: [{5342FBDA-59DA-436F-843B-BA9EA21385B1}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{3482C044-C065-4446-B3A1-0966A9D59E55}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{15622C57-4165-4EEE-BF48-5F14AE39DBCC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
          FirewallRules: [{EDFD4F25-5064-4C1A-95CB-6184FEB84D85}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
          FirewallRules: [{8CB17C54-99B4-4751-973C-1BB88CE0E2D1}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
          FirewallRules: [{3D91E4A5-C6CA-4E47-BC51-56C066663FB7}] => (Allow) C:\Program Files (x86)\AVG\Av\avgmfapx.exe
          FirewallRules: [{E548BFE3-BA0D-4FC4-AA02-CCDE0D3099F7}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
          FirewallRules: [{2ACBBB57-BCE0-4FDB-99E2-A51271342B7B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
          FirewallRules: [{F8FA7CC4-3AF7-43C4-B78A-7B4F21F92E1F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          FirewallRules: [{653D4769-3461-475F-959F-04669CD7AD22}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
          FirewallRules: [{536C9F15-19B0-431A-9458-7CB86E9E3C5F}] => (Allow) C:\Program Files (x86)\AVG\Av\avgdiagex.exe
          FirewallRules: [{80880676-33B5-4656-BA9D-2C900300FBC9}] => (Allow) C:\Program Files\iTunes\iTunes.exe
          FirewallRules: [{899BC080-38B9-459B-A74C-3977FC8B802C}] => (Allow) C:\Users\JBH\AppData\Roaming\uTorrent\uTorrent.exe
          FirewallRules: [{EF895C27-5D86-4627-85E8-C5A9FF4AE7EA}] => (Allow) C:\Users\JBH\AppData\Roaming\uTorrent\uTorrent.exe
          StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe] => Enabled:Spybot - Search & Destroy tray access
          StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe] => Enabled:Spybot-S&D; 2 Scanner Service
          StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe] => Enabled:Spybot-S&D; 2 Updater
          StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe] => Enabled:Spybot-S&D; 2 Background update service

          ==================== Restore Points =========================

          07-08-2016 11:37:10 Scheduled Checkpoint
          10-08-2016 22:20:38 Windows Update
          12-08-2016 19:05:09 Restore Operation

          ==================== Faulty Device Manager Devices =============

          Name: Teredo Tunneling Pseudo-Interface
          Description: Microsoft Teredo Tunneling Adapter
          Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
          Manufacturer: Microsoft
          Service: tunnel
          Problem: : This device cannot start. (Code10)
          Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
          On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

          Name: Security Processor Loader Driver
          Description: Security Processor Loader Driver
          Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
          Manufacturer:
          Service: spldr
          Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
          Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
          Devices stay in this state if they have been prepared for removal.
          After you remove the device, this error disappears.Remove the device, and this error should be resolved.


          ==================== Event log errors: =========================

          Application errors:
          ==================
          Error: (08/14/2016 06:05:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
          Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

          Error: (08/14/2016 06:05:40 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
          Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

          Error: (08/14/2016 06:02:30 PM) (Source: WinMgmt) (EventID: 10) (User: )
          Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

          Error: (08/14/2016 05:53:21 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
          Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

          Error: (08/14/2016 05:53:21 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
          Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

          Error: (08/14/2016 05:47:32 PM) (Source: WinMgmt) (EventID: 10) (User: )
          Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

          Error: (08/14/2016 03:30:16 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
          Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.

          Error: (08/14/2016 03:30:16 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
          Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.

          Error: (08/14/2016 03:23:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
          Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

          Error: (08/14/2016 01:20:16 PM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
          Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.


          System errors:
          =============
          Error: (08/14/2016 08:37:57 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
          Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
          %%1068 = The dependency service or group failed to start.

          Error: (08/14/2016 08:37:57 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
          Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
          %%1068 = The dependency service or group failed to start.

          Error: (08/14/2016 08:37:57 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
          Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
          %%1068 = The dependency service or group failed to start.

          Error: (08/14/2016 08:36:21 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
          Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
          %%1068 = The dependency service or group failed to start.

          Error: (08/14/2016 08:36:21 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
          Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
          %%1068 = The dependency service or group failed to start.

          Error: (08/14/2016 08:36:21 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
          Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
          %%1068 = The dependency service or group failed to start.

          Error: (08/14/2016 08:34:27 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
          Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
          %%1068 = The dependency service or group failed to start.

          Error: (08/14/2016 08:34:27 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
          Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
          %%1068 = The dependency service or group failed to start.

          Error: (08/14/2016 08:34:27 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
          Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
          %%1068 = The dependency service or group failed to start.

          Error: (08/14/2016 08:34:01 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
          Description: The Computer Browser service depends on the Server service which failed to start because of the following error:
          %%1068 = The dependency service or group failed to start.


          CodeIntegrity:
          ===================================
            Date: 2016-03-30 23:06:10.846
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_64.dll because the set of per-page image hashes could not be found on the system.

            Date: 2016-03-30 23:05:38.741
            Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Common Files\ATI Technologies\Multimedia\AMDMFTDecoder_64.dll because the set of per-page image hashes could not be found on the system.


          ==================== Memory info ===========================

          Processor: AMD A6-3420M APU with Radeon™ HD Graphics
          Percentage of memory in use: 28%
          Total physical RAM: 5606.11 MB
          Available physical RAM: 4005.07 MB
          Total Virtual: 11210.4 MB
          Available Virtual: 9725.2 MB

          ==================== Drives ================================

          Drive c: () (Fixed) (Total:421.81 GB) (Free:64.29 GB) NTFS
          Drive d: (LENOVO) (Fixed) (Total:29 GB) (Free:5.49 GB) NTFS

          ==================== MBR & Partition Table ==================

          ========================================================
          Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 5DD3F739)
          Partition 1: (Active) - (Size=200 MB) - (Type=07 NTFS)
          Partition 2: (Not Active) - (Size=421.8 GB) - (Type=07 NTFS)
          Partition 3: (Not Active) - (Size=29 GB) - (Type=OF Extended)
          Partition 4: (Not Active) - (Size=14.8 GB) - (Type=12)

          ==================== End of Addition.txt ============================

           

          I tried system restore. Succeeded but did not solve freeze problem. StartUp repair ran for 12 hours and did not repair the problem it detected. I cannot yet locate my windows 7 disc or I might have reinstalled by now. Thanks

          I see markers in your log for uTorrent, if you download any files or programs via any of the torrents your just asking for trouble.

           

          Spybot can cause issues on some systems if it was me I would uninstall it.

           

          You have so many programs loading on start up, you may want to look through them and remove the ones you dont really need from starting up when windows starts

           

           

          Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
          Please copy the entire contents Inside of the code box below beginning with START and ending with END
          (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
          Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
           
          Start
          CloseProcesses:
          CreateRestorePoint:
          CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
          HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
          HKU\S-1-5-21-3722793996-1674335959-776591757-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid={27DA12F0-F8DD-4EF9-B9E6-24B7D0F10108}&mid=f4cb15fd776347cdae952197b704771a-55b295471c69335542e9e8eb1ad090025cf084ef&lang=en&ds=AVG&coid=avgtbavg&cmpid=0616av&pr=fr&d=2016-06-08 14:39:58&v=4.3.1.831&pid=wtu&sg=&sap=hp
          SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
          SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=LENDF8&pc=MALN&src=IE-SearchBox
          SearchScopes: HKU\S-1-5-21-3722793996-1674335959-776591757-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={27DA12F0-F8DD-4EF9-B9E6-24B7D0F10108}&mid=f4cb15fd776347cdae952197b704771a-55b295471c69335542e9e8eb1ad090025cf084ef&lang=en&ds=AVG&coid=avgtbavg&cmpid=0616av&pr=fr&d=2016-06-08 14:39:58&v=4.3.1.831&pid=wtu&sg=&sap=dsp&q={searchTerms}
          FF DefaultSearchEngine: AVG Secure Search
          CHR DefaultSearchKeyword: Default -> lp
          2016-08-03 10:16 - 2016-08-14 13:44 - 00000000 ____D C:\Users\JBH\Downloads\Ambient Torrent 2
          2016-08-14 13:50 - 2014-08-19 15:37 - 00000000 ____D C:\Users\JBH\AppData\Roaming\uTorrent
          Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
          Task: {2F584210-A17E-40D2-8649-11B20458034B} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe [2016-03-21] (Safer-Networking Ltd.)
          Task: {4BB6AAB8-90FC-4817-8601-BD0DE259F9D1} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
          Task: {95E25DE0-CF3C-4D67-ACE0-DCC0686C1D61} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
          Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
          Task: {B73A016B-7321-4FDF-83A6-E1918528ED8D} - System32\Tasks\DSite => C:\Users\JBH\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE [Argument = /Check] <==== ATTENTION
          Task: {BB98D59B-C62C-479F-A7C9-077AF9720B09} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
          Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
          Task: {E1BA3EBA-7F51-45DE-BC73-4D6D1BE28623} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe [2014-06-27] (Safer-Networking Ltd.)
          Task: {E343F98A-BF87-4236-ADA8-1BD0FE3E5640} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe [2016-03-21] (Safer-Networking Ltd.)
          Task: C:\windows\Tasks\DriverToolkit Autorun.job => C:\Program Files (x86)\DriverToolkit\DriverToolkit.exe
          FirewallRules: [{899BC080-38B9-459B-A74C-3977FC8B802C}] => (Allow) C:\Users\JBH\AppData\Roaming\uTorrent\uTorrent.exe
          FirewallRules: [{EF895C27-5D86-4627-85E8-C5A9FF4AE7EA}] => (Allow) C:\Users\JBH\AppData\Roaming\uTorrent\uTorrent.exe
          CMD: ipconfig /flushdns
          Hosts:
          EmptyTemp:
          Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
          Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
          End
          
           
          NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

          I have used bit torrent for file sharing for years without much problem. I do want to purchase or otherwise use good protection and to be diligent. I am making some changes. But regarding the freeze problem. I upgraded from Windows 7 to Windows 10 and this seems to have solved the problem. Should I do more scans?

          Hi,
           
          You will love Windows 10, its so much secure than its predecessors, I have had it since day one and never had one problem. Windows 10 has Windows Defender built in and its smarter and stronger now, its what i use in lieu of having to purchase or use a free AV.  I also have the Premium version of Malwarebytes, the Premium version blocks known bad websites from loading. I also use Malwarebytes Anti Exploit , no scans to run with this one , it just sits in the background preventing most malware programs from installing.  Both of these programs are very reasonable, there all I use on my system and doing what I do I have been just fine. But whether you want to look into them is totally up to you.

           

          In case you need it

           

          https://www.malwarebytes.com/products/

           

           

          As far as the torrents, its your system, I cant tell you what to do I can just advise. Most Malware Removal forums will ask you to uninstall it prior to the cleaning, on this forum its kind of up to the helper. The theory is that you may have infected yourself using the torrents and after a helper spending time analyziing your logs and working up fixes , it makes no sense to keep using the torrents and get infected again then all our work will have been in vain. 

           

           

          You may want to keep a handle on any programs that you download and install from starting when windows starts. I know most programs do need to start like Malwarebytes and your AV for example but some can just be started when you need them. The less you have starting up the less system resouces are used.

           

          As far as seeing another log, I really didnt see any malware on your system so I dont think I need to see one.  If you feel you do let me know and I will post the instructions again.

           

           

          Ken :)

          Ask AI

          AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

          Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI