This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Norton finding a trojan Kotver!gm2 that is slowing my PC [Solved]

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

 

My Norton AV keeps finding Trojan.Kotver!2gm and says it needs to reboot to fix it. I've rebooted several times but it keeps coming up with the notice.

 

How can I get rid of this infection? I have downloaded the programs and am posting the required logs per your instructions below:

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-10-15 18:49:57
—————————–
18:49:57.327    OS Version: Windows x64 6.2.9200
18:49:57.330    Number of processors: 4 586 0x2A07
18:49:57.332    ComputerName: JIM  UserName: Dad
18:50:20.060    Initialze error C000010E - driver not loaded
18:50:20.150    write error "aswEngin.dll". The process cannot access the file because it is being used by another process.
18:53:08.106    AVAST engine defs: 16101500
18:53:46.155    Service scanning
18:54:12.070    Modules scanning
18:54:12.073    Disk 0 trace - called modules:
18:54:12.074    
18:54:18.548    AVAST engine scan C:\WINDOWS
18:54:25.760    AVAST engine scan C:\WINDOWS\system32
19:01:32.709    AVAST engine scan C:\WINDOWS\system32\drivers
19:02:50.417    AVAST engine scan C:\Users\Dad
20:00:12.258    AVAST engine scan C:\ProgramData
20:13:31.392    Scan finished successfully
20:50:09.835    The log file has been saved successfully to "C:\Users\Dad\Desktop\aswMBR.txt"


aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2016-10-15 18:49:57
—————————–
18:49:57.327    OS Version: Windows x64 6.2.9200
18:49:57.330    Number of processors: 4 586 0x2A07
18:49:57.332    ComputerName: JIM  UserName: Dad
18:50:20.060    Initialze error C000010E - driver not loaded
18:50:20.150    write error "aswEngin.dll". The process cannot access the file because it is being used by another process.
18:53:08.106    AVAST engine defs: 16101500
18:53:46.155    Service scanning
18:54:12.070    Modules scanning
18:54:12.073    Disk 0 trace - called modules:
18:54:12.074    
18:54:18.548    AVAST engine scan C:\WINDOWS
18:54:25.760    AVAST engine scan C:\WINDOWS\system32
19:01:32.709    AVAST engine scan C:\WINDOWS\system32\drivers
19:02:50.417    AVAST engine scan C:\Users\Dad
20:00:12.258    AVAST engine scan C:\ProgramData
20:13:31.392    Scan finished successfully
20:50:09.835    The log file has been saved successfully to "C:\Users\Dad\Desktop\aswMBR.txt"
20:50:33.986    The log file has been saved successfully to "C:\Users\Dad\Desktop\aswMBR.txt"

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 13-10-2016
Ran by [removed] (administrator) on JIM (15-10-2016 21:43:26)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
(IObit) C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe
(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Nero AG) C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccsvchst.exe
(Microsoft Corporation) C:\WINDOWS\System32\mqsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security with Backup\Engine\22.7.1.32\nsbu.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\SMService.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
(Seiko Epson Corporation) C:\WINDOWS\System32\escsvc64.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccsvchst.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security with Backup\Engine\22.7.1.32\nsbu.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\ClassicStart.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\StartMenu_Hook.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(WinZip Computing International, LLC) C:\Program Files\File Association Helper\FAHWindow.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\InstallServices.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
(PalmSource, Inc) C:\Program Files (x86)\Palm\Hotsync.exe
(KeirNet) C:\Program Files (x86)\KeirNet\K9\K9.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Firetrust) C:\Program Files (x86)\FireTrust\MailWasher\MailWasherPro.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
(Microsoft Corporation) C:\WINDOWS\System32\inetsrv\w3wp.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security with Backup\Engine\22.7.1.32\conathst.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
(Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16407296 2016-01-26] (Realtek Semiconductor)
HKLM\…\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [216248 2013-09-26] (WinZip Computing International, LLC)
HKLM\…\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.)
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776 2016-05-02] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\WINDOWS\system32\nvspcap64.dll [1767944 2016-05-02] (NVIDIA Corporation)
HKLM-x32\…\Run: [SSBkgdUpdate] => C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM-x32\…\Run: [PaperPort PTD] => C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe [29984 2008-01-14] (Nuance Communications, Inc.)
HKLM-x32\…\Run: [IObit Malware Fighter] => C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe [5976864 2016-06-28] (IObit)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598040 2016-06-22] (Oracle Corporation)
HKLM-x32\…\RunOnce: [Malwarebytes Anti-Malware (cleanup)] => C:\ProgramData\Malwarebytes\Malwarebytes Anti-Malware\mbamdor.exe [55264 2016-03-10] (Malwarebytes)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKLM\…\Policies\Explorer: [NoSetActiveDesktop] 0
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2023712 2016-07-27] (IObit)
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Run: [KGShareApp] => C:\Program Files (x86)\Kodak\KODAK Share Button App\KGShare_App.exe [394240 2015-02-09] (Eastman Kodak Company)
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8912088 2016-08-26] (Piriform Ltd)
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Run: [**iqnr<*>] => "C:\Users\Dad\AppData\Local\5b65\47e2.lnk" <===== ATTENTION (Value Name with invalid characters)
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Policies\Explorer: [NoSetActiveDesktop] 0
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\MountPoints2: {09331ad7-5447-11e3-901b-386077ec13ea} - "F:\KODAK_Camera_Setup_App.exe"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\MountPoints2: {112fa596-7e8f-11e3-91ef-386077ec13ea} - "F:\MotoCastSetup.exe" -a
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Ribbons.scr [132608 2014-11-21] (Microsoft Corporation)
HKU\S-1-5-18\…\Winlogon: [Shell] C:\WINDOWS\Explorer.exe [2755504 2016-09-20] (Microsoft Corporation) <==== ATTENTION
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Security with Backup\Engine64\22.7.1.32\buShell.dll [2016-08-15] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Security with Backup\Engine64\22.7.1.32\buShell.dll [2016-08-15] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Security with Backup\Engine64\22.7.1.32\buShell.dll [2016-08-15] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ SncrOverlays (Blocked)] -> {C418E880-6280-4010-A888-FD76028E5511} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [ SncrOverlays (InSync)] -> {5F4A6070-DB92-4C56-A487-F3850430608F} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [ SncrOverlays (Pending)] -> {EE73A341-C788-4A6B-B1EF-DDBFC0F190B6} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [ SncrOverlays (Syncing)] -> {28CDCD88-B179-49D6-8B21-1A9AF9C0AE13} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
Startup: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3edf.lnk [2016-10-15]
ShortcutTarget: 3edf.lnk -> C:\WINDOWS\System32\cmd.exe (Microsoft Corporation)
Startup: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MailWasherPro.lnk [2016-04-20]
ShortcutTarget: MailWasherPro.lnk -> C:\Program Files (x86)\FireTrust\MailWasher\MailWasherPro.exe (Firetrust)
BootExecute: RegistryDefragBootTime.exeautocheck autochk *
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

AutoConfigURL: [S-1-5-21-968235783-2654321925-1125524309-1000] => hxxp://proxy.kodak.com:81/proxy.pac
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3534EE43-8554-4DFD-B1F2-F34A35AF6B03}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{90616DFF-D831-4BD6-9124-AEF7F60BD2AA}: [DhcpNameServer] 75.75.75.75 75.75.76.76
ManualProxies: 0hxxp://proxy.kodak.com:81/proxy.pac

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
URLSearchHook: [S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = hxxp://search.myheritage.com?orig=ds&q;={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src;={referrer:source?}
SearchScopes: HKLM -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL =
SearchScopes: HKLM -> {31090377-0740-419E-BEFC-A56E50500D5B} URL =
SearchScopes: HKLM -> {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = hxxp://search.myheritage.com?orig=ds&q;={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\.DEFAULT -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o;=APN11913&l;=dis&prt;=NSBU&chn;=1000&geo;=US&ver;=22&locale;=en_US&gct;=kwd&qsrc;=2869
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2015-11-12] (IObit)
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-10-27] (RealDownloader)
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security with Backup\Engine64\22.7.1.32\coIEPlg.dll [2016-08-05] (Symantec Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_102\bin\ssv.dll [2016-08-04] (Oracle Corporation)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-07-03] (LastPass)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_102\bin\jp2ssv.dll [2016-08-04] (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-10-27] (RealDownloader)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security with Backup\Engine\22.7.1.32\coIEPlg.dll [2016-08-05] (Symantec Corporation)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-07-03] (LastPass)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-07-09] (IObit)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine64\22.7.1.32\coIEPlg.dll [2016-08-05] (Symantec Corporation)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-07-03] (LastPass)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine\22.7.1.32\coIEPlg.dll [2016-08-05] (Symantec Corporation)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-07-03] (LastPass)
Toolbar: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine64\22.7.1.32\coIEPlg.dll [2016-08-05] (Symantec Corporation)
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}

FireFox:
========
FF ProfilePath: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 [2016-10-15]
FF user.js: detected! => C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463\user.js [2016-03-22]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 -> Google
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 -> Google
FF Homepage: Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 -> about:blank
FF Extension: (LastPass) - C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463\Extensions\[removed] [2016-09-03]
FF Extension: (1-Click YouTube Video Downloader) - C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463\Extensions\[removed] [2016-08-24]
FF HKLM\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.6.0.142\coFFAddon
FF Extension: (Norton Identity Safe) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.6.0.142\coFFAddon [2016-09-26]
FF HKLM-x32\…\Firefox\Extensions: [{338950EA-82DB-44C1-930D-0C28E023C9F0}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2015-02-11] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\…\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-01-17] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.6.0.142\coFFAddon
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_162.dll [2016-09-26] ()
FF Plugin: @java.com/DTPlugin,version=11.102.2 -> C:\Program Files\Java\jre1.8.0_102\bin\dtplugin\npDeployJava1.dll [2016-08-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.102.2 -> C:\Program Files\Java\jre1.8.0_102\bin\plugin2\npjp2.dll [2016-08-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_162.dll [2016-09-26] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-02-22] (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-03-18] (Nero AG)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-06-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-06-02] (NVIDIA Corporation)
FF Plugin-x32: @palmsource.com/installer,version=1.0 -> C:\PROGRA~2\Palm\PACKAG~1\NPInstal.dll [2007-03-19] ()
FF Plugin-x32: @real.com/nppl3260;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2015-02-11] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.15 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-10-27] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2015-02-11] (RealPlayer Cloud)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-24] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-24] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-07] ()
FF Plugin-x32: @winzip.com/Winzip Courier -> C:\Program Files (x86)\WinZip Courier\npwzwmc.dll [2013-11-22] (WinZip Computing, S.L.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-07-28] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-968235783-2654321925-1125524309-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Dad\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-12-15] (Citrix Online)
FF Plugin HKU\S-1-5-21-968235783-2654321925-1125524309-1000: tdameritrade.com/thinkorswim -> C:\Program Files\thinkorswim\npthinkorswim.dll [2016-09-21] (TD Ameritrade)
FF Plugin HKU\S-1-5-21-968235783-2654321925-1125524309-1000: tdameritrade.com/tossc -> C:\Program Files\thinkorswim\nptossc.dll [2016-09-21] (TD Ameritrade)
FF Plugin ProgramFiles/Appdata: C:\Users\Dad\AppData\Roaming\mozilla\plugins\npatgpc.dll [2015-03-25] (Cisco WebEx LLC)

Chrome:
=======
CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security with Backup\Engine\22.7.1.32\Exts\Chrome.crx [2016-08-23]
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security with Backup\Engine\22.7.1.32\Exts\Chrome.crx [2016-08-23]
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [452384 2016-07-25] (IObit)
S3 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1165368 2016-05-02] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 IMFservice; C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe [1597728 2016-06-13] (IObit)
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-06-14] (IObit)
R2 MCLIENT; C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccSvcHst.exe [143928 2012-12-04] (Symantec Corporation)
S3 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [214896 2012-02-01] ()
R2 NSBU; C:\Program Files (x86)\Norton Security with Backup\Engine\22.7.1.32\NSBU.exe [289080 2016-08-16] (Symantec Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-05-02] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232 2016-05-02] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680 2016-05-02] (NVIDIA Corporation)
S3 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-10-26] ()
S3 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2015-02-11] (RealNetworks, Inc.)
S3 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31856 2014-10-30] ()
S3 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [614664 2014-04-01] (CyberLink)
R2 SMService; C:\Program Files (x86)\IObit\Classic Start\SMService.exe [1063200 2015-12-29] (IObit)
S3 vmicvss; C:\Windows\System32\ICSvc.dll [524800 2014-11-21] (Microsoft Corporation)
R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1049464 2016-04-19] (Western Digital Technologies, Inc.)
R3 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [314744 2016-04-19] (Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx64; C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\BASHDefs\20161005.001\BHDrvx64.sys [1854712 2016-08-18] (Symantec Corporation)
R1 ccSet_MCLIENT; C:\Windows\system32\drivers\MCLIENTx64\0302020.00C\ccSetx64.sys [168096 2012-10-03] (Symantec Corporation)
R1 ccSet_NSBU; C:\Windows\system32\drivers\NSBUx64\1607010.020\ccSetx64.sys [174328 2016-06-01] (Symantec Corporation)
R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [497368 2016-10-03] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [156888 2016-10-03] (Symantec Corporation)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-07-02] (REALiX™)
R1 IDSVia64; C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\IPSDefs\20161014.003\IDSvia64.sys [1012440 2016-09-26] (Symantec Corporation)
S4 IMFFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\IMFFilter.sys [22208 2016-04-01] (IObit)
S1 iSafeKrnlMon; no ImagePath
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2014-07-03] (Intel Corporation)
R2 mfmonitor; C:\Windows\System32\DRIVERS\mfmonitor_x64.sys [20696 2014-06-19] (Windows (R) Win 7 DDK provider)
R3 netr28x; C:\Windows\system32\DRIVERS\netr28x.sys [2541200 2016-03-04] (MediaTek Inc.)
U0 nhvtc; C:\Windows\System32\drivers\jykmlmx.sys [79064 2016-10-15] (Malwarebytes)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28216 2016-05-02] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
S3 RegFilter; C:\Program Files (x86)\IObit\IObit Malware Fighter\drivers\win7_amd64\regfilter.sys [34848 2016-01-11] (IObit.com)
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [413912 2016-04-23] (Realsil Semiconductor Corporation)
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2014-07-03] (Synaptics Incorporated)
R1 SRTSP; C:\Windows\System32\Drivers\NSBUx64\1607010.020\SRTSP64.SYS [773360 2016-08-09] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NSBUx64\1607010.020\SRTSPX64.SYS [48888 2016-06-01] (Symantec Corporation)
R0 SymEFASI; C:\Windows\System32\drivers\NSBUx64\1607010.020\SYMEFASI64.SYS [1627352 2016-06-01] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\NSBUx64\1607010.020\SymELAM.sys [24192 2016-02-23] (Symantec Corporation)
R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [101112 2016-06-27] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [78936 2013-09-09] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NSBUx64\1607010.020\Ironx64.SYS [291056 2016-06-01] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NSBUx64\1607010.020\SYMNETS.SYS [567536 2016-06-01] (Symantec Corporation)
U5 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2014-06-08] (Seiko Epson Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 NAVENG; \??\C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\SDSDefs\20161013.019\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\SDSDefs\20161013.019\EX64.SYS [X]
U3 aswMBR; \??\C:\Users\Dad\AppData\Local\Temp\aswMBR.sys [X]
U3 aswVmm; \??\C:\Users\Dad\AppData\Local\Temp\aswVmm.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-10-15 21:43 - 2016-10-15 21:44 - 00032031 _____ C:\Users\Dad\Desktop\FRST.txt
2016-10-15 20:50 - 2016-10-15 20:50 - 00002185 _____ C:\Users\Dad\Desktop\aswMBR.txt
2016-10-15 18:50 - 2016-10-15 21:43 - 00000000 ____D C:\FRST
2016-10-15 18:48 - 2016-10-15 18:48 - 00079064 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\jykmlmx.sys
2016-10-15 18:47 - 2016-10-15 18:47 - 02406912 _____ (Farbar) C:\Users\Dad\Desktop\FRST64.exe
2016-10-15 18:39 - 2016-10-15 18:39 - 05198336 _____ (AVAST Software) C:\Users\Dad\Desktop\aswMBR.exe
2016-10-14 14:56 - 2016-10-14 22:22 - 00012674 _____ C:\Users\Dad\Desktop\Medical Records.xlsx
2016-10-13 20:28 - 2016-10-13 20:28 - 00008192 _____ C:\WINDOWS\SysWOW64\WDPABKP.dat
2016-10-13 19:41 - 2016-09-30 19:15 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-10-13 19:41 - 2016-09-30 19:15 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-12 13:43 - 2016-10-12 13:43 - 00003150 _____ C:\WINDOWS\System32\Tasks\SmartDefrag_AutoAnalyze
2016-10-12 13:43 - 2016-10-12 13:43 - 00001182 _____ C:\Users\Public\Desktop\Smart Defrag 5.lnk
2016-10-12 13:43 - 2016-03-25 14:33 - 00128288 _____ (IObit) C:\WINDOWS\system32\IObitSmartDefragExtension.dll
2016-10-12 02:29 - 2016-09-30 19:22 - 07444312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-10-12 02:29 - 2016-09-30 02:55 - 25765376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-10-12 02:29 - 2016-09-30 01:25 - 02895360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-10-12 02:29 - 2016-09-30 01:25 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-10-12 02:29 - 2016-09-30 01:12 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-10-12 02:29 - 2016-09-30 01:09 - 06048256 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-10-12 02:29 - 2016-09-30 00:47 - 20306944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-10-12 02:29 - 2016-09-30 00:42 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-10-12 02:29 - 2016-09-30 00:41 - 01033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-10-12 02:29 - 2016-09-30 00:38 - 02286592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-10-12 02:29 - 2016-09-30 00:33 - 00724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-10-12 02:29 - 2016-09-30 00:33 - 00378880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-10-12 02:29 - 2016-09-30 00:32 - 00806912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-10-12 02:29 - 2016-09-30 00:32 - 00663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-10-12 02:29 - 2016-09-30 00:31 - 02131456 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-10-12 02:29 - 2016-09-30 00:21 - 15257088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-10-12 02:29 - 2016-09-30 00:17 - 02920960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-10-12 02:29 - 2016-09-30 00:12 - 04608512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-10-12 02:29 - 2016-09-30 00:11 - 00880640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-10-12 02:29 - 2016-09-30 00:06 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-10-12 02:29 - 2016-09-30 00:05 - 02055680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-10-12 02:29 - 2016-09-30 00:05 - 01544192 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-10-12 02:29 - 2016-09-30 00:05 - 00693248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-10-12 02:29 - 2016-09-30 00:03 - 13653504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-10-12 02:29 - 2016-09-29 23:54 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-10-12 02:29 - 2016-09-29 23:46 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-10-12 02:29 - 2016-09-29 23:43 - 01312768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-10-12 02:29 - 2016-09-29 23:42 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-10-12 02:29 - 2016-09-17 13:16 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
2016-10-12 02:29 - 2016-09-17 12:53 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2016-10-12 02:29 - 2016-09-17 12:21 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsmsext.dll
2016-10-12 02:29 - 2016-09-17 12:03 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2016-10-12 02:29 - 2016-09-17 12:02 - 01446400 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-10-12 02:29 - 2016-09-13 20:53 - 01663184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-10-12 02:29 - 2016-09-13 20:53 - 01523208 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-10-12 02:29 - 2016-09-13 20:53 - 01490112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-10-12 02:29 - 2016-09-13 20:53 - 01358952 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-10-12 02:29 - 2016-09-12 18:48 - 00085680 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-10-12 02:29 - 2016-09-12 17:03 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2016-10-12 02:29 - 2016-09-12 16:01 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2016-10-12 02:29 - 2016-09-09 09:17 - 04170752 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-10-12 02:29 - 2016-09-09 08:38 - 01629184 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00586752 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\centel.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-10-12 02:29 - 2016-09-08 15:41 - 00121176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2016-10-12 02:29 - 2016-09-08 09:00 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-10-12 02:29 - 2016-09-08 09:00 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-10-12 02:29 - 2016-09-07 17:07 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2016-10-12 02:29 - 2016-09-07 16:59 - 01754112 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-10-12 02:29 - 2016-09-07 16:59 - 01377792 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2016-10-12 02:29 - 2016-09-07 16:57 - 01560064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2016-10-12 02:29 - 2016-09-07 16:56 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-10-12 02:29 - 2016-08-31 12:22 - 03754496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2016-10-12 02:29 - 2016-08-31 11:33 - 02410496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2016-10-10 17:10 - 2016-10-10 17:10 - 00000000 ____D C:\Users\Dad\AppData\Roaming\0273
2016-10-10 17:10 - 2016-10-10 17:10 - 00000000 ____D C:\Users\Dad\AppData\Local\5b65
2016-10-07 21:36 - 2016-10-07 21:36 - 00344879 _____ C:\Users\Dad\Desktop\duplicates_20161007.d2fp
2016-10-07 20:42 - 2016-10-07 20:42 - 00533136 _____ C:\Users\Dad\Desktop\duplicates_20161007.dpfp
2016-10-07 20:18 - 2016-10-07 20:18 - 00001390 _____ C:\Users\Dad\Desktop\Duplicate Photo Finder Plus.lnk
2016-10-07 20:03 - 2016-10-07 20:18 - 00000000 ____D C:\Users\Dad\AppData\Local\TriSun_Software_Limited
2016-10-07 20:03 - 2016-10-07 20:03 - 00001378 _____ C:\Users\Dad\Desktop\Duplicate File Finder Plus.lnk
2016-09-29 17:39 - 2016-09-29 17:39 - 00001769 _____ C:\Users\Public\Desktop\iTunes.lnk
2016-09-29 17:39 - 2016-09-29 17:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-09-29 17:39 - 2016-09-29 17:39 - 00000000 ____D C:\Program Files\iTunes
2016-09-29 17:39 - 2016-09-29 17:39 - 00000000 ____D C:\Program Files\iPod
2016-09-24 10:33 - 2016-10-15 18:47 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-09-21 21:46 - 2016-09-21 21:46 - 00332644 _____ C:\Users\Dad\Desktop\45ed6h_5335874643p54ow64714e3.ged
2016-09-20 18:10 - 2016-09-20 18:10 - 00875720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00869576 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00678592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00536776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00029888 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00028352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aspnet_counters.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 15431168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 13317120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 09323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2016-09-20 18:08 - 2016-09-20 18:08 - 09323008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2016-09-20 18:08 - 2016-09-20 18:08 - 02896384 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 02537472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 02315496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01946176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01574912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2016-09-20 18:08 - 2016-09-20 18:08 - 01317888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00954880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00445765 _____ C:\WINDOWS\system32\ApnDatabase.xml
2016-09-20 18:08 - 2016-09-20 18:08 - 00420184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastapi.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastapi.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00162850 _____ C:\WINDOWS\SysWOW64\C_932.NLS
2016-09-20 18:08 - 2016-09-20 18:08 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS
2016-09-20 18:08 - 2016-09-20 18:08 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\parport.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwififlt.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifibus.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serenum.sys
2016-09-20 18:07 - 2016-09-20 18:07 - 22360288 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 19789232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 14466560 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 12879360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02881536 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02778624 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02755504 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-09-20 18:07 - 2016-09-20 18:07 - 02463744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02411048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-09-20 18:07 - 2016-09-20 18:07 - 01049600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\RestoreOptIn.exe
2016-09-20 18:07 - 2016-09-20 18:07 - 00113656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RestoreOptIn.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-10-15 18:48 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\Help
2016-10-15 18:07 - 2016-07-21 13:26 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-10-15 17:50 - 2014-10-08 10:40 - 00000000 ____D C:\Users\Dad\AppData\Local\NPE
2016-10-14 23:08 - 2015-02-18 10:06 - 00003598 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-968235783-2654321925-1125524309-1000
2016-10-14 22:32 - 2016-08-28 23:26 - 00002286 _____ C:\Users\Public\Desktop\Advanced SystemCare 9.lnk
2016-10-14 22:32 - 2015-05-04 19:51 - 01279488 ___SH C:\Users\Dad\Desktop\Thumbs.db
2016-10-14 22:27 - 2015-02-25 12:30 - 00000000 ____D C:\Users\DefaultAppPool
2016-10-14 22:24 - 2016-08-28 23:26 - 00000242 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_Dad.job
2016-10-14 20:29 - 2013-12-08 07:56 - 00000000 ____D C:\ProgramData\ProductData
2016-10-14 13:26 - 2015-10-27 10:11 - 00000000 ____D C:\WINDOWS\System32\Tasks\Remediation
2016-10-13 20:38 - 2012-06-19 17:09 - 00007642 _____ C:\Users\Dad\AppData\Local\resmon.resmoncfg
2016-10-13 20:25 - 2015-02-18 10:20 - 00000558 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000.job
2016-10-13 20:25 - 2013-08-22 09:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-10-13 20:24 - 2015-02-18 23:46 - 00000000 ____D C:\ProgramData\NVIDIA
2016-10-13 20:24 - 2013-08-22 09:44 - 00498224 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-10-13 20:24 - 2012-05-16 20:04 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-10-13 20:23 - 2011-10-27 05:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-10-13 20:21 - 2015-02-18 19:12 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-10-13 20:21 - 2014-11-21 11:17 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2016-10-13 19:42 - 2012-07-26 02:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-10-13 19:41 - 2013-07-28 13:36 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-10-13 19:29 - 2012-02-26 15:59 - 143495576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-10-13 19:27 - 2012-05-16 20:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-10-13 16:33 - 2012-04-28 20:39 - 00000000 ____D C:\Users\Dad\AppData\Local\CrashDumps
2016-10-13 10:22 - 2015-11-30 11:41 - 00003472 _____ C:\WINDOWS\System32\Tasks\ReclaimerUpdateXML_Dad
2016-10-13 10:22 - 2015-11-29 07:41 - 00003478 _____ C:\WINDOWS\System32\Tasks\ReclaimerUpdateFiles_Dad
2016-10-13 10:21 - 2015-05-08 01:18 - 00003542 _____ C:\WINDOWS\System32\Tasks\MotoCast Update
2016-10-13 10:21 - 2015-05-08 01:18 - 00003518 _____ C:\WINDOWS\System32\Tasks\MotoHelper Update
2016-10-13 10:21 - 2015-02-11 05:44 - 00003412 _____ C:\WINDOWS\System32\Tasks\RealDownloader Update Check
2016-10-13 10:21 - 2014-12-15 15:58 - 00003546 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:21 - 2014-12-14 00:42 - 00003350 _____ C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:21 - 2014-12-14 00:42 - 00003212 _____ C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:21 - 2014-11-19 11:36 - 00003190 _____ C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:16 - 2012-04-28 20:58 - 00000000 ____D C:\temp
2016-10-12 13:43 - 2016-07-21 13:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag
2016-10-11 16:20 - 2013-08-22 08:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2016-10-10 17:18 - 2015-05-20 08:18 - 146112512 _____ C:\WINDOWS\system32\config\SOFTWARE.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 07364608 _____ C:\WINDOWS\system32\config\DRIVERS.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 00778240 _____ C:\WINDOWS\system32\config\DEFAULT.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 00065536 _____ C:\WINDOWS\system32\config\SAM.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 00036864 _____ C:\WINDOWS\system32\config\SECURITY.iodefrag.bak
2016-10-10 07:44 - 2012-04-28 21:03 - 00000000 ____D C:\Users\Dad\AppData\Roaming\IObit
2016-10-10 00:38 - 2015-03-21 22:50 - 00063488 ___SH C:\Users\Dad\Downloads\Thumbs.db
2016-10-10 00:30 - 2014-11-21 03:43 - 00994144 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-10-10 00:30 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\Inf
2016-10-07 20:18 - 2016-07-02 10:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSSI
2016-10-07 20:18 - 2016-07-02 10:32 - 00000000 ____D C:\Program Files (x86)\TSSI
2016-10-05 21:47 - 2013-10-12 02:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2016-10-03 03:31 - 2012-07-26 03:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-10-03 03:30 - 2013-10-29 10:57 - 00000838 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-10-01 03:29 - 2012-04-28 21:22 - 00000000 ____D C:\Users\Dad\.frostwire5
2016-09-30 02:06 - 2015-02-18 23:53 - 00000000 ____D C:\Users\Dad
2016-09-29 17:39 - 2016-05-20 18:58 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-09-28 20:19 - 2015-03-02 04:23 - 00000000 ____D C:\WINDOWS\system32\Drivers\NSBUx64
2016-09-27 18:46 - 2016-08-18 06:12 - 00001143 _____ C:\Users\Dad\Desktop\MyHeritage Family Tree Builder.lnk
2016-09-27 18:46 - 2012-04-29 11:23 - 00000000 ____D C:\Program Files (x86)\MyHeritage
2016-09-26 13:43 - 2010-08-15 18:49 - 00000000 ____D C:\Users\Dad\Documents\MyHeritage
2016-09-26 09:52 - 2012-04-28 19:49 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-09-26 09:51 - 2013-08-22 10:36 - 00000000 ___RD C:\WINDOWS\ToastData
2016-09-26 09:27 - 2015-02-18 23:53 - 00000000 ____D C:\Users\Administrator
2016-09-26 03:12 - 2012-04-29 11:15 - 00000000 ____D C:\Program Files (x86)\Palm
2016-09-26 00:47 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-09-26 00:47 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-09-26 00:47 - 2012-04-28 19:49 - 00003744 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-09-24 13:06 - 2012-05-26 08:27 - 00007627 _____ C:\WINDOWS\wininit.ini
2016-09-21 20:54 - 2014-10-14 13:50 - 00000000 ____D C:\Program Files\thinkorswim
2016-09-21 20:54 - 2013-07-01 16:32 - 00000000 ____D C:\Users\Dad\.thinkorswim
2016-09-21 20:04 - 2015-03-25 00:07 - 00000000 ____D C:\Users\Dad\AppData\LocalLow\WebEx
2016-09-21 20:04 - 2011-01-26 21:03 - 00000000 __SHD C:\Users\Dad\Documents\cache
2016-09-17 06:30 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-09-16 01:34 - 2013-08-22 10:36 - 00000000 ___HD C:\Program Files\WindowsApps

==================== Files in the root of some directories =======

2014-03-22 00:17 - 2014-03-22 00:17 - 0003754 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2012-02-26 16:48 - 2016-05-14 03:00 - 21572120 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2013-05-08 08:39 - 2013-05-08 08:39 - 0000000 _____ () C:\Users\Dad\AppData\Roaming\SharedSettings.ccs
2012-05-05 22:19 - 2012-05-05 22:19 - 0019329 _____ () C:\Users\Dad\AppData\Roaming\UserTile.png
2014-05-13 01:21 - 2014-10-06 18:35 - 0000059 _____ () C:\Users\Dad\AppData\Roaming\WB.CFG
2013-05-12 07:17 - 2013-05-12 07:17 - 0045967 _____ () C:\Users\Dad\AppData\Local\amapeoch
2012-04-29 17:13 - 2016-01-05 06:32 - 0005120 _____ () C:\Users\Dad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-12-30 20:47 - 2012-12-30 20:47 - 0000036 _____ () C:\Users\Dad\AppData\Local\housecall.guid.cache
2012-06-19 17:15 - 2012-06-19 17:18 - 0000000 _____ () C:\Users\Dad\AppData\Local\null
2012-06-19 17:09 - 2016-10-13 20:38 - 0007642 _____ () C:\Users\Dad\AppData\Local\resmon.resmoncfg
2015-02-18 23:46 - 2015-02-18 23:46 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
====================
C:\Users\Dad\DesktopLSPFix.exe
C:\Users\Dad\DesktopSafeMSI.exe
C:\Users\Dad\DesktopWinsockxpFix.exe
C:\Users\Dad\hpothb07.dat
C:\Users\Dad\jobq.dat


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-18 23:44

==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-10-2016
Ran by [removed] (15-10-2016 21:44:22)
Running from C:\Users\[removed]\Desktop
Windows 8.1 Pro (Update) (X64) (2015-02-19 08:35:50)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-968235783-2654321925-1125524309-500 - Administrator - Enabled) => C:\Users\Administrator
Dad (S-1-5-21-968235783-2654321925-1125524309-1000 - Administrator - Enabled) => C:\Users\Dad
Guest (S-1-5-21-968235783-2654321925-1125524309-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Security (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: IObit Malware Fighter (Disabled - Out of date) {4D381C57-3C7A-6F22-07EB-639F49E836D4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
AS: Norton Security (Disabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton Security (Disabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

ABBYY FineReader 6.0 Sprint (HKLM-x32\…\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House)
Acoustica MP3 CD Burner (HKLM-x32\…\Acoustica MP3 CD Burner) (Version:  - Acoustica, Inc)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.017.20053 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 20.0.0.260 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.162 - Adobe Systems Incorporated)
Advanced SystemCare 9 (HKLM-x32\…\Advanced SystemCare_is1) (Version: 9.4.0 - IObit)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Audacity 2.0.2 (HKLM-x32\…\Audacity_is1) (Version: 2.0.2 - Audacity Team)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bonjour (HKLM\…\{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}) (Version: 2.0.2.0 - Apple Inc.)
Bonjour Print Services (HKLM\…\{0DA20600-6130-443B-9D4B-F30520315FA6}) (Version: 2.0.2.0 - Apple Inc.)
Build-a-lot 4 - Power Source (x32 Version: 2.2.0.97 - WildTangent) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.22 - Piriform)
Chord Pickout 3.0 (HKLM-x32\…\Chord Pickout 3.0) (Version: 3.0 - ChordPickout.com)
Chronicles of Albian (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cisco WebEx Meetings (HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Citrix Online Launcher (HKLM-x32\…\{1EFF9E6C-76E1-43F9-81FB-BC8C037B0902}) (Version: 1.0.258 - Citrix)
Cradle of Rome 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
CyberLink MediaEspresso (HKLM-x32\…\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1720_38230 - CyberLink Corp.)
CyberLink PowerDirector 13 (HKLM-x32\…\{BA385AFC-00B1-417C-8C20-74B996EF3AF0}) (Version: 13.0.2104.0 - CyberLink Corp.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.3313.52 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DriverTuner 3.1.0.1 (HKLM-x32\…\{520C1D80-935C-42B9-9340-E883849D804F}_is1) (Version: 3.1.0.1 - LionSea SoftWare)
Duplicate File Finder Plus 5.0 (HKLM-x32\…\Duplicate File Finder Plus_is1) (Version:  - TriSun Software Inc.)
Duplicate Photo Finder Plus 4.0 (HKLM-x32\…\Duplicate Photo Finder Plus_is1) (Version:  - TriSun Software Inc.)
eBay Worldwide (HKLM-x32\…\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
Epson Copy Utility 3.4 (HKLM-x32\…\{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}) (Version: 3.4.0.0 - )
EPSON GT-1500 User's Guide (HKLM-x32\…\Silent Package Run-Time Sample) (Version:  - )
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON Scan PDF EXtensions (HKLM-x32\…\{F9956472-6E16-4F83-BF9A-F887EF4A45B7}) (Version: 1.00.0000 - SEIKO EPSON Corp.)
EpsonNet Config V4 (HKLM-x32\…\{08013FB5-DF8B-4D29-9B5E-B3DE88EBA6CA}) (Version: 4.5.4 - SEIKO EPSON CORPORATION)
Etron USB3.0 Host Controller (x32 Version: 0.103 - Etron Technology) Hidden
FamilySearch Indexing 3.27.7 (HKLM-x32\…\0591-8077-9297-0833) (Version: 3.27.7 - FamilySearch)
ffdshow [rev 2527] [2008-12-19] (HKLM-x32\…\ffdshow_is1) (Version: 1.0 - )
File Association Helper (HKLM\…\{572D0504-2C67-4016-801F-D70879A3026A}) (Version: 1.1.6.53763 - WinZip Computing International, LLC)
File Association Manager (HKLM-x32\…\FileAssociationManager) (Version: 0.7 - Amnis Technology Ltd)
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
FrostWire 6.3.4 (HKLM-x32\…\FrostWire 6) (Version: 6.3.4.194 - FrostWire LLC)
Galerie de photos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Gateway Games (HKLM-x32\…\WildTangent gateway Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Gateway Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3502 - Gateway Incorporated)
Gateway Registration (HKLM-x32\…\Gateway Registration) (Version: 1.04.3503 - Gateway Incorporated)
Gateway ScreenSaver (HKLM-x32\…\Gateway Screensaver) (Version: 1.1.0225.2011 - Gateway Incorporated)
Gateway Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3500 - Gateway Incorporated)
Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\…\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
GoToMeeting 7.1.0.2352 (HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\GoToMeeting) (Version: 7.1.0.2352 - CitrixOnline)
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden
Hard Disk Sentinel PRO (HKLM-x32\…\Hard Disk Sentinel_is1) (Version:  - HDS)
Hotkey Utility (HKLM-x32\…\Hotkey Utility) (Version: 2.05.3505 - Gateway Incorporated)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3501 - Gateway Incorporated)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2353 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
IObit Malware Fighter 4 (HKLM-x32\…\IObit Malware Fighter_is1) (Version: 4.2 - IObit)
IObit Uninstaller (HKLM-x32\…\IObitUninstall) (Version: 5.4.0.125 - IObit)
ISIS Driver - EPSON GT-1500 v1.6.10802.6001 (HKLM-x32\…\{D41864EF-CC5D-4CF4-B0B9-CA3152164157}) (Version: 1.6.10802.6001 - EMC Captiva)
iTunes (HKLM\…\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.)
Java 8 Update 102 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F64180102F0}) (Version: 8.0.1020.14 - Oracle Corporation)
Jewel Match 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
K9 (HKLM-x32\…\K9) (Version:  - )
KODAK Share Button App (HKLM-x32\…\{F5930CDE-2FF5-4A8D-9DBD-3177C816D4A9}) (Version: 4.06.0015.0313 - Eastman Kodak Company)
LastPass (uninstall only) (HKLM-x32\…\LastPass) (Version:  - LastPass)
Logitech Harmony Remote Software 7 (HKLM-x32\…\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech)
Logitech SetPoint 6.65 (HKLM\…\sp6) (Version: 6.65.62 - Logitech)
MailWasherPro (HKLM-x32\…\{A5901025-525B-4B2A-ACF4-E742D989D008}) (Version: 7.8 - Firetrust)
MailWasherPro (HKLM-x32\…\{DE507F73-E58C-4291-BA6B-F2E7FD386E7E}) (Version: 1.20.0 - Firetrust)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MEGAsync (HKLM-x32\…\MEGAsync) (Version:  - Mega Limited)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\OneDriveSetup.exe) (Version: 17.3.6201.1019 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\…\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MotoCast (HKLM-x32\…\{5401CEE8-3C2D-4835-A802-213306537FF4}) (Version: 1.2.7 - Motorola Mobility)
MotoHelper 2.1.40 Driver 5.5.0 (HKLM-x32\…\MotoHelper) (Version: 2.1.40 - Motorola)
MotoHelper MergeModules (x32 Version: 1.2.0 - Motorola) Hidden
MOTOROLA MEDIA LINK (x32 Version: 1.7.0147.0 - Motorola) Hidden
Motorola Mobile Drivers Installation 5.5.0 (Version: 5.5.0 - Motorola Inc.) Hidden
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MozBackup 1.5.1 (HKLM-x32\…\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 49.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 49.0.1 (x86 en-US)) (Version: 49.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 49.0.1.6109 - Mozilla)
Mozilla Thunderbird 24.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Thunderbird 24.0.1 (x86 en-US)) (Version: 24.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyHeritage Family Tree Builder (HKLM-x32\…\Family Tree Builder) (Version: 8.0.0.8333 - MyHeritage.com)
Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
NewBlue Video Essentials for Windows (HKLM-x32\…\NewBlue Video Essentials for Windows) (Version: 3.0 - NewBlue)
Norton Management (HKLM-x32\…\MCLIENT) (Version: 3.2.2.12 - Symantec Corporation)
Norton Security with Backup (HKLM-x32\…\NSBU) (Version: 22.7.1.32 - Symantec Corporation)
NVIDIA 3D Vision Controller Driver 364.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 364.44 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 368.39 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 368.39 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.11.3.5 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.11.3.5 - NVIDIA Corporation)
NVIDIA Graphics Driver 368.39 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 368.39 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.14 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.14 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
Palm Desktop by ACCESS (HKLM-x32\…\{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}) (Version: 6.4.0.0 - Palm, Inc.)
PaperPort Image Printer 64-bit (HKLM\…\{ABA4FAF1-6389-45F9-92CE-3914A4E5C471}) (Version: 1.00.0000 - Nuance Communications, Inc.)
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
Prerequisite installer (x32 Version: 15.0.0005 - Nero AG) Hidden
QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
RealDownloader (x32 Version: 17.0.15.4 - RealNetworks, Inc.) Hidden
RealDownloader (x32 Version: 17.0.15.7 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2005 Runtime (x32 Version: 8.0 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\…\RealPlayer 17.0) (Version: 17.0.15 - RealNetworks)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7746 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
RootsMagic 6.3.0.4 (HKLM-x32\…\{94433E0D-764C-4964-AD0B-EC46BCA7E68E}_is1) (Version: RootsMagic 6.3.0.4 - RootsMagic, Inc.)
ScanSoft PaperPort 11 (HKLM-x32\…\{DEA18FF6-D84A-4242-9663-692E5BA56805}) (Version: 11.1.0000 - Nuance Communications, Inc.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.11.3.5 - NVIDIA Corporation) Hidden
Smart Defrag 5 (HKLM-x32\…\Smart Defrag_is1) (Version: 5.3.0 - IObit)
Software Informer 1.2 (HKLM\…\Software Informer_is1) (Version:  - Informer Technologies, Inc.)
Start Menu 8 (HKLM-x32\…\IObit_StartMenu8_is1) (Version: 3.1.0.3 - IObit)
Surfing Protection (HKLM-x32\…\IObit Surfing Protection_is1) (Version: 1.3 - IObit)
thinkorswim (HKLM\…\9968-4488-2169-7623) (Version: desktop - thinkorswim, Inc)
Torchlight (x32 Version: 2.2.0.97 - WildTangent) Hidden
Torrents Downloader (HKLM-x32\…\{6D9D814E-9605-11E2-80DC-95A26188709B}_is1) (Version: 0.3.20.14.06.30.-W.32 - Torrent Software S.L.)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
USB-Ir Adapter (HKLM-x32\…\{00F3D43F-B5A9-4C8D-B5A1-5FD2DE16CC21}) (Version: 1.03.0000 - )
USB-Ir Adapter (HKLM-x32\…\{76AD2AAC-14EE-4CE3-958A-BB3DF65E7F06}) (Version: 1.03.0000 - )
Verizon Cloud (HKLM\…\Verizon Cloud) (Version: 15.3.7.9 - Verizon)
Video Downloader (x32 Version: 1.0.0 - RealNetworks) Hidden
Virtual Villagers 5 - New Believers (x32 Version: 2.2.0.97 - WildTangent) Hidden
Vulkan Run Time Libraries 1.0.11.1 (HKLM\…\VulkanRT1.0.11.1-2) (Version: 1.0.11.1 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.11.1 (Version: 1.0.11.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.5.1 (HKLM\…\VulkanRT1.0.5.1) (Version: 1.0.5.1 - LunarG, Inc.)
WD My Cloud (HKLM-x32\…\WD My Cloud) (Version: 1.0.2.34 - Western Digital Technologies, Inc.)
WD Quick View (HKLM-x32\…\{F4F2EF32-EAFE-4F87-B7DC-E19C9F8E76FC}) (Version: 2.4.16.16 - Western Digital Technologies, Inc.)
WD SmartWare Installer (HKLM-x32\…\{4555885d-a64c-4234-9aac-72a8a6b5590b}) (Version: 2.4.16.16 - Western Digital Technologies, Inc.)
WebEx Support Manager for Internet Explorer (HKLM-x32\…\{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}) (Version: 6.5.47 - WebEx Communications Inc.)
Welcome Center (HKLM-x32\…\Gateway Welcome Center) (Version: 1.02.3504 - Gateway Incorporated)
WildTangent Games App (Gateway Games) (x32 Version: 4.0.5.14 - WildTangent) Hidden
Windows 10 Upgrade Assistant (HKLM-x32\…\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17332 - Microsoft Corporation)
Windows Driver Package - Eastman Kodak KODAK Digital Camera (01/29/2010 1.4.1.0) (HKLM\…\3D970B9F930E7AAE23C06D39A1AC98548C90B442) (Version: 01/29/2010 1.4.1.0 - Eastman Kodak)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 4.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinZip 18.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
WinZip Courier (HKLM-x32\…\{CD95F661-A5C4-11AF-B2CC-ABCD21A326A2}) (Version: 5.0.10661 - WinZip Computing, S.L. )
Wise Care 365 3.14 (HKLM-x32\…\Wise Care 365_is1) (Version: 3.14 - WiseCleaner.com, Inc.)
WorkForce GT-1500 Scanner Driver Update (HKLM-x32\…\{37D0F29D-AB95-4598-ACF0-D3CC38C161D9}) (Version:  - )
Yahoo! Messenger (HKLM-x32\…\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Zuma's Revenge (x32 Version: 2.2.0.97 - WildTangent) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-968235783-2654321925-1125524309-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Dad\AppData\Local\Citrix\GoToMeeting\2331\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0000B919-F681-4B54-828F-98EE446A4ABE} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {02AC57F2-B024-4079-B1EE-14F764046DD2} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {0452FD84-596C-44EC-BEF2-71F711B297BD} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {0A3A7074-ECAE-4E35-81AB-E8B0C570B05C} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Security with Backup\Engine\22.7.1.32\WSCStub.exe [2016-08-16] (Symantec Corporation)
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {0E1BE2DA-6B04-4C0A-B88E-9892DED632DD} - System32\Tasks\Norton Management\Norton Error Processor => C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\SymErr.exe [2012-10-18] (Symantec Corporation)
Task: {0F5B218F-1397-4BAC-8139-CFBB8A75D270} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-10-13] (Microsoft Corporation)
Task: {114E4F3E-9481-4827-8DD8-098B1EE15160} - System32\Tasks\Microsoft\Windows\PLA\System\{D3F84E41-38E7-46AD-9900-AC7AFDBF649A}_System Diagnostics => Rundll32.exe C:\Windows\system32\pla.dll,PlaHost "system\System Diagnostics" "$(Arg0)"
Task: {11711B8D-58D9-4599-BC56-17C832D3E1F4} - System32\Tasks\{878F1772-4AB7-44C8-BEB0-17F67BA8F7CA} => pcalua.exe -a C:\Epson\epson13550.exe -d C:\Epson
Task: {11FE180B-FF6A-4AA3-AF05-DF1C3FE8D817} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {144311FC-9410-4E32-96AA-97F469BD120B} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {17EDF0D1-6307-4E85-AB56-050EC420AC33} - System32\Tasks\RealDownloader Update Check => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [2014-10-29] ()
Task: {1A84DA6E-3F71-46B2-961D-D949C179BF2A} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {1C5113A8-3C8C-459C-9826-1DEA57F176C0} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2011-05-20] (CyberLink)
Task: {1CC1E9F4-2D54-442C-A480-569C303C44D1} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1010 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {1DACEE27-B4FC-4264-9829-71E3CBB4CBAE} - no filepath
Task: {1DF4F4A1-A69E-43E5-B6D5-05EF513C2DED} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\WINDOWS\system32\MRT.exe [2016-10-13] (Microsoft Corporation)
Task: {1E3D9FA5-76C4-4D0D-A79E-0724A29ADB5D} - System32\Tasks\Norton Security with Backup\Norton Error Analyzer => C:\Program Files (x86)\Norton Security with Backup\Engine\22.7.1.32\SymErr.exe [2016-05-23] (Symantec Corporation)
Task: {1E528A5A-342B-4C03-ACB6-810E496E8447} - System32\Tasks\{AE11724B-E59B-4B45-894D-D535ADF6C133} => pcalua.exe -a "C:\Program Files (x86)\Palm\Instapp.exe" -d "C:\Program Files (x86)\Palm\"
Task: {2391896C-BD42-4A39-9D96-EB2F89677607} - \SpeedFixToolPro_Popup -> No File <==== ATTENTION
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {242751DA-0C0A-4A97-AA54-4CFD90B25AB4} - System32\Tasks\Western Digital\SmartWare\____Volume_04d58046_2adf_11e1_adc2_806e6f6e6963__uuid_73656761_7465_7375_636b_0090a9beb7c2_Public_ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [2016-04-19] (Western Digital Technologies, Inc.)
Task: {276D15C3-17FA-4825-B06A-C04C60347642} - System32\Tasks\{84AA05B6-6C14-4B5A-BEAF-0D8C5D21DD85} => c:\Program Files\Microsoft Mouse and Keyboard Center\MouseKeyboardCenter.exe [2014-03-19] (Microsoft)
Task: {28BB85C9-E3D1-4567-A96E-1357A29470CD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-26] (Piriform Ltd)
Task: {294CB615-3543-4A98-9133-AB13C523F020} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {2AA350E3-9DF3-4311-86BD-8DCD140C9AC1} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {2DC0DDCC-0466-41A5-AE99-441EC497D78B} - System32\Tasks\ASC9_SkipUac_Dad => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-07-28] (IObit)
Task: {2FAA420C-2E2E-4530-AAF3-29437EA8A24F} - System32\Tasks\Driver Booster SkipUAC (Dad) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {30027EC5-B21F-4253-8B7E-84C60B0AE351} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {34160783-C4B4-4131-A34C-3FE5AC7434FF} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_Dad => C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe [2016-06-27] (H.D.S. Hungary)
Task: {345CA5BD-637C-4286-8D4E-6E11708052E6} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {359BB32E-A5DD-4CE1-B97F-69E59599E51A} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {386DB6E6-C842-434E-844F-23C5836DB2C2} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: {39C23A6D-6A73-4BB5-90C1-5BFC6B6919D7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {3CC7F30A-D22F-4A08-9D5F-F5F350B1C494} - System32\Tasks\Driver Booster Beta SkipUAC (Dad) => C:\Program Files (x86)\IObit\Driver Booster Beta\4.0.0\DriverBooster.exe
Task: {3E73DCFF-BF83-461B-9914-11880482FD22} - System32\Tasks\ReclaimerUpdateFiles_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {42BBA90C-92ED-4149-B918-0052E6BD1577} - System32\Tasks\{ABFB8086-32AB-48C7-AF44-CF3D1D8B6D36} => pcalua.exe -a C:\Nero\InCD-4.3.23.2.exe -d C:\Nero
Task: {42CE7EA5-D19C-4435-B796-0926121BAE50} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {479E6178-61D5-40D4-9A36-74FB1583003C} - System32\Tasks\MotoHelper Update => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {4AB21BBA-76B5-45E7-B69C-15DCF95F9310} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-26] (Adobe Systems Incorporated)
Task: {4D6CC432-3EF3-4ECC-9481-75AC4FE09D1A} - System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe => c:\Program Files\Microsoft Device Center\devicecenter.exe
Task: {4EDE0CF4-0D42-4C97-8F1B-2EE6EEE3187B} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: {5256830D-EF5F-4A2B-941C-4BAD9F3951D6} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1010 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {5856FC30-B706-4C98-BADA-9BD645B28BD8} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => C:\Windows\system32\GWX\GWX.exe
Task: {5B9334BA-ADC4-42A2-AE8B-719BC03B420C} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {5C7BDB02-B3E2-4C28-816E-2B91D7CE9859} - System32\Tasks\{F850ED23-C3D5-43F2-B9BC-A17167885D9D} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\7-Zip\7zFM.exe"
Task: {5DEB5A0E-094E-4E20-8C09-BD825E9A1FC9} - System32\Tasks\Norton Management\Norton Error Analyzer => C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\SymErr.exe [2012-10-18] (Symantec Corporation)
Task: {5F677AB0-DAB6-4B75-A2E9-D78FD384693D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-06-25] (Adobe Systems Incorporated)
Task: {66FA5938-862D-4D97-A64D-72AA0D340F50} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {69C7CF9C-020F-455A-BFE5-B63071BF9F28} - System32\Tasks\{DC3256B7-E258-4B58-9048-51D7DF51E46D} => pcalua.exe -a C:\Users\Dad\Desktop\jxpiinstall(1).exe -d C:\Users\Dad\Desktop
Task: {6F66763A-0B81-4E57-A300-19F36FC0AAC6} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => C:\Windows\system32\GWX\GWX.exe
Task: {723EB32C-4249-4787-8FE2-DF4260DFC146} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-10-26] (RealNetworks, Inc.)
Task: {72E5255E-0875-4813-B09F-FD232A5545EC} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {7467BB5D-28DD-4CFC-8316-E86266BAE878} - System32\Tasks\Microsoft\Windows\PLA\System\{950FE130-0326-4B76-9EA5-5F813F013A59}_System Diagnostics => Rundll32.exe C:\WINDOWS\system32\pla.dll,PlaHost "system\System Diagnostics" "$(Arg0)"
Task: {7910552E-EC04-4FC5-B158-74F97FDA1A23} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe
Task: {7AD4753A-5075-4846-B933-4FB4D8937816} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {7B5D1C74-AD6F-4715-9569-70787F9F544A} - System32\Tasks\{0B4A356D-228A-48A1-81FD-F42244C76E1F} => pcalua.exe -a C:\Users\Dad\Desktop\express_hd-en_2_5_113.exe -d C:\Users\Dad\Desktop
Task: {7B7CCB54-D476-4970-9F70-4F8CF79F5DA3} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d => C:\Windows\system32\GWX\GWX.exe
Task: {7BA72C5F-C9AC-4337-B4A7-9BB93D64A48C} - System32\Tasks\SmartDefrag_Update => C:\Program Files (x86)\IObit\Smart Defrag\AutoUpdate.exe [2016-07-22] (IObit)
Task: {7D4EC411-2076-41FE-B5A7-45F5FB1DC365} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {8147216B-D7D4-490C-8A57-C99E8CB09673} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {882E042B-1F64-49CC-9971-1446C9CCA820} - \SpeedFixToolPro_Start -> No File <==== ATTENTION
Task: {8B104B20-7279-4527-B8FB-1F367A544526} - System32\Tasks\Norton Security with Backup\Norton Error Processor => C:\Program Files (x86)\Norton Security with Backup\Engine\22.7.1.32\SymErr.exe [2016-05-23] (Symantec Corporation)
Task: {8C1FDF72-5716-404C-B64A-9CF4450B9BF6} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {8D5A910C-0A75-466E-87E2-1E77B48E40F8} - \Search-Protect -> No File <==== ATTENTION
Task: {8E3881FC-2D20-4276-8719-5E57F9876ABD} - System32\Tasks\{8AAFB465-D710-49A0-817A-25ED1D61B1E1} => pcalua.exe -a "C:\Program Files (x86)\Uniblue\RegistryBooster\rb_track_install.exe" -d "C:\Program Files (x86)\Uniblue\RegistryBooster"
Task: {8F0AA531-EDA2-47FF-B91C-98451EAFB836} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {8F13BC62-989B-4551-87BC-4E7897041568} - System32\Tasks\{D3EEF7C1-ABB2-4C4B-94F8-D9157D801C1E} => pcalua.exe -a "C:\Program Files (x86)\IObit\Advanced SystemCare 7\SecurityHole_Backup\KB2565063.exe" -d C:\Windows\system32 -c /quiet /norestart
Task: {94D5C23E-FB1A-49F1-907F-77177B3FA04B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {95BF0CE7-962C-4DEC-92CB-3421FD1F41C5} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {97CF5DD5-A51D-41AE-87C5-B4FD1F358C70} - System32\Tasks\ReclaimerUpdateXML_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {9B759EA6-A5AB-47ED-8CEE-3E62986F7726} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {9D2278A7-7FCF-46A4-81CA-5BB6EE5C9CB8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-24] (Google Inc.)
Task: {9E4C23AE-F294-4C05-B2F5-E00DE40A3AB4} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {9ECAC80C-95F1-4ECD-ADF7-43BD5D0E0B32} - System32\Tasks\SmartDefrag_AutoAnalyze => C:\Program Files (x86)\IObit\Smart Defrag\AutoDefrag.exe [2016-06-06] (IObit)
Task: {A177F73F-F74D-4AA2-A139-C5B522356209} - System32\Tasks\{C3CFB6E9-48A8-448F-AC01-70C101A5A0E5} => pcalua.exe -a C:\Users\Dad\Desktop\epson15561(1).exe -d C:\Users\Dad\Desktop
Task: {A2EB1708-4F29-4422-94E5-BF8A52F09C39} - System32\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000 => C:\Users\Dad\AppData\Local\Citrix\GoToMeeting\2352\g2mupdate.exe [2015-02-18] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {A52BB76E-951C-44F6-9E6D-7C8BD394218A} - System32\Tasks\{1EAA833A-9F24-413E-83E1-D7BE01CAFE79} => pcalua.exe -a "C:\Users\Dad\Desktop\Logitech 650HarmonyRemote7.7.0-WIN-x86.exe" -d C:\Users\Dad\Desktop
Task: {A65A0ACC-6A4D-474C-AAF2-E9DC6B09F05D} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {A94B86DD-CE9B-4D06-A8AB-0C4B044C56EA} - System32\Tasks\{9305B88E-04F4-4F7A-9EFA-3AB702618F79} => pcalua.exe -a D:\ENGLISH\QuikProtect\Setup.exe -d D:\ENGLISH\QuikProtect
Task: {A94EEAAD-AE37-4457-AB00-3E4F6390C8DE} - System32\Tasks\RNUpgradeHelperLogonPrompt_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {AF48D3C4-5B0D-4996-B1CE-CFFF8BAE74FC} - System32\Tasks\Western Digital\SmartWare\____Volume_04d58046_2adf_11e1_adc2_806e6f6e6963__uuid_73656761_7465_7375_636b_0090a9beb7c2_TimeMachineBackup_ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [2016-04-19] (Western Digital Technologies, Inc.)
Task: {AF88EC42-CB3E-4DAE-B2BF-0E5D68C42DF8} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Security\Upgrade.exe [2016-08-16] (Symantec Corporation)
Task: {BB5AE570-FDF9-4C37-B44E-B9F39C1E63E6} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BF1E8827-83C9-4066-B1C2-56BF616DF716} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {C3455D9F-F7A1-4DAE-A80D-2136FE0043CB} - System32\Tasks\ASC9_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [2016-07-20] (IObit)
Task: {C68402F4-E0DA-4AA7-B68A-15F0283429C0} - System32\Tasks\Uninstaller_SkipUac_Dad => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-06-24] (IObit)
Task: {CA5940DB-9B00-4239-A48A-141A2DC19AD9} - System32\Tasks\{70A11D50-D1CE-459B-94C3-BE1540DB15AD} => pcalua.exe -a C:\Users\Dad\Desktop\wlsetup-web(1).exe -d C:\Users\Dad\Desktop
Task: {CB61031D-4459-4488-9042-C51BB29A381E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-24] (Google Inc.)
Task: {CC0868F1-E784-47FE-A5EB-312211866188} - System32\Tasks\{5C717479-B68F-4619-B051-07EABCEA176C} => pcalua.exe -a "C:\Users\Dad\Downloads\free audio recorder setup.exe" -d C:\Users\Dad\Downloads
Task: {CE300405-17AE-40F2-BEE2-D1E8D174F0E4} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {D0BCBD01-C1BF-4E62-B01F-0738BB5FBB49} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {D2DBB9FC-AC9E-4473-BC14-F2805315AB36} - System32\Tasks\{AB7ACF4B-2835-47BB-976D-DA349FE5359A} => pcalua.exe -a C:\Users\Dad\Desktop\Acoustica-MP3-CD-Burner-Installer(1).exe -d C:\Users\Dad\Desktop
Task: {D836BFE8-AD65-4CC5-A20D-3B17B0A73E4F} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {D91E354B-9EF5-4BD4-9D80-D4DD8828601C} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Time-5d => C:\Windows\system32\GWX\GWX.exe
Task: {D99F0BF7-5D39-41D3-9378-4A4C4C48BB39} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe
Task: {DBED9451-604E-4D9E-BC25-B290D74851D1} - no filepath
Task: {DC0C82C1-5196-4B60-85C8-FB595D65F815} - System32\Tasks\{F0AA062F-A811-4913-8616-1586C4C104AB} => pcalua.exe -a "D:\WD SmartWare\dotnetfx35.exe" -d "D:\WD SmartWare"
Task: {DE3860C3-6209-4467-9CB2-4DCE6E38340E} - System32\Tasks\RNUpgradeHelperResumePrompt_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {DE7937FD-028A-4235-9D43-74C9D4D54A7D} - System32\Tasks\SmartDefrag_Startup => C:\Program Files (x86)\IObit\Smart Defrag\SmartDefrag.exe [2016-09-26] (IObit)
Task: {DF865F82-3A48-4EAE-BAB1-36F8E6C3ECF6} - System32\Tasks\{2669E051-8302-4910-87D9-1960015B033E} => Firefox.exe
Task: {E1431FDE-59BC-4B5F-BDD4-A4DFC391C365} - System32\Tasks\MotoCast Update => C:\Program Files (x86)\Motorola Mobility\MotoCast\LiveUpdate\MotoCastUpdate.exe [2012-02-09] ()
Task: {E4F59CFB-B00C-4E5B-A65E-F17CB49CF3DD} - System32\Tasks\{51CA52CC-2853-4A45-AFBA-112610F5AC17} => pcalua.exe -a C:\Users\Dad\Documents\Downloads\documentstogopro7006-en.exe -d C:\Users\Dad\Documents\Downloads
Task: {E77650C6-5C0E-41C9-915C-A69DF3B71A38} - System32\Tasks\{3497E5F7-9423-4E4B-96E9-54984E4C8053} => pcalua.exe -a C:\Users\Dad\Desktop\SetupStrategyDesk.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {EA78BE35-04C4-4134-8ACD-52793D84FA45} - System32\Tasks\Microsoft\Windows\Setup\EOONotify => C:\Windows\EOONotify\EOONotify.exe [2016-07-08] (Microsoft Corporation)
Task: {ED327880-0A3E-4649-A790-8BCD30FFD8D1} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {EF015110-BDA2-4514-B737-16F1EDD0FAB7} - System32\Tasks\MotoHelper Routing => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {EF75BABB-9A77-4BC8-B332-91A96482055D} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => C:\Windows\system32\GWX\GWXConfigManager.exe
Task: {F0DE022C-BDE0-42F3-B3C0-24234C10D9ED} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => C:\Windows\system32\GWX\GWX.exe
Task: {F485FC4B-1875-47D1-9D74-09706F59D1C2} - System32\Tasks\{52DC35EC-81F8-4964-8076-FDA7BF65EB24} => pcalua.exe -a C:\Epson\epson15546.exe -d C:\Epson
Task: {F6852A2F-CD85-43F5-823A-66EA81588F1A} - System32\Tasks\{5355B45C-4DD9-448E-9BB3-CAD6E6C94514} => msiexec.exe /package "C:\Users\Dad\Desktop\WD SmartWare Upgrader.msi"
Task: {F6CA1060-0EC0-4E1C-AF8F-AA4B0DFD51A6} - System32\Tasks\MotoHelper Initial Update => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {FABF09A5-4413-4E62-BB04-A032C1CC33B5} - System32\Tasks\{10EF5062-FADE-4238-95E4-4EA61663B88F}-Kodak Share Button App Camera detect => C:\Program Files (x86)\Kodak\KODAK Share Button App\Listener.exe [2015-02-09] (Eastman Kodak Company)
Task: {FBC5387B-8A12-416E-9E59-4D93C8943E47} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => C:\Windows\system32\GWX\GWX.exe
Task: {FD3AA1AA-228A-4F66-AB1F-94EE4B4E3154} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {FFCE48F4-CC06-4275-ADD2-BE639EBC5D7B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_Dad.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000.job => C:\Users\Dad\AppData\Local\Citrix\GoToMeeting\2352\g2mupdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\Uninstaller_SkipUac_Dad.job => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Dad\AppData\Local\5b65\47e2.lnk -> C:\Users\Dad\AppData\Local\5b65\05b1.bat ()
Shortcut: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FrostWire 6\FrostWire 6.3.4-SafeMode.lnk -> C:\Program Files (x86)\FrostWire 6\frostwire.bat ()

==================== Loaded Modules (Whitelisted) ==============

2015-02-18 23:45 - 2016-06-02 22:26 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-04-15 04:15 - 2016-05-02 00:54 - 00369208 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
2016-05-24 17:58 - 2016-05-02 00:55 - 00289848 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2016-04-15 04:15 - 2016-05-02 00:54 - 01148984 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\libprotobuf.dll
2016-04-15 04:15 - 2016-05-02 00:55 - 03613240 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll
2016-04-15 03:58 - 2016-05-02 00:55 - 01842232 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll
2016-01-29 00:21 - 2016-05-02 00:55 - 00208952 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll
2016-04-15 03:58 - 2016-05-02 00:55 - 01990200 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll
2016-04-15 03:58 - 2016-05-02 00:55 - 02667576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll
2016-05-24 17:58 - 2016-05-02 00:54 - 00035896 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_system-vc120-mt-1_58.dll
2016-05-24 17:58 - 2016-05-02 00:54 - 00921656 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_regex-vc120-mt-1_58.dll
2014-05-01 09:13 - 2014-05-01 09:13 - 00470016 _____ () C:\ProgramData\MEGAsync\ShellExtX64.dll
2012-02-07 16:54 - 2012-02-07 16:54 - 00128336 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\liveupdatetactics.dll
2012-02-07 16:53 - 2012-02-07 16:53 - 00023872 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\DbAccess.dll
2012-02-07 16:56 - 2012-02-07 16:56 - 00465632 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\sqlite3.dll
2012-02-07 16:54 - 2012-02-07 16:54 - 00045368 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\NAdvLog.dll
2012-02-07 16:54 - 2012-02-07 16:54 - 00034128 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\NFileCacheDBAccess.dll
2015-11-25 13:04 - 2015-11-06 13:05 - 00618784 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll
2016-08-30 13:47 - 2015-12-29 11:30 - 00355616 _____ () C:\Program Files (x86)\IObit\Classic Start\madExcept_.bpl
2016-08-30 13:47 - 2015-12-29 11:29 - 00190240 _____ () C:\Program Files (x86)\IObit\Classic Start\madBasic_.bpl
2016-08-30 13:47 - 2015-12-29 11:30 - 00057632 _____ () C:\Program Files (x86)\IObit\Classic Start\madDisAsm_.bpl
2016-08-30 13:47 - 2015-12-29 11:30 - 00275576 _____ () C:\Program Files (x86)\IObit\Classic Start\sqlite3.dll
2016-08-30 13:47 - 2015-12-29 11:30 - 00059680 _____ () C:\Program Files (x86)\IObit\Classic Start\parseAuto.dll
2016-08-30 13:47 - 2015-12-29 11:30 - 00625440 _____ () C:\Program Files (x86)\IObit\Classic Start\ProductStatistics.dll
2014-05-01 09:15 - 2014-05-01 09:15 - 00463360 _____ () C:\ProgramData\MEGAsync\ShellExtX32.dll
2016-08-30 13:47 - 2015-12-29 11:31 - 00047904 _____ () C:\Program Files (x86)\IObit\Classic Start\winkey.dll
2016-01-03 10:34 - 2016-05-02 01:02 - 00020536 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-08-28 23:26 - 2015-12-28 13:50 - 00899872 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\webres.dll
2016-08-28 23:26 - 2015-12-28 13:49 - 00629536 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\ProductStatistics.dll
2016-08-28 23:26 - 2015-12-23 18:32 - 00190240 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
2016-08-28 23:26 - 2015-12-23 18:32 - 00057632 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
2016-04-13 14:56 - 2016-04-13 14:56 - 00061952 _____ () C:\Program Files (x86)\FireTrust\MailWasher\MWPBridgeDLL.dll
2016-04-13 14:56 - 2016-04-13 14:56 - 05999616 _____ () C:\Program Files (x86)\FireTrust\MailWasher\MWPappDLL.dll
2016-04-18 13:14 - 2016-04-18 13:14 - 00069272 _____ () C:\Program Files (x86)\FireTrust\MailWasher\FTBridge.dll
2016-04-18 13:14 - 2016-04-18 13:14 - 00279704 _____ () C:\Program Files (x86)\FireTrust\MailWasher\FTClientNode.dll
2016-03-23 22:07 - 2016-03-23 22:07 - 00324608 _____ () C:\Program Files (x86)\FireTrust\MailWasher\MWPHeaderParser.dll
2016-08-28 23:26 - 2015-12-28 13:50 - 01293088 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\Scan.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_0news-1751121550 [2302]
AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_1messages-431041656 [2302]
AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_2events-250898981 [2302]
AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_3friends-215113587 [2302]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\IMFservice => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\str => ""="service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKU\S-1-5-21-968235783-2654321925-1125524309-1000\Software\Classes\1485: "C:\WINDOWS\system32\mshta.exe" "javascript:j4jyZx8Sw="66MzPC";z6o=new ActiveXObject("WScript.Shell");Frg45wQ="w0Fl3EY";VV6ju=z6o.RegRead("HKCU\\software\\cqnlmnybc\\vqkclc");vhOs9Gd="PQSxdUFN";eval(VV6ju);Z2R1BBr="r0hcE";" <===== ATTENTION

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\linkedin.com -> hxxps://www.linkedin.com
IE trusted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\microsoft.com -> hxxps://v4.update.microsoft.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\100sexlinks.com -> 100sexlinks.com

There are 4794 more sites.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-968235783-2654321925-1125524309-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: IDriverT => 3
MSCONFIG\Services: IMFservice => 3
MSCONFIG\Services: Live Updater Service => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: NAUpdate => 3
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: nvUpdatusService => 2
MSCONFIG\Services: RealNetworks Downloader Resolver Service => 2
MSCONFIG\Services: Stereo Service => 2
MSCONFIG\Services: UNS => 2
MSCONFIG\Services: WDDMService => 3
MSCONFIG\Services: WDFMEService => 2
MSCONFIG\Services: WDRulesService => 2
MSCONFIG\Services: WiseBootAssistant => 2
MSCONFIG\Services: YahooAUService => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HotSync Manager.lnk => C:\Windows\pss\HotSync Manager.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: EEventManager => C:\PROGRA~2\Epson Software\EVENTM~1\EEVENT~1.EXE
MSCONFIG\startupreg: Family Tree Builder Update => C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe
MSCONFIG\startupreg: HotSync =>
MSCONFIG\startupreg: IndexSearch => c:\program files (x86)\scansoft\paperport\indexsearch.exe
MSCONFIG\startupreg: MotoCast => "c:\program files (x86)\motorola mobility\motocast\motolauncher.lnk"
MSCONFIG\startupreg: PaperPort PTD => c:\program files (x86)\scansoft\paperport\pptd40nt.exe
MSCONFIG\startupreg: RtHDVCpl => c:\program files\realtek\audio\hda\ravcpl64.exe -s
MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\update\realsched.exe"  -osboot
MSCONFIG\startupreg: WD Quick View => c:\program files (x86)\western digital\wd quick view\wddmstatus.exe
HKLM\…\StartupApproved\StartupFolder: => "Install LastPass FF RunOnce.lnk"
HKLM\…\StartupApproved\StartupFolder: => "Install LastPass IE RunOnce.lnk"
HKLM\…\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\…\StartupApproved\Run: => "EvtMgr6"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\…\StartupApproved\Run32: => "IObit Malware Fighter"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\StartupFolder: => "JL Christmas Market.lnk"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\StartupFolder: => "JL Victorian Calendar.lnk"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\Run: => "KGShareApp"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [{868D6CCB-92A2-4F9A-B4BC-906CBE16C222}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [TCP Query User{7C7799AE-32CB-4FC4-94D9-7C8D5E49495B}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [UDP Query User{3F78ED35-0A0B-4195-A250-C62E303143DC}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [{A1752C7D-FED1-4AB7-BEA7-8702DFAE2466}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{CF3C48EB-F298-4234-BE76-4B77EFEF71F7}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{D896BF4A-B8C6-402E-8B26-FA941C35AFE0}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{4C362F15-FCBB-41F9-923C-66A2D0B598FC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C5ED500B-635C-4175-ACA3-39CB6B94F43B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{3A529617-79F5-4276-A1C4-25404C1FE206}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{8BB43B39-CDC3-4D33-97EF-DDB5B9A0D054}] => (Allow) LPort=2869
FirewallRules: [{62672AD7-4CF4-44FB-A466-22810DE4D035}] => (Allow) LPort=1900
FirewallRules: [{0D7AE57D-C1F0-48F2-95C3-169DFA7BAECC}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{15A4AE51-8E92-428D-8DCE-BDE09261B17F}] => (Allow) C:\Program Files (x86)\FrostWire 6\FrostWire.exe
FirewallRules: [{D98C2122-0505-4516-8F29-7E963577BCEE}] => (Allow) C:\Program Files (x86)\FrostWire 6\FrostWire.exe
FirewallRules: [{E478B0B2-92CC-48E0-9B6B-D49AFA484A95}] => (Allow) C:\Program Files (x86)\Torrents Downloader\torrents_downloader.exe
FirewallRules: [{3158406F-188C-4DF2-971A-61337A97AC01}] => (Allow) C:\Program Files (x86)\Torrents Downloader\torrents_downloader.exe
FirewallRules: [{5F9FD0D7-B1D6-4DEE-95F8-6E76040178F0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D1AAA7F3-3E29-49E2-94BF-AED3CFE8D9A2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1152F76F-B728-4C97-8802-157A0C4204F5}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [{A74FAC99-AEF8-48A5-A89E-657D832878A5}] => (Allow) C:\Program Files (x86)\Motorola Media Link\Lite\mml.exe
FirewallRules: [{B5F5A955-4CC4-4BC5-BFEF-FB7C7F7E6B12}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\motocast.exe
FirewallRules: [{17625B4E-A493-499C-A95F-31143906A465}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\motocast.exe
FirewallRules: [{FA9D6F73-C5DE-4965-B413-A29F7A8F2693}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
FirewallRules: [{F4B47BC7-2741-4916-8866-5CE3B5544D96}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
FirewallRules: [{7D0267C3-2162-422F-996C-A6F28E89F358}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5C9BECF9-CCCE-42F7-8CCE-E826B6904F55}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D21F0D44-CD0B-4750-900E-E42B4FED1C74}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{90F86A6A-E8A2-4C17-AD74-671DDE58A5D6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{6DE8CE4D-025E-43DF-9939-DE1033EDA368}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{6F144095-0AE5-4400-9979-FAA042B4D5E2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{C9C7278E-F6D6-45C5-AD8E-758B52E53881}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{A4D105D8-6C7A-46AA-9C85-9E8D872EB46F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{321C9C77-6047-43E4-99E1-E1EF259069ED}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{6F6773F0-90DC-4DB5-B739-8E39AC01BC3E}] => (Allow) C:\Program Files\iTunes\iTunes.exe
DomainProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7

==================== Restore Points =========================

13-10-2016 19:04:53 Windows Update

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/15/2016 09:15:22 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 11.0.9600.18124, time stamp: 0x2a425e19
Faulting module name: ntdll.dll, version: 6.3.9600.18233, time stamp: 0x56bb4e1d
Exception code: 0xc0000374
Fault offset: 0x000e6054
Faulting process id: 0x113c
Faulting application start time: 0x01d22752f7adbca6
Faulting application path: C:\Program Files (x86)\Internet Explorer\iexplore.exe
Faulting module path: C:\WINDOWS\SYSTEM32\ntdll.dll
Report Id: 64260e1f-9346-11e6-bf05-386077ec13ea
Faulting package full name:
Faulting package-relative application ID:

Error: (10/15/2016 08:39:47 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/15/2016 06:39:56 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/15/2016 04:39:47 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/15/2016 02:39:46 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/15/2016 12:28:50 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/15/2016 10:39:46 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/15/2016 08:39:46 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/15/2016 06:39:46 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/15/2016 04:39:46 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.


System errors:
=============
Error: (10/15/2016 08:45:27 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.

Error: (10/15/2016 08:45:11 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.

Error: (10/15/2016 08:41:42 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.

Error: (10/15/2016 08:25:03 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 40.

Error: (10/15/2016 07:25:29 PM) (Source: DCOM) (EventID: 10010) (User: JIM)
Description: The server {ED1D0FDF-4414-470A-A56D-CFB68623FC58} did not register with DCOM within the required timeout.

Error: (10/15/2016 05:28:03 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.

Error: (10/15/2016 04:47:20 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.

Error: (10/15/2016 04:31:20 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.

Error: (10/15/2016 04:24:55 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.

Error: (10/15/2016 04:06:32 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-2320 CPU @ 3.00GHz
Percentage of memory in use: 37%
Total physical RAM: 16364.29 MB
Available physical RAM: 10219.45 MB
Total Virtual: 32748.29 MB
Available Virtual: 26003.7 MB

==================== Drives ================================

Drive c: (Jim ) (Fixed) (Total:1848.92 GB) (Free:1595.05 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 686961D5)
Partition 1: (Not Active) - (Size=14 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=1848.9 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

Please advise on the next step(s). Thanks in advance!

 

Taz

 

:welcome:

 

Lets go over a couple of things.

 

One.

Your using Frostwire, not all but almost 99.99% of files or programs downloaded via file sharing are infected

 

Two.

IObit
 
I want to give you a heads up on IObit , its a program from China and not recommended. The Chinese company behind this product was found to be stealing Malwarebytes database. I would like you to uninstall it as there are better program out there,   why use one from from a questional company with unethical business practices.
 
http://blogs.computerworld.com/15026/iobit_accused_of_stealing_from_malwarebytes

 

 

Lets see if this removal tool from Norton will remove Trojan.Kotver!

https://www.symantec.com/security_response/writeup.jsp?docid=2015-092321-2230-99

Hi Ken,

 

After I posted this, I came across the Norton fix for this trojan. I ran it and it seems to have cleared it up. I also removed the "IOBIT" software per your recommendation. It really wasn't working anyway and I've always suspected it to be a bad actor.

 

Thanks for your prompt reply and quick fix to my issue. I'll be sure to keep a close eye on things! :)

 

Regards and thanks!

 

Taz

Thats great , glad it worked out. Your FRST log had an awful lot of entries for IOBIT, if you would like to run a new scan with FRST and post the logs  I can see if there are any remaining Iobit entries that need to be removed

 

Right click on FRST64 and select RUN AS ADMINISTRATOR , when it loads make sure to checkmark ADDITIONS,  leave everything else as is, then click on Scan and post both the FRST and Additions log.

Hi Ken,

 

I've done what you suggested and am posting the logs here. There are 2 IObit programs that I like and have served me well without incident - Advanced System and Classic Startup. The rest I purged from the system via Revo Uninstaller.

 

Here are the logs:

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-10-2016
Ran by [removed] (administrator) on JIM (17-10-2016 14:00:27)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Nero AG) C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccsvchst.exe
(Microsoft Corporation) C:\WINDOWS\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\SMService.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
(Seiko Epson Corporation) C:\WINDOWS\System32\escsvc64.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\nsbu.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccsvchst.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\ClassicStart.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\StartMenu_Hook.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\InstallServices.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(WinZip Computing International, LLC) C:\Program Files\File Association Helper\FAHWindow.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(Firetrust) C:\Program Files (x86)\FireTrust\MailWasher\MailWasherPro.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
(PalmSource, Inc) C:\Program Files (x86)\Palm\Hotsync.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\nsbu.exe
(KeirNet) C:\Program Files (x86)\KeirNet\K9\K9.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16407296 2016-01-26] (Realtek Semiconductor)
HKLM\…\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [216248 2013-09-26] (WinZip Computing International, LLC)
HKLM\…\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.)
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776 2016-05-02] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\WINDOWS\system32\nvspcap64.dll [1767944 2016-05-02] (NVIDIA Corporation)
HKLM-x32\…\Run: [SSBkgdUpdate] => C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM-x32\…\Run: [PaperPort PTD] => C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe [29984 2008-01-14] (Nuance Communications, Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598040 2016-06-22] (Oracle Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKLM\…\Policies\Explorer: [NoSetActiveDesktop] 0
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2023712 2016-07-27] (IObit)
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Run: [KGShareApp] => C:\Program Files (x86)\Kodak\KODAK Share Button App\KGShare_App.exe [394240 2015-02-09] (Eastman Kodak Company)
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8912088 2016-08-26] (Piriform Ltd)
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Policies\Explorer: [NoSetActiveDesktop] 0
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\MountPoints2: {09331ad7-5447-11e3-901b-386077ec13ea} - "F:\KODAK_Camera_Setup_App.exe"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\MountPoints2: {112fa596-7e8f-11e3-91ef-386077ec13ea} - "F:\MotoCastSetup.exe" -a
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Ribbons.scr [132608 2014-11-21] (Microsoft Corporation)
HKU\S-1-5-18\…\Winlogon: [Shell] C:\WINDOWS\Explorer.exe [2755504 2016-09-20] (Microsoft Corporation) <==== ATTENTION
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\buShell.dll [2016-09-23] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\buShell.dll [2016-09-23] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\buShell.dll [2016-09-23] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ SncrOverlays (Blocked)] -> {C418E880-6280-4010-A888-FD76028E5511} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [ SncrOverlays (InSync)] -> {5F4A6070-DB92-4C56-A487-F3850430608F} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [ SncrOverlays (Pending)] -> {EE73A341-C788-4A6B-B1EF-DDBFC0F190B6} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [ SncrOverlays (Syncing)] -> {28CDCD88-B179-49D6-8B21-1A9AF9C0AE13} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
Startup: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MailWasherPro.lnk [2016-04-20]
ShortcutTarget: MailWasherPro.lnk -> C:\Program Files (x86)\FireTrust\MailWasher\MailWasherPro.exe (Firetrust)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

AutoConfigURL: [S-1-5-21-968235783-2654321925-1125524309-1000] => hxxp://proxy.kodak.com:81/proxy.pac
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3534EE43-8554-4DFD-B1F2-F34A35AF6B03}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{90616DFF-D831-4BD6-9124-AEF7F60BD2AA}: [DhcpNameServer] 192.168.1.1
ManualProxies: 0hxxp://proxy.kodak.com:81/proxy.pac

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> DefaultScope {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = hxxp://search.myheritage.com?orig=ds&q;={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src;={referrer:source?}
SearchScopes: HKLM -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL =
SearchScopes: HKLM -> {31090377-0740-419E-BEFC-A56E50500D5B} URL =
SearchScopes: HKLM -> {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = hxxp://search.myheritage.com?orig=ds&q;={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\.DEFAULT -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o;=APN11913&l;=dis&prt;=NSBU&chn;=1000&geo;=US&ver;=22&locale;=en_US&gct;=kwd&qsrc;=2869
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-10-27] (RealDownloader)
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\coIEPlg.dll [2016-09-23] (Symantec Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_102\bin\ssv.dll [2016-08-04] (Oracle Corporation)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-07-03] (LastPass)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_102\bin\jp2ssv.dll [2016-08-04] (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-10-27] (RealDownloader)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\coIEPlg.dll [2016-09-23] (Symantec Corporation)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-07-03] (LastPass)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-07-09] (IObit)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\coIEPlg.dll [2016-09-23] (Symantec Corporation)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-07-03] (LastPass)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\coIEPlg.dll [2016-09-23] (Symantec Corporation)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-07-03] (LastPass)
Toolbar: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\coIEPlg.dll [2016-09-23] (Symantec Corporation)
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}

FireFox:
========
FF ProfilePath: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 [2016-10-17]
FF user.js: detected! => C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463\user.js [2016-03-22]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 -> Google
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 -> Google
FF Homepage: Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 -> about:blank
FF Extension: (LastPass) - C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463\Extensions\[removed] [2016-09-03]
FF Extension: (1-Click YouTube Video Downloader) - C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463\Extensions\[removed] [2016-08-24]
FF HKLM\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.6.0.142\coFFAddon
FF Extension: (Norton Security Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.6.0.142\coFFAddon [2016-10-16]
FF HKLM-x32\…\Firefox\Extensions: [{338950EA-82DB-44C1-930D-0C28E023C9F0}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2015-02-11] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\…\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-01-17] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.6.0.142\coFFAddon
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_162.dll [2016-09-26] ()
FF Plugin: @java.com/DTPlugin,version=11.102.2 -> C:\Program Files\Java\jre1.8.0_102\bin\dtplugin\npDeployJava1.dll [2016-08-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.102.2 -> C:\Program Files\Java\jre1.8.0_102\bin\plugin2\npjp2.dll [2016-08-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_162.dll [2016-09-26] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-02-22] (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-03-18] (Nero AG)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-06-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-06-02] (NVIDIA Corporation)
FF Plugin-x32: @palmsource.com/installer,version=1.0 -> C:\PROGRA~2\Palm\PACKAG~1\NPInstal.dll [2007-03-19] ()
FF Plugin-x32: @real.com/nppl3260;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2015-02-11] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.15 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-10-27] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2015-02-11] (RealPlayer Cloud)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-24] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-24] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-07] ()
FF Plugin-x32: @winzip.com/Winzip Courier -> C:\Program Files (x86)\WinZip Courier\npwzwmc.dll [2013-11-22] (WinZip Computing, S.L.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-968235783-2654321925-1125524309-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Dad\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-12-15] (Citrix Online)
FF Plugin HKU\S-1-5-21-968235783-2654321925-1125524309-1000: tdameritrade.com/thinkorswim -> C:\Program Files\thinkorswim\npthinkorswim.dll [2016-09-21] (TD Ameritrade)
FF Plugin HKU\S-1-5-21-968235783-2654321925-1125524309-1000: tdameritrade.com/tossc -> C:\Program Files\thinkorswim\nptossc.dll [2016-09-21] (TD Ameritrade)
FF Plugin ProgramFiles/Appdata: C:\Users\Dad\AppData\Roaming\mozilla\plugins\npatgpc.dll [2015-03-25] (Cisco WebEx LLC)

Chrome:
=======
CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\Exts\Chrome.crx [2016-09-28]
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\Exts\Chrome.crx [2016-09-28]
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [452384 2016-07-25] (IObit)
S3 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1165368 2016-05-02] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-06-14] (IObit)
R2 MCLIENT; C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccSvcHst.exe [143928 2012-12-04] (Symantec Corporation)
S3 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [214896 2012-02-01] ()
R2 NSBU; C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\NSBU.exe [289080 2016-09-23] (Symantec Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-05-02] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232 2016-05-02] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680 2016-05-02] (NVIDIA Corporation)
S3 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-10-26] ()
S3 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2015-02-11] (RealNetworks, Inc.)
S3 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31856 2014-10-30] ()
S3 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [614664 2014-04-01] (CyberLink)
R2 SMService; C:\Program Files (x86)\IObit\Classic Start\SMService.exe [1063200 2015-12-29] (IObit)
S3 vmicvss; C:\Windows\System32\ICSvc.dll [524800 2014-11-21] (Microsoft Corporation)
R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1049464 2016-04-19] (Western Digital Technologies, Inc.)
R3 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [314744 2016-04-19] (Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx64; C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\BASHDefs\20161005.001\BHDrvx64.sys [1854712 2016-08-18] (Symantec Corporation)
R1 ccSet_MCLIENT; C:\Windows\system32\drivers\MCLIENTx64\0302020.00C\ccSetx64.sys [168096 2012-10-03] (Symantec Corporation)
R1 ccSet_NSBU; C:\Windows\system32\drivers\NSBUx64\1608000.032\ccSetx64.sys [174328 2016-06-01] (Symantec Corporation)
R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [497368 2016-10-03] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [156888 2016-10-03] (Symantec Corporation)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-07-02] (REALiX™)
R1 IDSVia64; C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\IPSDefs\20161014.003\IDSvia64.sys [1012440 2016-09-26] (Symantec Corporation)
S1 iSafeKrnlMon; no ImagePath
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2014-07-03] (Intel Corporation)
R2 mfmonitor; C:\Windows\System32\DRIVERS\mfmonitor_x64.sys [20696 2014-06-19] (Windows (R) Win 7 DDK provider)
R3 netr28x; C:\Windows\system32\DRIVERS\netr28x.sys [2541200 2016-03-04] (MediaTek Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28216 2016-05-02] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [413912 2016-04-23] (Realsil Semiconductor Corporation)
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2014-07-03] (Synaptics Incorporated)
R1 SRTSP; C:\Windows\System32\Drivers\NSBUx64\1608000.032\SRTSP64.SYS [784624 2016-09-23] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NSBUx64\1608000.032\SRTSPX64.SYS [49400 2016-09-23] (Symantec Corporation)
R0 SymEFASI; C:\Windows\System32\drivers\NSBUx64\1608000.032\SYMEFASI64.SYS [1628888 2016-09-23] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\NSBUx64\1608000.032\SymELAM.sys [24192 2016-02-23] (Symantec Corporation)
R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [100592 2016-10-16] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [78936 2013-09-09] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NSBUx64\1608000.032\Ironx64.SYS [289520 2016-09-23] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NSBUx64\1608000.032\SYMNETS.SYS [567512 2016-09-23] (Symantec Corporation)
U5 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2014-06-08] (Seiko Epson Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 NAVENG; \??\C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\SDSDefs\20161013.019\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\SDSDefs\20161013.019\EX64.SYS [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-10-17 13:58 - 2016-10-17 14:00 - 00029637 _____ C:\Users\Dad\Desktop\FRST.txt
2016-10-17 13:58 - 2016-10-17 13:59 - 00066988 _____ C:\Users\Dad\Desktop\Addition.txt
2016-10-17 13:44 - 2016-10-17 13:44 - 02406912 _____ (Farbar) C:\Users\Dad\Desktop\FRST64.exe
2016-10-17 01:01 - 2016-10-17 01:01 - 04358478 _____ C:\Users\Dad\Desktop\Fanning Family of Edmund Fanning .pdf
2016-10-16 20:21 - 2016-10-16 20:21 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Security with Backup
2016-10-16 20:15 - 2016-10-16 20:15 - 00008192 _____ C:\WINDOWS\SysWOW64\WDPABKP.dat
2016-10-16 20:15 - 2016-10-16 20:15 - 00003240 _____ C:\WINDOWS\System32\Tasks\Norton WSC Integration
2016-10-16 20:14 - 2016-10-16 20:14 - 00002502 _____ C:\Users\Public\Desktop\Norton Security with Backup.lnk
2016-10-16 20:08 - 2016-10-16 20:08 - 00000000 ____H C:\asc_rdflag
2016-10-16 20:04 - 2016-10-16 20:17 - 00000000 ____D C:\Users\Dad\AppData\Roaming\0273
2016-10-16 20:04 - 2016-10-16 20:04 - 00000000 ____D C:\Users\Dad\AppData\Local\5b65
2016-10-16 19:59 - 2016-10-16 20:00 - 02805768 _____ (Symantec Corporation) C:\Users\Dad\Desktop\FixTool64.exe
2016-10-16 04:25 - 2016-10-16 04:25 - 00004476 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-10-16 04:24 - 2016-10-16 04:24 - 00002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-10-15 18:50 - 2016-10-17 14:00 - 00000000 ____D C:\FRST
2016-10-15 18:39 - 2016-10-15 18:39 - 05198336 _____ (AVAST Software) C:\Users\Dad\Desktop\aswMBR.exe
2016-10-14 14:56 - 2016-10-14 22:22 - 00012674 _____ C:\Users\Dad\Desktop\Medical Records.xlsx
2016-10-13 19:41 - 2016-09-30 19:15 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-10-13 19:41 - 2016-09-30 19:15 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-12 13:43 - 2016-03-25 14:33 - 00128288 _____ (IObit) C:\WINDOWS\system32\IObitSmartDefragExtension.dll
2016-10-12 02:29 - 2016-09-30 19:22 - 07444312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-10-12 02:29 - 2016-09-30 02:55 - 25765376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-10-12 02:29 - 2016-09-30 01:25 - 02895360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-10-12 02:29 - 2016-09-30 01:25 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-10-12 02:29 - 2016-09-30 01:12 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-10-12 02:29 - 2016-09-30 01:09 - 06048256 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-10-12 02:29 - 2016-09-30 00:47 - 20306944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-10-12 02:29 - 2016-09-30 00:42 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-10-12 02:29 - 2016-09-30 00:41 - 01033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-10-12 02:29 - 2016-09-30 00:38 - 02286592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-10-12 02:29 - 2016-09-30 00:33 - 00724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-10-12 02:29 - 2016-09-30 00:33 - 00378880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-10-12 02:29 - 2016-09-30 00:32 - 00806912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-10-12 02:29 - 2016-09-30 00:32 - 00663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-10-12 02:29 - 2016-09-30 00:31 - 02131456 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-10-12 02:29 - 2016-09-30 00:21 - 15257088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-10-12 02:29 - 2016-09-30 00:17 - 02920960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-10-12 02:29 - 2016-09-30 00:12 - 04608512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-10-12 02:29 - 2016-09-30 00:11 - 00880640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-10-12 02:29 - 2016-09-30 00:06 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-10-12 02:29 - 2016-09-30 00:05 - 02055680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-10-12 02:29 - 2016-09-30 00:05 - 01544192 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-10-12 02:29 - 2016-09-30 00:05 - 00693248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-10-12 02:29 - 2016-09-30 00:03 - 13653504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-10-12 02:29 - 2016-09-29 23:54 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-10-12 02:29 - 2016-09-29 23:46 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-10-12 02:29 - 2016-09-29 23:43 - 01312768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-10-12 02:29 - 2016-09-29 23:42 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-10-12 02:29 - 2016-09-17 13:16 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
2016-10-12 02:29 - 2016-09-17 12:53 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2016-10-12 02:29 - 2016-09-17 12:21 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsmsext.dll
2016-10-12 02:29 - 2016-09-17 12:03 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2016-10-12 02:29 - 2016-09-17 12:02 - 01446400 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-10-12 02:29 - 2016-09-13 20:53 - 01663184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-10-12 02:29 - 2016-09-13 20:53 - 01523208 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-10-12 02:29 - 2016-09-13 20:53 - 01490112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-10-12 02:29 - 2016-09-13 20:53 - 01358952 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-10-12 02:29 - 2016-09-12 18:48 - 00085680 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-10-12 02:29 - 2016-09-12 17:03 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2016-10-12 02:29 - 2016-09-12 16:01 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2016-10-12 02:29 - 2016-09-09 09:17 - 04170752 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-10-12 02:29 - 2016-09-09 08:38 - 01629184 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00586752 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\centel.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-10-12 02:29 - 2016-09-08 15:41 - 00121176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2016-10-12 02:29 - 2016-09-08 09:00 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-10-12 02:29 - 2016-09-08 09:00 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-10-12 02:29 - 2016-09-07 17:07 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2016-10-12 02:29 - 2016-09-07 16:59 - 01754112 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-10-12 02:29 - 2016-09-07 16:59 - 01377792 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2016-10-12 02:29 - 2016-09-07 16:57 - 01560064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2016-10-12 02:29 - 2016-09-07 16:56 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-10-12 02:29 - 2016-08-31 12:22 - 03754496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2016-10-12 02:29 - 2016-08-31 11:33 - 02410496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2016-10-07 21:36 - 2016-10-07 21:36 - 00344879 _____ C:\Users\Dad\Desktop\duplicates_20161007.d2fp
2016-10-07 20:42 - 2016-10-07 20:42 - 00533136 _____ C:\Users\Dad\Desktop\duplicates_20161007.dpfp
2016-10-07 20:18 - 2016-10-07 20:18 - 00001390 _____ C:\Users\Dad\Desktop\Duplicate Photo Finder Plus.lnk
2016-10-07 20:03 - 2016-10-07 20:18 - 00000000 ____D C:\Users\Dad\AppData\Local\TriSun_Software_Limited
2016-10-07 20:03 - 2016-10-07 20:03 - 00001378 _____ C:\Users\Dad\Desktop\Duplicate File Finder Plus.lnk
2016-09-29 17:39 - 2016-09-29 17:39 - 00001769 _____ C:\Users\Public\Desktop\iTunes.lnk
2016-09-29 17:39 - 2016-09-29 17:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-09-29 17:39 - 2016-09-29 17:39 - 00000000 ____D C:\Program Files\iTunes
2016-09-29 17:39 - 2016-09-29 17:39 - 00000000 ____D C:\Program Files\iPod
2016-09-24 10:33 - 2016-10-16 19:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-09-21 21:46 - 2016-09-21 21:46 - 00332644 _____ C:\Users\Dad\Desktop\45ed6h_5335874643p54ow64714e3.ged
2016-09-20 18:10 - 2016-09-20 18:10 - 00875720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00869576 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00678592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00536776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00029888 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00028352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aspnet_counters.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 15431168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 13317120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 09323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2016-09-20 18:08 - 2016-09-20 18:08 - 09323008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2016-09-20 18:08 - 2016-09-20 18:08 - 02896384 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 02537472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 02315496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01946176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01574912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2016-09-20 18:08 - 2016-09-20 18:08 - 01317888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00954880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00445765 _____ C:\WINDOWS\system32\ApnDatabase.xml
2016-09-20 18:08 - 2016-09-20 18:08 - 00420184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastapi.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastapi.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00162850 _____ C:\WINDOWS\SysWOW64\C_932.NLS
2016-09-20 18:08 - 2016-09-20 18:08 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS
2016-09-20 18:08 - 2016-09-20 18:08 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\parport.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwififlt.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifibus.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serenum.sys
2016-09-20 18:07 - 2016-09-20 18:07 - 22360288 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 19789232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 14466560 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 12879360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02881536 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02778624 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02755504 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-09-20 18:07 - 2016-09-20 18:07 - 02463744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02411048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-09-20 18:07 - 2016-09-20 18:07 - 01049600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\RestoreOptIn.exe
2016-09-20 18:07 - 2016-09-20 18:07 - 00113656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RestoreOptIn.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-10-17 13:56 - 2015-02-18 10:06 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-968235783-2654321925-1125524309-1000
2016-10-17 13:53 - 2012-04-28 21:03 - 00000000 ____D C:\Program Files (x86)\IObit
2016-10-17 13:51 - 2015-05-04 19:51 - 01279488 ___SH C:\Users\Dad\Desktop\Thumbs.db
2016-10-17 00:01 - 2016-08-28 23:26 - 00000242 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_Dad.job
2016-10-16 20:38 - 2015-10-27 10:11 - 00000000 ____D C:\WINDOWS\System32\Tasks\Remediation
2016-10-16 20:29 - 2014-10-08 10:40 - 00000000 ____D C:\Users\Dad\AppData\Local\NPE
2016-10-16 20:22 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-10-16 20:16 - 2015-02-25 12:30 - 00000000 ____D C:\Users\DefaultAppPool
2016-10-16 20:15 - 2015-03-02 04:23 - 00000000 ____D C:\WINDOWS\system32\Drivers\NSBUx64
2016-10-16 20:14 - 2016-03-21 21:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security with Backup
2016-10-16 20:14 - 2015-02-18 23:46 - 00000000 ____D C:\ProgramData\NVIDIA
2016-10-16 20:14 - 2013-08-22 09:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-10-16 20:14 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\Inf
2016-10-16 20:14 - 2012-07-26 03:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-10-16 13:15 - 2015-03-02 04:25 - 00100592 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS
2016-10-16 13:15 - 2015-03-02 04:25 - 00008319 _____ C:\WINDOWS\system32\Drivers\SYMEVENT64x86.CAT
2016-10-15 18:48 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\Help
2016-10-15 18:07 - 2016-07-21 13:26 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-10-14 22:32 - 2016-08-28 23:26 - 00002286 _____ C:\Users\Public\Desktop\Advanced SystemCare 9.lnk
2016-10-14 20:29 - 2013-12-08 07:56 - 00000000 ____D C:\ProgramData\ProductData
2016-10-13 20:38 - 2012-06-19 17:09 - 00007642 _____ C:\Users\Dad\AppData\Local\resmon.resmoncfg
2016-10-13 20:25 - 2015-02-18 10:20 - 00000558 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000.job
2016-10-13 20:24 - 2013-08-22 09:44 - 00498224 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-10-13 20:24 - 2012-05-16 20:04 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-10-13 20:23 - 2011-10-27 05:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-10-13 20:21 - 2015-02-18 19:12 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-10-13 20:21 - 2014-11-21 11:17 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2016-10-13 19:42 - 2012-07-26 02:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-10-13 19:41 - 2013-07-28 13:36 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-10-13 19:29 - 2012-02-26 15:59 - 143495576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-10-13 19:27 - 2012-05-16 20:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-10-13 16:33 - 2012-04-28 20:39 - 00000000 ____D C:\Users\Dad\AppData\Local\CrashDumps
2016-10-13 10:22 - 2015-11-30 11:41 - 00003472 _____ C:\WINDOWS\System32\Tasks\ReclaimerUpdateXML_Dad
2016-10-13 10:22 - 2015-11-29 07:41 - 00003478 _____ C:\WINDOWS\System32\Tasks\ReclaimerUpdateFiles_Dad
2016-10-13 10:21 - 2015-05-08 01:18 - 00003542 _____ C:\WINDOWS\System32\Tasks\MotoCast Update
2016-10-13 10:21 - 2015-05-08 01:18 - 00003518 _____ C:\WINDOWS\System32\Tasks\MotoHelper Update
2016-10-13 10:21 - 2015-02-11 05:44 - 00003412 _____ C:\WINDOWS\System32\Tasks\RealDownloader Update Check
2016-10-13 10:21 - 2014-12-15 15:58 - 00003546 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:21 - 2014-12-14 00:42 - 00003350 _____ C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:21 - 2014-12-14 00:42 - 00003212 _____ C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:21 - 2014-11-19 11:36 - 00003190 _____ C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:16 - 2012-04-28 20:58 - 00000000 ____D C:\temp
2016-10-11 16:20 - 2013-08-22 08:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2016-10-10 17:18 - 2015-05-20 08:18 - 146112512 _____ C:\WINDOWS\system32\config\SOFTWARE.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 07364608 _____ C:\WINDOWS\system32\config\DRIVERS.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 00778240 _____ C:\WINDOWS\system32\config\DEFAULT.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 00065536 _____ C:\WINDOWS\system32\config\SAM.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 00036864 _____ C:\WINDOWS\system32\config\SECURITY.iodefrag.bak
2016-10-10 07:44 - 2012-04-28 21:03 - 00000000 ____D C:\Users\Dad\AppData\Roaming\IObit
2016-10-10 00:38 - 2015-03-21 22:50 - 00063488 ___SH C:\Users\Dad\Downloads\Thumbs.db
2016-10-10 00:30 - 2014-11-21 03:43 - 00994144 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-10-07 20:18 - 2016-07-02 10:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSSI
2016-10-07 20:18 - 2016-07-02 10:32 - 00000000 ____D C:\Program Files (x86)\TSSI
2016-10-05 21:47 - 2013-10-12 02:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2016-10-03 03:31 - 2012-07-26 03:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-10-03 03:30 - 2013-10-29 10:57 - 00000838 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-10-01 03:29 - 2012-04-28 21:22 - 00000000 ____D C:\Users\Dad\.frostwire5
2016-09-30 02:06 - 2015-02-18 23:53 - 00000000 ____D C:\Users\Dad
2016-09-29 17:39 - 2016-05-20 18:58 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-09-27 18:46 - 2016-08-18 06:12 - 00001143 _____ C:\Users\Dad\Desktop\MyHeritage Family Tree Builder.lnk
2016-09-27 18:46 - 2012-04-29 11:23 - 00000000 ____D C:\Program Files (x86)\MyHeritage
2016-09-26 13:43 - 2010-08-15 18:49 - 00000000 ____D C:\Users\Dad\Documents\MyHeritage
2016-09-26 09:52 - 2012-04-28 19:49 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-09-26 09:51 - 2013-08-22 10:36 - 00000000 ___RD C:\WINDOWS\ToastData
2016-09-26 09:27 - 2015-02-18 23:53 - 00000000 ____D C:\Users\Administrator
2016-09-26 03:12 - 2012-04-29 11:15 - 00000000 ____D C:\Program Files (x86)\Palm
2016-09-26 00:47 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-09-26 00:47 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-09-26 00:47 - 2012-04-28 19:49 - 00003744 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-09-24 13:06 - 2012-05-26 08:27 - 00007627 _____ C:\WINDOWS\wininit.ini
2016-09-21 20:54 - 2014-10-14 13:50 - 00000000 ____D C:\Program Files\thinkorswim
2016-09-21 20:54 - 2013-07-01 16:32 - 00000000 ____D C:\Users\Dad\.thinkorswim
2016-09-21 20:04 - 2015-03-25 00:07 - 00000000 ____D C:\Users\Dad\AppData\LocalLow\WebEx
2016-09-21 20:04 - 2011-01-26 21:03 - 00000000 __SHD C:\Users\Dad\Documents\cache

==================== Files in the root of some directories =======

2014-03-22 00:17 - 2014-03-22 00:17 - 0003754 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2012-02-26 16:48 - 2016-05-14 03:00 - 21572120 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2013-05-08 08:39 - 2013-05-08 08:39 - 0000000 _____ () C:\Users\Dad\AppData\Roaming\SharedSettings.ccs
2012-05-05 22:19 - 2012-05-05 22:19 - 0019329 _____ () C:\Users\Dad\AppData\Roaming\UserTile.png
2014-05-13 01:21 - 2014-10-06 18:35 - 0000059 _____ () C:\Users\Dad\AppData\Roaming\WB.CFG
2013-05-12 07:17 - 2013-05-12 07:17 - 0045967 _____ () C:\Users\Dad\AppData\Local\amapeoch
2012-04-29 17:13 - 2016-01-05 06:32 - 0005120 _____ () C:\Users\Dad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-12-30 20:47 - 2012-12-30 20:47 - 0000036 _____ () C:\Users\Dad\AppData\Local\housecall.guid.cache
2012-06-19 17:15 - 2012-06-19 17:18 - 0000000 _____ () C:\Users\Dad\AppData\Local\null
2012-06-19 17:09 - 2016-10-13 20:38 - 0007642 _____ () C:\Users\Dad\AppData\Local\resmon.resmoncfg
2015-02-18 23:46 - 2015-02-18 23:46 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
====================
C:\Users\Dad\DesktopLSPFix.exe
C:\Users\Dad\DesktopSafeMSI.exe
C:\Users\Dad\DesktopWinsockxpFix.exe
C:\Users\Dad\hpothb07.dat
C:\Users\Dad\jobq.dat


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-18 23:44

==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-10-2016
Ran by [removed] (17-10-2016 14:00:50)
Running from C:\Users\[removed]\Desktop
Windows 8.1 Pro (Update) (X64) (2015-02-19 08:35:50)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-968235783-2654321925-1125524309-500 - Administrator - Enabled) => C:\Users\Administrator
Dad (S-1-5-21-968235783-2654321925-1125524309-1000 - Administrator - Enabled) => C:\Users\Dad
Guest (S-1-5-21-968235783-2654321925-1125524309-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Security (Enabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: IObit Malware Fighter (Disabled - Out of date) {4D381C57-3C7A-6F22-07EB-639F49E836D4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
AS: Norton Security (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton Security (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

ABBYY FineReader 6.0 Sprint (HKLM-x32\…\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House)
Acoustica MP3 CD Burner (HKLM-x32\…\Acoustica MP3 CD Burner) (Version:  - Acoustica, Inc)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.020.20039 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 20.0.0.260 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.162 - Adobe Systems Incorporated)
Advanced SystemCare 9 (HKLM-x32\…\Advanced SystemCare_is1) (Version: 9.4.0 - IObit)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Audacity 2.0.2 (HKLM-x32\…\Audacity_is1) (Version: 2.0.2 - Audacity Team)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bonjour (HKLM\…\{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}) (Version: 2.0.2.0 - Apple Inc.)
Bonjour Print Services (HKLM\…\{0DA20600-6130-443B-9D4B-F30520315FA6}) (Version: 2.0.2.0 - Apple Inc.)
Build-a-lot 4 - Power Source (x32 Version: 2.2.0.97 - WildTangent) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.22 - Piriform)
Chord Pickout 3.0 (HKLM-x32\…\Chord Pickout 3.0) (Version: 3.0 - ChordPickout.com)
Chronicles of Albian (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cisco WebEx Meetings (HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Citrix Online Launcher (HKLM-x32\…\{1EFF9E6C-76E1-43F9-81FB-BC8C037B0902}) (Version: 1.0.258 - Citrix)
Cradle of Rome 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
CyberLink MediaEspresso (HKLM-x32\…\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1720_38230 - CyberLink Corp.)
CyberLink PowerDirector 13 (HKLM-x32\…\{BA385AFC-00B1-417C-8C20-74B996EF3AF0}) (Version: 13.0.2104.0 - CyberLink Corp.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.3313.52 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DriverTuner 3.1.0.1 (HKLM-x32\…\{520C1D80-935C-42B9-9340-E883849D804F}_is1) (Version: 3.1.0.1 - LionSea SoftWare)
Duplicate File Finder Plus 5.0 (HKLM-x32\…\Duplicate File Finder Plus_is1) (Version:  - TriSun Software Inc.)
Duplicate Photo Finder Plus 4.0 (HKLM-x32\…\Duplicate Photo Finder Plus_is1) (Version:  - TriSun Software Inc.)
eBay Worldwide (HKLM-x32\…\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
Epson Copy Utility 3.4 (HKLM-x32\…\{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}) (Version: 3.4.0.0 - )
EPSON GT-1500 User's Guide (HKLM-x32\…\Silent Package Run-Time Sample) (Version:  - )
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON Scan PDF EXtensions (HKLM-x32\…\{F9956472-6E16-4F83-BF9A-F887EF4A45B7}) (Version: 1.00.0000 - SEIKO EPSON Corp.)
EpsonNet Config V4 (HKLM-x32\…\{08013FB5-DF8B-4D29-9B5E-B3DE88EBA6CA}) (Version: 4.5.4 - SEIKO EPSON CORPORATION)
Etron USB3.0 Host Controller (x32 Version: 0.103 - Etron Technology) Hidden
FamilySearch Indexing 3.27.7 (HKLM-x32\…\0591-8077-9297-0833) (Version: 3.27.7 - FamilySearch)
ffdshow [rev 2527] [2008-12-19] (HKLM-x32\…\ffdshow_is1) (Version: 1.0 - )
File Association Helper (HKLM\…\{572D0504-2C67-4016-801F-D70879A3026A}) (Version: 1.1.6.53763 - WinZip Computing International, LLC)
File Association Manager (HKLM-x32\…\FileAssociationManager) (Version: 0.7 - Amnis Technology Ltd)
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
FrostWire 6.3.4 (HKLM-x32\…\FrostWire 6) (Version: 6.3.4.194 - FrostWire LLC)
Galerie de photos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Gateway Games (HKLM-x32\…\WildTangent gateway Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Gateway Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3502 - Gateway Incorporated)
Gateway Registration (HKLM-x32\…\Gateway Registration) (Version: 1.04.3503 - Gateway Incorporated)
Gateway ScreenSaver (HKLM-x32\…\Gateway Screensaver) (Version: 1.1.0225.2011 - Gateway Incorporated)
Gateway Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3500 - Gateway Incorporated)
Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\…\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
GoToMeeting 7.1.0.2352 (HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\GoToMeeting) (Version: 7.1.0.2352 - CitrixOnline)
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden
Hard Disk Sentinel PRO (HKLM-x32\…\Hard Disk Sentinel_is1) (Version:  - HDS)
Hotkey Utility (HKLM-x32\…\Hotkey Utility) (Version: 2.05.3505 - Gateway Incorporated)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3501 - Gateway Incorporated)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2353 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
ISIS Driver - EPSON GT-1500 v1.6.10802.6001 (HKLM-x32\…\{D41864EF-CC5D-4CF4-B0B9-CA3152164157}) (Version: 1.6.10802.6001 - EMC Captiva)
iTunes (HKLM\…\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.)
Java 8 Update 102 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F64180102F0}) (Version: 8.0.1020.14 - Oracle Corporation)
Jewel Match 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
K9 (HKLM-x32\…\K9) (Version:  - )
KODAK Share Button App (HKLM-x32\…\{F5930CDE-2FF5-4A8D-9DBD-3177C816D4A9}) (Version: 4.06.0015.0313 - Eastman Kodak Company)
LastPass (uninstall only) (HKLM-x32\…\LastPass) (Version:  - LastPass)
Logitech Harmony Remote Software 7 (HKLM-x32\…\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech)
Logitech SetPoint 6.65 (HKLM\…\sp6) (Version: 6.65.62 - Logitech)
MailWasherPro (HKLM-x32\…\{A5901025-525B-4B2A-ACF4-E742D989D008}) (Version: 7.8 - Firetrust)
MailWasherPro (HKLM-x32\…\{DE507F73-E58C-4291-BA6B-F2E7FD386E7E}) (Version: 1.20.0 - Firetrust)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MEGAsync (HKLM-x32\…\MEGAsync) (Version:  - Mega Limited)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\OneDriveSetup.exe) (Version: 17.3.6201.1019 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\…\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MotoCast (HKLM-x32\…\{5401CEE8-3C2D-4835-A802-213306537FF4}) (Version: 1.2.7 - Motorola Mobility)
MotoHelper 2.1.40 Driver 5.5.0 (HKLM-x32\…\MotoHelper) (Version: 2.1.40 - Motorola)
MotoHelper MergeModules (x32 Version: 1.2.0 - Motorola) Hidden
MOTOROLA MEDIA LINK (x32 Version: 1.7.0147.0 - Motorola) Hidden
Motorola Mobile Drivers Installation 5.5.0 (Version: 5.5.0 - Motorola Inc.) Hidden
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MozBackup 1.5.1 (HKLM-x32\…\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 49.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 49.0.1 (x86 en-US)) (Version: 49.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 49.0.1.6109 - Mozilla)
Mozilla Thunderbird 24.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Thunderbird 24.0.1 (x86 en-US)) (Version: 24.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyHeritage Family Tree Builder (HKLM-x32\…\Family Tree Builder) (Version: 8.0.0.8333 - MyHeritage.com)
Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
NewBlue Video Essentials for Windows (HKLM-x32\…\NewBlue Video Essentials for Windows) (Version: 3.0 - NewBlue)
Norton Management (HKLM-x32\…\MCLIENT) (Version: 3.2.2.12 - Symantec Corporation)
Norton Security with Backup (HKLM-x32\…\NSBU) (Version: 22.8.0.50 - Symantec Corporation)
NVIDIA 3D Vision Controller Driver 364.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 364.44 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 368.39 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 368.39 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.11.3.5 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.11.3.5 - NVIDIA Corporation)
NVIDIA Graphics Driver 368.39 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 368.39 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.14 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.14 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
Palm Desktop by ACCESS (HKLM-x32\…\{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}) (Version: 6.4.0.0 - Palm, Inc.)
PaperPort Image Printer 64-bit (HKLM\…\{ABA4FAF1-6389-45F9-92CE-3914A4E5C471}) (Version: 1.00.0000 - Nuance Communications, Inc.)
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
Prerequisite installer (x32 Version: 15.0.0005 - Nero AG) Hidden
QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
RealDownloader (x32 Version: 17.0.15.4 - RealNetworks, Inc.) Hidden
RealDownloader (x32 Version: 17.0.15.7 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2005 Runtime (x32 Version: 8.0 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\…\RealPlayer 17.0) (Version: 17.0.15 - RealNetworks)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7746 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
RootsMagic 6.3.0.4 (HKLM-x32\…\{94433E0D-764C-4964-AD0B-EC46BCA7E68E}_is1) (Version: RootsMagic 6.3.0.4 - RootsMagic, Inc.)
ScanSoft PaperPort 11 (HKLM-x32\…\{DEA18FF6-D84A-4242-9663-692E5BA56805}) (Version: 11.1.0000 - Nuance Communications, Inc.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.11.3.5 - NVIDIA Corporation) Hidden
Software Informer 1.2 (HKLM\…\Software Informer_is1) (Version:  - Informer Technologies, Inc.)
Start Menu 8 (HKLM-x32\…\IObit_StartMenu8_is1) (Version: 3.1.0.3 - IObit)
Surfing Protection (HKLM-x32\…\IObit Surfing Protection_is1) (Version: 1.3 - IObit)
thinkorswim (HKLM\…\9968-4488-2169-7623) (Version: desktop - thinkorswim, Inc)
Torchlight (x32 Version: 2.2.0.97 - WildTangent) Hidden
Torrents Downloader (HKLM-x32\…\{6D9D814E-9605-11E2-80DC-95A26188709B}_is1) (Version: 0.3.20.14.06.30.-W.32 - Torrent Software S.L.)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
USB-Ir Adapter (HKLM-x32\…\{00F3D43F-B5A9-4C8D-B5A1-5FD2DE16CC21}) (Version: 1.03.0000 - )
USB-Ir Adapter (HKLM-x32\…\{76AD2AAC-14EE-4CE3-958A-BB3DF65E7F06}) (Version: 1.03.0000 - )
Verizon Cloud (HKLM\…\Verizon Cloud) (Version: 15.3.7.9 - Verizon)
Video Downloader (x32 Version: 1.0.0 - RealNetworks) Hidden
Virtual Villagers 5 - New Believers (x32 Version: 2.2.0.97 - WildTangent) Hidden
Vulkan Run Time Libraries 1.0.11.1 (HKLM\…\VulkanRT1.0.11.1-2) (Version: 1.0.11.1 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.11.1 (Version: 1.0.11.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.5.1 (HKLM\…\VulkanRT1.0.5.1) (Version: 1.0.5.1 - LunarG, Inc.)
WD My Cloud (HKLM-x32\…\WD My Cloud) (Version: 1.0.2.34 - Western Digital Technologies, Inc.)
WD Quick View (HKLM-x32\…\{F4F2EF32-EAFE-4F87-B7DC-E19C9F8E76FC}) (Version: 2.4.16.16 - Western Digital Technologies, Inc.)
WD SmartWare Installer (HKLM-x32\…\{4555885d-a64c-4234-9aac-72a8a6b5590b}) (Version: 2.4.16.16 - Western Digital Technologies, Inc.)
WebEx Support Manager for Internet Explorer (HKLM-x32\…\{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}) (Version: 6.5.47 - WebEx Communications Inc.)
Welcome Center (HKLM-x32\…\Gateway Welcome Center) (Version: 1.02.3504 - Gateway Incorporated)
WildTangent Games App (Gateway Games) (x32 Version: 4.0.5.14 - WildTangent) Hidden
Windows 10 Upgrade Assistant (HKLM-x32\…\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17332 - Microsoft Corporation)
Windows Driver Package - Eastman Kodak KODAK Digital Camera (01/29/2010 1.4.1.0) (HKLM\…\3D970B9F930E7AAE23C06D39A1AC98548C90B442) (Version: 01/29/2010 1.4.1.0 - Eastman Kodak)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 4.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinZip 18.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
WinZip Courier (HKLM-x32\…\{CD95F661-A5C4-11AF-B2CC-ABCD21A326A2}) (Version: 5.0.10661 - WinZip Computing, S.L. )
Wise Care 365 3.14 (HKLM-x32\…\Wise Care 365_is1) (Version: 3.14 - WiseCleaner.com, Inc.)
WorkForce GT-1500 Scanner Driver Update (HKLM-x32\…\{37D0F29D-AB95-4598-ACF0-D3CC38C161D9}) (Version:  - )
Yahoo! Messenger (HKLM-x32\…\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Zuma's Revenge (x32 Version: 2.2.0.97 - WildTangent) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-968235783-2654321925-1125524309-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Dad\AppData\Local\Citrix\GoToMeeting\2331\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0000B919-F681-4B54-828F-98EE446A4ABE} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {02AC57F2-B024-4079-B1EE-14F764046DD2} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {0452FD84-596C-44EC-BEF2-71F711B297BD} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {0E1BE2DA-6B04-4C0A-B88E-9892DED632DD} - System32\Tasks\Norton Management\Norton Error Processor => C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\SymErr.exe [2012-10-18] (Symantec Corporation)
Task: {0F5B218F-1397-4BAC-8139-CFBB8A75D270} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-10-13] (Microsoft Corporation)
Task: {114E4F3E-9481-4827-8DD8-098B1EE15160} - System32\Tasks\Microsoft\Windows\PLA\System\{D3F84E41-38E7-46AD-9900-AC7AFDBF649A}_System Diagnostics => Rundll32.exe C:\Windows\system32\pla.dll,PlaHost "system\System Diagnostics" "$(Arg0)"
Task: {11711B8D-58D9-4599-BC56-17C832D3E1F4} - System32\Tasks\{878F1772-4AB7-44C8-BEB0-17F67BA8F7CA} => pcalua.exe -a C:\Epson\epson13550.exe -d C:\Epson
Task: {11FE180B-FF6A-4AA3-AF05-DF1C3FE8D817} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {144311FC-9410-4E32-96AA-97F469BD120B} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {15E261A2-4061-436E-9F15-C2D00CDC1885} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Security\Upgrade.exe [2016-09-23] (Symantec Corporation)
Task: {17EDF0D1-6307-4E85-AB56-050EC420AC33} - System32\Tasks\RealDownloader Update Check => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [2014-10-29] ()
Task: {1A84DA6E-3F71-46B2-961D-D949C179BF2A} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {1BE7C143-ED7C-4677-907C-65F4642DF93A} - System32\Tasks\Norton Security with Backup\Norton Error Analyzer => C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\SymErr.exe [2016-09-23] (Symantec Corporation)
Task: {1C5113A8-3C8C-459C-9826-1DEA57F176C0} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2011-05-20] (CyberLink)
Task: {1CC1E9F4-2D54-442C-A480-569C303C44D1} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1010 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {1DACEE27-B4FC-4264-9829-71E3CBB4CBAE} - no filepath
Task: {1DF4F4A1-A69E-43E5-B6D5-05EF513C2DED} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\WINDOWS\system32\MRT.exe [2016-10-13] (Microsoft Corporation)
Task: {1E528A5A-342B-4C03-ACB6-810E496E8447} - System32\Tasks\{AE11724B-E59B-4B45-894D-D535ADF6C133} => pcalua.exe -a "C:\Program Files (x86)\Palm\Instapp.exe" -d "C:\Program Files (x86)\Palm\"
Task: {2391896C-BD42-4A39-9D96-EB2F89677607} - \SpeedFixToolPro_Popup -> No File <==== ATTENTION
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {242751DA-0C0A-4A97-AA54-4CFD90B25AB4} - System32\Tasks\Western Digital\SmartWare\____Volume_04d58046_2adf_11e1_adc2_806e6f6e6963__uuid_73656761_7465_7375_636b_0090a9beb7c2_Public_ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [2016-04-19] (Western Digital Technologies, Inc.)
Task: {276D15C3-17FA-4825-B06A-C04C60347642} - System32\Tasks\{84AA05B6-6C14-4B5A-BEAF-0D8C5D21DD85} => c:\Program Files\Microsoft Mouse and Keyboard Center\MouseKeyboardCenter.exe [2014-03-19] (Microsoft)
Task: {28BB85C9-E3D1-4567-A96E-1357A29470CD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-26] (Piriform Ltd)
Task: {294CB615-3543-4A98-9133-AB13C523F020} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {2AA350E3-9DF3-4311-86BD-8DCD140C9AC1} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {2DC0DDCC-0466-41A5-AE99-441EC497D78B} - System32\Tasks\ASC9_SkipUac_Dad => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-07-28] (IObit)
Task: {2FAA420C-2E2E-4530-AAF3-29437EA8A24F} - System32\Tasks\Driver Booster SkipUAC (Dad) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {30027EC5-B21F-4253-8B7E-84C60B0AE351} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {34160783-C4B4-4131-A34C-3FE5AC7434FF} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_Dad => C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe [2016-06-27] (H.D.S. Hungary)
Task: {345CA5BD-637C-4286-8D4E-6E11708052E6} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {359BB32E-A5DD-4CE1-B97F-69E59599E51A} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {386DB6E6-C842-434E-844F-23C5836DB2C2} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: {39C23A6D-6A73-4BB5-90C1-5BFC6B6919D7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {3CC7F30A-D22F-4A08-9D5F-F5F350B1C494} - System32\Tasks\Driver Booster Beta SkipUAC (Dad) => C:\Program Files (x86)\IObit\Driver Booster Beta\4.0.0\DriverBooster.exe
Task: {3E73DCFF-BF83-461B-9914-11880482FD22} - System32\Tasks\ReclaimerUpdateFiles_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {42BBA90C-92ED-4149-B918-0052E6BD1577} - System32\Tasks\{ABFB8086-32AB-48C7-AF44-CF3D1D8B6D36} => pcalua.exe -a C:\Nero\InCD-4.3.23.2.exe -d C:\Nero
Task: {42CE7EA5-D19C-4435-B796-0926121BAE50} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {479E6178-61D5-40D4-9A36-74FB1583003C} - System32\Tasks\MotoHelper Update => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {494A2782-FF45-440A-84EA-B3FB183DA468} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-16] (Adobe Systems Incorporated)
Task: {4AB21BBA-76B5-45E7-B69C-15DCF95F9310} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-26] (Adobe Systems Incorporated)
Task: {4D6CC432-3EF3-4ECC-9481-75AC4FE09D1A} - System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe => c:\Program Files\Microsoft Device Center\devicecenter.exe
Task: {4EDE0CF4-0D42-4C97-8F1B-2EE6EEE3187B} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: {5256830D-EF5F-4A2B-941C-4BAD9F3951D6} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1010 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {5856FC30-B706-4C98-BADA-9BD645B28BD8} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => C:\Windows\system32\GWX\GWX.exe
Task: {5B9334BA-ADC4-42A2-AE8B-719BC03B420C} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {5C7BDB02-B3E2-4C28-816E-2B91D7CE9859} - System32\Tasks\{F850ED23-C3D5-43F2-B9BC-A17167885D9D} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\7-Zip\7zFM.exe"
Task: {5DEB5A0E-094E-4E20-8C09-BD825E9A1FC9} - System32\Tasks\Norton Management\Norton Error Analyzer => C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\SymErr.exe [2012-10-18] (Symantec Corporation)
Task: {66FA5938-862D-4D97-A64D-72AA0D340F50} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {69C7CF9C-020F-455A-BFE5-B63071BF9F28} - System32\Tasks\{DC3256B7-E258-4B58-9048-51D7DF51E46D} => pcalua.exe -a C:\Users\Dad\Desktop\jxpiinstall(1).exe -d C:\Users\Dad\Desktop
Task: {6F66763A-0B81-4E57-A300-19F36FC0AAC6} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => C:\Windows\system32\GWX\GWX.exe
Task: {723EB32C-4249-4787-8FE2-DF4260DFC146} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-10-26] (RealNetworks, Inc.)
Task: {72E5255E-0875-4813-B09F-FD232A5545EC} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {7467BB5D-28DD-4CFC-8316-E86266BAE878} - System32\Tasks\Microsoft\Windows\PLA\System\{950FE130-0326-4B76-9EA5-5F813F013A59}_System Diagnostics => Rundll32.exe C:\WINDOWS\system32\pla.dll,PlaHost "system\System Diagnostics" "$(Arg0)"
Task: {7910552E-EC04-4FC5-B158-74F97FDA1A23} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe
Task: {7A4ED00F-6437-4A14-A10E-AED03DF334B2} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\WSCStub.exe [2016-09-23] (Symantec Corporation)
Task: {7AD4753A-5075-4846-B933-4FB4D8937816} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {7B5D1C74-AD6F-4715-9569-70787F9F544A} - System32\Tasks\{0B4A356D-228A-48A1-81FD-F42244C76E1F} => pcalua.exe -a C:\Users\Dad\Desktop\express_hd-en_2_5_113.exe -d C:\Users\Dad\Desktop
Task: {7B7CCB54-D476-4970-9F70-4F8CF79F5DA3} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d => C:\Windows\system32\GWX\GWX.exe
Task: {7D4EC411-2076-41FE-B5A7-45F5FB1DC365} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {8147216B-D7D4-490C-8A57-C99E8CB09673} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {83827CAF-CC2B-47D7-B189-AABDF37D1C36} - System32\Tasks\Norton Security with Backup\Norton Error Processor => C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\SymErr.exe [2016-09-23] (Symantec Corporation)
Task: {882E042B-1F64-49CC-9971-1446C9CCA820} - \SpeedFixToolPro_Start -> No File <==== ATTENTION
Task: {8C1FDF72-5716-404C-B64A-9CF4450B9BF6} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {8D5A910C-0A75-466E-87E2-1E77B48E40F8} - \Search-Protect -> No File <==== ATTENTION
Task: {8E3881FC-2D20-4276-8719-5E57F9876ABD} - System32\Tasks\{8AAFB465-D710-49A0-817A-25ED1D61B1E1} => pcalua.exe -a "C:\Program Files (x86)\Uniblue\RegistryBooster\rb_track_install.exe" -d "C:\Program Files (x86)\Uniblue\RegistryBooster"
Task: {8F0AA531-EDA2-47FF-B91C-98451EAFB836} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {8F13BC62-989B-4551-87BC-4E7897041568} - System32\Tasks\{D3EEF7C1-ABB2-4C4B-94F8-D9157D801C1E} => pcalua.exe -a "C:\Program Files (x86)\IObit\Advanced SystemCare 7\SecurityHole_Backup\KB2565063.exe" -d C:\Windows\system32 -c /quiet /norestart
Task: {94D5C23E-FB1A-49F1-907F-77177B3FA04B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {95BF0CE7-962C-4DEC-92CB-3421FD1F41C5} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {97CF5DD5-A51D-41AE-87C5-B4FD1F358C70} - System32\Tasks\ReclaimerUpdateXML_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {9B759EA6-A5AB-47ED-8CEE-3E62986F7726} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {9D2278A7-7FCF-46A4-81CA-5BB6EE5C9CB8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-24] (Google Inc.)
Task: {9E4C23AE-F294-4C05-B2F5-E00DE40A3AB4} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {A177F73F-F74D-4AA2-A139-C5B522356209} - System32\Tasks\{C3CFB6E9-48A8-448F-AC01-70C101A5A0E5} => pcalua.exe -a C:\Users\Dad\Desktop\epson15561(1).exe -d C:\Users\Dad\Desktop
Task: {A2EB1708-4F29-4422-94E5-BF8A52F09C39} - System32\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000 => C:\Users\Dad\AppData\Local\Citrix\GoToMeeting\2352\g2mupdate.exe [2015-02-18] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {A52BB76E-951C-44F6-9E6D-7C8BD394218A} - System32\Tasks\{1EAA833A-9F24-413E-83E1-D7BE01CAFE79} => pcalua.exe -a "C:\Users\Dad\Desktop\Logitech 650HarmonyRemote7.7.0-WIN-x86.exe" -d C:\Users\Dad\Desktop
Task: {A65A0ACC-6A4D-474C-AAF2-E9DC6B09F05D} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {A94B86DD-CE9B-4D06-A8AB-0C4B044C56EA} - System32\Tasks\{9305B88E-04F4-4F7A-9EFA-3AB702618F79} => pcalua.exe -a D:\ENGLISH\QuikProtect\Setup.exe -d D:\ENGLISH\QuikProtect
Task: {A94EEAAD-AE37-4457-AB00-3E4F6390C8DE} - System32\Tasks\RNUpgradeHelperLogonPrompt_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {AF48D3C4-5B0D-4996-B1CE-CFFF8BAE74FC} - System32\Tasks\Western Digital\SmartWare\____Volume_04d58046_2adf_11e1_adc2_806e6f6e6963__uuid_73656761_7465_7375_636b_0090a9beb7c2_TimeMachineBackup_ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [2016-04-19] (Western Digital Technologies, Inc.)
Task: {BB5AE570-FDF9-4C37-B44E-B9F39C1E63E6} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BF1E8827-83C9-4066-B1C2-56BF616DF716} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {C3455D9F-F7A1-4DAE-A80D-2136FE0043CB} - System32\Tasks\ASC9_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [2016-07-20] (IObit)
Task: {CA5940DB-9B00-4239-A48A-141A2DC19AD9} - System32\Tasks\{70A11D50-D1CE-459B-94C3-BE1540DB15AD} => pcalua.exe -a C:\Users\Dad\Desktop\wlsetup-web(1).exe -d C:\Users\Dad\Desktop
Task: {CB61031D-4459-4488-9042-C51BB29A381E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-24] (Google Inc.)
Task: {CC0868F1-E784-47FE-A5EB-312211866188} - System32\Tasks\{5C717479-B68F-4619-B051-07EABCEA176C} => pcalua.exe -a "C:\Users\Dad\Downloads\free audio recorder setup.exe" -d C:\Users\Dad\Downloads
Task: {CE300405-17AE-40F2-BEE2-D1E8D174F0E4} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {D0BCBD01-C1BF-4E62-B01F-0738BB5FBB49} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {D2DBB9FC-AC9E-4473-BC14-F2805315AB36} - System32\Tasks\{AB7ACF4B-2835-47BB-976D-DA349FE5359A} => pcalua.exe -a C:\Users\Dad\Desktop\Acoustica-MP3-CD-Burner-Installer(1).exe -d C:\Users\Dad\Desktop
Task: {D836BFE8-AD65-4CC5-A20D-3B17B0A73E4F} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {D91E354B-9EF5-4BD4-9D80-D4DD8828601C} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Time-5d => C:\Windows\system32\GWX\GWX.exe
Task: {D99F0BF7-5D39-41D3-9378-4A4C4C48BB39} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe
Task: {DBED9451-604E-4D9E-BC25-B290D74851D1} - no filepath
Task: {DC0C82C1-5196-4B60-85C8-FB595D65F815} - System32\Tasks\{F0AA062F-A811-4913-8616-1586C4C104AB} => pcalua.exe -a "D:\WD SmartWare\dotnetfx35.exe" -d "D:\WD SmartWare"
Task: {DE3860C3-6209-4467-9CB2-4DCE6E38340E} - System32\Tasks\RNUpgradeHelperResumePrompt_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {DF865F82-3A48-4EAE-BAB1-36F8E6C3ECF6} - System32\Tasks\{2669E051-8302-4910-87D9-1960015B033E} => Firefox.exe
Task: {E1431FDE-59BC-4B5F-BDD4-A4DFC391C365} - System32\Tasks\MotoCast Update => C:\Program Files (x86)\Motorola Mobility\MotoCast\LiveUpdate\MotoCastUpdate.exe [2012-02-09] ()
Task: {E4F59CFB-B00C-4E5B-A65E-F17CB49CF3DD} - System32\Tasks\{51CA52CC-2853-4A45-AFBA-112610F5AC17} => pcalua.exe -a C:\Users\Dad\Documents\Downloads\documentstogopro7006-en.exe -d C:\Users\Dad\Documents\Downloads
Task: {E77650C6-5C0E-41C9-915C-A69DF3B71A38} - System32\Tasks\{3497E5F7-9423-4E4B-96E9-54984E4C8053} => pcalua.exe -a C:\Users\Dad\Desktop\SetupStrategyDesk.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {EA78BE35-04C4-4134-8ACD-52793D84FA45} - System32\Tasks\Microsoft\Windows\Setup\EOONotify => C:\Windows\EOONotify\EOONotify.exe [2016-07-08] (Microsoft Corporation)
Task: {ED327880-0A3E-4649-A790-8BCD30FFD8D1} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {EF015110-BDA2-4514-B737-16F1EDD0FAB7} - System32\Tasks\MotoHelper Routing => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {EF75BABB-9A77-4BC8-B332-91A96482055D} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => C:\Windows\system32\GWX\GWXConfigManager.exe
Task: {F0DE022C-BDE0-42F3-B3C0-24234C10D9ED} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => C:\Windows\system32\GWX\GWX.exe
Task: {F485FC4B-1875-47D1-9D74-09706F59D1C2} - System32\Tasks\{52DC35EC-81F8-4964-8076-FDA7BF65EB24} => pcalua.exe -a C:\Epson\epson15546.exe -d C:\Epson
Task: {F6852A2F-CD85-43F5-823A-66EA81588F1A} - System32\Tasks\{5355B45C-4DD9-448E-9BB3-CAD6E6C94514} => msiexec.exe /package "C:\Users\Dad\Desktop\WD SmartWare Upgrader.msi"
Task: {F6CA1060-0EC0-4E1C-AF8F-AA4B0DFD51A6} - System32\Tasks\MotoHelper Initial Update => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {FABF09A5-4413-4E62-BB04-A032C1CC33B5} - System32\Tasks\{10EF5062-FADE-4238-95E4-4EA61663B88F}-Kodak Share Button App Camera detect => C:\Program Files (x86)\Kodak\KODAK Share Button App\Listener.exe [2015-02-09] (Eastman Kodak Company)
Task: {FBC5387B-8A12-416E-9E59-4D93C8943E47} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => C:\Windows\system32\GWX\GWX.exe
Task: {FD3AA1AA-228A-4F66-AB1F-94EE4B4E3154} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {FFCE48F4-CC06-4275-ADD2-BE639EBC5D7B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_Dad.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000.job => C:\Users\Dad\AppData\Local\Citrix\GoToMeeting\2352\g2mupdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Dad\AppData\Local\5b65\47e2.lnk -> C:\Users\Dad\AppData\Local\5b65\05b1.bat ()
Shortcut: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FrostWire 6\FrostWire 6.3.4-SafeMode.lnk -> C:\Program Files (x86)\FrostWire 6\frostwire.bat ()

==================== Loaded Modules (Whitelisted) ==============

2015-02-18 23:45 - 2016-06-02 22:26 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-04-15 04:15 - 2016-05-02 00:54 - 00369208 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
2016-05-24 17:58 - 2016-05-02 00:55 - 00289848 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2016-04-15 04:15 - 2016-05-02 00:54 - 01148984 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\libprotobuf.dll
2016-04-15 04:15 - 2016-05-02 00:55 - 03613240 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll
2016-04-15 03:58 - 2016-05-02 00:55 - 01842232 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll
2016-01-29 00:21 - 2016-05-02 00:55 - 00208952 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll
2016-04-15 03:58 - 2016-05-02 00:55 - 02667576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll
2016-04-15 03:58 - 2016-05-02 00:55 - 01990200 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll
2016-05-24 17:58 - 2016-05-02 00:54 - 00035896 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_system-vc120-mt-1_58.dll
2016-05-24 17:58 - 2016-05-02 00:54 - 00921656 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_regex-vc120-mt-1_58.dll
2014-05-01 09:13 - 2014-05-01 09:13 - 00470016 _____ () C:\ProgramData\MEGAsync\ShellExtX64.dll
2012-02-07 16:54 - 2012-02-07 16:54 - 00128336 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\liveupdatetactics.dll
2012-02-07 16:53 - 2012-02-07 16:53 - 00023872 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\DbAccess.dll
2012-02-07 16:56 - 2012-02-07 16:56 - 00465632 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\sqlite3.dll
2012-02-07 16:54 - 2012-02-07 16:54 - 00045368 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\NAdvLog.dll
2012-02-07 16:54 - 2012-02-07 16:54 - 00034128 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\NFileCacheDBAccess.dll
2015-11-25 13:04 - 2015-11-06 13:05 - 00618784 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll
2016-08-30 13:47 - 2015-12-29 11:30 - 00355616 _____ () C:\Program Files (x86)\IObit\Classic Start\madExcept_.bpl
2016-08-30 13:47 - 2015-12-29 11:29 - 00190240 _____ () C:\Program Files (x86)\IObit\Classic Start\madBasic_.bpl
2016-08-30 13:47 - 2015-12-29 11:30 - 00057632 _____ () C:\Program Files (x86)\IObit\Classic Start\madDisAsm_.bpl
2016-08-30 13:47 - 2015-12-29 11:30 - 00275576 _____ () C:\Program Files (x86)\IObit\Classic Start\sqlite3.dll
2016-08-30 13:47 - 2015-12-29 11:30 - 00059680 _____ () C:\Program Files (x86)\IObit\Classic Start\parseAuto.dll
2016-08-30 13:47 - 2015-12-29 11:30 - 00625440 _____ () C:\Program Files (x86)\IObit\Classic Start\ProductStatistics.dll
2014-05-01 09:15 - 2014-05-01 09:15 - 00463360 _____ () C:\ProgramData\MEGAsync\ShellExtX32.dll
2016-08-30 13:47 - 2015-12-29 11:31 - 00047904 _____ () C:\Program Files (x86)\IObit\Classic Start\winkey.dll
2016-01-03 10:34 - 2016-05-02 01:02 - 00020536 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-08-28 23:26 - 2015-12-28 13:50 - 00899872 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\webres.dll
2016-08-28 23:26 - 2015-12-28 13:49 - 00629536 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\ProductStatistics.dll
2016-04-13 14:56 - 2016-04-13 14:56 - 00061952 _____ () C:\Program Files (x86)\FireTrust\MailWasher\MWPBridgeDLL.dll
2016-04-13 14:56 - 2016-04-13 14:56 - 05999616 _____ () C:\Program Files (x86)\FireTrust\MailWasher\MWPappDLL.dll
2016-04-18 13:14 - 2016-04-18 13:14 - 00069272 _____ () C:\Program Files (x86)\FireTrust\MailWasher\FTBridge.dll
2016-04-18 13:14 - 2016-04-18 13:14 - 00279704 _____ () C:\Program Files (x86)\FireTrust\MailWasher\FTClientNode.dll
2016-03-23 22:07 - 2016-03-23 22:07 - 00324608 _____ () C:\Program Files (x86)\FireTrust\MailWasher\MWPHeaderParser.dll
2016-08-28 23:26 - 2015-12-28 13:50 - 01293088 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\Scan.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_0news-1751121550 [2302]
AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_1messages-431041656 [2302]
AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_2events-250898981 [2302]
AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_3friends-215113587 [2302]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\str => ""="service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\linkedin.com -> hxxps://www.linkedin.com
IE trusted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\microsoft.com -> hxxps://v4.update.microsoft.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\100sexlinks.com -> 100sexlinks.com

There are 4794 more sites.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-968235783-2654321925-1125524309-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: IDriverT => 3
MSCONFIG\Services: IMFservice => 3
MSCONFIG\Services: Live Updater Service => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: NAUpdate => 3
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: nvUpdatusService => 2
MSCONFIG\Services: RealNetworks Downloader Resolver Service => 2
MSCONFIG\Services: Stereo Service => 2
MSCONFIG\Services: UNS => 2
MSCONFIG\Services: WDDMService => 3
MSCONFIG\Services: WDFMEService => 2
MSCONFIG\Services: WDRulesService => 2
MSCONFIG\Services: WiseBootAssistant => 2
MSCONFIG\Services: YahooAUService => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HotSync Manager.lnk => C:\Windows\pss\HotSync Manager.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: EEventManager => C:\PROGRA~2\Epson Software\EVENTM~1\EEVENT~1.EXE
MSCONFIG\startupreg: Family Tree Builder Update => C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe
MSCONFIG\startupreg: HotSync =>
MSCONFIG\startupreg: IndexSearch => c:\program files (x86)\scansoft\paperport\indexsearch.exe
MSCONFIG\startupreg: MotoCast => "c:\program files (x86)\motorola mobility\motocast\motolauncher.lnk"
MSCONFIG\startupreg: PaperPort PTD => c:\program files (x86)\scansoft\paperport\pptd40nt.exe
MSCONFIG\startupreg: RtHDVCpl => c:\program files\realtek\audio\hda\ravcpl64.exe -s
MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\update\realsched.exe"  -osboot
MSCONFIG\startupreg: WD Quick View => c:\program files (x86)\western digital\wd quick view\wddmstatus.exe
HKLM\…\StartupApproved\StartupFolder: => "Install LastPass FF RunOnce.lnk"
HKLM\…\StartupApproved\StartupFolder: => "Install LastPass IE RunOnce.lnk"
HKLM\…\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\…\StartupApproved\Run: => "EvtMgr6"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\…\StartupApproved\Run32: => "PaperPort PTD"
HKLM\…\StartupApproved\Run32: => "IObit Malware Fighter"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\StartupFolder: => "MailWasherPro.lnk"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\StartupFolder: => "JL Christmas Market.lnk"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\StartupFolder: => "JL Victorian Calendar.lnk"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\Run: => "Advanced SystemCare 9"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\Run: => "KGShareApp"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [{868D6CCB-92A2-4F9A-B4BC-906CBE16C222}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [TCP Query User{7C7799AE-32CB-4FC4-94D9-7C8D5E49495B}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [UDP Query User{3F78ED35-0A0B-4195-A250-C62E303143DC}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [{A1752C7D-FED1-4AB7-BEA7-8702DFAE2466}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{CF3C48EB-F298-4234-BE76-4B77EFEF71F7}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{D896BF4A-B8C6-402E-8B26-FA941C35AFE0}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{4C362F15-FCBB-41F9-923C-66A2D0B598FC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C5ED500B-635C-4175-ACA3-39CB6B94F43B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{3A529617-79F5-4276-A1C4-25404C1FE206}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{8BB43B39-CDC3-4D33-97EF-DDB5B9A0D054}] => (Allow) LPort=2869
FirewallRules: [{62672AD7-4CF4-44FB-A466-22810DE4D035}] => (Allow) LPort=1900
FirewallRules: [{0D7AE57D-C1F0-48F2-95C3-169DFA7BAECC}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{15A4AE51-8E92-428D-8DCE-BDE09261B17F}] => (Allow) C:\Program Files (x86)\FrostWire 6\FrostWire.exe
FirewallRules: [{D98C2122-0505-4516-8F29-7E963577BCEE}] => (Allow) C:\Program Files (x86)\FrostWire 6\FrostWire.exe
FirewallRules: [{E478B0B2-92CC-48E0-9B6B-D49AFA484A95}] => (Allow) C:\Program Files (x86)\Torrents Downloader\torrents_downloader.exe
FirewallRules: [{3158406F-188C-4DF2-971A-61337A97AC01}] => (Allow) C:\Program Files (x86)\Torrents Downloader\torrents_downloader.exe
FirewallRules: [{5F9FD0D7-B1D6-4DEE-95F8-6E76040178F0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D1AAA7F3-3E29-49E2-94BF-AED3CFE8D9A2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1152F76F-B728-4C97-8802-157A0C4204F5}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [{A74FAC99-AEF8-48A5-A89E-657D832878A5}] => (Allow) C:\Program Files (x86)\Motorola Media Link\Lite\mml.exe
FirewallRules: [{B5F5A955-4CC4-4BC5-BFEF-FB7C7F7E6B12}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\motocast.exe
FirewallRules: [{17625B4E-A493-499C-A95F-31143906A465}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\motocast.exe
FirewallRules: [{FA9D6F73-C5DE-4965-B413-A29F7A8F2693}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
FirewallRules: [{F4B47BC7-2741-4916-8866-5CE3B5544D96}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
FirewallRules: [{7D0267C3-2162-422F-996C-A6F28E89F358}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5C9BECF9-CCCE-42F7-8CCE-E826B6904F55}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D21F0D44-CD0B-4750-900E-E42B4FED1C74}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{90F86A6A-E8A2-4C17-AD74-671DDE58A5D6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{6DE8CE4D-025E-43DF-9939-DE1033EDA368}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{6F144095-0AE5-4400-9979-FAA042B4D5E2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{C9C7278E-F6D6-45C5-AD8E-758B52E53881}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{A4D105D8-6C7A-46AA-9C85-9E8D872EB46F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{321C9C77-6047-43E4-99E1-E1EF259069ED}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{6F6773F0-90DC-4DB5-B739-8E39AC01BC3E}] => (Allow) C:\Program Files\iTunes\iTunes.exe
DomainProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7

==================== Restore Points =========================

13-10-2016 19:04:53 Windows Update
16-10-2016 20:39:02 Revo Uninstaller's restore point - IObit Malware Fighter 4
17-10-2016 13:50:46 Revo Uninstaller's restore point - IObit Uninstaller
17-10-2016 13:52:36 Revo Uninstaller's restore point - Smart Defrag 5

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/17/2016 01:52:36 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (10/17/2016 01:50:53 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (10/17/2016 12:29:05 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 10:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 08:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 06:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 04:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 02:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 02:17:00 AM) (Source: Windows Search Service) (EventID: 3079) (User: )
Description: Notifications for the volume C:\ are not active.

Context: Windows Application

Details:
    The parameter is incorrect.  (HRESULT : 0x80070057) (0x80070057)

Error: (10/17/2016 12:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.


System errors:
=============
Error: (10/16/2016 08:39:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The IMF Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (10/16/2016 08:15:27 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network Connectivity Assistant service depends on the IP Helper service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Error: (10/16/2016 08:14:28 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942402.

Error: (10/16/2016 08:14:28 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942402.

Error: (10/16/2016 08:10:51 PM) (Source: volmgr) (EventID: 46) (User: )
Description: Crash dump initialization failed!

Error: (10/16/2016 08:14:14 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:45:00 PM on ‎10/‎16/‎2016 was unexpected.

Error: (10/16/2016 06:53:08 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.

Error: (10/16/2016 06:25:36 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.

Error: (10/16/2016 05:32:28 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.

Error: (10/16/2016 05:12:09 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-2320 CPU @ 3.00GHz
Percentage of memory in use: 22%
Total physical RAM: 16364.29 MB
Available physical RAM: 12653.62 MB
Total Virtual: 32748.29 MB
Available Virtual: 28924.34 MB

==================== Drives ================================

Drive c: (Jim ) (Fixed) (Total:1848.92 GB) (Free:1586.53 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 686961D5)
Partition 1: (Not Active) - (Size=14 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=1848.9 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

Let me know how I did and if there are any other issues that need attention by me…

 

Thanks!

 

Taz

Hi Ken,

 

I've done what you suggested and am posting the logs here. There are 2 IObit programs that I like and have served me well without incident - Advanced System and Classic Startup. The rest I purged from the system via Revo Uninstaller.

 

Here are the logs:

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-10-2016
Ran by [removed] (administrator) on JIM (17-10-2016 14:00:27)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe
(NVIDIA Corporation) C:\WINDOWS\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvscpapisvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(Nero AG) C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe
(Acer Incorporated) C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
(IObit) C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccsvchst.exe
(Microsoft Corporation) C:\WINDOWS\System32\mqsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\SMService.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe
(Seiko Epson Corporation) C:\WINDOWS\System32\escsvc64.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\nsbu.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccsvchst.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\ClassicStart.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\StartMenu_Hook.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(IObit) C:\Program Files (x86)\IObit\Classic Start\InstallServices.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(WinZip Computing International, LLC) C:\Program Files\File Association Helper\FAHWindow.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe
(Firetrust) C:\Program Files (x86)\FireTrust\MailWasher\MailWasherPro.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe
(PalmSource, Inc) C:\Program Files (x86)\Palm\Hotsync.exe
(Symantec Corporation) C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\nsbu.exe
(KeirNet) C:\Program Files (x86)\KeirNet\K9\K9.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(IObit) C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE


==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [16407296 2016-01-26] (Realtek Semiconductor)
HKLM\…\Run: [FAHConsole] => C:\Program Files\File Association Helper\FAHConsole.exe [216248 2013-09-26] (WinZip Computing International, LLC)
HKLM\…\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3100440 2014-05-19] (Logitech, Inc.)
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2398776 2016-05-02] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\WINDOWS\system32\nvspcap64.dll [1767944 2016-05-02] (NVIDIA Corporation)
HKLM-x32\…\Run: [SSBkgdUpdate] => C:\Program Files (x86)\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [210472 2006-10-25] (Nuance Communications, Inc.)
HKLM-x32\…\Run: [PaperPort PTD] => C:\Program Files (x86)\ScanSoft\PaperPort\pptd40nt.exe [29984 2008-01-14] (Nuance Communications, Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [598040 2016-06-22] (Oracle Corporation)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKLM\…\Policies\Explorer: [NoSetActiveDesktop] 0
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Run: [Advanced SystemCare 9] => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCTray.exe [2023712 2016-07-27] (IObit)
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Run: [KGShareApp] => C:\Program Files (x86)\Kodak\KODAK Share Button App\KGShare_App.exe [394240 2015-02-09] (Eastman Kodak Company)
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8912088 2016-08-26] (Piriform Ltd)
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Policies\Explorer: [NoSetActiveDesktop] 0
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\Policies\Explorer: [NoLowDiskSpaceChecks] 1
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\MountPoints2: {09331ad7-5447-11e3-901b-386077ec13ea} - "F:\KODAK_Camera_Setup_App.exe"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\MountPoints2: {112fa596-7e8f-11e3-91ef-386077ec13ea} - "F:\MotoCastSetup.exe" -a
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Ribbons.scr [132608 2014-11-21] (Microsoft Corporation)
HKU\S-1-5-18\…\Winlogon: [Shell] C:\WINDOWS\Explorer.exe [2755504 2016-09-20] (Microsoft Corporation) <==== ATTENTION
ShellIconOverlayIdentifiers: [  OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\buShell.dll [2016-09-23] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\buShell.dll [2016-09-23] (Symantec Corporation)
ShellIconOverlayIdentifiers: [  OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\buShell.dll [2016-09-23] (Symantec Corporation)
ShellIconOverlayIdentifiers: [ SncrOverlays (Blocked)] -> {C418E880-6280-4010-A888-FD76028E5511} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [ SncrOverlays (InSync)] -> {5F4A6070-DB92-4C56-A487-F3850430608F} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [ SncrOverlays (Pending)] -> {EE73A341-C788-4A6B-B1EF-DDBFC0F190B6} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [ SncrOverlays (Syncing)] -> {28CDCD88-B179-49D6-8B21-1A9AF9C0AE13} => C:\Program Files\Verizon\VerizonCloud\x64\Sncr.Overlays.dll [2015-12-03] (Synchronoss Technologies Inc.)
ShellIconOverlayIdentifiers: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX64.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtPending] -> {056D528D-CE28-4194-9BA3-BA2E9197FF8C} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSynced] -> {05B38830-F4E9-4329-978B-1DD28605D202} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
ShellIconOverlayIdentifiers-x32: [###MegaShellExtSyncing] -> {0596C850-7BDD-4C9D-AFDF-873BE6890637} => C:\ProgramData\MEGAsync\ShellExtX32.dll [2014-05-01] ()
Startup: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MailWasherPro.lnk [2016-04-20]
ShortcutTarget: MailWasherPro.lnk -> C:\Program Files (x86)\FireTrust\MailWasher\MailWasherPro.exe (Firetrust)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

AutoConfigURL: [S-1-5-21-968235783-2654321925-1125524309-1000] => hxxp://proxy.kodak.com:81/proxy.pac
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{3534EE43-8554-4DFD-B1F2-F34A35AF6B03}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{90616DFF-D831-4BD6-9124-AEF7F60BD2AA}: [DhcpNameServer] 192.168.1.1
ManualProxies: 0hxxp://proxy.kodak.com:81/proxy.pac

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKLM -> DefaultScope {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = hxxp://search.myheritage.com?orig=ds&q;={searchTerms}
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://search.live.com/results.aspx?q={searchTerms}&src;={referrer:source?}
SearchScopes: HKLM -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL =
SearchScopes: HKLM -> {31090377-0740-419E-BEFC-A56E50500D5B} URL =
SearchScopes: HKLM -> {BE28C22E-F666-424d-B5FD-125C4AFEE34E} URL = hxxp://search.myheritage.com?orig=ds&q;={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\.DEFAULT -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\.DEFAULT -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> DefaultScope {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> {0191A6B0-1154-4C22-9182-23A95BBE92D9} URL = hxxp://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxps://nortonsafe.search.ask.com/web?q={searchTerms}&o;=APN11913&l;=dis&prt;=NSBU&chn;=1000&geo;=US&ver;=22&locale;=en_US&gct;=kwd&qsrc;=2869
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-10-27] (RealDownloader)
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\coIEPlg.dll [2016-09-23] (Symantec Corporation)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_102\bin\ssv.dll [2016-08-04] (Oracle Corporation)
BHO: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-07-03] (LastPass)
BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_102\bin\jp2ssv.dll [2016-08-04] (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-10-27] (RealDownloader)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\coIEPlg.dll [2016-09-23] (Symantec Corporation)
BHO-x32: LastPass Vault -> {95D9ECF5-2A4D-4550-BE49-70D42F71296E} -> C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-07-03] (LastPass)
BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2014-05-19] (Logitech, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Advanced SystemCare Surfing Protection -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> C:\Program Files (x86)\IObit\Surfing Protection\BrowerProtect\ASCPlugin_Protection.dll [2015-07-09] (IObit)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\coIEPlg.dll [2016-09-23] (Symantec Corporation)
Toolbar: HKLM - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar_x64.dll [2016-07-03] (LastPass)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\coIEPlg.dll [2016-09-23] (Symantec Corporation)
Toolbar: HKLM-x32 - LastPass Toolbar - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPToolbar.dll [2016-07-03] (LastPass)
Toolbar: HKU\S-1-5-21-968235783-2654321925-1125524309-1000 -> Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security with Backup\Engine64\22.8.0.50\coIEPlg.dll [2016-09-23] (Symantec Corporation)
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}

FireFox:
========
FF ProfilePath: C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 [2016-10-17]
FF user.js: detected! => C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463\user.js [2016-03-22]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 -> Google
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 -> Google
FF Homepage: Mozilla\Firefox\Profiles\zk63e570.default-1424918862463 -> about:blank
FF Extension: (LastPass) - C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463\Extensions\[removed] [2016-09-03]
FF Extension: (1-Click YouTube Video Downloader) - C:\Users\Dad\AppData\Roaming\Mozilla\Firefox\Profiles\zk63e570.default-1424918862463\Extensions\[removed] [2016-08-24]
FF HKLM\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.6.0.142\coFFAddon
FF Extension: (Norton Security Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.6.0.142\coFFAddon [2016-10-16]
FF HKLM-x32\…\Firefox\Extensions: [{338950EA-82DB-44C1-930D-0C28E023C9F0}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2015-02-11] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\…\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt
FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2015-01-17] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{C1A2A613-35F1-4FCF-B27F-2840527B6556}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NSBU_22.6.0.142\coFFAddon
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_23_0_0_162.dll [2016-09-26] ()
FF Plugin: @java.com/DTPlugin,version=11.102.2 -> C:\Program Files\Java\jre1.8.0_102\bin\dtplugin\npDeployJava1.dll [2016-08-04] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.102.2 -> C:\Program Files\Java\jre1.8.0_102\bin\plugin2\npjp2.dll [2016-08-04] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_162.dll [2016-09-26] ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2015-05-21] (Google)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6 -> C:\Program Files (x86)\Yahoo!\Shared\npYState.dll [2012-02-22] (Yahoo! Inc.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\Microsoft Office\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2014-03-18] (Nero AG)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2016-06-02] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2016-06-02] (NVIDIA Corporation)
FF Plugin-x32: @palmsource.com/installer,version=1.0 -> C:\PROGRA~2\Palm\PACKAG~1\NPInstal.dll [2007-03-19] ()
FF Plugin-x32: @real.com/nppl3260;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2015-02-11] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.15 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-10-27] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.15.10 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2015-02-11] (RealPlayer Cloud)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-24] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-08-24] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2010-12-07] ()
FF Plugin-x32: @winzip.com/Winzip Courier -> C:\Program Files (x86)\WinZip Courier\npwzwmc.dll [2013-11-22] (WinZip Computing, S.L.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-968235783-2654321925-1125524309-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Dad\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-12-15] (Citrix Online)
FF Plugin HKU\S-1-5-21-968235783-2654321925-1125524309-1000: tdameritrade.com/thinkorswim -> C:\Program Files\thinkorswim\npthinkorswim.dll [2016-09-21] (TD Ameritrade)
FF Plugin HKU\S-1-5-21-968235783-2654321925-1125524309-1000: tdameritrade.com/tossc -> C:\Program Files\thinkorswim\nptossc.dll [2016-09-21] (TD Ameritrade)
FF Plugin ProgramFiles/Appdata: C:\Users\Dad\AppData\Roaming\mozilla\plugins\npatgpc.dll [2015-03-25] (Cisco WebEx LLC)

Chrome:
=======
CHR HKLM\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\Exts\Chrome.crx [2016-09-28]
CHR HKLM\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [cjabmdjcfcfdmffimndhafhblfmpjdpe] - C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\Exts\Chrome.crx [2016-09-28]
CHR HKLM-x32\…\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 AdvancedSystemCareService9; C:\Program Files (x86)\IObit\Advanced SystemCare\ASCService.exe [452384 2016-07-25] (IObit)
S3 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)
R2 EpsonScanSvc; C:\WINDOWS\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation)
R2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1165368 2016-05-02] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [2960672 2016-06-14] (IObit)
R2 MCLIENT; C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\ccSvcHst.exe [143928 2012-12-04] (Symantec Corporation)
S3 MotoHelper; C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperService.exe [214896 2012-02-01] ()
R2 NSBU; C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\NSBU.exe [289080 2016-09-23] (Symantec Corporation)
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1881144 2016-05-02] (NVIDIA Corporation)
R3 NvStreamNetworkSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe [3634232 2016-05-02] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamService.exe [2522680 2016-05-02] (NVIDIA Corporation)
S3 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-10-26] ()
S3 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2015-02-11] (RealNetworks, Inc.)
S3 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31856 2014-10-30] ()
S3 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [614664 2014-04-01] (CyberLink)
R2 SMService; C:\Program Files (x86)\IObit\Classic Start\SMService.exe [1063200 2015-12-29] (IObit)
S3 vmicvss; C:\Windows\System32\ICSvc.dll [524800 2014-11-21] (Microsoft Corporation)
R2 WDBackup; C:\Program Files (x86)\Western Digital\WD SmartWare\WDBackupEngine.exe [1049464 2016-04-19] (Western Digital Technologies, Inc.)
R3 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [314744 2016-04-19] (Western Digital Technologies, Inc.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 BHDrvx64; C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\BASHDefs\20161005.001\BHDrvx64.sys [1854712 2016-08-18] (Symantec Corporation)
R1 ccSet_MCLIENT; C:\Windows\system32\drivers\MCLIENTx64\0302020.00C\ccSetx64.sys [168096 2012-10-03] (Symantec Corporation)
R1 ccSet_NSBU; C:\Windows\system32\drivers\NSBUx64\1608000.032\ccSetx64.sys [174328 2016-06-01] (Symantec Corporation)
R3 dot4; C:\Windows\system32\DRIVERS\Dot4.sys [151968 2012-10-19] (Windows (R) Win 7 DDK provider)
R3 Dot4Print; C:\Windows\System32\drivers\Dot4Prt.sys [27040 2012-10-19] (Windows (R) Win 7 DDK provider)
S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [497368 2016-10-03] (Symantec Corporation)
R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [156888 2016-10-03] (Symantec Corporation)
R1 HWiNFO32; C:\WINDOWS\SysWOW64\drivers\HWiNFO64A.SYS [27552 2016-07-02] (REALiX™)
R1 IDSVia64; C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\IPSDefs\20161014.003\IDSvia64.sys [1012440 2016-09-26] (Symantec Corporation)
S1 iSafeKrnlMon; no ImagePath
R3 MEIx64; C:\Windows\system32\DRIVERS\TeeDriverx64.sys [100312 2014-07-03] (Intel Corporation)
R2 mfmonitor; C:\Windows\System32\DRIVERS\mfmonitor_x64.sys [20696 2014-06-19] (Windows (R) Win 7 DDK provider)
R3 netr28x; C:\Windows\system32\DRIVERS\netr28x.sys [2541200 2016-03-04] (MediaTek Inc.)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [28216 2016-05-02] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [56384 2016-04-14] (NVIDIA Corporation)
R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [413912 2016-04-23] (Realsil Semiconductor Corporation)
S3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33008 2014-07-03] (Synaptics Incorporated)
R1 SRTSP; C:\Windows\System32\Drivers\NSBUx64\1608000.032\SRTSP64.SYS [784624 2016-09-23] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\NSBUx64\1608000.032\SRTSPX64.SYS [49400 2016-09-23] (Symantec Corporation)
R0 SymEFASI; C:\Windows\System32\drivers\NSBUx64\1608000.032\SYMEFASI64.SYS [1628888 2016-09-23] (Symantec Corporation)
S0 SymELAM; C:\Windows\System32\drivers\NSBUx64\1608000.032\SymELAM.sys [24192 2016-02-23] (Symantec Corporation)
R3 SymEvent; C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS [100592 2016-10-16] (Symantec Corporation)
S1 SymIM; C:\Windows\System32\DRIVERS\SymIMv.sys [78936 2013-09-09] (Symantec Corporation)
R1 SymIRON; C:\Windows\system32\drivers\NSBUx64\1608000.032\Ironx64.SYS [289520 2016-09-23] (Symantec Corporation)
R1 SymNetS; C:\Windows\System32\Drivers\NSBUx64\1608000.032\SYMNETS.SYS [567512 2016-09-23] (Symantec Corporation)
U5 TMUSB; C:\Windows\System32\DRIVERS\TMUSB64.SYS [63096 2014-06-08] (Seiko Epson Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 NAVENG; \??\C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\SDSDefs\20161013.019\ENG64.SYS [X]
S3 NAVEX15; \??\C:\Program Files (x86)\Norton Security with Backup\NortonData\22.6.0.142\Definitions\SDSDefs\20161013.019\EX64.SYS [X]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-10-17 13:58 - 2016-10-17 14:00 - 00029637 _____ C:\Users\Dad\Desktop\FRST.txt
2016-10-17 13:58 - 2016-10-17 13:59 - 00066988 _____ C:\Users\Dad\Desktop\Addition.txt
2016-10-17 13:44 - 2016-10-17 13:44 - 02406912 _____ (Farbar) C:\Users\Dad\Desktop\FRST64.exe
2016-10-17 01:01 - 2016-10-17 01:01 - 04358478 _____ C:\Users\Dad\Desktop\Fanning Family of Edmund Fanning .pdf
2016-10-16 20:21 - 2016-10-16 20:21 - 00000000 ____D C:\WINDOWS\System32\Tasks\Norton Security with Backup
2016-10-16 20:15 - 2016-10-16 20:15 - 00008192 _____ C:\WINDOWS\SysWOW64\WDPABKP.dat
2016-10-16 20:15 - 2016-10-16 20:15 - 00003240 _____ C:\WINDOWS\System32\Tasks\Norton WSC Integration
2016-10-16 20:14 - 2016-10-16 20:14 - 00002502 _____ C:\Users\Public\Desktop\Norton Security with Backup.lnk
2016-10-16 20:08 - 2016-10-16 20:08 - 00000000 ____H C:\asc_rdflag
2016-10-16 20:04 - 2016-10-16 20:17 - 00000000 ____D C:\Users\Dad\AppData\Roaming\0273
2016-10-16 20:04 - 2016-10-16 20:04 - 00000000 ____D C:\Users\Dad\AppData\Local\5b65
2016-10-16 19:59 - 2016-10-16 20:00 - 02805768 _____ (Symantec Corporation) C:\Users\Dad\Desktop\FixTool64.exe
2016-10-16 04:25 - 2016-10-16 04:25 - 00004476 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2016-10-16 04:24 - 2016-10-16 04:24 - 00002487 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2016-10-15 18:50 - 2016-10-17 14:00 - 00000000 ____D C:\FRST
2016-10-15 18:39 - 2016-10-15 18:39 - 05198336 _____ (AVAST Software) C:\Users\Dad\Desktop\aswMBR.exe
2016-10-14 14:56 - 2016-10-14 22:22 - 00012674 _____ C:\Users\Dad\Desktop\Medical Records.xlsx
2016-10-13 19:41 - 2016-09-30 19:15 - 00828408 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2016-10-13 19:41 - 2016-09-30 19:15 - 00176632 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-12 13:43 - 2016-03-25 14:33 - 00128288 _____ (IObit) C:\WINDOWS\system32\IObitSmartDefragExtension.dll
2016-10-12 02:29 - 2016-09-30 19:22 - 07444312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2016-10-12 02:29 - 2016-09-30 02:55 - 25765376 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2016-10-12 02:29 - 2016-09-30 01:25 - 02895360 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2016-10-12 02:29 - 2016-09-30 01:25 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2016-10-12 02:29 - 2016-09-30 01:12 - 00817664 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2016-10-12 02:29 - 2016-09-30 01:09 - 06048256 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2016-10-12 02:29 - 2016-09-30 00:47 - 20306944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2016-10-12 02:29 - 2016-09-30 00:42 - 00498688 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2016-10-12 02:29 - 2016-09-30 00:41 - 01033216 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2016-10-12 02:29 - 2016-09-30 00:38 - 02286592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2016-10-12 02:29 - 2016-09-30 00:33 - 00724992 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2016-10-12 02:29 - 2016-09-30 00:33 - 00378880 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2016-10-12 02:29 - 2016-09-30 00:32 - 00806912 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2016-10-12 02:29 - 2016-09-30 00:32 - 00663552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2016-10-12 02:29 - 2016-09-30 00:31 - 02131456 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2016-10-12 02:29 - 2016-09-30 00:21 - 15257088 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2016-10-12 02:29 - 2016-09-30 00:17 - 02920960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2016-10-12 02:29 - 2016-09-30 00:12 - 04608512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2016-10-12 02:29 - 2016-09-30 00:11 - 00880640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2016-10-12 02:29 - 2016-09-30 00:06 - 00330752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2016-10-12 02:29 - 2016-09-30 00:05 - 02055680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2016-10-12 02:29 - 2016-09-30 00:05 - 01544192 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2016-10-12 02:29 - 2016-09-30 00:05 - 00693248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2016-10-12 02:29 - 2016-09-30 00:03 - 13653504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2016-10-12 02:29 - 2016-09-29 23:54 - 00800768 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2016-10-12 02:29 - 2016-09-29 23:46 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2016-10-12 02:29 - 2016-09-29 23:43 - 01312768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2016-10-12 02:29 - 2016-09-29 23:42 - 00710144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2016-10-12 02:29 - 2016-09-17 13:16 - 00103424 _____ (Microsoft Corporation) C:\WINDOWS\system32\adsmsext.dll
2016-10-12 02:29 - 2016-09-17 12:53 - 00445440 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2016-10-12 02:29 - 2016-09-17 12:21 - 00089600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\adsmsext.dll
2016-10-12 02:29 - 2016-09-17 12:03 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2016-10-12 02:29 - 2016-09-17 12:02 - 01446400 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2016-10-12 02:29 - 2016-09-13 20:53 - 01663184 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2016-10-12 02:29 - 2016-09-13 20:53 - 01523208 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2016-10-12 02:29 - 2016-09-13 20:53 - 01490112 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2016-10-12 02:29 - 2016-09-13 20:53 - 01358952 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2016-10-12 02:29 - 2016-09-12 18:48 - 00085680 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2016-10-12 02:29 - 2016-09-12 17:03 - 00061440 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2016-10-12 02:29 - 2016-09-12 16:01 - 00047104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2016-10-12 02:29 - 2016-09-09 09:17 - 04170752 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32k.sys
2016-10-12 02:29 - 2016-09-09 08:38 - 01629184 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 01226752 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00586752 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00575488 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00314368 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00273408 _____ (Microsoft Corporation) C:\WINDOWS\system32\centel.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2016-10-12 02:29 - 2016-09-09 08:38 - 00129024 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2016-10-12 02:29 - 2016-09-08 15:41 - 00121176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2016-10-12 02:29 - 2016-09-08 09:00 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys
2016-10-12 02:29 - 2016-09-08 09:00 - 00138240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dfsc.sys
2016-10-12 02:29 - 2016-09-07 17:07 - 01988096 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2016-10-12 02:29 - 2016-09-07 16:59 - 01754112 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2016-10-12 02:29 - 2016-09-07 16:59 - 01377792 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2016-10-12 02:29 - 2016-09-07 16:57 - 01560064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2016-10-12 02:29 - 2016-09-07 16:56 - 01491456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2016-10-12 02:29 - 2016-08-31 12:22 - 03754496 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVidCtl.dll
2016-10-12 02:29 - 2016-08-31 11:33 - 02410496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVidCtl.dll
2016-10-07 21:36 - 2016-10-07 21:36 - 00344879 _____ C:\Users\Dad\Desktop\duplicates_20161007.d2fp
2016-10-07 20:42 - 2016-10-07 20:42 - 00533136 _____ C:\Users\Dad\Desktop\duplicates_20161007.dpfp
2016-10-07 20:18 - 2016-10-07 20:18 - 00001390 _____ C:\Users\Dad\Desktop\Duplicate Photo Finder Plus.lnk
2016-10-07 20:03 - 2016-10-07 20:18 - 00000000 ____D C:\Users\Dad\AppData\Local\TriSun_Software_Limited
2016-10-07 20:03 - 2016-10-07 20:03 - 00001378 _____ C:\Users\Dad\Desktop\Duplicate File Finder Plus.lnk
2016-09-29 17:39 - 2016-09-29 17:39 - 00001769 _____ C:\Users\Public\Desktop\iTunes.lnk
2016-09-29 17:39 - 2016-09-29 17:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2016-09-29 17:39 - 2016-09-29 17:39 - 00000000 ____D C:\Program Files\iTunes
2016-09-29 17:39 - 2016-09-29 17:39 - 00000000 ____D C:\Program Files\iPod
2016-09-24 10:33 - 2016-10-16 19:45 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-09-21 21:46 - 2016-09-21 21:46 - 00332644 _____ C:\Users\Dad\Desktop\45ed6h_5335874643p54ow64714e3.ged
2016-09-20 18:10 - 2016-09-20 18:10 - 00875720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00869576 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcr120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00678592 _____ (Microsoft Corporation) C:\WINDOWS\system32\msvcp120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00536776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp120_clr0400.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00029888 _____ (Microsoft Corporation) C:\WINDOWS\system32\aspnet_counters.dll
2016-09-20 18:10 - 2016-09-20 18:10 - 00028352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aspnet_counters.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 15431168 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 13317120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 09323008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmploc.DLL
2016-09-20 18:08 - 2016-09-20 18:08 - 09323008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmploc.DLL
2016-09-20 18:08 - 2016-09-20 18:08 - 02896384 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 02537472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 02315496 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d11.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01946176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d11.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01574912 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbengine.exe
2016-09-20 18:08 - 2016-09-20 18:08 - 01317888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01220096 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Streaming.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00954880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00747008 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntshrui.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00678400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntshrui.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00445765 _____ C:\WINDOWS\system32\ApnDatabase.xml
2016-09-20 18:08 - 2016-09-20 18:08 - 00420184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00289792 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00222208 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastapi.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00207872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastapi.dll
2016-09-20 18:08 - 2016-09-20 18:08 - 00162850 _____ C:\WINDOWS\SysWOW64\C_932.NLS
2016-09-20 18:08 - 2016-09-20 18:08 - 00162850 _____ C:\WINDOWS\system32\C_932.NLS
2016-09-20 18:08 - 2016-09-20 18:08 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\parport.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00083456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serial.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00071680 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwififlt.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00038912 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifimp.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00024576 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vwifibus.sys
2016-09-20 18:08 - 2016-09-20 18:08 - 00023040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\serenum.sys
2016-09-20 18:07 - 2016-09-20 18:07 - 22360288 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 19789232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 14466560 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 12879360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02881536 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02778624 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02755504 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2016-09-20 18:07 - 2016-09-20 18:07 - 02463744 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 02411048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2016-09-20 18:07 - 2016-09-20 18:07 - 01049600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2016-09-20 18:07 - 2016-09-20 18:07 - 00133256 _____ (Microsoft Corporation) C:\WINDOWS\system32\RestoreOptIn.exe
2016-09-20 18:07 - 2016-09-20 18:07 - 00113656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RestoreOptIn.exe

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-10-17 13:56 - 2015-02-18 10:06 - 00003596 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-968235783-2654321925-1125524309-1000
2016-10-17 13:53 - 2012-04-28 21:03 - 00000000 ____D C:\Program Files (x86)\IObit
2016-10-17 13:51 - 2015-05-04 19:51 - 01279488 ___SH C:\Users\Dad\Desktop\Thumbs.db
2016-10-17 00:01 - 2016-08-28 23:26 - 00000242 _____ C:\WINDOWS\Tasks\ASC9_SkipUac_Dad.job
2016-10-16 20:38 - 2015-10-27 10:11 - 00000000 ____D C:\WINDOWS\System32\Tasks\Remediation
2016-10-16 20:29 - 2014-10-08 10:40 - 00000000 ____D C:\Users\Dad\AppData\Local\NPE
2016-10-16 20:22 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\AppReadiness
2016-10-16 20:16 - 2015-02-25 12:30 - 00000000 ____D C:\Users\DefaultAppPool
2016-10-16 20:15 - 2015-03-02 04:23 - 00000000 ____D C:\WINDOWS\system32\Drivers\NSBUx64
2016-10-16 20:14 - 2016-03-21 21:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Security with Backup
2016-10-16 20:14 - 2015-02-18 23:46 - 00000000 ____D C:\ProgramData\NVIDIA
2016-10-16 20:14 - 2013-08-22 09:45 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2016-10-16 20:14 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\Inf
2016-10-16 20:14 - 2012-07-26 03:12 - 00000000 ___HD C:\WINDOWS\ELAMBKUP
2016-10-16 13:15 - 2015-03-02 04:25 - 00100592 _____ (Symantec Corporation) C:\WINDOWS\system32\Drivers\SYMEVENT64x86.SYS
2016-10-16 13:15 - 2015-03-02 04:25 - 00008319 _____ C:\WINDOWS\system32\Drivers\SYMEVENT64x86.CAT
2016-10-15 18:48 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\Help
2016-10-15 18:07 - 2016-07-21 13:26 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2016-10-14 22:32 - 2016-08-28 23:26 - 00002286 _____ C:\Users\Public\Desktop\Advanced SystemCare 9.lnk
2016-10-14 20:29 - 2013-12-08 07:56 - 00000000 ____D C:\ProgramData\ProductData
2016-10-13 20:38 - 2012-06-19 17:09 - 00007642 _____ C:\Users\Dad\AppData\Local\resmon.resmoncfg
2016-10-13 20:25 - 2015-02-18 10:20 - 00000558 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000.job
2016-10-13 20:24 - 2013-08-22 09:44 - 00498224 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2016-10-13 20:24 - 2012-05-16 20:04 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2016-10-13 20:23 - 2011-10-27 05:42 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2016-10-13 20:21 - 2015-02-18 19:12 - 00000000 ____D C:\WINDOWS\system32\appraiser
2016-10-13 20:21 - 2014-11-21 11:17 - 00000000 ___SD C:\WINDOWS\system32\CompatTel
2016-10-13 19:42 - 2012-07-26 02:59 - 00000000 ____D C:\WINDOWS\CbsTemp
2016-10-13 19:41 - 2013-07-28 13:36 - 00000000 ____D C:\WINDOWS\system32\MRT
2016-10-13 19:29 - 2012-02-26 15:59 - 143495576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2016-10-13 19:27 - 2012-05-16 20:04 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2016-10-13 16:33 - 2012-04-28 20:39 - 00000000 ____D C:\Users\Dad\AppData\Local\CrashDumps
2016-10-13 10:22 - 2015-11-30 11:41 - 00003472 _____ C:\WINDOWS\System32\Tasks\ReclaimerUpdateXML_Dad
2016-10-13 10:22 - 2015-11-29 07:41 - 00003478 _____ C:\WINDOWS\System32\Tasks\ReclaimerUpdateFiles_Dad
2016-10-13 10:21 - 2015-05-08 01:18 - 00003542 _____ C:\WINDOWS\System32\Tasks\MotoCast Update
2016-10-13 10:21 - 2015-05-08 01:18 - 00003518 _____ C:\WINDOWS\System32\Tasks\MotoHelper Update
2016-10-13 10:21 - 2015-02-11 05:44 - 00003412 _____ C:\WINDOWS\System32\Tasks\RealDownloader Update Check
2016-10-13 10:21 - 2014-12-15 15:58 - 00003546 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:21 - 2014-12-14 00:42 - 00003350 _____ C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:21 - 2014-12-14 00:42 - 00003212 _____ C:\WINDOWS\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:21 - 2014-11-19 11:36 - 00003190 _____ C:\WINDOWS\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000
2016-10-13 10:16 - 2012-04-28 20:58 - 00000000 ____D C:\temp
2016-10-11 16:20 - 2013-08-22 08:25 - 00262144 ___SH C:\WINDOWS\system32\config\ELAM
2016-10-10 17:18 - 2015-05-20 08:18 - 146112512 _____ C:\WINDOWS\system32\config\SOFTWARE.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 07364608 _____ C:\WINDOWS\system32\config\DRIVERS.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 00778240 _____ C:\WINDOWS\system32\config\DEFAULT.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 00065536 _____ C:\WINDOWS\system32\config\SAM.iodefrag.bak
2016-10-10 17:18 - 2015-05-20 08:18 - 00036864 _____ C:\WINDOWS\system32\config\SECURITY.iodefrag.bak
2016-10-10 07:44 - 2012-04-28 21:03 - 00000000 ____D C:\Users\Dad\AppData\Roaming\IObit
2016-10-10 00:38 - 2015-03-21 22:50 - 00063488 ___SH C:\Users\Dad\Downloads\Thumbs.db
2016-10-10 00:30 - 2014-11-21 03:43 - 00994144 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2016-10-07 20:18 - 2016-07-02 10:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TSSI
2016-10-07 20:18 - 2016-07-02 10:32 - 00000000 ____D C:\Program Files (x86)\TSSI
2016-10-05 21:47 - 2013-10-12 02:14 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2016-10-03 03:31 - 2012-07-26 03:12 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2016-10-03 03:30 - 2013-10-29 10:57 - 00000838 _____ C:\Users\Public\Desktop\CCleaner.lnk
2016-10-01 03:29 - 2012-04-28 21:22 - 00000000 ____D C:\Users\Dad\.frostwire5
2016-09-30 02:06 - 2015-02-18 23:53 - 00000000 ____D C:\Users\Dad
2016-09-29 17:39 - 2016-05-20 18:58 - 00000000 ____D C:\Program Files\Common Files\Apple
2016-09-27 18:46 - 2016-08-18 06:12 - 00001143 _____ C:\Users\Dad\Desktop\MyHeritage Family Tree Builder.lnk
2016-09-27 18:46 - 2012-04-29 11:23 - 00000000 ____D C:\Program Files (x86)\MyHeritage
2016-09-26 13:43 - 2010-08-15 18:49 - 00000000 ____D C:\Users\Dad\Documents\MyHeritage
2016-09-26 09:52 - 2012-04-28 19:49 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2016-09-26 09:51 - 2013-08-22 10:36 - 00000000 ___RD C:\WINDOWS\ToastData
2016-09-26 09:27 - 2015-02-18 23:53 - 00000000 ____D C:\Users\Administrator
2016-09-26 03:12 - 2012-04-29 11:15 - 00000000 ____D C:\Program Files (x86)\Palm
2016-09-26 00:47 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2016-09-26 00:47 - 2013-08-22 10:36 - 00000000 ____D C:\WINDOWS\system32\Macromed
2016-09-26 00:47 - 2012-04-28 19:49 - 00003744 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater
2016-09-24 13:06 - 2012-05-26 08:27 - 00007627 _____ C:\WINDOWS\wininit.ini
2016-09-21 20:54 - 2014-10-14 13:50 - 00000000 ____D C:\Program Files\thinkorswim
2016-09-21 20:54 - 2013-07-01 16:32 - 00000000 ____D C:\Users\Dad\.thinkorswim
2016-09-21 20:04 - 2015-03-25 00:07 - 00000000 ____D C:\Users\Dad\AppData\LocalLow\WebEx
2016-09-21 20:04 - 2011-01-26 21:03 - 00000000 __SHD C:\Users\Dad\Documents\cache

==================== Files in the root of some directories =======

2014-03-22 00:17 - 2014-03-22 00:17 - 0003754 _____ () C:\Program Files (x86)\Mozilla Firefoxsafeguard-secure-search.xml
2012-02-26 16:48 - 2016-05-14 03:00 - 21572120 _____ (LastPass) C:\Program Files (x86)\Common Files\lpuninstall.exe
2013-05-08 08:39 - 2013-05-08 08:39 - 0000000 _____ () C:\Users\Dad\AppData\Roaming\SharedSettings.ccs
2012-05-05 22:19 - 2012-05-05 22:19 - 0019329 _____ () C:\Users\Dad\AppData\Roaming\UserTile.png
2014-05-13 01:21 - 2014-10-06 18:35 - 0000059 _____ () C:\Users\Dad\AppData\Roaming\WB.CFG
2013-05-12 07:17 - 2013-05-12 07:17 - 0045967 _____ () C:\Users\Dad\AppData\Local\amapeoch
2012-04-29 17:13 - 2016-01-05 06:32 - 0005120 _____ () C:\Users\Dad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2012-12-30 20:47 - 2012-12-30 20:47 - 0000036 _____ () C:\Users\Dad\AppData\Local\housecall.guid.cache
2012-06-19 17:15 - 2012-06-19 17:18 - 0000000 _____ () C:\Users\Dad\AppData\Local\null
2012-06-19 17:09 - 2016-10-13 20:38 - 0007642 _____ () C:\Users\Dad\AppData\Local\resmon.resmoncfg
2015-02-18 23:46 - 2015-02-18 23:46 - 0000000 ____H () C:\ProgramData\DP45977C.lfl

Files to move or delete:
====================
C:\Users\Dad\DesktopLSPFix.exe
C:\Users\Dad\DesktopSafeMSI.exe
C:\Users\Dad\DesktopWinsockxpFix.exe
C:\Users\Dad\hpothb07.dat
C:\Users\Dad\jobq.dat


==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2015-02-18 23:44

==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-10-2016
Ran by [removed] (17-10-2016 14:00:50)
Running from C:\Users\[removed]\Desktop
Windows 8.1 Pro (Update) (X64) (2015-02-19 08:35:50)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-968235783-2654321925-1125524309-500 - Administrator - Enabled) => C:\Users\Administrator
Dad (S-1-5-21-968235783-2654321925-1125524309-1000 - Administrator - Enabled) => C:\Users\Dad
Guest (S-1-5-21-968235783-2654321925-1125524309-501 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Norton Security (Enabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: IObit Malware Fighter (Disabled - Out of date) {4D381C57-3C7A-6F22-07EB-639F49E836D4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: IObit Malware Fighter (Disabled - Up to date) {A751AC20-3B48-5237-898A-78C4436BB78D}
AS: Norton Security (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66}
FW: Norton Security (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

ABBYY FineReader 6.0 Sprint (HKLM-x32\…\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.1395.4512 - ABBYY Software House)
Acoustica MP3 CD Burner (HKLM-x32\…\Acoustica MP3 CD Burner) (Version:  - Acoustica, Inc)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.020.20039 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 20.0.0.260 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.162 - Adobe Systems Incorporated)
Advanced SystemCare 9 (HKLM-x32\…\Advanced SystemCare_is1) (Version: 9.4.0 - IObit)
Agatha Christie - Death on the Nile (x32 Version: 2.2.0.98 - WildTangent) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Audacity 2.0.2 (HKLM-x32\…\Audacity_is1) (Version: 2.0.2 - Audacity Team)
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Bonjour (HKLM\…\{B91110FB-33B4-468B-90C2-4D5E8AE3FAE1}) (Version: 2.0.2.0 - Apple Inc.)
Bonjour Print Services (HKLM\…\{0DA20600-6130-443B-9D4B-F30520315FA6}) (Version: 2.0.2.0 - Apple Inc.)
Build-a-lot 4 - Power Source (x32 Version: 2.2.0.97 - WildTangent) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.22 - Piriform)
Chord Pickout 3.0 (HKLM-x32\…\Chord Pickout 3.0) (Version: 3.0 - ChordPickout.com)
Chronicles of Albian (x32 Version: 2.2.0.95 - WildTangent) Hidden
Cisco WebEx Meetings (HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\ActiveTouchMeetingClient) (Version:  - Cisco WebEx LLC)
Citrix Online Launcher (HKLM-x32\…\{1EFF9E6C-76E1-43F9-81FB-BC8C037B0902}) (Version: 1.0.258 - Citrix)
Cradle of Rome 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
CyberLink MediaEspresso (HKLM-x32\…\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.1720_38230 - CyberLink Corp.)
CyberLink PowerDirector 13 (HKLM-x32\…\{BA385AFC-00B1-417C-8C20-74B996EF3AF0}) (Version: 13.0.2104.0 - CyberLink Corp.)
CyberLink PowerDVD 10 (HKLM-x32\…\InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}) (Version: 10.0.3313.52 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
DriverTuner 3.1.0.1 (HKLM-x32\…\{520C1D80-935C-42B9-9340-E883849D804F}_is1) (Version: 3.1.0.1 - LionSea SoftWare)
Duplicate File Finder Plus 5.0 (HKLM-x32\…\Duplicate File Finder Plus_is1) (Version:  - TriSun Software Inc.)
Duplicate Photo Finder Plus 4.0 (HKLM-x32\…\Duplicate Photo Finder Plus_is1) (Version:  - TriSun Software Inc.)
eBay Worldwide (HKLM-x32\…\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
Epson Copy Utility 3.4 (HKLM-x32\…\{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}) (Version: 3.4.0.0 - )
EPSON GT-1500 User's Guide (HKLM-x32\…\Silent Package Run-Time Sample) (Version:  - )
EPSON Scan (HKLM-x32\…\EPSON Scanner) (Version:  - Seiko Epson Corporation)
EPSON Scan PDF EXtensions (HKLM-x32\…\{F9956472-6E16-4F83-BF9A-F887EF4A45B7}) (Version: 1.00.0000 - SEIKO EPSON Corp.)
EpsonNet Config V4 (HKLM-x32\…\{08013FB5-DF8B-4D29-9B5E-B3DE88EBA6CA}) (Version: 4.5.4 - SEIKO EPSON CORPORATION)
Etron USB3.0 Host Controller (x32 Version: 0.103 - Etron Technology) Hidden
FamilySearch Indexing 3.27.7 (HKLM-x32\…\0591-8077-9297-0833) (Version: 3.27.7 - FamilySearch)
ffdshow [rev 2527] [2008-12-19] (HKLM-x32\…\ffdshow_is1) (Version: 1.0 - )
File Association Helper (HKLM\…\{572D0504-2C67-4016-801F-D70879A3026A}) (Version: 1.1.6.53763 - WinZip Computing International, LLC)
File Association Manager (HKLM-x32\…\FileAssociationManager) (Version: 0.7 - Amnis Technology Ltd)
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
FrostWire 6.3.4 (HKLM-x32\…\FrostWire 6) (Version: 6.3.4.194 - FrostWire LLC)
Galerie de photos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Gateway Games (HKLM-x32\…\WildTangent gateway Master Uninstall) (Version: 1.0.2.5 - WildTangent)
Gateway Recovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3502 - Gateway Incorporated)
Gateway Registration (HKLM-x32\…\Gateway Registration) (Version: 1.04.3503 - Gateway Incorporated)
Gateway ScreenSaver (HKLM-x32\…\Gateway Screensaver) (Version: 1.1.0225.2011 - Gateway Incorporated)
Gateway Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3500 - Gateway Incorporated)
Google Earth (HKLM-x32\…\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\…\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
GoToMeeting 7.1.0.2352 (HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\GoToMeeting) (Version: 7.1.0.2352 - CitrixOnline)
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.95 - WildTangent) Hidden
Hard Disk Sentinel PRO (HKLM-x32\…\Hard Disk Sentinel_is1) (Version:  - HDS)
Hotkey Utility (HKLM-x32\…\Hotkey Utility) (Version: 2.05.3505 - Gateway Incorporated)
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3501 - Gateway Incorporated)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2353 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
ISIS Driver - EPSON GT-1500 v1.6.10802.6001 (HKLM-x32\…\{D41864EF-CC5D-4CF4-B0B9-CA3152164157}) (Version: 1.6.10802.6001 - EMC Captiva)
iTunes (HKLM\…\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.)
Java 8 Update 102 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F64180102F0}) (Version: 8.0.1020.14 - Oracle Corporation)
Jewel Match 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
K9 (HKLM-x32\…\K9) (Version:  - )
KODAK Share Button App (HKLM-x32\…\{F5930CDE-2FF5-4A8D-9DBD-3177C816D4A9}) (Version: 4.06.0015.0313 - Eastman Kodak Company)
LastPass (uninstall only) (HKLM-x32\…\LastPass) (Version:  - LastPass)
Logitech Harmony Remote Software 7 (HKLM-x32\…\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech)
Logitech SetPoint 6.65 (HKLM\…\sp6) (Version: 6.65.62 - Logitech)
MailWasherPro (HKLM-x32\…\{A5901025-525B-4B2A-ACF4-E742D989D008}) (Version: 7.8 - Firetrust)
MailWasherPro (HKLM-x32\…\{DE507F73-E58C-4291-BA6B-F2E7FD386E7E}) (Version: 1.20.0 - Firetrust)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MEGAsync (HKLM-x32\…\MEGAsync) (Version:  - Mega Limited)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office Home and Student 2010 (HKLM-x32\…\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\OneDriveSetup.exe) (Version: 17.3.6201.1019 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\…\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\…\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MotoCast (HKLM-x32\…\{5401CEE8-3C2D-4835-A802-213306537FF4}) (Version: 1.2.7 - Motorola Mobility)
MotoHelper 2.1.40 Driver 5.5.0 (HKLM-x32\…\MotoHelper) (Version: 2.1.40 - Motorola)
MotoHelper MergeModules (x32 Version: 1.2.0 - Motorola) Hidden
MOTOROLA MEDIA LINK (x32 Version: 1.7.0147.0 - Motorola) Hidden
Motorola Mobile Drivers Installation 5.5.0 (Version: 5.5.0 - Motorola Inc.) Hidden
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
MozBackup 1.5.1 (HKLM-x32\…\MozBackup) (Version:  - Pavel Cvrcek)
Mozilla Firefox 49.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 49.0.1 (x86 en-US)) (Version: 49.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 49.0.1.6109 - Mozilla)
Mozilla Thunderbird 24.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Thunderbird 24.0.1 (x86 en-US)) (Version: 24.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyHeritage Family Tree Builder (HKLM-x32\…\Family Tree Builder) (Version: 8.0.0.8333 - MyHeritage.com)
Mystery of Mortlake Mansion (x32 Version: 2.2.0.98 - WildTangent) Hidden
NewBlue Video Essentials for Windows (HKLM-x32\…\NewBlue Video Essentials for Windows) (Version: 3.0 - NewBlue)
Norton Management (HKLM-x32\…\MCLIENT) (Version: 3.2.2.12 - Symantec Corporation)
Norton Security with Backup (HKLM-x32\…\NSBU) (Version: 22.8.0.50 - Symantec Corporation)
NVIDIA 3D Vision Controller Driver 364.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 364.44 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 368.39 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 368.39 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.11.3.5 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.11.3.5 - NVIDIA Corporation)
NVIDIA Graphics Driver 368.39 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 368.39 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.34.14 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.34.14 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
Palm Desktop by ACCESS (HKLM-x32\…\{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}) (Version: 6.4.0.0 - Palm, Inc.)
PaperPort Image Printer 64-bit (HKLM\…\{ABA4FAF1-6389-45F9-92CE-3914A4E5C471}) (Version: 1.00.0000 - Nuance Communications, Inc.)
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9 - Google, Inc.)
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
Prerequisite installer (x32 Version: 15.0.0005 - Nero AG) Hidden
QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
RealDownloader (x32 Version: 17.0.15.4 - RealNetworks, Inc.) Hidden
RealDownloader (x32 Version: 17.0.15.7 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2005 Runtime (x32 Version: 8.0 - RealNetworks) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\…\RealPlayer 17.0) (Version: 17.0.15 - RealNetworks)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10586.31222 - Realtek Semiconduct Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7746 - Realtek Semiconductor Corp.)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
Revo Uninstaller 1.95 (HKLM-x32\…\Revo Uninstaller) (Version: 1.95 - VS Revo Group)
RootsMagic 6.3.0.4 (HKLM-x32\…\{94433E0D-764C-4964-AD0B-EC46BCA7E68E}_is1) (Version: RootsMagic 6.3.0.4 - RootsMagic, Inc.)
ScanSoft PaperPort 11 (HKLM-x32\…\{DEA18FF6-D84A-4242-9663-692E5BA56805}) (Version: 11.1.0000 - Nuance Communications, Inc.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SHIELD Streaming (Version: 7.1.0280 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 2.11.3.5 - NVIDIA Corporation) Hidden
Software Informer 1.2 (HKLM\…\Software Informer_is1) (Version:  - Informer Technologies, Inc.)
Start Menu 8 (HKLM-x32\…\IObit_StartMenu8_is1) (Version: 3.1.0.3 - IObit)
Surfing Protection (HKLM-x32\…\IObit Surfing Protection_is1) (Version: 1.3 - IObit)
thinkorswim (HKLM\…\9968-4488-2169-7623) (Version: desktop - thinkorswim, Inc)
Torchlight (x32 Version: 2.2.0.97 - WildTangent) Hidden
Torrents Downloader (HKLM-x32\…\{6D9D814E-9605-11E2-80DC-95A26188709B}_is1) (Version: 0.3.20.14.06.30.-W.32 - Torrent Software S.L.)
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
USB-Ir Adapter (HKLM-x32\…\{00F3D43F-B5A9-4C8D-B5A1-5FD2DE16CC21}) (Version: 1.03.0000 - )
USB-Ir Adapter (HKLM-x32\…\{76AD2AAC-14EE-4CE3-958A-BB3DF65E7F06}) (Version: 1.03.0000 - )
Verizon Cloud (HKLM\…\Verizon Cloud) (Version: 15.3.7.9 - Verizon)
Video Downloader (x32 Version: 1.0.0 - RealNetworks) Hidden
Virtual Villagers 5 - New Believers (x32 Version: 2.2.0.97 - WildTangent) Hidden
Vulkan Run Time Libraries 1.0.11.1 (HKLM\…\VulkanRT1.0.11.1-2) (Version: 1.0.11.1 - LunarG, Inc.)
Vulkan Run Time Libraries 1.0.11.1 (Version: 1.0.11.1 - LunarG, Inc.) Hidden
Vulkan Run Time Libraries 1.0.5.1 (HKLM\…\VulkanRT1.0.5.1) (Version: 1.0.5.1 - LunarG, Inc.)
WD My Cloud (HKLM-x32\…\WD My Cloud) (Version: 1.0.2.34 - Western Digital Technologies, Inc.)
WD Quick View (HKLM-x32\…\{F4F2EF32-EAFE-4F87-B7DC-E19C9F8E76FC}) (Version: 2.4.16.16 - Western Digital Technologies, Inc.)
WD SmartWare Installer (HKLM-x32\…\{4555885d-a64c-4234-9aac-72a8a6b5590b}) (Version: 2.4.16.16 - Western Digital Technologies, Inc.)
WebEx Support Manager for Internet Explorer (HKLM-x32\…\{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}) (Version: 6.5.47 - WebEx Communications Inc.)
Welcome Center (HKLM-x32\…\Gateway Welcome Center) (Version: 1.02.3504 - Gateway Incorporated)
WildTangent Games App (Gateway Games) (x32 Version: 4.0.5.14 - WildTangent) Hidden
Windows 10 Upgrade Assistant (HKLM-x32\…\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17332 - Microsoft Corporation)
Windows Driver Package - Eastman Kodak KODAK Digital Camera (01/29/2010 1.4.1.0) (HKLM\…\3D970B9F930E7AAE23C06D39A1AC98548C90B442) (Version: 01/29/2010 1.4.1.0 - Eastman Kodak)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 4.20 (64-bit) (HKLM\…\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH)
WinZip 18.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E3}) (Version: 18.5.11111 - WinZip Computing, S.L. )
WinZip Courier (HKLM-x32\…\{CD95F661-A5C4-11AF-B2CC-ABCD21A326A2}) (Version: 5.0.10661 - WinZip Computing, S.L. )
Wise Care 365 3.14 (HKLM-x32\…\Wise Care 365_is1) (Version: 3.14 - WiseCleaner.com, Inc.)
WorkForce GT-1500 Scanner Driver Update (HKLM-x32\…\{37D0F29D-AB95-4598-ACF0-D3CC38C161D9}) (Version:  - )
Yahoo! Messenger (HKLM-x32\…\Yahoo! Messenger) (Version:  - Yahoo! Inc.)
Zuma's Revenge (x32 Version: 2.2.0.97 - WildTangent) Hidden

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-968235783-2654321925-1125524309-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Dad\AppData\Local\Citrix\GoToMeeting\2331\G2MOutlookAddin64.dll (Citrix Online, a division of Citrix Systems, Inc.)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0000B919-F681-4B54-828F-98EE446A4ABE} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {02AC57F2-B024-4079-B1EE-14F764046DD2} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {0452FD84-596C-44EC-BEF2-71F711B297BD} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {0E1BE2DA-6B04-4C0A-B88E-9892DED632DD} - System32\Tasks\Norton Management\Norton Error Processor => C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\SymErr.exe [2012-10-18] (Symantec Corporation)
Task: {0F5B218F-1397-4BAC-8139-CFBB8A75D270} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2016-10-13] (Microsoft Corporation)
Task: {114E4F3E-9481-4827-8DD8-098B1EE15160} - System32\Tasks\Microsoft\Windows\PLA\System\{D3F84E41-38E7-46AD-9900-AC7AFDBF649A}_System Diagnostics => Rundll32.exe C:\Windows\system32\pla.dll,PlaHost "system\System Diagnostics" "$(Arg0)"
Task: {11711B8D-58D9-4599-BC56-17C832D3E1F4} - System32\Tasks\{878F1772-4AB7-44C8-BEB0-17F67BA8F7CA} => pcalua.exe -a C:\Epson\epson13550.exe -d C:\Epson
Task: {11FE180B-FF6A-4AA3-AF05-DF1C3FE8D817} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {144311FC-9410-4E32-96AA-97F469BD120B} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {15E261A2-4061-436E-9F15-C2D00CDC1885} - System32\Tasks\Remediation\AntimalwareMigrationTask => C:\Program Files\Common Files\AV\Norton Security\Upgrade.exe [2016-09-23] (Symantec Corporation)
Task: {17EDF0D1-6307-4E85-AB56-050EC420AC33} - System32\Tasks\RealDownloader Update Check => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [2014-10-29] ()
Task: {1A84DA6E-3F71-46B2-961D-D949C179BF2A} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {1BE7C143-ED7C-4677-907C-65F4642DF93A} - System32\Tasks\Norton Security with Backup\Norton Error Analyzer => C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\SymErr.exe [2016-09-23] (Symantec Corporation)
Task: {1C5113A8-3C8C-459C-9826-1DEA57F176C0} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2011-05-20] (CyberLink)
Task: {1CC1E9F4-2D54-442C-A480-569C303C44D1} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1010 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {1DACEE27-B4FC-4264-9829-71E3CBB4CBAE} - no filepath
Task: {1DF4F4A1-A69E-43E5-B6D5-05EF513C2DED} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_ERROR_HB => C:\WINDOWS\system32\MRT.exe [2016-10-13] (Microsoft Corporation)
Task: {1E528A5A-342B-4C03-ACB6-810E496E8447} - System32\Tasks\{AE11724B-E59B-4B45-894D-D535ADF6C133} => pcalua.exe -a "C:\Program Files (x86)\Palm\Instapp.exe" -d "C:\Program Files (x86)\Palm\"
Task: {2391896C-BD42-4A39-9D96-EB2F89677607} - \SpeedFixToolPro_Popup -> No File <==== ATTENTION
Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {242751DA-0C0A-4A97-AA54-4CFD90B25AB4} - System32\Tasks\Western Digital\SmartWare\____Volume_04d58046_2adf_11e1_adc2_806e6f6e6963__uuid_73656761_7465_7375_636b_0090a9beb7c2_Public_ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [2016-04-19] (Western Digital Technologies, Inc.)
Task: {276D15C3-17FA-4825-B06A-C04C60347642} - System32\Tasks\{84AA05B6-6C14-4B5A-BEAF-0D8C5D21DD85} => c:\Program Files\Microsoft Mouse and Keyboard Center\MouseKeyboardCenter.exe [2014-03-19] (Microsoft)
Task: {28BB85C9-E3D1-4567-A96E-1357A29470CD} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-26] (Piriform Ltd)
Task: {294CB615-3543-4A98-9133-AB13C523F020} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {2AA350E3-9DF3-4311-86BD-8DCD140C9AC1} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {2DC0DDCC-0466-41A5-AE99-441EC497D78B} - System32\Tasks\ASC9_SkipUac_Dad => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe [2016-07-28] (IObit)
Task: {2FAA420C-2E2E-4530-AAF3-29437EA8A24F} - System32\Tasks\Driver Booster SkipUAC (Dad) => C:\Program Files (x86)\IObit\Driver Booster\DriverBooster.exe
Task: {30027EC5-B21F-4253-8B7E-84C60B0AE351} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {34160783-C4B4-4131-A34C-3FE5AC7434FF} - System32\Tasks\HardDiskSentinel\Hard Disk Sentinel_Dad => C:\Program Files (x86)\Hard Disk Sentinel\HDSentinel.exe [2016-06-27] (H.D.S. Hungary)
Task: {345CA5BD-637C-4286-8D4E-6E11708052E6} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {359BB32E-A5DD-4CE1-B97F-69E59599E51A} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {386DB6E6-C842-434E-844F-23C5836DB2C2} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: {39C23A6D-6A73-4BB5-90C1-5BFC6B6919D7} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {3CC7F30A-D22F-4A08-9D5F-F5F350B1C494} - System32\Tasks\Driver Booster Beta SkipUAC (Dad) => C:\Program Files (x86)\IObit\Driver Booster Beta\4.0.0\DriverBooster.exe
Task: {3E73DCFF-BF83-461B-9914-11880482FD22} - System32\Tasks\ReclaimerUpdateFiles_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {42BBA90C-92ED-4149-B918-0052E6BD1577} - System32\Tasks\{ABFB8086-32AB-48C7-AF44-CF3D1D8B6D36} => pcalua.exe -a C:\Nero\InCD-4.3.23.2.exe -d C:\Nero
Task: {42CE7EA5-D19C-4435-B796-0926121BAE50} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {479E6178-61D5-40D4-9A36-74FB1583003C} - System32\Tasks\MotoHelper Update => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {494A2782-FF45-440A-84EA-B3FB183DA468} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-09-16] (Adobe Systems Incorporated)
Task: {4AB21BBA-76B5-45E7-B69C-15DCF95F9310} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-26] (Adobe Systems Incorporated)
Task: {4D6CC432-3EF3-4ECC-9481-75AC4FE09D1A} - System32\Tasks\Microsoft_Hardware_Launch_devicecenter_exe => c:\Program Files\Microsoft Device Center\devicecenter.exe
Task: {4EDE0CF4-0D42-4C97-8F1B-2EE6EEE3187B} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-10-27] (RealNetworks, Inc.)
Task: {5256830D-EF5F-4A2B-941C-4BAD9F3951D6} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1010 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {5856FC30-B706-4C98-BADA-9BD645B28BD8} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Logon-5d => C:\Windows\system32\GWX\GWX.exe
Task: {5B9334BA-ADC4-42A2-AE8B-719BC03B420C} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {5C7BDB02-B3E2-4C28-816E-2B91D7CE9859} - System32\Tasks\{F850ED23-C3D5-43F2-B9BC-A17167885D9D} => pcalua.exe -a C:\Windows\system32\pcwrun.exe -c "C:\Program Files (x86)\7-Zip\7zFM.exe"
Task: {5DEB5A0E-094E-4E20-8C09-BD825E9A1FC9} - System32\Tasks\Norton Management\Norton Error Analyzer => C:\Program Files (x86)\Norton Management\Engine\3.2.2.12\SymErr.exe [2012-10-18] (Symantec Corporation)
Task: {66FA5938-862D-4D97-A64D-72AA0D340F50} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {69C7CF9C-020F-455A-BFE5-B63071BF9F28} - System32\Tasks\{DC3256B7-E258-4B58-9048-51D7DF51E46D} => pcalua.exe -a C:\Users\Dad\Desktop\jxpiinstall(1).exe -d C:\Users\Dad\Desktop
Task: {6F66763A-0B81-4E57-A300-19F36FC0AAC6} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d => C:\Windows\system32\GWX\GWX.exe
Task: {723EB32C-4249-4787-8FE2-DF4260DFC146} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-10-26] (RealNetworks, Inc.)
Task: {72E5255E-0875-4813-B09F-FD232A5545EC} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {7467BB5D-28DD-4CFC-8316-E86266BAE878} - System32\Tasks\Microsoft\Windows\PLA\System\{950FE130-0326-4B76-9EA5-5F813F013A59}_System Diagnostics => Rundll32.exe C:\WINDOWS\system32\pla.dll,PlaHost "system\System Diagnostics" "$(Arg0)"
Task: {7910552E-EC04-4FC5-B158-74F97FDA1A23} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => C:\Windows\system32\GWX\GWXUXWorker.exe
Task: {7A4ED00F-6437-4A14-A10E-AED03DF334B2} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\WSCStub.exe [2016-09-23] (Symantec Corporation)
Task: {7AD4753A-5075-4846-B933-4FB4D8937816} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {7B5D1C74-AD6F-4715-9569-70787F9F544A} - System32\Tasks\{0B4A356D-228A-48A1-81FD-F42244C76E1F} => pcalua.exe -a C:\Users\Dad\Desktop\express_hd-en_2_5_113.exe -d C:\Users\Dad\Desktop
Task: {7B7CCB54-D476-4970-9F70-4F8CF79F5DA3} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d => C:\Windows\system32\GWX\GWX.exe
Task: {7D4EC411-2076-41FE-B5A7-45F5FB1DC365} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {8147216B-D7D4-490C-8A57-C99E8CB09673} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {83827CAF-CC2B-47D7-B189-AABDF37D1C36} - System32\Tasks\Norton Security with Backup\Norton Error Processor => C:\Program Files (x86)\Norton Security with Backup\Engine\22.8.0.50\SymErr.exe [2016-09-23] (Symantec Corporation)
Task: {882E042B-1F64-49CC-9971-1446C9CCA820} - \SpeedFixToolPro_Start -> No File <==== ATTENTION
Task: {8C1FDF72-5716-404C-B64A-9CF4450B9BF6} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {8D5A910C-0A75-466E-87E2-1E77B48E40F8} - \Search-Protect -> No File <==== ATTENTION
Task: {8E3881FC-2D20-4276-8719-5E57F9876ABD} - System32\Tasks\{8AAFB465-D710-49A0-817A-25ED1D61B1E1} => pcalua.exe -a "C:\Program Files (x86)\Uniblue\RegistryBooster\rb_track_install.exe" -d "C:\Program Files (x86)\Uniblue\RegistryBooster"
Task: {8F0AA531-EDA2-47FF-B91C-98451EAFB836} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {8F13BC62-989B-4551-87BC-4E7897041568} - System32\Tasks\{D3EEF7C1-ABB2-4C4B-94F8-D9157D801C1E} => pcalua.exe -a "C:\Program Files (x86)\IObit\Advanced SystemCare 7\SecurityHole_Backup\KB2565063.exe" -d C:\Windows\system32 -c /quiet /norestart
Task: {94D5C23E-FB1A-49F1-907F-77177B3FA04B} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {95BF0CE7-962C-4DEC-92CB-3421FD1F41C5} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
Task: {97CF5DD5-A51D-41AE-87C5-B4FD1F358C70} - System32\Tasks\ReclaimerUpdateXML_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {9B759EA6-A5AB-47ED-8CEE-3E62986F7726} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {9D2278A7-7FCF-46A4-81CA-5BB6EE5C9CB8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-24] (Google Inc.)
Task: {9E4C23AE-F294-4C05-B2F5-E00DE40A3AB4} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-968235783-2654321925-1125524309-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-10-30] (RealNetworks, Inc.)
Task: {A177F73F-F74D-4AA2-A139-C5B522356209} - System32\Tasks\{C3CFB6E9-48A8-448F-AC01-70C101A5A0E5} => pcalua.exe -a C:\Users\Dad\Desktop\epson15561(1).exe -d C:\Users\Dad\Desktop
Task: {A2EB1708-4F29-4422-94E5-BF8A52F09C39} - System32\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000 => C:\Users\Dad\AppData\Local\Citrix\GoToMeeting\2352\g2mupdate.exe [2015-02-18] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {A52BB76E-951C-44F6-9E6D-7C8BD394218A} - System32\Tasks\{1EAA833A-9F24-413E-83E1-D7BE01CAFE79} => pcalua.exe -a "C:\Users\Dad\Desktop\Logitech 650HarmonyRemote7.7.0-WIN-x86.exe" -d C:\Users\Dad\Desktop
Task: {A65A0ACC-6A4D-474C-AAF2-E9DC6B09F05D} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {A94B86DD-CE9B-4D06-A8AB-0C4B044C56EA} - System32\Tasks\{9305B88E-04F4-4F7A-9EFA-3AB702618F79} => pcalua.exe -a D:\ENGLISH\QuikProtect\Setup.exe -d D:\ENGLISH\QuikProtect
Task: {A94EEAAD-AE37-4457-AB00-3E4F6390C8DE} - System32\Tasks\RNUpgradeHelperLogonPrompt_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {AF48D3C4-5B0D-4996-B1CE-CFFF8BAE74FC} - System32\Tasks\Western Digital\SmartWare\____Volume_04d58046_2adf_11e1_adc2_806e6f6e6963__uuid_73656761_7465_7375_636b_0090a9beb7c2_TimeMachineBackup_ => C:\Program Files (x86)\Western Digital\WD SmartWare\BackupTask.exe [2016-04-19] (Western Digital Technologies, Inc.)
Task: {BB5AE570-FDF9-4C37-B44E-B9F39C1E63E6} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BF1E8827-83C9-4066-B1C2-56BF616DF716} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {C3455D9F-F7A1-4DAE-A80D-2136FE0043CB} - System32\Tasks\ASC9_PerformanceMonitor => C:\Program Files (x86)\IObit\Advanced SystemCare\Monitor.exe [2016-07-20] (IObit)
Task: {CA5940DB-9B00-4239-A48A-141A2DC19AD9} - System32\Tasks\{70A11D50-D1CE-459B-94C3-BE1540DB15AD} => pcalua.exe -a C:\Users\Dad\Desktop\wlsetup-web(1).exe -d C:\Users\Dad\Desktop
Task: {CB61031D-4459-4488-9042-C51BB29A381E} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-24] (Google Inc.)
Task: {CC0868F1-E784-47FE-A5EB-312211866188} - System32\Tasks\{5C717479-B68F-4619-B051-07EABCEA176C} => pcalua.exe -a "C:\Users\Dad\Downloads\free audio recorder setup.exe" -d C:\Users\Dad\Downloads
Task: {CE300405-17AE-40F2-BEE2-D1E8D174F0E4} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {D0BCBD01-C1BF-4E62-B01F-0738BB5FBB49} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {D2DBB9FC-AC9E-4473-BC14-F2805315AB36} - System32\Tasks\{AB7ACF4B-2835-47BB-976D-DA349FE5359A} => pcalua.exe -a C:\Users\Dad\Desktop\Acoustica-MP3-CD-Burner-Installer(1).exe -d C:\Users\Dad\Desktop
Task: {D836BFE8-AD65-4CC5-A20D-3B17B0A73E4F} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {D91E354B-9EF5-4BD4-9D80-D4DD8828601C} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\Time-5d => C:\Windows\system32\GWX\GWX.exe
Task: {D99F0BF7-5D39-41D3-9378-4A4C4C48BB39} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime => C:\Windows\system32\GWX\GWXUXWorker.exe
Task: {DBED9451-604E-4D9E-BC25-B290D74851D1} - no filepath
Task: {DC0C82C1-5196-4B60-85C8-FB595D65F815} - System32\Tasks\{F0AA062F-A811-4913-8616-1586C4C104AB} => pcalua.exe -a "D:\WD SmartWare\dotnetfx35.exe" -d "D:\WD SmartWare"
Task: {DE3860C3-6209-4467-9CB2-4DCE6E38340E} - System32\Tasks\RNUpgradeHelperResumePrompt_Dad => C:\Users\Dad\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.01\agent\rnupgagent.exe [2015-11-21] (RealNetworks, Inc.)
Task: {DF865F82-3A48-4EAE-BAB1-36F8E6C3ECF6} - System32\Tasks\{2669E051-8302-4910-87D9-1960015B033E} => Firefox.exe
Task: {E1431FDE-59BC-4B5F-BDD4-A4DFC391C365} - System32\Tasks\MotoCast Update => C:\Program Files (x86)\Motorola Mobility\MotoCast\LiveUpdate\MotoCastUpdate.exe [2012-02-09] ()
Task: {E4F59CFB-B00C-4E5B-A65E-F17CB49CF3DD} - System32\Tasks\{51CA52CC-2853-4A45-AFBA-112610F5AC17} => pcalua.exe -a C:\Users\Dad\Documents\Downloads\documentstogopro7006-en.exe -d C:\Users\Dad\Documents\Downloads
Task: {E77650C6-5C0E-41C9-915C-A69DF3B71A38} - System32\Tasks\{3497E5F7-9423-4E4B-96E9-54984E4C8053} => pcalua.exe -a C:\Users\Dad\Desktop\SetupStrategyDesk.exe -d "C:\Program Files (x86)\Mozilla Firefox"
Task: {EA78BE35-04C4-4134-8ACD-52793D84FA45} - System32\Tasks\Microsoft\Windows\Setup\EOONotify => C:\Windows\EOONotify\EOONotify.exe [2016-07-08] (Microsoft Corporation)
Task: {ED327880-0A3E-4649-A790-8BCD30FFD8D1} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {EF015110-BDA2-4514-B737-16F1EDD0FAB7} - System32\Tasks\MotoHelper Routing => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {EF75BABB-9A77-4BC8-B332-91A96482055D} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => C:\Windows\system32\GWX\GWXConfigManager.exe
Task: {F0DE022C-BDE0-42F3-B3C0-24234C10D9ED} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d => C:\Windows\system32\GWX\GWX.exe
Task: {F485FC4B-1875-47D1-9D74-09706F59D1C2} - System32\Tasks\{52DC35EC-81F8-4964-8076-FDA7BF65EB24} => pcalua.exe -a C:\Epson\epson15546.exe -d C:\Epson
Task: {F6852A2F-CD85-43F5-823A-66EA81588F1A} - System32\Tasks\{5355B45C-4DD9-448E-9BB3-CAD6E6C94514} => msiexec.exe /package "C:\Users\Dad\Desktop\WD SmartWare Upgrader.msi"
Task: {F6CA1060-0EC0-4E1C-AF8F-AA4B0DFD51A6} - System32\Tasks\MotoHelper Initial Update => C:\Program Files (x86)\Motorola\MotoHelper\MotoHelperUpdate.exe [2012-02-01] ()
Task: {FABF09A5-4413-4E62-BB04-A032C1CC33B5} - System32\Tasks\{10EF5062-FADE-4238-95E4-4EA61663B88F}-Kodak Share Button App Camera detect => C:\Program Files (x86)\Kodak\KODAK Share Button App\Listener.exe [2015-02-09] (Eastman Kodak Company)
Task: {FBC5387B-8A12-416E-9E59-4D93C8943E47} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d => C:\Windows\system32\GWX\GWX.exe
Task: {FD3AA1AA-228A-4F66-AB1F-94EE4B4E3154} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {FFCE48F4-CC06-4275-ADD2-BE639EBC5D7B} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\ASC9_SkipUac_Dad.job => C:\Program Files (x86)\IObit\Advanced SystemCare\ASC.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-968235783-2654321925-1125524309-1000.job => C:\Users\Dad\AppData\Local\Citrix\GoToMeeting\2352\g2mupdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

Shortcut: C:\Users\Dad\AppData\Local\5b65\47e2.lnk -> C:\Users\Dad\AppData\Local\5b65\05b1.bat ()
Shortcut: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FrostWire 6\FrostWire 6.3.4-SafeMode.lnk -> C:\Program Files (x86)\FrostWire 6\frostwire.bat ()

==================== Loaded Modules (Whitelisted) ==============

2015-02-18 23:45 - 2016-06-02 22:26 - 00134712 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2016-04-15 04:15 - 2016-05-02 00:54 - 00369208 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\MessageBus.dll
2016-05-24 17:58 - 2016-05-02 00:55 - 00289848 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamBase.dll
2016-04-15 04:15 - 2016-05-02 00:54 - 01148984 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\libprotobuf.dll
2016-04-15 04:15 - 2016-05-02 00:55 - 03613240 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Poco.dll
2016-04-15 03:58 - 2016-05-02 00:55 - 01842232 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\RtspPlugin.dll
2016-01-29 00:21 - 2016-05-02 00:55 - 00208952 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\RtspServer.dll
2016-04-15 03:58 - 2016-05-02 00:55 - 02667576 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvMdnsPlugin.dll
2016-04-15 03:58 - 2016-05-02 00:55 - 01990200 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\Plugins\NSS\NvPortForwardPlugin.dll
2016-05-24 17:58 - 2016-05-02 00:54 - 00035896 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_system-vc120-mt-1_58.dll
2016-05-24 17:58 - 2016-05-02 00:54 - 00921656 _____ () C:\Program Files\NVIDIA Corporation\NvStreamSrv\boost_regex-vc120-mt-1_58.dll
2014-05-01 09:13 - 2014-05-01 09:13 - 00470016 _____ () C:\ProgramData\MEGAsync\ShellExtX64.dll
2012-02-07 16:54 - 2012-02-07 16:54 - 00128336 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\liveupdatetactics.dll
2012-02-07 16:53 - 2012-02-07 16:53 - 00023872 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\DbAccess.dll
2012-02-07 16:56 - 2012-02-07 16:56 - 00465632 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\sqlite3.dll
2012-02-07 16:54 - 2012-02-07 16:54 - 00045368 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\NAdvLog.dll
2012-02-07 16:54 - 2012-02-07 16:54 - 00034128 _____ () C:\Program Files (x86)\Motorola Media Link\Lite\NFileCacheDBAccess.dll
2015-11-25 13:04 - 2015-11-06 13:05 - 00618784 _____ () C:\Program Files (x86)\IObit\LiveUpdate\ProductStatistics.dll
2016-08-30 13:47 - 2015-12-29 11:30 - 00355616 _____ () C:\Program Files (x86)\IObit\Classic Start\madExcept_.bpl
2016-08-30 13:47 - 2015-12-29 11:29 - 00190240 _____ () C:\Program Files (x86)\IObit\Classic Start\madBasic_.bpl
2016-08-30 13:47 - 2015-12-29 11:30 - 00057632 _____ () C:\Program Files (x86)\IObit\Classic Start\madDisAsm_.bpl
2016-08-30 13:47 - 2015-12-29 11:30 - 00275576 _____ () C:\Program Files (x86)\IObit\Classic Start\sqlite3.dll
2016-08-30 13:47 - 2015-12-29 11:30 - 00059680 _____ () C:\Program Files (x86)\IObit\Classic Start\parseAuto.dll
2016-08-30 13:47 - 2015-12-29 11:30 - 00625440 _____ () C:\Program Files (x86)\IObit\Classic Start\ProductStatistics.dll
2014-05-01 09:15 - 2014-05-01 09:15 - 00463360 _____ () C:\ProgramData\MEGAsync\ShellExtX32.dll
2016-08-30 13:47 - 2015-12-29 11:31 - 00047904 _____ () C:\Program Files (x86)\IObit\Classic Start\winkey.dll
2016-01-03 10:34 - 2016-05-02 01:02 - 00020536 _____ () C:\Program Files (x86)\NVIDIA Corporation\Update Core\detoured.dll
2016-08-28 23:26 - 2015-12-28 13:50 - 00899872 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\webres.dll
2016-08-28 23:26 - 2015-12-28 13:49 - 00629536 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\ProductStatistics.dll
2016-04-13 14:56 - 2016-04-13 14:56 - 00061952 _____ () C:\Program Files (x86)\FireTrust\MailWasher\MWPBridgeDLL.dll
2016-04-13 14:56 - 2016-04-13 14:56 - 05999616 _____ () C:\Program Files (x86)\FireTrust\MailWasher\MWPappDLL.dll
2016-04-18 13:14 - 2016-04-18 13:14 - 00069272 _____ () C:\Program Files (x86)\FireTrust\MailWasher\FTBridge.dll
2016-04-18 13:14 - 2016-04-18 13:14 - 00279704 _____ () C:\Program Files (x86)\FireTrust\MailWasher\FTClientNode.dll
2016-03-23 22:07 - 2016-03-23 22:07 - 00324608 _____ () C:\Program Files (x86)\FireTrust\MailWasher\MWPHeaderParser.dll
2016-08-28 23:26 - 2015-12-28 13:50 - 01293088 _____ () C:\Program Files (x86)\IObit\Advanced SystemCare\Scan.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_0news-1751121550 [2302]
AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_1messages-431041656 [2302]
AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_2events-250898981 [2302]
AlternateDataStreams: C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Start Menu\Facebook.website:TASKICON_3friends-215113587 [2302]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\str => ""="service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)

IE trusted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\linkedin.com -> hxxps://www.linkedin.com
IE trusted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\microsoft.com -> hxxps://v4.update.microsoft.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\100sexlinks.com -> 100sexlinks.com

There are 4794 more sites.


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 08:25 - 2013-08-22 08:25 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-968235783-2654321925-1125524309-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dad\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\Services: IAStorDataMgrSvc => 2
MSCONFIG\Services: IDriverT => 3
MSCONFIG\Services: IMFservice => 3
MSCONFIG\Services: Live Updater Service => 2
MSCONFIG\Services: LMS => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: NAUpdate => 3
MSCONFIG\Services: nvsvc => 2
MSCONFIG\Services: nvUpdatusService => 2
MSCONFIG\Services: RealNetworks Downloader Resolver Service => 2
MSCONFIG\Services: Stereo Service => 2
MSCONFIG\Services: UNS => 2
MSCONFIG\Services: WDDMService => 3
MSCONFIG\Services: WDFMEService => 2
MSCONFIG\Services: WDRulesService => 2
MSCONFIG\Services: WiseBootAssistant => 2
MSCONFIG\Services: YahooAUService => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HotSync Manager.lnk => C:\Windows\pss\HotSync Manager.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => c:\program files (x86)\common files\adobe\arm\1.0\adobearm.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: EEventManager => C:\PROGRA~2\Epson Software\EVENTM~1\EEVENT~1.EXE
MSCONFIG\startupreg: Family Tree Builder Update => C:\Program Files (x86)\MyHeritage\Bin\FTBCheckUpdates.exe
MSCONFIG\startupreg: HotSync =>
MSCONFIG\startupreg: IndexSearch => c:\program files (x86)\scansoft\paperport\indexsearch.exe
MSCONFIG\startupreg: MotoCast => "c:\program files (x86)\motorola mobility\motocast\motolauncher.lnk"
MSCONFIG\startupreg: PaperPort PTD => c:\program files (x86)\scansoft\paperport\pptd40nt.exe
MSCONFIG\startupreg: RtHDVCpl => c:\program files\realtek\audio\hda\ravcpl64.exe -s
MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\update\realsched.exe"  -osboot
MSCONFIG\startupreg: WD Quick View => c:\program files (x86)\western digital\wd quick view\wddmstatus.exe
HKLM\…\StartupApproved\StartupFolder: => "Install LastPass FF RunOnce.lnk"
HKLM\…\StartupApproved\StartupFolder: => "Install LastPass IE RunOnce.lnk"
HKLM\…\StartupApproved\Run: => "Logitech Download Assistant"
HKLM\…\StartupApproved\Run: => "EvtMgr6"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\…\StartupApproved\Run32: => "PaperPort PTD"
HKLM\…\StartupApproved\Run32: => "IObit Malware Fighter"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\StartupFolder: => "MailWasherPro.lnk"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\StartupFolder: => "JL Christmas Market.lnk"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\StartupFolder: => "JL Victorian Calendar.lnk"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\Run: => "CCleaner Monitoring"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\Run: => "Advanced SystemCare 9"
HKU\S-1-5-21-968235783-2654321925-1125524309-1000\…\StartupApproved\Run: => "KGShareApp"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [{868D6CCB-92A2-4F9A-B4BC-906CBE16C222}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD10\PowerDVD10.EXE
FirewallRules: [TCP Query User{7C7799AE-32CB-4FC4-94D9-7C8D5E49495B}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [UDP Query User{3F78ED35-0A0B-4195-A250-C62E303143DC}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe] => (Allow) C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe
FirewallRules: [{A1752C7D-FED1-4AB7-BEA7-8702DFAE2466}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
FirewallRules: [{CF3C48EB-F298-4234-BE76-4B77EFEF71F7}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{D896BF4A-B8C6-402E-8B26-FA941C35AFE0}] => (Allow) C:\Windows\SysWOW64\msiexec.exe
FirewallRules: [{4C362F15-FCBB-41F9-923C-66A2D0B598FC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{C5ED500B-635C-4175-ACA3-39CB6B94F43B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{3A529617-79F5-4276-A1C4-25404C1FE206}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{8BB43B39-CDC3-4D33-97EF-DDB5B9A0D054}] => (Allow) LPort=2869
FirewallRules: [{62672AD7-4CF4-44FB-A466-22810DE4D035}] => (Allow) LPort=1900
FirewallRules: [{0D7AE57D-C1F0-48F2-95C3-169DFA7BAECC}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{15A4AE51-8E92-428D-8DCE-BDE09261B17F}] => (Allow) C:\Program Files (x86)\FrostWire 6\FrostWire.exe
FirewallRules: [{D98C2122-0505-4516-8F29-7E963577BCEE}] => (Allow) C:\Program Files (x86)\FrostWire 6\FrostWire.exe
FirewallRules: [{E478B0B2-92CC-48E0-9B6B-D49AFA484A95}] => (Allow) C:\Program Files (x86)\Torrents Downloader\torrents_downloader.exe
FirewallRules: [{3158406F-188C-4DF2-971A-61337A97AC01}] => (Allow) C:\Program Files (x86)\Torrents Downloader\torrents_downloader.exe
FirewallRules: [{5F9FD0D7-B1D6-4DEE-95F8-6E76040178F0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D1AAA7F3-3E29-49E2-94BF-AED3CFE8D9A2}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{1152F76F-B728-4C97-8802-157A0C4204F5}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [{A74FAC99-AEF8-48A5-A89E-657D832878A5}] => (Allow) C:\Program Files (x86)\Motorola Media Link\Lite\mml.exe
FirewallRules: [{B5F5A955-4CC4-4BC5-BFEF-FB7C7F7E6B12}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\motocast.exe
FirewallRules: [{17625B4E-A493-499C-A95F-31143906A465}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\motocast.exe
FirewallRules: [{FA9D6F73-C5DE-4965-B413-A29F7A8F2693}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
FirewallRules: [{F4B47BC7-2741-4916-8866-5CE3B5544D96}] => (Allow) C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe
FirewallRules: [{7D0267C3-2162-422F-996C-A6F28E89F358}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5C9BECF9-CCCE-42F7-8CCE-E826B6904F55}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D21F0D44-CD0B-4750-900E-E42B4FED1C74}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{90F86A6A-E8A2-4C17-AD74-671DDE58A5D6}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{6DE8CE4D-025E-43DF-9939-DE1033EDA368}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{6F144095-0AE5-4400-9979-FAA042B4D5E2}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamNetworkService.exe
FirewallRules: [{C9C7278E-F6D6-45C5-AD8E-758B52E53881}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{A4D105D8-6C7A-46AA-9C85-9E8D872EB46F}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{321C9C77-6047-43E4-99E1-E1EF259069ED}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{6F6773F0-90DC-4DB5-B739-8E39AC01BC3E}] => (Allow) C:\Program Files\iTunes\iTunes.exe
DomainProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7
StandardProfile\AuthorizedApplications: [C:\Program Files (x86)\Logitech\Logitech Harmony Remote Software 7\HarmonyRemote.exe] => Enabled:Logitech Harmony Remote Software 7

==================== Restore Points =========================

13-10-2016 19:04:53 Windows Update
16-10-2016 20:39:02 Revo Uninstaller's restore point - IObit Malware Fighter 4
17-10-2016 13:50:46 Revo Uninstaller's restore point - IObit Uninstaller
17-10-2016 13:52:36 Revo Uninstaller's restore point - Smart Defrag 5

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/17/2016 01:52:36 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (10/17/2016 01:50:53 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (10/17/2016 12:29:05 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 10:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 08:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 06:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 04:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 02:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.

Error: (10/17/2016 02:17:00 AM) (Source: Windows Search Service) (EventID: 3079) (User: )
Description: Notifications for the volume C:\ are not active.

Context: Windows Application

Details:
    The parameter is incorrect.  (HRESULT : 0x80070057) (0x80070057)

Error: (10/17/2016 12:29:05 AM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: JIM)
Description: Activation of app Microsoft.BingSports_8wekyb3d8bbwe!AppexSports failed with error: -2144927148 See the Microsoft-Windows-TWinUI/Operational log for additional information.


System errors:
=============
Error: (10/16/2016 08:39:50 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The IMF Service service terminated unexpectedly.  It has done this 1 time(s).

Error: (10/16/2016 08:15:27 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Network Connectivity Assistant service depends on the IP Helper service which failed to start because of the following error:
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.

Error: (10/16/2016 08:14:28 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942402.

Error: (10/16/2016 08:14:28 PM) (Source: Microsoft-Windows-TaskScheduler) (EventID: 413) (User: NT AUTHORITY)
Description: Task Scheduler service failed to load tasks at service startup. Additional Data: Error Value: 2147942402.

Error: (10/16/2016 08:10:51 PM) (Source: volmgr) (EventID: 46) (User: )
Description: Crash dump initialization failed!

Error: (10/16/2016 08:14:14 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 7:45:00 PM on ‎10/‎16/‎2016 was unexpected.

Error: (10/16/2016 06:53:08 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.

Error: (10/16/2016 06:25:36 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.

Error: (10/16/2016 05:32:28 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.

Error: (10/16/2016 05:12:09 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i5-2320 CPU @ 3.00GHz
Percentage of memory in use: 22%
Total physical RAM: 16364.29 MB
Available physical RAM: 12653.62 MB
Total Virtual: 32748.29 MB
Available Virtual: 28924.34 MB

==================== Drives ================================

Drive c: (Jim ) (Fixed) (Total:1848.92 GB) (Free:1586.53 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 686961D5)
Partition 1: (Not Active) - (Size=14 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=1848.9 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

Let me know how I did and if there are any other issues that need attention by me…

 

Thanks!

 

Taz

Well, I wouldnt want anything by Iobit on my system but if your happy with them and there causing no problems than lets just let them be.

 

 

Any other issues right now ?

Ken,

 

Nope, no other issues. PC was running fine before the trojan and I expect that it will return to that state now that it's gone.

 

Thanks for all your assistance, I certainly do appreciate it!

 

Regards,

 

Taz

Great, I will leave this thread open for you for about 3 days in case you have to post back, after the thread is closed if you need addtional help just start a new topic.

 

Ken :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI