This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer acting odd

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, Lately my PC has been running slow and has an occasion freeze up on start up. I'm not sure whats going on. Below is the result of the scans I ran. Any help would be appreciated. Thanks

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-09-04 05:32:25
—————————–
05:32:25.384    OS Version: Windows x64 6.2.9200 
05:32:25.384    Number of processors: 8 586 0x1A05
05:32:25.385    ComputerName: ERIC-PC  UserName: Eric
05:32:26.592    Initialize success
05:32:26.667    VM: initialized successfully
05:32:26.668    VM: Intel CPU supported 
05:32:48.530    VM: disk I/O storahci.sys
05:36:40.279    The log file has been saved successfully to "C:\Users\Eric\Desktop\what the tech\aswMBR.txt"
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016
Ran by [removed] (administrator) on ERIC-PC (04-09-2016 05:40:06)
Running from C:\Users\[removed]\Desktop\what the tech
[removed]
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Broadcom Corp.) C:\Program Files\Broadcom\BPowMon\BPowMon.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Memeo) C:\Program Files (x86)\Seagate\Seagate Dashboard\SeagateDashboardService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
() C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
() C:\Program Files\GoPro\GoPro Desktop App\GoProDesktopSystemTray.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCServiceController.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienwareAlienFXController.exe
(Alienware) C:\Program Files\Alienware\Command Center\ThermalController.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher32.exe
(Alienware) C:\Program Files\Alienware\Command Center\AWCCApplicationWatcher64.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionService.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVaultWiz.exe
(Alienware) C:\Program Files\Alienware\Command Center\AlienFusionController.exe
() C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe
(Dell Inc.) C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe
(Dell Inc.) C:\Program Files\Dell\DellDataVault\DellDataVault.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
(AOL Inc.) C:\Program Files (x86)\Common Files\AOL\1296124505\ee\aolsoftware.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.8.2\waol.exe
(AOL Inc.) C:\Program Files (x86)\AOL Desktop 9.8.2\shellmon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 31-08-2016
Ran by [removed] (04-09-2016 05:40:59)
Running from C:\Users\[removed]\Desktop\what the tech
Windows 10 Pro Version 1511 (X64) (2015-12-10 18:15:46)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1685030488-3750137779-1738601272-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1685030488-3750137779-1738601272-503 - Limited - Disabled)
Eric (S-1-5-21-1685030488-3750137779-1738601272-1001 - Administrator - Enabled) => C:\Users\Eric
Guest (S-1-5-21-1685030488-3750137779-1738601272-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1685030488-3750137779-1738601272-1006 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Flash Player 22 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 22.0.0.209 - Adobe Systems Incorporated)
Adobe Reader XI (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.00 - Adobe Systems Incorporated)
Alienware Command Center (HKLM-x32\…\InstallShield_{ACBE8264-9018-49B8-9041-3A74E2596BF3}) (Version: 2.8.9.0 - Alienware Corp.)
Alienware Command Center (Version: 2.8.9.0 - Alienware Corp.) Hidden
AMD Catalyst Control Center (HKLM-x32\…\WUCCCApp) (Version: 1.00.0000 - AMD)
AMD Catalyst Install Manager (HKLM\…\{66AFB595-BC05-2913-7696-6D58F9B733E1}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.)
Ancestry World Archives Project - Keying Tool (HKLM-x32\…\{2CF35B35-BD8A-4DC0-8916-F028D4B58DF8}) (Version: 1.1.0096 - Ancestry.com)
AOL Toolbar (HKLM-x32\…\AOL Toolbar) (Version:  - AOL Inc.)
AOL Toolbar (HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\AOL Toolbar) (Version:  - )
AOL Uninstaller (Choose which Products to Remove) (HKLM-x32\…\AOL Uninstaller) (Version:  - AOL Inc.)
Apple Application Support (32-bit) (HKLM-x32\…\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
ArcSoft MediaImpression (HKLM-x32\…\{A4646CC8-905B-4E6D-A094-4C9FB1621042}) (Version: 1.2.26.429 - ArcSoft)
ATI AVIVO64 Codecs (Version: 11.6.0.10627 - ATI Technologies Inc.) Hidden
ATI Catalyst Registration (x32 Version: 3.00.0000 - ATI Technologies Inc.) Hidden
Body Tracker (HKLM-x32\…\{20B707DD-CD6C-40FD-9625-4C0EA5334BB3}) (Version: 6.30.0000 - Linear Software)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Broadcom Management Programs (HKLM\…\{688758A2-8520-4470-8FA6-765BAC86FC53}) (Version: 12.53.01 - Broadcom Corporation)
Catalyst Control Center (HKLM-x32\…\{8B1A559A-FB9D-42F5-A8A7-2F132CF28414}) (Version: 1.00.0000 - )
CRMsphere Office Plugin 9.0 (HKLM-x32\…\{4DB971D3-C279-4FC9-9766-7F2D6951DD44}) (Version:  - )
CRMsphere ReportViewer (HKLM-x32\…\{0560D17F-5F7B-4251-975F-542726D6D0DD}) (Version:  - )
Dell Data Vault (Version: 4.3.5.1 - Dell Inc.) Hidden
Dell InHome Service Agreement (HKLM-x32\…\{41AA8F20-FD30-4878-9080-6D5BE575FD41}) (Version: 2.0.0 - Dell Inc.)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.3.6817.133 - Dell)
Dell SupportAssistAgent (HKLM-x32\…\{287348C8-8B47-4C36-AF28-441A3B7D8722}) (Version: 1.1.1.14 - Dell)
DirectX 9 Runtime (x32 Version: 1.00.0000 - Sonic Solutions) Hidden
Download Updater (AOL Inc.) (HKLM-x32\…\SoftwareUpdUtility) (Version:  - AOL Inc.) <==== ATTENTION
Dropbox (HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\Dropbox) (Version: 2.0.26 - Dropbox, Inc.)
EaseUS Data Recovery Wizard Free Edition 5.5.1 (HKLM-x32\…\EaseUS Data Recovery Wizard Free Edition 5.5.1_is1) (Version:  - EaseUS)
Easy Phone Sync (HKLM-x32\…\{02007371-F011-4016-A664-ED99890331AB}) (Version: 63 - Media Mushroom Limited)
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
Family Tree Maker 2011 (HKLM-x32\…\Family Tree Maker 2011) (Version: 20.0.368 - Ancestry.com)
Family Tree Maker 2011 (x32 Version: 20.0.368 - Ancestry.com) Hidden
Garmin Communicator Plugin (HKLM-x32\…\{17079027-EB8A-42C6-9BF8-825B78889F6A}) (Version: 4.0.1 - Garmin Ltd or its subsidiaries)
Garmin Communicator Plugin x64 (HKLM\…\{EB418DDD-5365-4381-87F6-D8BBB21CC1CA}) (Version: 4.0.1 - Garmin Ltd or its subsidiaries)
Garmin USB Drivers (HKLM-x32\…\{510D2239-6C2E-457B-9590-485EC552D94D}) (Version: 2.3.0.0 - Garmin Ltd or its subsidiaries)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 52.0.2743.116 - Google Inc.)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
GoPro (Version: 0.1.2733 - GoPro, Inc.) Hidden
GoPro for Desktop (HKLM-x32\…\{88734dc7-c200-4ad3-b29f-bb5e436cb30f}) (Version: 1.4.0.2733 - GoPro, Inc.)
GoPro Studio (x32 Version: 5.9.2733 - GoPro, Inc.) Hidden
HydraVision (x32 Version: 4.2.208.0 - ATI Technologies Inc.) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden <==== ATTENTION
iTunes (HKLM\…\{E109B4A3-9883-4E6E-9A19-4D7E1A88AFE8}) (Version: 12.4.2.4 - Apple Inc.)
Java 8 Update 101 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F32180101F0}) (Version: 8.0.1010.13 - Oracle Corporation)
Lorex Auto Port Forwarding (HKLM-x32\…\Lorex Auto Port Forwarding) (Version: 1.4.2 - Lorex Technology Powered By PcWinTech.com)
Lorex Client 10 (HKLM-x32\…\Lorex Client) (Version: 10 - )
Lorex Player10 1.0.1.14 (HKLM-x32\…\Lorex Player10) (Version: 1.0.1.14 - )
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Memeo Instant Backup (HKLM-x32\…\{8E666407-AC41-46a2-9692-6C7BFCBFDD37}) (Version: 4.60.0.7876 - Memeo Inc.)
Microsoft LifeCam (HKLM\…\{8EC9E7BB-2443-49B1-8476-490EBF932C2E}) (Version: 4.25.512.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.5.166.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office Enterprise 2007 (HKLM-x32\…\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office XP Web Components (HKLM-x32\…\{90260409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6619.0 - Microsoft Corporation)
Microsoft Primary Interoperability Assemblies 2005 (HKLM-x32\…\{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.41105.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\…\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}) (Version: 8.0.58299 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\…\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{820B6609-4C97-3A2B-B644-573B06A0F0CC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\…\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
OpenAL (HKLM-x32\…\OpenAL) (Version:  - )
Photo Explosion Album SE (HKLM-x32\…\{822944D4-BC5D-44AE-9315-16C174D318B0}) (Version: 4.0.2.10 - Nova Development)
PhotoShowExpress (x32 Version: 2.0.028 - Sonic Solutions) Hidden
ProTrack 2008 (HKLM-x32\…\{2305226F-5F9B-408A-A149-C76E64144DD2}) (Version: 8.00.1000 - DakotaFit Software)
Raptr (HKLM-x32\…\Raptr) (Version: 5.1.2-r111396-release - Raptr, Inc)
RBVirtualFolder64Inst (Version: 1.00.0000 - Roxio, Inc.) Hidden
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Roxio Burn (HKLM-x32\…\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.8.57.4 - Roxio)
Roxio Creator Starter (HKLM-x32\…\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.40.0 - Roxio)
Roxio File Backup (Version: 1.3.2 - Roxio) Hidden
SafeHouse Explorer 3.01 (HKLM-x32\…\SafeHouseExplorer) (Version: 3.01.00.1 - PC Dynamics, Inc.)
Seagate Dashboard (HKLM-x32\…\{C3A11907-930D-41AC-A135-CC3B12F92011}) (Version: 1.1.0.1421 - Memeo Inc.)
Skype Click to Call (HKLM-x32\…\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 8.3.0.9150 - Microsoft Corporation)
Skype™ 7.26 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
Snip (HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\{525d439e-e22a-4221-8fd1-25b845fe0038}) (Version: 0.1.5119.0 - Microsoft Corporation)
Snip (x32 Version: 0.1.5119.0 - Microsoft) Hidden
Sonic CinePlayer Decoder Pack (x32 Version: 4.3.0 - Sonic Solutions) Hidden
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 11 (HKLM-x32\…\TeamViewer) (Version: 11.0.59518 - TeamViewer)
THX TruStudio PC (HKLM-x32\…\{010A785B-F920-4350-821B-6309909C20BB}) (Version: 1.0 - Creative Technology Limited)
TomTom HOME (HKLM-x32\…\{5DCB2EB3-87AD-426E-8D74-8B92C9D731C4}) (Version: 2.9.8 - TomTom)
TomTom HOME Visual Studio Merge Modules (HKLM-x32\…\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
VFW_Codec32 (x32 Version: 0.1.160.0 - GoPro, Inc.) Hidden
VFW_Codec64 (Version: 0.1.160.0 - GoPro, Inc.) Hidden
Viewpoint Media Player (HKLM-x32\…\ViewpointMediaPlayer) (Version:  - )
WebEx (HKLM-x32\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Windows Driver Package - Garmin (grmnusb) GARMIN Devices  (06/03/2009 2.3.0.0) (HKLM\…\49CF605F02C7954F4E139D18828DE298CD59217C) (Version: 06/03/2009 2.3.0.0 - Garmin)
Windows Driver Package - OEM (mr8980) Image  (07/02/2010 1.0.0.0) (HKLM\…\20F0C2E01A2738D42AF045B4204926E265FF40DE) (Version: 07/02/2010 1.0.0.0 - OEM)
Windows Media Encoder 9 Series (HKLM-x32\…\Windows Media Encoder 9) (Version:  - )
Windows Movie Maker 2.6 (HKLM-x32\…\{B3DAF54F-DB25-4586-9EF1-96D24BB14088}) (Version: 2.6.4037.0 - Microsoft Corporation)
Wireless Monitoring System (HKLM-x32\…\InstallShield_{1E6679EB-C736-40E6-A1E5-F97F69A096E3}) (Version: 1.00.0000 - MR8980)
Wireless Monitoring System (x32 Version: 1.00.0000 - MR8980) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1685030488-3750137779-1738601272-1001_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Eric\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1685030488-3750137779-1738601272-1001_Classes\CLSID\{71DCE5D6-4B57-496B-AC21-CD5B54EB93FD}\localserver32 -> C:\Users\Eric\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\FileCoAuth.exe (Microsoft Corporation)
CustomCLSID: HKU\S-1-5-21-1685030488-3750137779-1738601272-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1685030488-3750137779-1738601272-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1685030488-3750137779-1738601272-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-1685030488-3750137779-1738601272-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.19.dll (Dropbox, Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0251BDCA-6B96-4E9A-9726-2EFC3D55EB9F} - System32\Tasks\{E26093F2-71B3-4132-A279-5DC1BAC7AAEB} => C:\Users\Eric\Desktop\Eric\avira_antivir_personal_en.exe
Task: {07771C41-5354-4ACD-8B34-E739D5C4A8B9} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {08304B64-6F67-4710-BD90-DC5CFE7FE251} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {0C76897A-7841-4A5C-A653-46559D7FF9C2} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {0D08CCF0-B33E-481B-AD36-19145FC90877} - System32\Tasks\Optimize Push Notification Data File-S-1-5-21-1685030488-3750137779-1738601272-1001
Task: {1292DEE4-C1EB-4AA5-99C4-B9A4016784A6} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files (x86)\Dell\SupportAssistAgent\bin\SupportAssist.exe [2015-09-30] (Dell Inc.)
Task: {15156DA7-9894-425D-91B0-C63EE5FB3098} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {1522C444-0F53-4477-AE1F-C3A330DB8AA3} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {17E6973C-31AE-4716-8B6C-95E3F8B9A22D} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {1CB699FE-1F9E-4A7A-9F24-2B59043987FF} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2015-07-08] (Microsoft Corporation)
Task: {1E442312-A91E-4264-AEBF-BE6215DFA3F8} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Alienware\SupportAssist\sessionchecker.exe [2016-08-02] (PC-Doctor, Inc.)
Task: {21B262D8-80A0-4FCC-BC01-EF54D2D082FE} - System32\Tasks\{EE708ACE-9825-4008-8324-88554041923F} => pcalua.exe -a C:\Users\Eric\Desktop\avira_antivir_personal_en.exe -d C:\Users\Eric\Desktop
Task: {23A3F1BC-F9A9-4BF2-82B5-E2C3917C4960} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {2765A58A-693B-4421-B6F7-4A23088399ED} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {2FD9A600-9C92-4830-9542-3F90254D0E57} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {3746DF00-B783-4882-9218-C063F7F31B4D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {3E606981-410E-4917-A62F-F19C5C594F38} - System32\Tasks\Adobe Flash Player Updater => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-12] (Adobe Systems Incorporated)
Task: {401E2FD6-B9FD-459B-B1B0-E424C8718B4F} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {48A00DAD-845B-4FA4-BB5F-857FA91D89D6} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {525E503F-6D1C-489F-8C80-47FA1C74A9F5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {52B45B97-EA75-45B7-8810-0D4AD5C23610} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {5453D445-FE2E-4A27-B4F8-6D1C7D58332E} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1685030488-3750137779-1738601272-1001Core => C:\Users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {5D35EE07-B37D-4D96-8540-384D7C911166} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {60AE47AF-7EDF-4926-B3DE-7247C29AB170} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {61DD05B5-C280-4B48-A130-926548F27025} - System32\Tasks\{57383FC8-97D1-497C-91F8-F2AE101027E3} => pcalua.exe -a C:\Users\Eric\Desktop\Eric\avira_antivir_personal_en.exe -d C:\Users\Eric\Desktop\Eric
Task: {6435FA0C-0DD2-48A6-8F71-453CC82CE604} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {66F7F15D-5D0C-4690-AA19-F9E66C90B682} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {68B15FC9-B308-4A60-8D7F-32BF1AC7FCE7} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-08-11] (Microsoft Corporation)
Task: {6971C92A-7714-4514-8466-3D3712E283F8} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2015-07-08] (Microsoft Corporation)
Task: {70A2E464-1117-4A75-B937-E29732846BAD} - System32\Tasks\{014CF6DD-7473-4777-A7F9-B1FA38067140} => pcalua.exe -a D:\setup.exe -d D:\
Task: {7979F36D-4F9C-494F-94E6-EB776BE47E33} - System32\Tasks\PCDDataUploadTask => uaclauncher.exe
Task: {7D92229F-349D-43A6-BC7F-7B998D402BB7} - System32\Tasks\{8767F0DF-13C6-4A44-B277-1F28E3D8BD12} => C:\Users\Eric\Desktop\Eric\avira_antivir_personal_en.exe
Task: {82A83C02-F7E2-4BA6-A85E-F5C155CBD6BB} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {8AC20CE3-8F95-4846-831B-19BFECE5D2C3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {8F2D0142-5415-459D-91D3-C959B8858EC4} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\Alienware\SupportAssist\uaclauncher.exe [2016-08-02] (PC-Doctor, Inc.)
Task: {9348EDE7-DD4D-4BA4-A43E-F9E7EED1E2E3} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {99AC33DA-F02F-4117-AE29-499215DC867D} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {A2D918E5-7B77-4D4B-BCB9-DBAFA9CC7758} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {A774A864-4870-414D-A582-099E9BCB6DFA} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {A7AF381C-46E4-44F8-BC03-2ECB81547784} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {AA04121B-EA96-43F5-ADAC-1C3FB51B92A0} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {B15FFDD0-AF10-4A5B-B297-10F995E4DEDA} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2015-07-08] (Microsoft Corporation)
Task: {B48A728F-198B-4327-B10A-9C7286029B54} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {B8B47147-EB70-422D-8B34-889750B1DED4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1685030488-3750137779-1738601272-1001UA => C:\Users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {BE1D0C9B-91BF-47F1-9500-4C5069618705} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {C0DEFB82-2DB7-4FB1-A134-3900BEF632EB} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {C908AE6A-C1EB-453F-BD58-3F07018E4361} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2015-07-08] (Microsoft)
Task: {D0808545-E431-4778-8C1C-DEF980C29D40} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2015-07-08] (Microsoft Corporation)
Task: {D171B41B-AF87-423D-89A6-FFFD21155C18} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {D20F308A-1AC2-4AE5-A3A8-F08B0D462BF4} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {D4659594-5823-4E9F-83F7-1D9E932FD353} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {E30B7AD2-01B2-4E15-A323-0B48CDA87C33} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {E960A7B4-EDEA-4965-94E1-0D3979D8A140} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {EB9DF709-45D6-4728-9E97-839D61DB9CF3} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {EBB3019A-60C5-4A5F-B593-07E9A1FFF5FA} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {EE98AAA2-8CC0-4910-8F53-40F20F5480BE} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {EEF04CF7-A720-436E-B75D-0040F07C7F0A} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {EF2CC2C3-4E0A-4BDD-9496-B6C8930C9EA3} - System32\Tasks\{96199D7A-5B39-48C7-9E8F-6DC0F8CD9FE6} => C:\Program Files (x86)\Windows Live\Photo Gallery\MovieMaker.exe
Task: {F9ABE033-D018-49A6-86BD-7EC2D153119C} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\WINDOWS\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1685030488-3750137779-1738601272-1001Core.job => C:\Users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-1685030488-3750137779-1738601272-1001UA.job => C:\Users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\Eric\AppData\Local\Microsoft\Windows\RoamingTiles\18296756730.lnk -> hxxp://www.linkedin.com/home
 
ShortcutWithArgument: C:\Users\Eric\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\18296756730.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -pinnedSite -contentTile -formatVersion 0x00000002 -pinnedTimeLow 0x5ee91793 -pinnedTimeHigh 0x01ce14e1 -securityFlags 0x00000000 -url 0x0000001c hxxp://www.linkedin.com/home
ShortcutWithArgument: C:\Users\Eric\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\9176798760.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -pinnedSite -contentTile -formatVersion 0x00000002 -pinnedTimeLow 0x59065024 -pinnedTimeHigh 0x01ce14e6 -securityFlags 0x00000000 -url 0x00000019 hxxps://www.facebook.com/
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-10-30 03:17 - 2015-10-30 03:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll
2015-10-30 03:18 - 2015-10-30 03:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-03-18 22:56 - 2016-03-18 22:56 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-07-05 15:23 - 2016-07-05 15:23 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-07-13 04:21 - 2016-07-01 00:48 - 02656408 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-07-13 04:21 - 2016-07-01 00:48 - 02656408 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2016-04-19 05:54 - 2016-04-19 05:54 - 00144384 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeHost.exe
2015-12-18 09:17 - 2015-12-07 00:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-07-13 04:22 - 2016-06-30 23:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-07-13 04:23 - 2016-06-30 23:49 - 00674816 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\MtcUvc.dll
2016-07-13 04:21 - 2016-06-30 23:27 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-07-13 04:21 - 2016-06-30 23:21 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2016-07-13 04:21 - 2016-06-30 23:22 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-07-13 04:21 - 2016-06-30 23:24 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-05-12 00:39 - 2016-05-12 00:39 - 01088944 _____ () C:\Program Files\GoPro\GoPro Desktop App\GoProDesktopSystemTray.exe
2016-05-12 00:39 - 2016-05-12 00:39 - 00037808 _____ () C:\Program Files\GoPro\GoPro Desktop App\GoProDeviceDetection.exe
2016-04-19 05:54 - 2016-04-19 05:54 - 00141312 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkypeBackgroundTasks.dll
2016-04-19 05:54 - 2016-04-19 05:54 - 22284800 _____ () C:\Program Files\WindowsApps\Microsoft.Messaging_2.15.20002.0_x86__8wekyb3d8bbwe\SkyWrap.dll
2015-12-15 12:14 - 2015-12-15 12:14 - 00048640 _____ () C:\Program Files (x86)\AOL Desktop 9.8.2\zlib.dll
2015-12-15 12:14 - 2015-12-15 12:14 - 21151232 _____ () C:\Program Files (x86)\AOL Desktop 9.8.2\libcef.dll
2015-12-15 12:14 - 2015-12-15 12:14 - 00648704 _____ () C:\Program Files (x86)\AOL Desktop 9.8.2\libglesv2.dll
2015-12-15 12:14 - 2015-12-15 12:14 - 00122880 _____ () C:\Program Files (x86)\AOL Desktop 9.8.2\libegl.dll
2016-08-11 14:42 - 2016-08-02 20:24 - 01771336 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libglesv2.dll
2016-08-11 14:42 - 2016-08-02 20:23 - 00094024 _____ () C:\Program Files (x86)\Google\Chrome\Application\52.0.2743.116\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\dell.com -> dell.com
IE trusted site: HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\gbc.com -> hxxps://service.gbc.com
IE trusted site: HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\kronos.net -> hxxps://accobrands.kronos.net
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2012-10-23 04:50 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
127.0.0.1       localhost
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Eric\AppData\Roaming\Microsoft\Windows Photo Viewer\Windows Photo Viewer Wallpaper.jpg
DNS Servers: 10.1.10.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
MSCONFIG\Services: iphlpsvc => 2
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: Adobe Reader Speed Launcher => "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
MSCONFIG\startupreg: AOL Fast Start => "C:\Program Files (x86)\AOL Desktop 9.6\AOL.EXE" -b
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\oem\Roxio Burn\RoxioBurnLauncher.exe"
MSCONFIG\startupreg: EEventManager => C:\PROGRA~2\EPSONS~1\EVENTM~1\EEVENT~1.EXE
MSCONFIG\startupreg: Google Update => "C:\Users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: GrooveMonitor => "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
MSCONFIG\startupreg: HostManager => C:\Program Files (x86)\Common Files\AOL\1296124505\ee\AOLSoftware.exe
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: LifeCam => "C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe"
MSCONFIG\startupreg: MobileDocuments => C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM\…\StartupApproved\Run: => "iTunesHelper"
HKLM\…\StartupApproved\Run32: => "Adobe ARM"
HKLM\…\StartupApproved\Run32: => "APSDaemon"
HKLM\…\StartupApproved\Run32: => "ATICustomerCare"
HKLM\…\StartupApproved\Run32: => "StartCCC"
HKLM\…\StartupApproved\Run32: => "iTunesHelper"
HKLM\…\StartupApproved\Run32: => "LifeCam"
HKLM\…\StartupApproved\Run32: => "QuickTime Task"
HKLM\…\StartupApproved\Run32: => "THX Audio Control Panel"
HKLM\…\StartupApproved\Run32: => "HostManager"
HKLM\…\StartupApproved\Run32: => "ArcSoft Connection Service"
HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\StartupApproved\Run: => "ApplePhotoStreams"
HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\StartupApproved\Run: => "AOL Fast Start"
HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\StartupApproved\Run: => "HydraVisionDesktopManager"
HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\StartupApproved\Run: => "EPSON WorkForce 600 Series"
HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\StartupApproved\Run: => "TomTomHOME.exe"
HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\…\StartupApproved\Run: => "Snip"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{63DE113A-A65D-4646-9913-3070C3B20789}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.8.1\waol.exe
FirewallRules: [{34E47021-98C3-4520-A812-7F28E2910FD1}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.8.1\waol.exe
FirewallRules: [{97CAD054-FFF7-4D17-84C8-44DE8EB99973}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{A4CF3338-BCEA-42D6-A592-890FA3614677}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe
FirewallRules: [{DE92C1EC-A405-4106-9330-D8E28EB53F5F}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{CB560150-8921-458F-ADF7-9761012F4D2D}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe
FirewallRules: [{D85C464A-028E-4CC7-943A-BF5D404F2A76}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.8.0\waol.exe
FirewallRules: [{409F25F2-8A42-42AA-8272-C3A1187C186B}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.8.0\waol.exe
FirewallRules: [{0A6D8B23-9E0F-4647-AEF2-A0DC2AB26CD4}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CBD3ADEB-FA89-41AD-B037-F4E127E72E96}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{9519CFB4-AA0D-4A1E-BEF6-34D3C7792F49}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{A7031D64-37B9-444C-8DE7-7E41FC2F1F46}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2403821D-C777-4A86-9644-1FE18C4A565D}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLDial.exe
FirewallRules: [{21E85D47-79D2-4CBE-9844-FA45488C5154}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLDial.exe
FirewallRules: [{4A51836E-DE44-4919-B36B-E2E9EB5343C0}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
FirewallRules: [{7B77AE78-0D08-4CB8-871E-3A3146FCE02C}] => (Allow) C:\Program Files (x86)\Common Files\AOL\acs\AOLacsd.exe
FirewallRules: [{9CD81F45-AFF0-4CB8-BC6D-CF10C86107CE}] => (Allow) C:\Program Files (x86)\Common Files\AOL\1296124505\ee\aolsoftware.exe
FirewallRules: [{653E181E-56B2-4AA2-8DC6-31F74AAE0850}] => (Allow) C:\Program Files (x86)\Common Files\AOL\1296124505\ee\aolsoftware.exe
FirewallRules: [{16D8CC33-D131-4596-8F19-6B87100282C5}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7a\waol.exe
FirewallRules: [{CC1AFC75-6955-475E-ABB3-3FE990DA226C}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7a\waol.exe
FirewallRules: [{0E6DBBBD-E4C4-4411-88C9-095DDD96A29D}] => (Allow) C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe
FirewallRules: [{0D845DC7-E63A-4C92-9918-B46D8AEE908F}] => (Allow) C:\Program Files (x86)\Common Files\AOL\Loader\aolload.exe
FirewallRules: [{6F061730-956D-4C65-ABAD-4947BA068F41}] => (Allow) C:\Program Files (x86)\Common Files\AOL\System Information\sinf.exe
FirewallRules: [{6E6290ED-9986-4727-A5D2-8FBB88120F92}] => (Allow) C:\Program Files (x86)\Common Files\AOL\System Information\sinf.exe
FirewallRules: [{C38595B5-11BB-4D67-924E-AB8019617AFC}] => (Allow) C:\Program Files (x86)\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{83568A36-F4EF-4431-85B5-A70602069A7F}] => (Allow) C:\Program Files (x86)\Common Files\AOL\TopSpeed\3.0\aoltpsd3.exe
FirewallRules: [{51EBBD95-0CE8-4D37-87FB-087FA892D043}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7a\AOLBrowser\aolbrowser.exe
FirewallRules: [{5498BEC2-0E14-4D9D-AC08-D9F46B249767}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7a\AOLBrowser\aolbrowser.exe
FirewallRules: [TCP Query User{A1FAECC2-3B10-48EC-B24C-0938323B0579}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe
FirewallRules: [UDP Query User{F276A38B-C7CB-4888-A8B2-43EB8B7B336C}C:\program files (x86)\steam\steam.exe] => (Allow) C:\program files (x86)\steam\steam.exe
FirewallRules: [{D817B83D-3CD8-4043-B841-FD4323BCC840}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7b\waol.exe
FirewallRules: [{E0A9FF49-DAFE-4005-9A10-8DB8FDC4A09E}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7b\waol.exe
FirewallRules: [{A08EF46C-26E6-49D8-91A4-4C95D8362CDC}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7b\aolbrowser.exe
FirewallRules: [{44515761-4329-45D2-A115-0E6BDEAB947F}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7b\aolbrowser.exe
FirewallRules: [{3381CF76-DF9F-4051-A8C6-E942455E4743}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7c\waol.exe
FirewallRules: [{8B2AB45D-C94A-4A2A-BD49-D12F528BD979}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7c\waol.exe
FirewallRules: [{A57F5E6B-4DFF-4B77-8920-28C90324789E}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\waol.exe
FirewallRules: [{9CFD3E39-E2B8-4647-815E-370CA0A21EE4}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.7\waol.exe
FirewallRules: [{45D87717-1C1E-4240-AA0A-2DFC86081403}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.8.2\waol.exe
FirewallRules: [{24E36255-70AE-40EF-97B4-FFB6D98BB0DA}] => (Allow) C:\Program Files (x86)\AOL Desktop 9.8.2\waol.exe
FirewallRules: [{71CF83C9-8CCE-43B5-A513-B99581D5167C}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{62D852D8-AFEC-4D5D-8430-BB1738273714}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr.exe
FirewallRules: [{9FEEC7DC-0966-4CE0-902D-909D682E9199}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{019CCF24-5A96-42FD-ADCF-B3DBBAF7DB52}] => (Allow) C:\Program Files (x86)\Raptr Inc\Raptr\raptr_im.exe
FirewallRules: [{723873F2-50F8-4799-9851-694FDA0DEEE5}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{5AFE2382-73CD-48DA-8C3C-B18E1B8E2860}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [{31E66AFE-4743-4169-AA23-CD2A0046B6FA}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [TCP Query User{A0A8521B-E980-4BE2-B001-0A064998BA11}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{85E29296-6AF0-426D-ADC1-091A413E7867}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{6C117CDF-C303-4664-95CB-71CFF9777281}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{88C63AB3-E27B-4842-851C-388CF53A1854}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{06235542-6099-41D3-91B4-EC8FB4532A28}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{4CAAFD89-E7FA-4570-B532-4B4166D37F67}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{7627EA5F-9410-4F09-9CD1-5A21CB40638F}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [{65F3F080-645C-4A55-AB54-F6A8802ED87F}] => (Allow) C:\Program Files (x86)\Raptr Inc\PlaysTV\playstv.exe
FirewallRules: [{BB0D4F64-73E4-4C6B-AF78-DF9A8B54E0E4}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{3637EE1E-8AF6-4551-BBC3-DE318B2209DD}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{BEA7DA02-FEA9-490B-9235-C66B340B2339}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoPro.exe
FirewallRules: [{D65F7E2E-04F4-4533-9BA0-B2DC5B600238}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProMsgBus.exe
FirewallRules: [{CBCFF990-3B3F-407A-91FE-EE7725139BDC}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProIDService.exe
FirewallRules: [{73AC0352-30F8-44BD-B472-819F0C4B3085}] => (Allow) C:\Program Files\GoPro\GoPro Desktop App\GoProLauncher.exe
 
==================== Restore Points =========================
 
15-08-2016 14:59:22 GoPro for Desktop
24-08-2016 10:23:28 Windows Update
01-09-2016 08:00:08 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (09/04/2016 04:14:45 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.
 
Error: (09/04/2016 04:14:45 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (09/04/2016 04:11:28 AM) (Source: ATIeRecord) (EventID: 16396) (User: )
Description: ATI EEU PnP start/stop failed
 
Error: (09/04/2016 04:06:57 AM) (Source: ATIeRecord) (EventID: 16396) (User: )
Description: ATI EEU PnP start/stop failed
 
Error: (09/03/2016 09:30:37 PM) (Source: ATIeRecord) (EventID: 16396) (User: )
Description: ATI EEU PnP start/stop failed
 
Error: (09/03/2016 10:35:02 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (09/03/2016 06:05:44 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3011) (User: NT AUTHORITY)
Description: Unloading the performance counter strings for service WmiApRpl (WmiApRpl) failed. The first DWORD in the Data section contains the error code.
 
Error: (09/03/2016 06:05:44 AM) (Source: Microsoft-Windows-LoadPerf) (EventID: 3012) (User: NT AUTHORITY)
Description: The performance strings in the Performance registry value is corrupted when process Performance extension counter provider. The BaseIndex value from the Performance registry is the first DWORD in the Data section, LastCounter value is the second DWORD in the Data section, and LastHelp value is the third DWORD in the Data section.
 
Error: (09/03/2016 06:02:45 AM) (Source: ATIeRecord) (EventID: 16396) (User: )
Description: ATI EEU PnP start/stop failed
 
Error: (09/03/2016 05:54:37 AM) (Source: ATIeRecord) (EventID: 16396) (User: )
Description: ATI EEU PnP start/stop failed
 
 
System errors:
=============
Error: (09/04/2016 04:32:23 AM) (Source: DCOM) (EventID: 10016) (User: ERIC-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID 
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user Eric-PC\Eric SID (S-1-5-21-1685030488-3750137779-1738601272-1001) from address LocalHost (Using LRPC) running in the application container Weather.TheWeatherChannel_2016.614.79.0_x64__t3yemqpq4kp7p SID (S-1-15-2-1823816767-1701819125-4016690874-1675459659-2418940871-1162039928-1983191223). This security permission can be modified using the Component Services administrative tool.
 
Error: (09/04/2016 04:32:16 AM) (Source: DCOM) (EventID: 10016) (User: ERIC-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID 
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user Eric-PC\Eric SID (S-1-5-21-1685030488-3750137779-1738601272-1001) from address LocalHost (Using LRPC) running in the application container Weather.TheWeatherChannel_2016.614.79.0_x64__t3yemqpq4kp7p SID (S-1-15-2-1823816767-1701819125-4016690874-1675459659-2418940871-1162039928-1983191223). This security permission can be modified using the Component Services administrative tool.
 
Error: (09/04/2016 04:32:16 AM) (Source: DCOM) (EventID: 10016) (User: ERIC-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{C2F03A33-21F5-47FA-B4BB-156362A2F239}
 and APPID 
{316CDED5-E4AE-4B15-9113-7055D84DCC97}
 to the user Eric-PC\Eric SID (S-1-5-21-1685030488-3750137779-1738601272-1001) from address LocalHost (Using LRPC) running in the application container Weather.TheWeatherChannel_2016.614.79.0_x64__t3yemqpq4kp7p SID (S-1-15-2-1823816767-1701819125-4016690874-1675459659-2418940871-1162039928-1983191223). This security permission can be modified using the Component Services administrative tool.
 
Error: (09/04/2016 04:12:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RzWizardService service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (09/04/2016 04:12:15 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the RzWizardService service to connect.
 
Error: (09/04/2016 04:12:15 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The MemeoBackgroundService service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (09/04/2016 04:12:15 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the MemeoBackgroundService service to connect.
 
Error: (09/04/2016 04:11:26 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 4:06:52 AM on ‎9/‎4/‎2016 was unexpected.
 
Error: (09/04/2016 04:07:35 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The RzWizardService service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (09/04/2016 04:07:35 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the RzWizardService service to connect.
 
 
CodeIntegrity:
===================================
  Date: 2016-09-04 05:42:32.568
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-09-04 05:42:32.555
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-09-04 05:39:15.747
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-09-04 05:39:15.735
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-09-04 05:39:15.573
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-09-04 05:39:15.559
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-09-04 05:39:15.544
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-09-04 05:32:53.891
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-09-04 05:32:53.879
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2016-09-04 05:32:53.510
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i7 CPU 930 @ 2.80GHz
Percentage of memory in use: 33%
Total physical RAM: 6134.92 MB
Available physical RAM: 4066.26 MB
Total Virtual: 7158.92 MB
Available Virtual: 4643.72 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:922.74 GB) (Free:654.49 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 77E3ED41)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=8.7 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=922.7 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

 

Do you connect to the internet by AOL?
The reason I ask, some tools find a few tools installed by AOL as intrusive and will remove them, would likely mean you would have to reinstall those browser tool bar helpers and a couple other related items.

Running from C:\Users\Eric\Desktop\what the tech

It's best we move Farbar's to desktop.

Please go to your C:\Users\Eric\Desktop\what the tech folder, locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden <==== ATTENTION
Task: {0C76897A-7841-4A5C-A653-46559D7FF9C2} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {17E6973C-31AE-4716-8B6C-95E3F8B9A22D} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {23A3F1BC-F9A9-4BF2-82B5-E2C3917C4960} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {52B45B97-EA75-45B7-8810-0D4AD5C23610} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {66F7F15D-5D0C-4690-AA19-F9E66C90B682} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {8AC20CE3-8F95-4846-831B-19BFECE5D2C3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {9348EDE7-DD4D-4BA4-A43E-F9E7EED1E2E3} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {A2D918E5-7B77-4D4B-BCB9-DBAFA9CC7758} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {A774A864-4870-414D-A582-099E9BCB6DFA} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {D20F308A-1AC2-4AE5-A3A8-F08B0D462BF4} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {E30B7AD2-01B2-4E15-A323-0B48CDA87C33} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {EB9DF709-45D6-4728-9E97-839D61DB9CF3} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
ShortcutWithArgument: C:\Users\Eric\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\18296756730.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -pinnedSite -contentTile -formatVersion 0x00000002 -pinnedTimeLow 0x5ee91793 -pinnedTimeHigh 0x01ce14e1 -securityFlags 0x00000000 -url 0x0000001c hxxp://www.linkedin.com/home
ShortcutWithArgument: C:\Users\Eric\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\9176798760.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -pinnedSite -contentTile -formatVersion 0x00000002 -pinnedTimeLow 0x59065024 -pinnedTimeHigh 0x01ce14e6 -securityFlags 0x00000000 -url 0x00000019 hxxps://www.facebook.com
EmptyTemp:
End


Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~~~~~~
Now please go to your add/remove programs list, locate Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc)
This needs to be deleted/uninstalled.

~~~~~~~~`

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
    In order to use AdwCleaner, you have to agree the Eula:
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
– File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.

~~~~~~~
Please download Junkware Removal Tool
or from here http://downloads.malwarebytes.org/file/jrt
to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
***
please post
Fixlog.txt
AdwCleaner[C1].txt
JRT.txt

Hi Juliet, I tried to do what you asked but I received this prompt while it was attempting the fix. I get this prompt- there is no disk in the drive. please insert a disk into drive E. I cannot cancel, try again or continue??

Hi Juliet, I tried to do what you asked but I received this prompt while it was attempting the fix. I get this prompt- there is no disk in the drive. please insert a disk into drive E. I cannot cancel, try again or continue??

wowssa, that was unexpected and a first for me.

If you click on continue does it allow you to do anything at all?

ok I ran  adw and JRT, below are the results. I did not attach the fix log because of the problem I mention above. BTW, I do have a removable drive that I connect every once in a while to save files and photos. Should I connect it and try to run FRST again?

 

# AdwCleaner v6.010 - Logfile created 06/09/2016 at 07:00:21
# Updated on 12/08/2016 by ToolsLib
# Database : 2016-09-05.1 [Server]
# Operating System : Windows 10 Pro  (X64)
# Username : Eric - ERIC-PC
# Running from : C:\Users\Eric\Desktop\AdwCleaner.exe
# Mode: Clean
# Support : https://toolslib.net/forum
 
 
 
***** [ Services ] *****
 
 
 
***** [ Folders ] *****
 
[!] Folder not deleted: C:\Users\Eric\AppData\Local\AOL Toolbar
[-] Folder deleted: C:\Users\Eric\AppData\LocalLow\surfcanyon
[!] Folder not deleted: C:\ProgramData\AOL Toolbar
[-] Folder deleted: C:\ProgramData\apn
[!] Folder not deleted: C:\ProgramData\Viewpoint
[!] Folder not deleted: C:\ProgramData\Application Data\AOL Toolbar
[#] Folder deleted on reboot: C:\ProgramData\Application Data\apn
[!] Folder not deleted: C:\ProgramData\Application Data\Viewpoint
[!] Folder not deleted: C:\Program Files (x86)\AOL Toolbar
[!] Folder not deleted: C:\Program Files (x86)\Viewpoint
[!] Folder not deleted: C:\Program Files (x86)\Common Files\Software Update Utility
 
 
***** [ Files ] *****
 
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
[-] Key deleted: HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
[-] Key deleted: HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
[-] Key deleted: HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
[-] Key deleted: HKLM\SOFTWARE\Classes\dnUpdate
[-] Key deleted: HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
[-] Key deleted: HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
[-] Key deleted: HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
[-] Key deleted: HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{03F998B2-0E00-11D3-A498-00104B6EB52E}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{1663C10B-0D55-438D-8496-19A3DBAEC0E4}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{6E993643-8FBC-44FE-BC85-D318495C4D96}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{3CCC052E-BDEE-408A-BEA7-90914EF2964B}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{61F47056-E400-43D3-AF1E-AB7DFFD4C4AD}
[-] Key deleted: HKLM\SOFTWARE\Classes\CLSID\{E2B98EEA-EE55-4E9B-A8C1-6E5288DF785A}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{7697BC38-D0FA-454B-AC75-968B4CCABFCE}
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
[-] Key deleted: HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\Software\Cr_Installer
[-] Key deleted: HKU\S-1-5-21-1685030488-3750137779-1738601272-1001\Software\YahooPartnerToolbar
[#] Key deleted on reboot: HKCU\Software\Cr_Installer
[#] Key deleted on reboot: HKCU\Software\YahooPartnerToolbar
[-] Key deleted: HKLM\SOFTWARE\firstsearch
[-] Key deleted: HKLM\SOFTWARE\InfoAtoms
[-] Key deleted: HKLM\SOFTWARE\MetaStream
[-] Key deleted: HKLM\SOFTWARE\Viewpoint
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ViewpointMediaPlayer
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{730E03E4-350E-48E5-9D3E-4329903D454D}
[-] Key deleted: [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\4E30E037E0535E84D9E3349209D354D4
[-] Key deleted: [x64] HKLM\SOFTWARE\Classes\Installer\Products\4E30E037E0535E84D9E3349209D354D4
[-] Key deleted: HKLM\SOFTWARE\Classes\Installer\Features\4E30E037E0535E84D9E3349209D354D4
[#] Key deleted on reboot: HKLM\SOFTWARE\Classes\Installer\Products\4E30E037E0535E84D9E3349209D354D4
[-] Key deleted: HKLM\SOFTWARE\Classes\AppID\dnu.EXE
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\{03F998B2-0E00-11D3-A498-00104B6EB52E}
[-] Key deleted: HKLM\SOFTWARE\MozillaPlugins\@viewpoint.com/VMP
 
 
***** [ Web browsers ] *****
 
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [5201 Bytes] - [06/09/2016 07:00:21]
C:\AdwCleaner\AdwCleaner[S0].txt - [5185 Bytes] - [06/09/2016 06:53:16]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [5347 Bytes] ##########
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.7 (07.03.2016)
Operating System: Windows 10 Pro x64 
Ran by [removed] (Administrator) on Tue 09/06/2016 at  7:11:37.29
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 17 
 
Successfully deleted: C:\ProgramData\aol toolbar (Folder) 
Successfully deleted: C:\ProgramData\viewpoint (Folder) 
Successfully deleted: C:\Users\Eric\AppData\Local\{087538B6-47DA-41BC-A12B-0185989F856D} (Empty Folder)
Successfully deleted: C:\Users\Eric\AppData\Local\{448AA002-3FE5-46D9-B82E-1C8835428ECD} (Empty Folder)
Successfully deleted: C:\Users\Eric\AppData\Local\{7144E14B-DA8F-4F99-85FB-C05B54A27857} (Empty Folder)
Successfully deleted: C:\Users\Eric\AppData\Local\{9536D5C4-38B8-4FEE-AA68-A33A8E40BD25} (Empty Folder)
Successfully deleted: C:\Users\Eric\AppData\Local\{995AFA18-25AF-433A-BE1F-DA935CE51646} (Empty Folder)
Successfully deleted: C:\Users\Eric\AppData\Local\{A6086140-E16A-4BE7-9E0C-440BC7DD1CD3} (Empty Folder)
Successfully deleted: C:\Users\Eric\AppData\Local\{AFD66BCB-3AA7-463E-B563-E0B424206F29} (Empty Folder)
Successfully deleted: C:\Users\Eric\AppData\Local\{EB1F74E7-487D-4685-8F1B-9839BE9CC6DB} (Empty Folder)
Successfully deleted: C:\Users\Eric\AppData\Local\{EF639325-BD33-4989-9AC3-D4C3CAF47AFF} (Empty Folder)
Successfully deleted: C:\Users\Eric\AppData\Local\aol toolbar (Folder) 
Successfully deleted: C:\WINDOWS\system32\Tasks\PCDEventLauncherTask (Task)
Successfully deleted: C:\WINDOWS\system32\Tasks\PCDoctorBackgroundMonitorTask (Task)
Successfully deleted: C:\Program Files (x86)\aol toolbar (Folder) 
Successfully deleted: C:\Program Files (x86)\Common Files\software update utility (Folder) 
Successfully deleted: C:\Program Files (x86)\viewpoint (Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 09/06/2016 at  7:13:37.85
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

 

I did not attach the fix log because of the problem I mention above. BTW, I do have a removable drive that I connect every once in a while to save files and photos. Should I connect it and try to run FRST again?

researching the error it seemed to relate to a removable drive,  although I thought that crazy.

Give it a try,  let's see what happens.

Let's see what E drive is and if we can disable it temporarily.

Right click on the windows Orb button, click on Windows explorer
when that window opens, look to the left pane, click on Computer, what is designated to Drive E?
When you double click the drive, what does it tell you about the device status? Does it say the device would be working correctly or is there some error?

Hi Juliet, Drive E is designated as USB and it is working properly. I was also able to run the FRST script in safe mode, below. 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 31-08-2016
Ran by [removed] (06-09-2016 16:12:34) Run:3
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Safe Mode (minimal)
==============================================
 
fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden <==== ATTENTION
Task: {0C76897A-7841-4A5C-A653-46559D7FF9C2} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {17E6973C-31AE-4716-8B6C-95E3F8B9A22D} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {23A3F1BC-F9A9-4BF2-82B5-E2C3917C4960} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {52B45B97-EA75-45B7-8810-0D4AD5C23610} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {66F7F15D-5D0C-4690-AA19-F9E66C90B682} - \CCleanerSkipUAC -> No File <==== ATTENTION
Task: {8AC20CE3-8F95-4846-831B-19BFECE5D2C3} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {9348EDE7-DD4D-4BA4-A43E-F9E7EED1E2E3} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {A2D918E5-7B77-4D4B-BCB9-DBAFA9CC7758} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {A774A864-4870-414D-A582-099E9BCB6DFA} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {D20F308A-1AC2-4AE5-A3A8-F08B0D462BF4} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {E30B7AD2-01B2-4E15-A323-0B48CDA87C33} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {EB9DF709-45D6-4728-9E97-839D61DB9CF3} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
ShortcutWithArgument: C:\Users\Eric\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\18296756730.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -pinnedSite -contentTile -formatVersion 0x00000002 -pinnedTimeLow 0x5ee91793 -pinnedTimeHigh 0x01ce14e1 -securityFlags 0x00000000 -url 0x0000001c hxxp://www.linkedin.com/home
ShortcutWithArgument: C:\Users\Eric\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\9176798760.lnk -> C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) -> -pinnedSite -contentTile -formatVersion 0x00000002 -pinnedTimeLow 0x59065024 -pinnedTimeHigh 0x01ce14e6 -securityFlags 0x00000000 -url 0x00000019 hxxps://www.facebook.com
EmptyTemp:
End
*****************
 
Error: Restore point can only be created in normal mode.
Processes closed successfully.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\\SystemComponent => value not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0C76897A-7841-4A5C-A653-46559D7FF9C2} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{17E6973C-31AE-4716-8B6C-95E3F8B9A22D} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{23A3F1BC-F9A9-4BF2-82B5-E2C3917C4960} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{52B45B97-EA75-45B7-8810-0D4AD5C23610} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{66F7F15D-5D0C-4690-AA19-F9E66C90B682} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\CCleanerSkipUAC => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8AC20CE3-8F95-4846-831B-19BFECE5D2C3} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9348EDE7-DD4D-4BA4-A43E-F9E7EED1E2E3} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A2D918E5-7B77-4D4B-BCB9-DBAFA9CC7758} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A774A864-4870-414D-A582-099E9BCB6DFA} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D20F308A-1AC2-4AE5-A3A8-F08B0D462BF4} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E30B7AD2-01B2-4E15-A323-0B48CDA87C33} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB9DF709-45D6-4728-9E97-839D61DB9CF3} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd => key not found. 
C:\Users\Eric\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\18296756730.lnk => Shortcut argument removed successfully.
C:\Users\Eric\AppData\Local\Microsoft\Windows\Application Shortcuts\Microsoft.InternetExplorer.Default\9176798760.lnk => Shortcut argument removed successfully.
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12716280 B
Java, Flash, Steam htmlcache => 855 B
Windows/system/drivers => 18258 B
Edge => 60700204 B
Chrome => 12108051 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 3186 B
Eric => 598831 B
 
RecycleBin => 0 B
EmptyTemp: => 82.2 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 16:12:46 ====

Ran by [removed] (06-09-2016 16:12:34) Run:3
it ran and you couldn't tell it but all is OK

Since you already have Malwarebytes Anti-Malware on board, let's update it and run a scan.

  • Open Malwarebytes
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards.
  • If threats are detected, click Remove Selected. If you are prompted to reboot, click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs, followed by the first Scan Log.
  • Click Export, followed by Copy to Clipboard. Paste the log in your next reply.
     

~~~~~~~~~~~`

Please download Emsisoft Emergency Kit and save it to your desktop.
Double click on the EmsisoftEmergencyKit file you downloaded to extract its contents and create a shortcut on the desktop.

  • Leave all settings as they are and click the Extract button at the bottom.
  • A folder named EEK will be created in the root of the drive (usually c:\).
  • After extraction please double-click on the new Start Emsisoft Emergency Kit icon on your desktop.
  • The first time you launch it, Emsisoft Emergency Kit will recommend that you allow it to download updates.
  • Please click Yes so that it downloads the latest database updates.
  • When the update process is complete, a new button will appear in the lower-left corner that says Back. Click on this button to return to the Overview screen.
  • Click on Scan to be taken to the scan options.
  • If you are asked if you want the scanner to scan for Potentially Unwanted Programs, then click Yes.
  • Click on the Malware Scan button to start the scan.
  • When the scan is completed click the View report button in the lower-right corner, and the scan log will be opened in Notepad.
  • Please save the log in Notepad on your desktop, and copy it to your next reply.
  • When you close Emsisoft Emergency Kit, it will give you an option to sign up for a newsletter. This is optional, and is not necessary for the malware removal process.

~~

 

How is your computer now?

Malwarebytes log: eek to follow. Appears much better 

 

Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 9/6/2016
Scan Time: 6:45 PM
Logfile: 
Administrator: Yes
 
Version: 2.2.1.1043
Malware Database: v2016.09.06.10
Rootkit Database: v2016.08.15.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 10
CPU: x64
File System: NTFS
User: Eric
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 371352
Time Elapsed: 26 min, 35 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI