This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

PC keeps locking up, running extremely slow [Solved]

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Lately my win7 home premium  pc keeps locking up, running very slowly and many times I cannot access the web sites I used to be able to get to.

:welcome:

 

Lets see whats going on. Its important that you download and run any tools or scanners we ask for from the desktop in lieu of being buried in a folder. I also ask that when the reports open in Notepad for you to copy and paste them back in this thead in lieu of attaching them

 

[external image: 1QYkxTZ.jpg] Please download aswMBR to your DESKTOP <<<<<
 
  •  
  • Right click the aswMBR icon and select Run as Administrator
  • XP users just Double Click it to run
  • If it says that this computer supports VIRTUALIZATION TECHNOLOGY do you want to use it say Yes
  • Click the Scan button to start scan.
  • Select Quickscan on the dropdown list
  • If you are asked to update the Avast Virus database please allow it to do so.
  • The scan could take 20 minutes or more , please be patient and let it finish
  • It will say Scan Finished when its done.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
 
 
I just want to see the report….Please Do Not Fix Anything
 
============================================================================
 
 
Please download Farbar Recovery Scan Tool and save it to your DESKTOP<<<<<<
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  •  
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
 

Here are the results from the Farbar tool. 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-11-2016 01
Ran by [removed] (administrator) on ARTADI-PC (22-11-2016 10:27:30)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\wtoolex\wpsupdatesvr.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
(Visicom Media Inc.) C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(IObit) C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMonitor.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 4510 series\Bin\ScanToPCActivationApp.exe
() C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe
(Flux Software LLC) C:\Users\Bryan\AppData\Local\FluxSoftware\Flux\flux.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
() C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officec2rclient.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exe
 
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2015-01-15] (NVIDIA Corporation)
HKLM\…\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-10] (Egis Technology Inc.)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-08-12] (NewTech Infosystems, Inc.)
HKLM-x32\…\Run: [Acer Assist Launcher] => C:\Program Files (x86)\Acer\Acer Assist\launcher.exe [1261568 2007-11-19] ()
HKLM-x32\…\Run: [Hotkey Utility] => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [629280 2009-08-17] ()
HKLM-x32\…\Run: [EgisTecLiveUpdate] => C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [199464 2009-08-03] (Egis Technology Inc.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Panda Security URL Filtering] => "C:\Program Files\Panda Security URL Filtering\Panda_URL_Filtering.exe"
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-11-15] (AVAST Software)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [Google Update] => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-31] (Google Inc.)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8641240 2016-02-12] (Piriform Ltd)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [HP ENVY 4510 series (NET)] => C:\Program Files\HP\HP ENVY 4510 series\Bin\ScanToPCActivationApp.exe [3651080 2015-03-09] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [OpenDNS Updater] => C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe [839680 2010-06-16] ()
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [f.lux] => C:\Users\Bryan\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {14d88b8c-41df-11e5-81d8-00262d289fc4} - G:\LG_PC_Programs.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {2ed78b9e-4ad6-11e4-b18e-00262d289fc4} - G:\LG_PC_Programs.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {a21070b2-0165-11e6-bda4-00262d289fc4} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {bb746c77-426c-11e4-b370-00262d289fc4} - G:\LaunchU3.exe -a
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {ce33646d-05b5-11e6-8974-00262d289fc4} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {eabd1f25-3ae8-11e4-ae5d-806e6f6e6963} - D:\setup\rsrc\Autorun.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-13] (Microsoft Corporation)
HKU\S-1-5-18\…\Run: [AviraSpeedup] => "C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun
ShellIconOverlayIdentifiers: [    BoxSyncFileLocked] -> {2a607da5-abe8-358e-a881-c0f5faf2d3a5} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncFileLockedByOther] -> {f7d2951f-0b6b-346c-99ec-69cffc30a364} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncNotSynced] -> {5ea95e3d-3e46-3812-b03c-49785fa67d41} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncProblem] -> {a88b7184-bfa1-3d14-8efb-2225df9699bc} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncSynced] -> {c89f9943-8f58-3eca-bd55-a658f53b2f48} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-28] (AVAST Software)
ShellIconOverlayIdentifiers: [1MediaFireIconError] -> {5EE8C634-CDC0-453D-9731-DF0B19F4E807} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon3_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconReadOnly] -> {7995D0FC-769B-4197-AEC0-991921CB99E1} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon5_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconSynched] -> {9A3B79CB-D899-40B5-8DBC-20447F1ADC8F} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconSyncing] -> {C4D81971-6B13-4173-AB21-F83AD20CCC04} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon2_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll [2009-09-10] (Egis Technology Inc.)
ShellIconOverlayIdentifiers: [MediaFireIconLock] -> {759F3E92-F4E8-4953-8315-238B8B17E0F3} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon4_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\psdprotect.dll [2009-09-10] (Egis Technology Inc.)
Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-05-06]
ShortcutTarget: Dropbox.lnk -> C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
BootExecute: autocheck autochk * sdnclean64.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Winsock: Catalog9-x64 01 C:\Windows\system32\nvLsp64.dll [434208 2009-04-19] (NVIDIA)
Winsock: Catalog9-x64 02 C:\Windows\system32\nvLsp64.dll [434208 2009-04-19] (NVIDIA)
Winsock: Catalog9-x64 03 C:\Windows\system32\nvLsp64.dll [434208 2009-04-19] (NVIDIA)
Winsock: Catalog9-x64 04 C:\Windows\system32\nvLsp64.dll [434208 2009-04-19] (NVIDIA)
Winsock: Catalog9-x64 05 C:\Windows\system32\nvLsp64.dll [434208 2009-04-19] (NVIDIA)
Winsock: Catalog9-x64 06 C:\Windows\system32\nvLsp64.dll [434208 2009-04-19] (NVIDIA)
Winsock: Catalog9-x64 17 C:\Windows\system32\nvLsp64.dll [434208 2009-04-19] (NVIDIA)
Winsock: Catalog9-x64 18 C:\Windows\system32\nvLsp64.dll [434208 2009-04-19] (NVIDIA)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{C9178436-B2FA-4276-BD10-820A7192F6DA}: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://duckduckgo.com/
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0409&m;=aspire_x1301&r;=17360914s707p0428v1j5w45j1t539
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACAW
SearchScopes: HKLM-x32 -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACAW_enUS605
SearchScopes: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit)
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-10-11] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-09-20] (Microsoft Corporation)
BHO: Panda Safe Web -> {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} -> C:\Program Files (x86)\pandasecuritytb\pandasecurityDx64.dll [2016-05-11] ()
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-09-27] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-28] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-09-20] (Microsoft Corporation)
BHO-x32: Panda Safe Web -> {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} -> C:\Program Files (x86)\pandasecuritytb\pandasecurityDx.dll [2016-05-11] ()
Toolbar: HKLM - Panda Safe Web - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files (x86)\pandasecuritytb\pandasecurityDx64.dll [2016-05-11] ()
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
Toolbar: HKLM-x32 - Panda Safe Web - {B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4} - C:\Program Files (x86)\pandasecuritytb\pandasecurityDx.dll [2016-05-11] ()
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-28] (Google Inc.)
Toolbar: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-19] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default [2016-09-05]
FF Extension: (Avira Browser Safety) - C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default\Extensions\[removed] [2015-09-21] [not signed]
FF Extension: (Panda Security Toolbar) - C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default\Extensions\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}.xpi [2016-04-26]
FF SearchPlugin: C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default\searchplugins\google-lavasoft.xml [2016-08-20]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-10-27]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-10-27]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_185.dll [2016-10-27] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_185.dll [2016-10-27] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-08-26] (Google, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-15] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-03] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-03] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-06-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1069211171-1032678597-3133260682-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1069211171-1032678597-3133260682-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com","hxxp://xfinity.comcast.net/?cid=insDate09172012","","file:///usr/share/doc/home.htm"
CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> duckduckgo.com
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.823\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\PepperFlash\18.0.0.209\pepflashplayer.dll => No File
CHR Profile: C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default [2016-11-22]
CHR Extension: (Google Slides) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-03]
CHR Extension: (Google Docs) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-03]
CHR Extension: (Google Drive) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2016-08-08]
CHR Extension: (DuckDuckGo Search) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2016-10-13]
CHR Extension: (YouTube) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (uBlock Origin) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2016-10-27]
CHR Extension: (Google Search) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Dropbox for Gmail) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2015-12-04]
CHR Extension: (Google Sheets) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-03]
CHR Extension: (Avira Browser Safety) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-09-22]
CHR Extension: (Google Docs Offline) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Privacy Cleaner) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\liiikhhbkpmpomjmdofandjmdgapiahi [2016-07-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-01]
CHR Extension: (Gmail) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-29]
CHR HKLM\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-28] (AVAST Software)
S3 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [28696 2014-09-24] (Box, Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3040496 2016-10-04] (Microsoft Corporation)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [625184 2009-04-19] ()
S3 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2015-01-15] (NVIDIA Corporation)
S3 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [28552 2016-04-26] (Hewlett-Packard Company)
R2 Kingsoft_WPS_UpdateService; C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\wtoolex\wpsupdatesvr.exe [133376 2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [3046688 2016-07-29] (IObit)
S3 MF NTFS Monitor; C:\Users\Bryan\AppData\Local\MediaFire Desktop\MFUsnMonitorService.exe [456504 2015-03-23] ()
S3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-10] (Egis Technology Inc.)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [207904 2009-04-19] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2015-01-15] (NVIDIA Corporation)
S3 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833360 2015-01-15] (NVIDIA Corporation)
R2 panda_url_filtering; C:\Program Files\Panda Security URL Filtering\Panda_URL_Filteringb.exe [287752 2015-11-06] (Visicom Media Inc.)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-05-24] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S3 wpscloudsvr; C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\wpscloudsvr.exe [162048 2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
S2 NetDrive2_Service_NetDrive2; C:\Program Files\NetDrive2\nd2svc.exe [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2014-05-27] (Google Inc) [File not signed]
S3 AndnetBus; C:\Windows\System32\DRIVERS\lgandnetbus64.sys [20992 2014-05-27] (LG Electronics Inc.) [File not signed]
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2014-07-07] (LG Electronics Inc.) [File not signed]
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2014-07-07] (LG Electronics Inc.) [File not signed]
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-28] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-28] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-28] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-08-28] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-28] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-10-27] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-10-27] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-08-28] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-27] (AVAST Software)
S3 DigiartyVirtualCDBus; C:\Windows\System32\drivers\DigiartyVirtualCDBus.sys [276256 2015-10-25] (Digiarty Software, Inc.)
S0 eorclc; no ImagePath
U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-04] (Microsoft Corporation)
R3 hsCDFiDrv; C:\Windows\System32\DRIVERS\hsCDFiDrv.sys [7168 2010-07-16] ()
S3 MDA_NTDRV; C:\Windows\system32\MDA_NTDRV.sys [21208 2013-02-25] ()
R2 mfmonitor; C:\Windows\System32\DRIVERS\mfmonitor_x64.sys [20696 2015-03-23] (Windows (R) Win 7 DDK provider)
R2 npf; C:\Windows\System32\drivers\npf.sys [36600 2015-11-15] (Riverbed Technology, Inc.)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-01-15] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
R3 panda_url_filteringd; C:\Program Files\Panda Security URL Filtering\panda_url_filteringd.sys [51288 2014-03-19] (Visicom Media Inc.)
S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2014-11-28] (Secunia)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [92848 2016-08-19] ()
R1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [26800 2016-08-19] ()
R1 Uim_IM; C:\Windows\System32\DRIVERS\uim_im.sys [484528 2016-08-19] ()
S3 uvhid; C:\Windows\System32\DRIVERS\uvhid.sys [25592 2015-07-25] (Windows (R) Win 7 DDK provider)
R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [117768 2015-08-13] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [146072 2015-08-13] (Oracle Corporation)
S3 avchv; system32\DRIVERS\avchv.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
U3 aswMBR; \??\C:\Users\Bryan\AppData\Local\Temp\aswMBR.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-11-22 10:27 - 2016-11-22 10:28 - 00031432 _____ C:\Users\Bryan\Desktop\FRST.txt
2016-11-22 10:27 - 2016-11-22 10:27 - 00000000 ____D C:\FRST
2016-11-22 10:15 - 2016-11-22 10:15 - 00000565 _____ C:\Users\Bryan\Documents\aswMBR.txt
2016-11-22 09:54 - 2016-11-22 09:54 - 02412544 _____ (Farbar) C:\Users\Bryan\Desktop\FRST64.exe
2016-11-22 09:53 - 2016-11-22 09:53 - 05198336 _____ (AVAST Software) C:\Users\Bryan\Desktop\aswMBR.exe
2016-11-13 15:30 - 2016-11-02 07:36 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-11-13 15:30 - 2016-11-02 07:32 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-11-13 15:30 - 2016-11-02 07:32 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-11-13 15:30 - 2016-11-02 07:32 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-11-13 15:30 - 2016-11-02 07:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-11-13 15:30 - 2016-11-02 07:22 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-11-13 15:30 - 2016-11-02 07:16 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2016-11-13 15:30 - 2016-11-02 07:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2016-11-13 15:30 - 2016-11-02 07:16 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2016-11-13 15:30 - 2016-11-02 06:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2016-11-13 15:30 - 2016-10-27 19:59 - 00394440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-11-13 15:30 - 2016-10-27 19:14 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-11-13 15:30 - 2016-10-27 11:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-11-13 15:30 - 2016-10-27 11:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-11-13 15:30 - 2016-10-27 10:55 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-11-13 15:30 - 2016-10-27 10:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-11-13 15:30 - 2016-10-27 10:54 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-11-13 15:30 - 2016-10-27 10:53 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-11-13 15:30 - 2016-10-27 10:53 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-11-13 15:30 - 2016-10-27 10:51 - 02896384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-11-13 15:30 - 2016-10-27 10:44 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-11-13 15:30 - 2016-10-27 10:43 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-11-13 15:30 - 2016-10-27 10:38 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-11-13 15:30 - 2016-10-27 10:37 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-11-13 15:30 - 2016-10-27 10:37 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-11-13 15:30 - 2016-10-27 10:37 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-11-13 15:30 - 2016-10-27 10:37 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-11-13 15:30 - 2016-10-27 10:28 - 25763328 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-11-13 15:30 - 2016-10-27 10:28 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-11-13 15:30 - 2016-10-27 10:24 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-11-13 15:30 - 2016-10-27 10:19 - 06047744 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-11-13 15:30 - 2016-10-27 10:15 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-11-13 15:30 - 2016-10-27 10:13 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-11-13 15:30 - 2016-10-27 10:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-11-13 15:30 - 2016-10-27 10:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-11-13 15:30 - 2016-10-27 10:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-11-13 15:30 - 2016-10-27 10:02 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-11-13 15:30 - 2016-10-27 09:49 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-11-13 15:30 - 2016-10-27 09:46 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-11-13 15:30 - 2016-10-27 09:46 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-11-13 15:30 - 2016-10-27 09:44 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-11-13 15:30 - 2016-10-27 09:44 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-11-13 15:30 - 2016-10-27 09:17 - 15257088 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-11-13 15:30 - 2016-10-27 09:16 - 02920448 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-11-13 15:30 - 2016-10-27 09:03 - 01543680 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-11-13 15:30 - 2016-10-27 08:54 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-11-13 15:30 - 2016-10-27 07:05 - 20304896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-11-13 15:30 - 2016-10-25 07:02 - 03219456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-11-13 15:30 - 2016-10-22 09:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-11-13 15:30 - 2016-10-22 09:36 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-11-13 15:30 - 2016-10-22 09:36 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-11-13 15:30 - 2016-10-22 09:35 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-11-13 15:30 - 2016-10-22 09:35 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-11-13 15:30 - 2016-10-22 09:34 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-11-13 15:30 - 2016-10-22 09:27 - 02287616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-11-13 15:30 - 2016-10-22 09:27 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-11-13 15:30 - 2016-10-22 09:26 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-11-13 15:30 - 2016-10-22 09:22 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-11-13 15:30 - 2016-10-22 09:21 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-11-13 15:30 - 2016-10-22 09:21 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-11-13 15:30 - 2016-10-22 09:20 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-11-13 15:30 - 2016-10-22 09:09 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-11-13 15:30 - 2016-10-22 09:04 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-11-13 15:30 - 2016-10-22 09:03 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-11-13 15:30 - 2016-10-22 08:59 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-11-13 15:30 - 2016-10-22 08:58 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-11-13 15:30 - 2016-10-22 08:56 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-11-13 15:30 - 2016-10-22 08:54 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-11-13 15:30 - 2016-10-22 08:46 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-11-13 15:30 - 2016-10-22 08:45 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-11-13 15:30 - 2016-10-22 08:44 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-11-13 15:30 - 2016-10-22 08:43 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-11-13 15:30 - 2016-10-22 08:43 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-11-13 15:30 - 2016-10-22 08:30 - 13654016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-11-13 15:30 - 2016-10-22 08:12 - 02444800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-11-13 15:30 - 2016-10-22 08:09 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-11-13 15:30 - 2016-10-22 08:09 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-11-13 15:30 - 2016-10-15 07:31 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-11-13 15:30 - 2016-10-15 07:31 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2016-11-13 15:30 - 2016-10-15 07:13 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2016-11-13 15:30 - 2016-10-15 07:13 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2016-11-13 15:30 - 2016-10-11 07:37 - 00370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2016-11-13 15:30 - 2016-10-11 07:31 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2016-11-13 15:30 - 2016-10-11 07:31 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2016-11-13 15:30 - 2016-10-11 07:31 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2016-11-13 15:30 - 2016-10-11 07:31 - 00457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2016-11-13 15:30 - 2016-10-11 07:31 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 01027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME
2016-11-13 15:30 - 2016-10-11 07:18 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2016-11-13 15:30 - 2016-10-11 07:18 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2016-11-13 15:30 - 2016-10-11 07:18 - 00430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2016-11-13 15:30 - 2016-10-11 07:18 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime
2016-11-13 15:30 - 2016-10-11 05:33 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2016-11-13 15:30 - 2016-10-11 05:06 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2016-11-13 15:30 - 2016-10-10 07:38 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-11-13 15:30 - 2016-10-10 07:38 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-11-13 15:30 - 2016-10-10 07:34 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-11-13 15:30 - 2016-10-10 07:34 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-11-13 15:30 - 2016-10-10 07:34 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-11-13 15:30 - 2016-10-10 07:34 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 01462272 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-11-13 15:30 - 2016-10-10 07:02 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-11-13 15:30 - 2016-10-10 06:56 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-11-13 15:30 - 2016-10-10 06:55 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-11-13 15:30 - 2016-10-10 06:55 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-11-13 15:30 - 2016-10-10 06:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-11-13 15:30 - 2016-10-10 06:54 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-11-13 15:30 - 2016-10-10 06:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-11-13 15:30 - 2016-10-07 07:40 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-11-13 15:30 - 2016-10-07 07:37 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-11-13 15:30 - 2016-10-07 07:37 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-11-13 15:30 - 2016-10-07 07:35 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 03649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00877056 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:18 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-11-13 15:30 - 2016-10-07 07:18 - 03944680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-11-13 15:30 - 2016-10-07 07:15 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:04 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-11-13 15:30 - 2016-10-07 07:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-11-13 15:30 - 2016-10-07 07:04 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-11-13 15:30 - 2016-10-07 07:01 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-11-13 15:30 - 2016-10-07 07:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-11-13 15:30 - 2016-10-07 06:56 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-11-13 15:30 - 2016-10-07 06:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-11-13 15:30 - 2016-10-07 06:50 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-11-13 15:30 - 2016-10-07 06:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-11-13 15:30 - 2016-10-07 06:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-11-13 15:30 - 2016-10-07 06:49 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 06:49 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 06:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 06:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-11-13 15:30 - 2016-10-05 06:54 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2016-11-13 15:30 - 2016-09-15 06:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2016-11-13 15:30 - 2016-09-13 07:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-11-13 15:30 - 2016-09-13 07:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-11-13 15:30 - 2016-09-09 10:20 - 00756736 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2016-11-13 15:30 - 2016-09-09 10:00 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2016-11-13 15:30 - 2016-08-22 08:19 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2016-11-09 07:29 - 2016-11-09 07:31 - 00870704 _____ C:\Windows\Minidump\110916-32822-01.dmp
2016-11-09 07:29 - 2016-11-09 07:29 - 654737022 _____ C:\Windows\MEMORY.DMP
2016-11-02 09:50 - 2016-11-02 09:50 - 00000063 _____ C:\Users\Bryan\Desktop\Terms of Use.url
2016-11-01 17:49 - 2016-11-01 17:49 - 00002864 _____ C:\Users\Ashanthe\Downloads\graph.pdf
2016-10-28 19:44 - 2016-10-28 19:44 - 00167296 _____ (Gibson Research Corp.) C:\Users\Bryan\Downloads\DNSBench.exe
2016-10-27 11:07 - 2016-10-27 11:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-10-27 10:52 - 2016-10-27 10:52 - 00001926 _____ C:\Users\Public\Desktop\Avast Pro Antivirus.lnk
2016-10-27 10:52 - 2016-10-27 10:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-10-27 10:51 - 2016-10-27 10:51 - 00044952 _____ () C:\Windows\system32\Drivers\staport.sys
2016-10-27 10:50 - 2016-08-28 10:50 - 00391496 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-10-27 08:00 - 2016-10-27 08:00 - 06306112 _____ (AVAST Software) C:\Users\Bryan\Downloads\avast_pro_antivirus_setup_online.exe
2016-10-23 18:55 - 2016-10-23 18:55 - 00000059 _____ C:\Users\Bryan\Desktop\Lineups.url
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-11-22 10:26 - 2016-05-24 11:14 - 00000000 ____D C:\Users\Bryan\AppData\Local\CrashDumps
2016-11-22 10:23 - 2016-08-04 17:37 - 00000706 _____ C:\Windows\Tasks\WpsKtpcntrQingTask_Bryan.job
2016-11-22 09:59 - 2015-02-18 04:38 - 00000908 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA.job
2016-11-22 09:50 - 2016-07-28 14:45 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-11-22 08:42 - 2016-08-04 17:37 - 00000412 _____ C:\Windows\Tasks\WpsExternal_20160804183703.job
2016-11-22 07:13 - 2016-08-28 10:51 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-11-21 15:59 - 2015-02-18 04:38 - 00000856 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001Core.job
2016-11-21 15:50 - 2016-07-28 14:45 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-11-21 15:05 - 2009-07-13 20:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-11-21 15:05 - 2009-07-13 20:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-11-21 14:51 - 2014-09-12 18:01 - 00000000 ____D C:\ProgramData\NVIDIA
2016-11-21 14:51 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-11-21 11:49 - 2016-07-30 09:39 - 00000000 ____D C:\ProgramData\panda_url_filtering
2016-11-19 19:51 - 2009-10-27 22:10 - 00000000 ____D C:\ProgramData\Google
2016-11-18 01:07 - 2009-07-13 21:13 - 00781790 _____ C:\Windows\system32\PerfStringBackup.INI
2016-11-18 01:07 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\inf
2016-11-17 14:55 - 2016-08-20 10:17 - 00000000 ____D C:\ProgramData\ProductData
2016-11-15 06:23 - 2015-02-15 01:17 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-11-15 06:21 - 2015-02-15 01:15 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-11-14 14:52 - 2014-09-12 19:37 - 00002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-14 11:40 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2016-11-14 03:22 - 2016-07-31 05:06 - 00374816 _____ C:\Windows\system32\FNTCACHE.DAT
2016-11-11 03:16 - 2014-09-12 20:01 - 00000000 ____D C:\Windows\system32\MRT
2016-11-11 03:04 - 2014-09-12 20:01 - 141011376 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-11-09 07:33 - 2016-08-20 10:17 - 00000000 ____D C:\ProgramData\IObit
2016-11-09 07:29 - 2015-11-17 00:58 - 00000000 ____D C:\Windows\Minidump
2016-11-08 19:09 - 2014-09-12 22:59 - 00004320 _____ C:\Windows\wininit.ini
2016-11-08 17:24 - 2015-07-11 09:04 - 00000000 ____D C:\Users\Ashanthe\AppData\Local\Google
2016-11-07 20:06 - 2015-07-26 15:33 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-11-01 17:46 - 2015-07-11 09:05 - 00085192 _____ C:\Users\Ashanthe\AppData\Local\GDIPFONTCACHEV1.DAT
2016-11-01 10:03 - 2014-09-16 21:13 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-11-01 09:52 - 2016-08-28 13:38 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-10-28 18:16 - 2014-09-12 19:28 - 00000000 ____D C:\Users\Bryan\AppData\Local\Google
2016-10-27 11:07 - 2016-04-16 16:36 - 00000000 ____D C:\Program Files (x86)\7-Zip
2016-10-27 11:06 - 2015-07-16 02:52 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-10-27 11:06 - 2015-07-16 02:52 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-27 11:06 - 2015-07-16 02:52 - 00003770 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-10-27 11:06 - 2014-09-15 17:46 - 00000000 ____D C:\Windows\system32\Macromed
2016-10-27 11:06 - 2009-10-27 22:25 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-10-27 11:05 - 2014-09-13 10:28 - 00000000 ____D C:\Program Files\7-Zip
2016-10-27 11:03 - 2016-08-28 11:05 - 00003892 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1472411119
2016-10-27 10:51 - 2016-08-28 10:51 - 00969184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2016-10-27 10:51 - 2016-08-28 10:51 - 00513632 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2016-10-27 10:51 - 2016-08-28 10:51 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-10-27 10:50 - 2016-08-28 10:51 - 00513496 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.147759427456810
2016-10-27 10:50 - 2016-08-28 10:51 - 00292704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.147759427419212
2016-10-27 10:49 - 2016-08-28 10:51 - 00969560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.147759427235107
 
==================== Files in the root of some directories =======
 
2016-08-28 13:52 - 2016-08-28 14:17 - 0000120 _____ () C:\Users\Bryan\AppData\Roaming\wklnhst.dat
2016-05-24 08:42 - 2016-05-24 08:42 - 0000017 _____ () C:\Users\Bryan\AppData\Local\resmon.resmoncfg
2016-01-11 22:28 - 2016-01-11 22:28 - 0986063 _____ () C:\Users\Bryan\AppData\Local\Zip-File-Opener_1706.rar
2015-01-02 21:38 - 2015-01-02 21:38 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-18 12:30 - 2015-12-18 12:38 - 0000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
 
Some files in TEMP:
====================
C:\Users\Bryan\AppData\Local\Temp\safezone_installer_201610275131460.dll
C:\Users\Bryan\AppData\Local\Temp\{87FE1528-560C-4FE1-A94F-B7E25C825A42}.exe
C:\Users\Zanthia\AppData\Local\Temp\avgnt.exe
 
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-11-14 00:38
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-11-2016 01
Ran by [removed] (22-11-2016 10:29:28)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2014-09-13 02:47:10)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1069211171-1032678597-3133260682-500 - Administrator - Disabled)
Ashanthe (S-1-5-21-1069211171-1032678597-3133260682-1005 - Limited - Enabled) => C:\Users\Ashanthe
Bryan (S-1-5-21-1069211171-1032678597-3133260682-1001 - Administrator - Enabled) => C:\Users\Bryan
danbear11 (S-1-5-21-1069211171-1032678597-3133260682-1004 - Limited - Enabled) => C:\Users\danbear11
Guest (S-1-5-21-1069211171-1032678597-3133260682-501 - Limited - Enabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-1069211171-1032678597-3133260682-1002 - Limited - Enabled)
SophosSAUARTADI-PC0 (S-1-5-21-1069211171-1032678597-3133260682-1006 - Limited - Enabled)
Zanthia (S-1-5-21-1069211171-1032678597-3133260682-1003 - Administrator - Enabled) => C:\Users\Zanthia
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 16.01 (HKLM-x32\…\7-Zip) (Version: 16.01 - Igor Pavlov)
7-Zip 16.02 (x64) (HKLM\…\7-Zip) (Version: 16.02 - Igor Pavlov)
7-Zip 16.04 (HKLM-x32\…\{23170F69-40C1-2701-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
7-Zip 16.04 (x64 edition) (HKLM\…\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
Acer Assist (HKLM-x32\…\Acer Assist) (Version:  - Acer Incorporated)
Acer Backup Manager (HKLM-x32\…\InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}) (Version: 2.0.2.19 - NewTech Infosystems)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Acer Incorporated)
Acer Games (HKLM-x32\…\WildTangent acer Master Uninstall) (Version: 1.0.0.71 - WildTangent)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.02.3006 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\…\Acer Screensaver) (Version: 1.2.0812 - Acer Incorporated)
Acer Updater (HKLM-x32\…\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.01.3017 - Acer Incorporated)
Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 23.0.0.257 - Adobe Systems Incorporated)
Adobe Flash Player 23 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.17) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.17 - Adobe Systems Incorporated)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
Amazon Music (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Amazon Amazon Music) (Version: 3.8.1.754 - Amazon Services LLC)
Avast Pro Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)
Backup Manager Advance (x32 Version: 2.0.2.19 - NewTech Infosystems) Hidden
Box Sync (HKLM\…\{8706624B-B498-455D-9606-3130782C20B3}) (Version: 4.0.6621.0 - Box, Inc.)
Box Sync (x32 Version: 4.0.5253.0 - Box Inc.) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.15 - Piriform)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Core Temp 1.1 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.1 - Alcpu)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Defraggler (HKLM\…\Defraggler) (Version: 2.21 - Piriform)
Dropbox (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Dropbox) (Version: 3.16.1 - Dropbox, Inc.)
Duplicate File Finder (HKLM-x32\…\{0670E1C9-84EF-4C85-B030-CF0A5A76B212}_is1) (Version: 5.4 - Ashisoft)
EaseUS Data Recovery Wizard 9.5 (HKLM\…\EaseUS Data Recovery Wizard 9.5_is1) (Version:  - EaseUS)
EasyDuplicateFinder v4.7 (HKLM\…\Easy Duplicate Finder 4_is1) (Version:  - WebMinds, Inc.)
eSobi v2 (HKLM-x32\…\InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.4.000274 - esobi Inc.)
eSobi v2 (x32 Version: 2.0.4.000274 - esobi Inc.) Hidden
f.lux (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Flux) (Version:  - )
FrostWire 6.0.6 (HKLM-x32\…\FrostWire 6) (Version: 6.0.6.1 - FrostWire LLC)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 54.0.2840.99 - Google Inc.)
Google Earth Pro (HKLM-x32\…\{44FC61F0-2F8A-11E3-8CAE-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Photos Backup (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
HostsMan 4.1.96 (HKLM-x32\…\{1A3DD1A9-7B7B-4ECA-AD2F-98466F49F62C}_is1) (Version: 4.1.96.0 - abelhadigital.com)
Hotkey Utility (HKLM-x32\…\Hotkey Utility) (Version: 1.00.3004 - Acer Incorporated)
HP Dropbox Plugin (HKLM-x32\…\{23617173-F935-4C17-A323-EB1207F3ED49}) (Version: 36.0.31.53050 - Hewlett-Packard Co.)
HP ENVY 4510 series Basic Device Software (HKLM\…\{E9FE2E2C-FF62-4C23-B816-62B6EEA1A772}) (Version: 36.0.72.54013 - Hewlett-Packard Co.)
HP ENVY 4510 series Help (HKLM-x32\…\{CB5C9CB2-B471-42CC-93E6-D0E15021D5C2}) (Version: 36.0.0 - Hewlett Packard)
HP FWUpdateEDO2 (HKLM-x32\…\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Google Drive Plugin (HKLM-x32\…\{AFF80405-E56A-48E7-98FC-8E46E261949F}) (Version: 36.0.31.53050 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Support Solutions Framework (HKLM-x32\…\{A772EA32-AE5B-4474-BFC0-4C69C04AFF6A}) (Version: 12.4.18.7 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3002 - Acer Incorporated)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
IObit Uninstaller (HKLM-x32\…\IObitUninstall) (Version: 6.0.2.143 - IObit)
Jarte (HKLM-x32\…\Jarte_is1) (Version: 5.4 - Carolina Road Software L.L.C.)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
LG United Mobile Driver (HKLM-x32\…\{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}) (Version: 3.12.3.0 - LG Electronics)
LGFlashTool 1.8.1.1023 (HKLM-x32\…\LGFlashTool) (Version: 1.8.1.1023 - LGE)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MediaFire Desktop (HKLM-x32\…\MediaFire Desktop 1.4.25.10813) (Version: 1.4.26.10815 - MediaFire)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\OneDriveSetup.exe) (Version: 17.3.6390.0509 - Microsoft Corporation)
Microsoft OneNote 2013 - en-us (HKLM\…\OneNoteFreeRetail - en-us) (Version: 15.0.4875.1001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\…\{E4A1FDA3-689D-44DA-9B39-86BD2270F522}) (Version: 11.2.5058.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\…\{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\…\{99AC7F47-A4E0-4706-9C65-8948775C2652}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Works (HKLM-x32\…\{67E03279-F703-408F-B4BF-46B5FC8D70CD}) (Version: 9.7.0621 - Microsoft Corporation)
MiniTool Partition Wizard Professional Edition 9.1 (HKLM\…\{69237D97-3063-450F-AE49-2357B191EA5D}_is1) (Version:  - MiniTool Solution Ltd.)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 38.0.5 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 38.0.5 (x86 en-US)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 38.0.5 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyWinLocker (HKLM-x32\…\{68301905-2DEA-41CE-A4D4-E8B443B099BA}) (Version: 3.1.76.0 - Egis Technology Inc.)
Nero 9 Essentials (HKLM-x32\…\{0b739e85-e796-499c-98fe-3be76860dfd0}) (Version:  - Nero AG)
Nmap 7.00 (HKLM-x32\…\Nmap) (Version:  - )
NVIDIA 3D Vision Controller Driver 340.50 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 341.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 341.44 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation)
NVIDIA ForceWare Network Access Manager (HKLM-x32\…\InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}) (Version:  - )
NVIDIA GeForce Experience 2.2.2 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)
NVIDIA Graphics Driver 341.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.44 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\…\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4875.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4875.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4875.1001 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\…\OpenAL) (Version:  - )
OpenDNS Updater 2.2.1 (HKLM-x32\…\OpenDNS Updater) (Version: 2.2.1 - )
Oracle VM VirtualBox 5.0.2 (HKLM\…\{6CB00039-29CC-42A1-8ED2-820821DA2B8A}) (Version: 5.0.2 - Oracle Corporation)
Panda Safe Web (HKLM-x32\…\pandasecuritytb) (Version: 4.3.1.18 - Panda Security and Visicom Media Inc.)
Paragon Backup and Recovery™ 16 (HKLM\…\{DADAA9CF-36B6-11E6-B0B5-005056C00008}) (Version: 10.28.101 - Paragon Software)
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9.140.248 - Google, Inc.)
PokerStars (HKLM-x32\…\PokerStars) (Version:  - PokerStars)
Product Improvement Study for HP ENVY 4510 series (HKLM\…\{CE8D3871-0B4C-45A8-8380-1F1BBD4AD33D}) (Version: 36.0.72.54013 - Hewlett-Packard Co.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5898 - Realtek Semiconductor Corp.)
Recuva (HKLM\…\Recuva) (Version: 1.52 - Piriform)
SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden
Serif PanoramaPlus Starter Edition (HKLM-x32\…\{64AEB598-E518-4AD0-B02B-99F365B8054C}) (Version: 2.0.0.001 - Serif (Europe) Ltd)
SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden
System Requirements Lab Detection (HKLM-x32\…\{B9C5A961-B5D5-4F55-9E9E-006FE3A85227}) (Version: 2.2.1.0 - Husdawg, LLC)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Watermark Software 8.1 (HKLM-x32\…\Watermark Software) (Version: 8.1 - watermark-software.com)
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.00.3008 - Acer Incorporated)
Windows Driver Package - Hisense Corporation hsCDFiDrv CDROM  (07/12/2010 1.01.00) (HKLM\…\D6CCB3CCE9E8F1119A58ECAB8CE0B3B24A78942E) (Version: 07/12/2010 1.01.00 - Hisense Corporation)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2980 - CACE Technologies)
WinX DVD Copy Pro 3.6.5 (HKLM\…\WinX DVD Copy Pro_is1) (Version:  - Digiarty Software,Inc.)
WinX DVD Ripper Platinum 7.5.11 (HKLM-x32\…\WinX DVD Ripper Platinum_is1) (Version:  - Digiarty Software, Inc.)
WinX HD Video Converter Deluxe 5.6.2 (HKLM-x32\…\WinX HD Video Converter Deluxe_is1) (Version:  - Digiarty Software, Inc.)
Wireshark 2.0.1 (64-bit) (HKLM-x32\…\Wireshark) (Version: 2.0.1 - The Wireshark developer community, hxxps://www.wireshark.org)
WPS Office (10.1.0.5656) (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Kingsoft Office) (Version: 10.1.0.5656 - Kingsoft Corp.)
Zynewave Podium Free 3.2.1 (x64) (HKLM\…\{EFA46A5D-4ACD-4665-A074-1B7CF713A9BB}) (Version: 3.2.1 - Zynewave)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll ()
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll (Google Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {064EE1AB-DBC2-458B-AB6E-5384536BCF1D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-02-12] (Piriform Ltd)
Task: {0BD32A31-137B-4365-945B-BA45E90EC8D4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-10-21] (Adobe Systems Incorporated)
Task: {0D30B4CF-2B59-4B0E-AFD1-8E7F32225BF5} - System32\Tasks\HPCustParticipation HP ENVY 4510 series => C:\Program Files\HP\HP ENVY 4510 series\Bin\HPCustPartic.exe [2015-03-09] (Hewlett-Packard Development Company, LP)
Task: {16C7614F-D73D-4768-9C12-E865A2B1D45B} - System32\Tasks\Acer\Acer Assist\New Message Check - Ashanthe => C:\Program Files (x86)\Acer\Acer Assist\AcerAssist.exe [2007-11-19] (Acer Incorporated)
Task: {1DC1AC47-164F-4ED1-8924-087079AE1EC1} - System32\Tasks\Uninstaller_SkipUac_Bryan => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-08-12] (IObit)
Task: {29A91802-4F76-47C9-B845-647A97387C4A} - System32\Tasks\SafeZone scheduled Autoupdate 1472411119 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software)
Task: {2A84CF68-5A68-418E-9C27-DC135EC32E85} - System32\Tasks\googleupdatetaskmachinecore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {2BC2695E-8B0A-4AD2-AB6C-20EC1AD53AB7} - System32\Tasks\WpsKtpcntrQingTask_Bryan => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exe [2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {325D5EEC-A3D8-4FCE-92A8-417092DCF0A5} - System32\Tasks\WpsExternal_20160804183703 => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\ksolaunch.exe [2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {3C5FF15A-D333-4AE9-8AAD-A696E1ADDB0D} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-28] (AVAST Software)
Task: {3FE34152-9031-4426-AB0D-73A87CB472E3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-05-09] (Hewlett-Packard)
Task: {591201AC-6F77-4EE9-9330-4ADDC8F7D1E6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-10-04] (Microsoft Corporation)
Task: {7330AB6F-E50C-47E3-BE07-62C22864CF88} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-08-28] (AVAST Software)
Task: {79C9FB33-975A-4580-9897-6E8615E55720} - System32\Tasks\{486A61CF-7BE3-4D52-81C7-6AE86E41C66E} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.3.73.105.457/en/abandoninstall?page=tsWLM
Task: {79E3E16F-73E3-4D37-B7DA-975698283354} - System32\Tasks\googleupdatetaskmachineua => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {885DF136-CC62-42EA-8722-CA0D7A03CB15} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-10-04] (Microsoft Corporation)
Task: {89A88E6B-9624-4C8F-9ABB-92125ED0B39A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-27] (Adobe Systems Incorporated)
Task: {9E5D32EE-277C-4623-810F-C69B3A0E5978} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {AA6D2334-BA38-4774-91D4-64A432DAE773} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001Core => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {B3CEDE53-F48D-4FF5-A3C0-8E94190DF8DC} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA => C:\Users\Bryan\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-14] (Dropbox, Inc.)
Task: {C6BFBECF-A713-4CBE-9CE3-36C96C805246} - System32\Tasks\Acer Registration Data Sending => C:\Program Files (x86)\Acer\Registration\GREG.exe [2009-08-28] (Acer Incorporated)
Task: {E0B01958-B00F-4779-A383-FDA5C239721E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-05-04] (Hewlett-Packard)
Task: {FDCCDC42-8A37-4C52-A163-A5AF0DEDCF96} - System32\Tasks\dropboxupdatetaskusers-1-5-21-1069211171-1032678597-3133260682-1001core => C:\Users\Bryan\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-14] (Dropbox, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001Core.job => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA.job => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\WpsExternal_20160804183703.job => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\ksolaunch.exe
Task: C:\Windows\Tasks\WpsKtpcntrQingTask_Bryan.job => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exeÃqing 10.1.0.5656 xxx server_url=hxxp:/kdl1.cache.wps.com/ksodl/wpscfg/client/____client____html____service____bubble.html ic_server_url=hxxp:/info.kingsoftstore.com/wpsv6internet/infos.ads
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
Shortcut: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FrostWire 6\FrostWire 6.0.6-SafeMode.lnk -> C:\Program Files (x86)\FrostWire\frostwire.bat ()
 
ShortcutWithArgument: C:\Users\Public\Desktop\Netflix.lnk -> C:\ProgramData\OEM_E471269A730D\Netflix\StartURL.exe () -> hxxp://homepage.acer.com/redirect.aspx?rid=09000001
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-09-13 16:32 - 2015-02-03 18:21 - 00115400 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-02-15 01:15 - 2016-05-24 09:51 - 00116416 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2016-05-24 21:18 - 2016-05-24 21:27 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2009-04-19 07:34 - 2009-04-19 07:34 - 00625184 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
2009-04-19 07:34 - 2009-04-19 07:34 - 00070176 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll
2009-04-19 07:34 - 2009-04-19 07:34 - 00578080 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll
2009-04-19 07:34 - 2009-04-19 07:34 - 00207904 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
2016-05-21 13:12 - 2016-05-21 13:12 - 00959168 _____ () C:\Users\Bryan\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-07-24 02:24 - 2016-05-24 08:43 - 08909504 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2010-06-16 13:42 - 2010-06-16 13:42 - 00839680 _____ () C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe
2009-08-17 23:27 - 2009-08-17 23:27 - 00629280 _____ () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
2016-08-28 10:50 - 2016-08-28 10:50 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-08-28 10:50 - 2016-08-28 10:50 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-11-22 07:13 - 2016-11-22 07:13 - 03129808 _____ () C:\Program Files\AVAST Software\Avast\defs\16112200\algo.dll
2009-02-02 16:33 - 2009-02-02 16:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2008-09-28 16:55 - 2008-09-28 16:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
2016-08-20 10:17 - 2016-06-21 18:30 - 00442144 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madExcept_.bpl
2016-08-20 10:17 - 2016-06-21 18:29 - 00210720 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madBasic_.bpl
2016-08-20 10:17 - 2016-06-21 18:29 - 00059680 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\madDisAsm_.bpl
2016-08-20 10:17 - 2016-05-23 20:49 - 00899872 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\webres.dll
2016-08-20 10:17 - 2016-06-14 15:35 - 00625440 _____ () C:\Program Files (x86)\IObit\IObit Uninstaller\ProductStatistics.dll
2009-08-17 23:31 - 2009-08-17 23:31 - 00163840 _____ () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
2016-05-21 13:11 - 2016-05-21 13:12 - 00679624 _____ () C:\Users\Bryan\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\ClientTelemetry.dll
2016-11-14 14:52 - 2016-11-08 12:29 - 01819240 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libglesv2.dll
2016-11-14 14:52 - 2016-11-08 12:29 - 00093288 _____ () C:\Program Files (x86)\Google\Chrome\Application\54.0.2840.99\libegl.dll
2016-08-28 10:50 - 2016-08-28 10:50 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com
 
There are 7865 more sites.
 
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\facebook.com -> hxxps://staticxx.facebook.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\facebook.net -> hxxps://connect.facebook.net
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\fbcdn.net -> hxxps://static.xx.fbcdn.net
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\google-analytics.com -> hxxps://www.google-analytics.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\hosts -> hxxps://hosts
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\paragon-software.com -> hxxps://bo4-fe.paragon-software.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\pch.com -> hxxps://pch.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\pga.com -> hxxps://pga.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123simsen.com -> www.123simsen.com
 
There are 7865 more sites.
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 18:34 - 2016-09-05 20:15 - 00948898 ____R C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com
 
There are 27258 more lines.
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: AdobeARMservice => 3
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{8C3230A9-3B37-4AB0-BF07-F92E56E6D000}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [UDP Query User{C5ECB86D-D992-4133-85A8-E2375ADBE977}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [{C1131851-AE0D-47EC-985D-3B54FFB37410}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A2186EEF-31C0-4771-8F5C-20057A62313F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{1F0A2EEF-2338-4C46-B282-735BCF6E757B}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [UDP Query User{EEF57E84-7427-4683-9F0A-911AF23E417E}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [TCP Query User{022FA091-367D-4079-A8A2-ED2592DD7D24}C:\program files (x86)\frostwire\frostwire.exe] => (Block) C:\program files (x86)\frostwire\frostwire.exe
FirewallRules: [UDP Query User{09F60FA5-71A9-473F-8B6A-E4D4253CEA95}C:\program files (x86)\frostwire\frostwire.exe] => (Block) C:\program files (x86)\frostwire\frostwire.exe
FirewallRules: [{B3DA051D-830C-4383-97B3-86C0DDE059B8}] => (Allow) C:\Users\Bryan\Downloads\solutoinstaller.exe
FirewallRules: [{012249DF-E899-4E68-ADA6-4099377F6DD7}] => (Allow) C:\Users\Bryan\Downloads\solutoinstaller.exe
FirewallRules: [{044001A0-E716-4D0D-81B1-70E9FD015F95}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9283772B-511B-4821-B133-BED4BF4AB2AC}] => (Allow) LPort=2869
FirewallRules: [{DCDC16A6-6A0C-4C05-AA19-AFE390FD2405}] => (Allow) LPort=1900
FirewallRules: [{2260B718-D95B-4B4D-95FA-609C9FBB7636}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{695FD75E-C711-464D-BAB3-B87FFB5CB693}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{39F77321-AFFB-49F6-9E20-BB09C6108758}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{5FE532DA-7DCE-4498-B1D7-2EA7839AA5AE}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{8C3A945E-2263-4351-957B-7DB970A38D0C}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{A7F95135-CCD5-473A-839D-E4F426AB21F8}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS09EB\HP.EasyStart.exe
FirewallRules: [{984BB3F6-E964-4B8E-9BA2-E6A1510F0A5E}] => (Allow) C:\Program Files\HP\HP ENVY 4510 series\Bin\DeviceSetup.exe
FirewallRules: [{3BDD8F22-9012-4F6D-9C1A-BED6890F1F1F}] => (Allow) LPort=5357
FirewallRules: [{C7ED9287-EAE5-4029-85CD-CBC94782DC03}] => (Allow) C:\Program Files\HP\HP ENVY 4510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{57ED47F0-4F49-456A-929B-2E775595F985}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2E65\HPDiagnosticCoreUI.exe
FirewallRules: [{539324E4-FE1E-4767-8DC0-C08D87D50E71}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2E65\HPDiagnosticCoreUI.exe
FirewallRules: [{D51CA84B-F225-4D3E-98D5-0E86499BA40A}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2EAD\HPDiagnosticCoreUI.exe
FirewallRules: [{574DA190-38B0-4004-BBAC-4C39E5F47175}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2EAD\HPDiagnosticCoreUI.exe
FirewallRules: [{A00F1B2E-031B-480F-AE27-B72AF2D5E08A}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
FirewallRules: [{AEF819C4-15BE-4827-A80D-FEFD9DAD7A9A}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
FirewallRules: [{65ABF914-9DF7-4667-940A-D38951B87F6C}] => (Allow) C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{57E388FA-A5E9-44F8-8988-CF70A5ECAF01}] => (Allow) C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{F2301F04-2268-4612-B640-411F080B6C2A}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS5761\HPDiagnosticCoreUI.exe
FirewallRules: [{BA79D814-7ED2-49B5-ACE1-BF9408D60E3A}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS5761\HPDiagnosticCoreUI.exe
FirewallRules: [{40DE9545-9D62-4219-8336-F7C9D640F5AE}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS6D1A\HPDiagnosticCoreUI.exe
FirewallRules: [{57991DE4-5A64-4175-AB5C-8C993868D41E}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS6D1A\HPDiagnosticCoreUI.exe
FirewallRules: [{610620A6-A213-4C59-AA61-47EDA9D1CC90}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS57A1\HPDiagnosticCoreUI.exe
FirewallRules: [{EBE92228-91A5-4A53-8D86-A7EF6CD77ED4}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS57A1\HPDiagnosticCoreUI.exe
FirewallRules: [{677AB390-0B4C-4ED8-9ADB-8A1E7BAD8891}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
14-10-2016 02:00:15 Windows Update
02-11-2016 15:17:13 Removed HP ENVY 4510 series Basic Device Software
11-11-2016 03:01:23 Windows Update
14-11-2016 03:00:13 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/22/2016 10:26:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: aswMBR.exe, version: 1.0.1.2252, time stamp: 0x5465ba64
Faulting module name: ntdll.dll, version: 6.1.7601.23569, time stamp: 0x57f7bb79
Exception code: 0xc0000005
Fault offset: 0x0002e43e
Faulting process id: 0x1370
Faulting application start time: 0x01d244eda90b3a88
Faulting application path: C:\Users\Bryan\Desktop\aswMBR.exe
Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report Id: 2209f578-b0e1-11e6-b836-00262d289fc4
 
Error: (11/22/2016 10:16:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: aswMBR.exe, version: 1.0.1.2252, time stamp: 0x5465ba64
Faulting module name: ntdll.dll, version: 6.1.7601.23569, time stamp: 0x57f7bb79
Exception code: 0xc0000005
Fault offset: 0x0002e43e
Faulting process id: 0x1b28
Faulting application start time: 0x01d244ec4ffaa678
Faulting application path: C:\Users\Bryan\Desktop\aswMBR.exe
Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report Id: db81bc18-b0df-11e6-b836-00262d289fc4
 
Error: (11/20/2016 01:02:01 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (2768) WebCacheLocal: An attempt to open the file "C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.chk" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (11/20/2016 12:06:28 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (11/20/2016 07:56:25 AM) (Source: ESENT) (EventID: 439) (User: )
Description: Windows (3820) Windows: Unable to write a shadowed header for file C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk. Error -1032.
 
Error: (11/20/2016 07:56:25 AM) (Source: ESENT) (EventID: 490) (User: )
Description: Windows (3820) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (11/18/2016 02:31:34 PM) (Source: MsiInstaller) (EventID: 1024) (User: Artadi-PC)
Description: Product: Adobe Reader XI (11.0.18) - Update 'Adobe Reader XI (11.0.18)' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
 
Error: (11/18/2016 02:31:33 PM) (Source: MsiInstaller) (EventID: 11311) (User: Artadi-PC)
Description: Product: Adobe Reader XI (11.0.18) – Error 1311.Source file not found(cabinet): C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}\Data1.cab.  Verify that the file exists and that you can access it.
 
Error: (11/15/2016 07:38:02 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (11/15/2016 12:41:44 PM) (Source: MsiInstaller) (EventID: 1024) (User: Artadi-PC)
Description: Product: Adobe Reader XI (11.0.18) - Update 'Adobe Reader XI (11.0.18)' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
 
 
System errors:
=============
Error: (11/21/2016 02:53:43 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
eorclc
 
Error: (11/21/2016 02:52:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NetDrive2_Service_NetDrive2 service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (11/21/2016 02:51:39 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 2:49:53 PM on ‎11/‎21/‎2016 was unexpected.
 
Error: (11/20/2016 01:02:01 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The IPsec Policy Agent service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (11/20/2016 01:02:01 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the IPsec Policy Agent service to connect.
 
Error: (11/20/2016 01:01:28 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
eorclc
 
Error: (11/20/2016 01:00:46 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Live ID Sign-in Assistant service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (11/20/2016 01:00:45 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Live ID Sign-in Assistant service to connect.
 
Error: (11/20/2016 12:59:54 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NetDrive2_Service_NetDrive2 service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (11/20/2016 12:59:35 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 12:55:30 PM on ‎11/‎20/‎2016 was unexpected.
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ II X2 215 Processor 
Percentage of memory in use: 50%
Total physical RAM: 3838.55 MB
Available physical RAM: 1896.71 MB
Total Virtual: 7675.29 MB
Available Virtual: 5046.29 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:698.63 GB) (Free:604.65 GB) NTFS ==>[drive with boot components (obtained from BCD)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 698.6 GB) (Disk ID: 6E286E28)
Partition 1: (Active) - (Size=698.6 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 
I'm sorry. when I tried to run the ASWMBR scan the first 2 times it stopped with an error message that the Avast anti rootkit was bad, I'm not sure that is the exact wording. I tried a third time and the scan was running for over an hour, yes it was the quickscan. I had to help my wife, she has cancer and needs help frequently. so I missed what happened with the scan but when I got back to the PC the screen was showing a request for the boot disk. I don't have one and I had to shut the system down and pray it would restart normally which it did. But I lost the original copies and replies to you so I am sending these 2 logs and then when we get back from the oncologist I will try the other scan once again and hopefully will be able to be here when it finishes and I can get a log from it. Either way I will send you an update as soon as I can. Thank You very much for your patince and help.

So  sorry to hear about your wife, my wishes for a complete recovery.

 

Your doing just fine, lets bypass aswMBR for a bit and move on.

 

Somethings to go over

 

IObit
 
I want to give you a heads up on IObit , its a program from China and not recommended. The Chinese company behind this product was found to be stealing Malwarebytes database. I would like you to uninstall it as there are better program out there,   why use one from from a questional company with unethical business practices.
 
http://blogs.computerworld.com/15026/iobit_accused_of_stealing_from_malwarebytes
 
 
 
CCleaner is a great program and use it myself, but dont get into the registry part , if you remove the wrong entries it can cause severe problems including a possiblity that your computer wont boot.

 

EasyDuplicateFinder <– I wouldn't be concened about duplicates ,again remove the wrong one and you could have problems, i would suggest uninstalling this 

 

Frostwire  <  Any form of file sharing is dangerous, I would suggest uninstalling this and stay away from any form of file sharing.

 

Panda Safe Web <-  You dont need this one either, 

 

 

 

All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
 
[external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
 
===============================================================================
 
 
You already have Malwarebytes installed, set it up this way, run the Threat scan and post that log also please
 

[external image: MBAM221%201043_zpsdtasp5xe.jpg]
 
  •  
  • On the Dashboard click on Update Now
  • Go to the Setting Tab
  • Under Setting go to Detection and Protection
  • Under PUP and PUM make sure both are set to show Treat Detections as Malware
  • Go to Advanced setting and make sure Automatically Quarantine Detected Items is checked
  • Then on the Dashboard click on Scan
  • Make sure to select THREAT SCAN
  • Then click on Scan
  • When the scan is finished on the bottom right click on SAVE RESULTS then select Copy to Clipboard
  • Please paste the log back into this thread for review
  • Exit Malwarebytes
 

 

Heres the newest logs.

 

# AdwCleaner v6.030 - Logfile created 22/11/2016 at 16:38:11
# Updated on 19/10/2016 by Malwarebytes
# Database : 2016-11-22.1 [Server]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Bryan - ARTADI-PC
# Running from : C:\Users\Bryan\Desktop\AdwCleaner.exe
# Mode: Clean
# Support : hxxps://www.malwarebytes.com/support
 
 
 
***** [ Services ] *****
 
 
 
***** [ Folders ] *****
 
[-] Folder deleted: C:\Users\Bryan\AppData\Local\eSupport.com
[-] Folder deleted: C:\Users\Zanthia\AppData\LocalLow\Inbox Toolbar
[-] Folder deleted: C:\Users\Ashanthe\AppData\LocalLow\pandasecuritytb
[-] Folder deleted: C:\Program Files\Enigma Software Group
[-] Folder deleted: C:\ProgramData\Partner
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Partner
[-] Folder deleted: C:\Program Files (x86)\BearShare Applications
[-] Folder deleted: C:\Program Files (x86)\eSupport.com
[-] Folder deleted: C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\ceopoaldcnmhechacafgagdkklcogkgd
 
 
***** [ Files ] *****
 
[-] File deleted: C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ceopoaldcnmhechacafgagdkklcogkgd_0.localstorage
[-] File deleted: C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_ceopoaldcnmhechacafgagdkklcogkgd_0.localstorage-journal
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.Protector
[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.Protector.1
[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
[-] Key deleted: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\protector_dll.Protector
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\protector_dll.Protector.1
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
[#] Key deleted on reboot: [x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
[-] Key deleted: HKLM\SOFTWARE\Classes\Interface\{CE057E0D-2D7E-4DFF-A890-07BA69B8C762}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{C4C4F1F4-3074-4CB6-9FB8-0A64273166F0}
[-] Key deleted: HKLM\SOFTWARE\Classes\TypeLib\{CBEF8724-D080-4737-88DA-111EEC6651AA}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B821BF60-5C2D-41EB-92DC-3E4CCD3A22E4}
[-] Key deleted: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\eSupport.com
[-] Key deleted: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\AppDataLow\Software\adawarebp
[#] Key deleted on reboot: HKCU\Software\eSupport.com
[#] Key deleted on reboot: HKCU\Software\AppDataLow\Software\adawarebp
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
[#] Key deleted on reboot: [x64] HKCU\Software\eSupport.com
[#] Key deleted on reboot: [x64] HKCU\Software\AppDataLow\Software\adawarebp
[-] Key deleted: HKCU\Software\Google\Chrome\Extensions\bmkckgpgekmanipelfidlhmkfcjicion
[#] Key deleted on reboot: [x64] HKCU\Software\Google\Chrome\Extensions\bmkckgpgekmanipelfidlhmkfcjicion
 
 
***** [ Web browsers ] *****
 
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: bmkckgpgekmanipelfidlhmkfcjicion
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: ceopoaldcnmhechacafgagdkklcogkgd
[-] [C:\Users\Zanthia\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\Zanthia\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: www2.inbox.com
[-] [C:\Users\Zanthia\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
[-] [C:\Users\danbear11\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\Ashanthe\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\Ashanthe\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
[-] [C:\Users\Ashanthe\AppData\Local\Google\Chrome\User Data\Profile 1\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\Ashanthe\AppData\Local\Google\Chrome\User Data\Profile 1\Web data] [Search Provider] Deleted: ask.com
[-] [C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [5082 Bytes] - [22/11/2016 16:38:11]
C:\AdwCleaner\AdwCleaner[R0].txt - [12080 Bytes] - [21/01/2015 15:16:46]
C:\AdwCleaner\AdwCleaner[S0].txt - [5098 Bytes] - [22/11/2016 16:37:23]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [5302 Bytes] ##########
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.9 (09.30.2016)
Operating System: Windows 7 Home Premium x64 
Ran by [removed] (Administrator) on Tue 11/22/2016 at 16:54:13.61
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 21 
 
Successfully deleted: C:\ProgramData\productdata (Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\nico mak computing (Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Roaming\productdata (Folder) 
Successfully deleted: C:\Users\Bryan\Documents\add-in express (Folder) 
Successfully deleted: C:\Windows\wininit.ini (File) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0FFKXXZS (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2V4TE728 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HJU2JXHC (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TAS29ZY8 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0FFKXXZS (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2V4TE728 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HJU2JXHC (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\TAS29ZY8 (Temporary Internet Files Folder) 
 
 
 
Registry: 1 
 
Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value) 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Tue 11/22/2016 at 16:58:08.35
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 11/22/2016
Scan Time: 5:03 PM
Logfile: malware bytes scan.txt
Administrator: Yes
 
Version: 2.2.1.1043
Malware Database: v2016.11.23.01
Rootkit Database: v2016.11.20.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Bryan
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 441123
Time Elapsed: 35 min, 7 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 85
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\adapter, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\abstractbutton, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\abstractbutton\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\alert, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\alert\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedhtml, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedhtml\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedhtml\html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedhtml\js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedscript, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedscript\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedscript\html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedscript\js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\flare, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\flare\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\flare\icons, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\generic, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\generic\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\link, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\link\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\images, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\rss, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\rss\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\thirdparty, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\thirdparty\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\uninstall, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\uninstall\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\weather, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\weather\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\common, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\radio, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\radio\css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\radio\js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\rss, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\rss\js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\test, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\topapps, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\topapps\css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\topapps\js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\weather, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\weather\css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\weather\js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\api, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\api\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\api\window, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\foreground, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\moviereviews, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\moviereviews\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\moviereviews\css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\moviereviews\html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\moviereviews\js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\radio, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\radio\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\radio\css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\radio\foreground, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\radio\radioWrapper, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\search, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\search\background, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\search\html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab\css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab\html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab\js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\icons, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\native, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\native\libs, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\_metadata, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd, , [921b0db67d1d53e3377d3efda45f4cb4], 
 
Files: 237
PUP.Optional.DriverAgent, C:\Users\Bryan\Downloads\driveragent-setup-987.exe, , [1499a81b3f5b3105bc624497867d5fa1], 
PUP.Optional.SpyHunter, C:\Users\Bryan\Downloads\SpyHunter-Installer.exe, , [8528b40fecaeee48cb4e429aba49629e], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\manifest.json, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\spent.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\bg.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\buildVars, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\buildVars.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\companionSW.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\config.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\contentScript.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\contentScript.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\debug.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\debug.jade, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\extension_toolbar_api.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\initWidgetWindow.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\newTabContentScript.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\options.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\spent.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\spent.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\spent2.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\spent2.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\spentJ.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\spentK.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\spentK.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\startup.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\stub.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\stubby.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\superFrame.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\toolbar.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\toolbar.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\toolbarUI.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\toolbarUI.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\toolbarUI.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\url.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\webtooltab.cs.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\adapter\adapterUtil.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\adapter\widget-adapter.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\abstractbutton\background\abstractButton.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\alert\background\alertButton.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedhtml\background\embedHtmlWidget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedhtml\html\embedHtmlTemplate.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedhtml\html\innerEmbedHtmlTemplate.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedhtml\js\embedHtmlUI.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedscript\background\embedScriptWidget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedscript\html\embedScriptTemplate.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedscript\html\innerEmbedScriptTemplate.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\embedscript\js\embedScriptUI.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\flare\background\FlareWidget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\flare\icons\Icon_Flare_blue.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\flare\icons\Icon_Flare_pink.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\flare\icons\Thumbs.db, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\generic\background\GenericWidget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\link\background\linkButton.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\README.txt, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\background\menuButton.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\css\menuframe.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\html\menuframe.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\images\right_arrow.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\images\right_arrow_white.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\js\jquery-1.7.1.min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\js\menuframe.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\js\query-string.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\menu\js\underscore-1.3.1.min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\rss\background\RssWidget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\thirdparty\background\thirdPartyWidget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\uninstall\background\uninstallButton.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\components\weather\background\weatherButton.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\bs.30.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\common.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\dynamic.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\enableDetect.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\eventListening.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\global.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\jquery-1.7.1.min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\list-interaction.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\messageEventListener.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\navRedirector.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\paramReplacer.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\PartnerId.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\set.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\underscore-1.3.1.min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\underscore-1.5.2.min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\js\unifiedLogging.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widget-context-1.0.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\common\common.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\common\eventListening.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\common\jquery-1.7.1.min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\common\list-interaction.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\common\set.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\common\underscore-1.3.1.min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\radio\radio-widget.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\radio\css\radio-widget.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\radio\js\radio-custom.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\radio\js\radio-parser.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\radio\js\radio-widget-ui.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\radio\js\radio-widget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\rss\rssWidget.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\rss\js\rss-widget-custom.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\rss\js\rss-widget-parse.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\rss\js\rss-widget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\test\invalid.json, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\test\jquery.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\test\qunit.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\test\qunit.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\test\resource.json, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\test\resource.xml, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\test\testWidget.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\test\testWidget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\topapps\widget.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\topapps\css\widget.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\topapps\js\nanigans-topapps-feed.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\topapps\js\topapps-config.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\topapps\js\widget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\weather\weatherButton.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\weather\css\weatherButton.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\common\widget-api\widgets\weather\js\weather.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\api\background\ApiBasedWidget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\api\background\widget-api-impl.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\api\window\hiddenWidgetWindow.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\api\window\hiddenWidgetWindow.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\api\window\hiddenWidgetWindowInit.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\api\window\widgetWindow.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\api\window\widgetWindow.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\background\updateSearch.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\background\updateSearchPromptBg.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\foreground\07_buttons2.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\foreground\08_buttons2.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\foreground\defaultSearchModal.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\foreground\defaultSearchModalInjector.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\foreground\defaultSearchModalInjector.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\foreground\tvf_btn_ok.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\foreground\tvf_btn_ok2.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\foreground\tvf_restart_alert_icon.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\foreground\tvf_restart_icon.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\defaultSearch\foreground\updateSearchPromptFg.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\moviereviews\background\MovieReviewsWidget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\moviereviews\css\movieReviews.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\moviereviews\html\movieReviews.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\moviereviews\js\movieReviews.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\radio\background\RadioWidget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\radio\css\toolbar-item.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\radio\foreground\button.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\radio\radioWrapper\radioWrapper.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\radio\radioWrapper\radioWrapper.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\search\background\searchBox.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\search\html\searchSuggestions.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\search\html\searchSuggestions.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\search\html\searchSuggestions.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\search\html\searchSuggestionsInit.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab\css\supertab.css, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab\html\supertab.html, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab\js\newtabfork.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab\js\reporting.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab\js\srchsugg.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab\js\supertab.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab\js\unifiedLogging.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\components\supertab\js\__utm.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\icons\arrowSprite.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\icons\icon128.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\icons\icon16.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\icons\icon19disabled.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\icons\icon19on.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\icons\icon48.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\icons\tb_icon_search_disappearing_ask.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\223756496.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\223756500.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\223756515.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\223756519.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\223756521.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\223756543.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\224441887.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\down_arrow.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\IDR_PRODUCT_LOGO_16.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\IDR_WEBSTORE_ICON.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\magnifying_glass.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\RadioPlayerSprite.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\search_button.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\tvf_icon_guide.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\tvf_logo.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\images\wrench.png, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\newTabInitialize.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\chromeStorage.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\chromeUtils.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\companionSWUtils.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\exeManager.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\exeManagerNMD.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\exePackageManager.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\focusManager.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\globalBlacklistManager.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\messaging.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\mutation_summary-min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\mutation_summary.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\nativeMessagingDispatcher.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\newTabInfo.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\options.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\readLocalStorage.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\reservespacefortoolbar.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\reservespaceifenabled.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\scriptInjector.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\searchContext.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\settingsOverrides.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\toolbarCookieParser.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\toolbarPreinit.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\underscore-1.3.1.min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\URILoaderContentScript.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\webTooltabAPI.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\Widget.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\widgetContentScriptInjectee.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\widgetFactory.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\js\widgetWindowManager.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\native\cache.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\native\ce.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\native\debug.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\native\ss.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\native\libs\jquery-1.7.1.min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\native\libs\jquery-1.9.1.min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\native\libs\underscore-1.5.2.min.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\activePing.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\buttonLogger.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\competitorDnsList.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\console.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\FFPreferencesPersister.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\httpTransport.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\HttpURL.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\internationalSearch.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\LocalStoragePersister.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\MindsparkGlobal.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\MindsparkGlobal.unitTest.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\MindsparkGlobalNotes.txt, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\rsvp-latest.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\searchSuggestLocale.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\testHttpTransport.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\unifiedLogger.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\unifiedLogging.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\universalConsole.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\shared\utils.js, , [921b0db67d1d53e3377d3efda45f4cb4], 
PUP.Optional.MindSpark, C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd\12.202.10.29979_1\_metadata\verified_contents.json, , [921b0db67d1d53e3377d3efda45f4cb4], 
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)
 
Thank you again.
 

I forgot to mention that I tried to uninstall the Easy Duplicate Finder4 and or the original Easy duplicate Finder app and I keep getting an error message saying it doesn't exist. but it does and when I click on the app it opens up. Should i re-install Revo uninstaller that i had b4 I installed IObit uninstaller?

 

Are there any other ways to uninstall the duplicate finder?

Good Morning

 

Yes you can give Revo Uninstaller another shot 

 

Let me ask you, the Malwarebytes log shows so many entries but none of them are shown as Quarantined, did you have Malwarebytes remove them like I showed in my instructions, they need to be gone

 

This is just an example from another pc not yours but this is how those entries should look on your log if you Quarantined them

 

PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\TYPELIB\{B0660298-91AA-421F-BF0D-BFF6BB8BF3AE}, Quarantined, [d8771a9c444610265bd9f3af73904ab6],
PUP.Optional.Amonetize.A, HKLM\SOFTWARE\CLASSES\INTERFACE\{EAC7DE5C-9520-435D-91AA-4A02E4773CEA}, Quarantined, [d8771a9c444610265bd9f3af73904ab6],
 
 
If you did not have Malwarebytes Quarantine them then you need to run Malwarebytes again and have them removed.
 
You can also do it this way

 
  •  
  • You can highlight one of the detections by left clicking on it.
  • Then, right click on the highlighted detection, and select 'Check All Items'.
  • Next, click 'Remove Selected'. That should remove them all
 
 
 
 
After you use Revo to uninstall that program, let me know if it was successful or not because we can use FRST to remove any leftovers. Also let me know if you where successful in removing all those Malwarebytes entries
 
THEN, open up FRST64 by right clicking on it and select RUN AS ADMINISTRATOR, make sure there is a checkmark in ADDITIONS, leave everything else as is, click on SCAN and post both the new FRST64 and Additions logs
 
 

OK FRST scan done and here are the logs. I reinstalled Revo and uninstalled duplicate file finder successfully. Also the detections from Malwarebytes were quarantined and now I have deleted them.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-11-2016 01
Ran by [removed] (administrator) on ARTADI-PC (23-11-2016 07:31:44)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\wtoolex\wpsupdatesvr.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.31.5\GoogleCrashHandler64.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2015-01-15] (NVIDIA Corporation)
HKLM\…\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-10] (Egis Technology Inc.)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-08-12] (NewTech Infosystems, Inc.)
HKLM-x32\…\Run: [Acer Assist Launcher] => C:\Program Files (x86)\Acer\Acer Assist\launcher.exe [1261568 2007-11-19] ()
HKLM-x32\…\Run: [Hotkey Utility] => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [629280 2009-08-17] ()
HKLM-x32\…\Run: [EgisTecLiveUpdate] => C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [199464 2009-08-03] (Egis Technology Inc.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-11-15] (AVAST Software)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [Google Update] => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe [144200 2015-08-31] (Google Inc.)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8641240 2016-02-12] (Piriform Ltd)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [HP ENVY 4510 series (NET)] => C:\Program Files\HP\HP ENVY 4510 series\Bin\ScanToPCActivationApp.exe [3651080 2015-03-09] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [OpenDNS Updater] => C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe [839680 2010-06-16] ()
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [f.lux] => C:\Users\Bryan\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {14d88b8c-41df-11e5-81d8-00262d289fc4} - G:\LG_PC_Programs.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {2ed78b9e-4ad6-11e4-b18e-00262d289fc4} - G:\LG_PC_Programs.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {a21070b2-0165-11e6-bda4-00262d289fc4} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {bb746c77-426c-11e4-b370-00262d289fc4} - G:\LaunchU3.exe -a
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {ce33646d-05b5-11e6-8974-00262d289fc4} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {eabd1f25-3ae8-11e4-ae5d-806e6f6e6963} - D:\setup\rsrc\Autorun.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-13] (Microsoft Corporation)
HKU\S-1-5-18\…\Run: [AviraSpeedup] => "C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun
ShellIconOverlayIdentifiers: [    BoxSyncFileLocked] -> {2a607da5-abe8-358e-a881-c0f5faf2d3a5} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncFileLockedByOther] -> {f7d2951f-0b6b-346c-99ec-69cffc30a364} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncNotSynced] -> {5ea95e3d-3e46-3812-b03c-49785fa67d41} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncProblem] -> {a88b7184-bfa1-3d14-8efb-2225df9699bc} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncSynced] -> {c89f9943-8f58-3eca-bd55-a658f53b2f48} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-08-28] (AVAST Software)
ShellIconOverlayIdentifiers: [1MediaFireIconError] -> {5EE8C634-CDC0-453D-9731-DF0B19F4E807} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon3_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconReadOnly] -> {7995D0FC-769B-4197-AEC0-991921CB99E1} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon5_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconSynched] -> {9A3B79CB-D899-40B5-8DBC-20447F1ADC8F} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconSyncing] -> {C4D81971-6B13-4173-AB21-F83AD20CCC04} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon2_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll [2009-09-10] (Egis Technology Inc.)
ShellIconOverlayIdentifiers: [MediaFireIconLock] -> {759F3E92-F4E8-4953-8315-238B8B17E0F3} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon4_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\psdprotect.dll [2009-09-10] (Egis Technology Inc.)
Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-05-06]
ShortcutTarget: Dropbox.lnk -> C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
BootExecute: autocheck autochk * sdnclean64.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{C9178436-B2FA-4276-BD10-820A7192F6DA}: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://duckduckgo.com/
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0409&m;=aspire_x1301&r;=17360914s707p0428v1j5w45j1t539
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACAW
SearchScopes: HKLM-x32 -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACAW_enUS605
SearchScopes: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2016-10-11] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2016-10-24] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2016-09-20] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2016-09-27] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2016-10-24] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-28] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2016-09-20] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-28] (Google Inc.)
Toolbar: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-19] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default [2016-11-22]
FF Extension: (Avira Browser Safety) - C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default\Extensions\[removed] [2015-09-21] [not signed]
FF SearchPlugin: C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default\searchplugins\google-lavasoft.xml [2016-08-20]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-10-27]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-10-27]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_23_0_0_185.dll [2016-10-27] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_23_0_0_185.dll [2016-10-27] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-08-26] (Google, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-15] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-03] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-03] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-06-23] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1069211171-1032678597-3133260682-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-1069211171-1032678597-3133260682-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com","hxxp://xfinity.comcast.net/?cid=insDate09172012","","file:///usr/share/doc/home.htm"
CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> duckduckgo.com
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.823\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\PepperFlash\18.0.0.209\pepflashplayer.dll => No File
CHR Profile: C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default [2016-11-23]
CHR Extension: (Google Slides) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-03]
CHR Extension: (Google Docs) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-03]
CHR Extension: (Google Drive) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2016-08-08]
CHR Extension: (DuckDuckGo Search) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2016-10-13]
CHR Extension: (YouTube) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (OnlineMapFinder) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd [2016-11-22]
CHR Extension: (uBlock Origin) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2016-10-27]
CHR Extension: (Google Search) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Dropbox for Gmail) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2015-12-04]
CHR Extension: (Google Sheets) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-03]
CHR Extension: (Avira Browser Safety) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-09-22]
CHR Extension: (Google Docs Offline) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (Privacy Cleaner) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\liiikhhbkpmpomjmdofandjmdgapiahi [2016-07-11]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-01]
CHR Extension: (Gmail) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-10-29]
CHR HKLM\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [197128 2016-08-28] (AVAST Software)
S3 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [28696 2014-09-24] (Box, Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3040496 2016-10-04] (Microsoft Corporation)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [625184 2009-04-19] ()
S3 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2015-01-15] (NVIDIA Corporation)
S3 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [28552 2016-04-26] (Hewlett-Packard Company)
R2 Kingsoft_WPS_UpdateService; C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\wtoolex\wpsupdatesvr.exe [133376 2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [3046688 2016-07-29] (IObit)
S3 MF NTFS Monitor; C:\Users\Bryan\AppData\Local\MediaFire Desktop\MFUsnMonitorService.exe [456504 2015-03-23] ()
S3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-10] (Egis Technology Inc.)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [207904 2009-04-19] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2015-01-15] (NVIDIA Corporation)
S3 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833360 2015-01-15] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-05-24] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S3 wpscloudsvr; C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\wpscloudsvr.exe [162048 2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
S2 NetDrive2_Service_NetDrive2; C:\Program Files\NetDrive2\nd2svc.exe [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2014-05-27] (Google Inc) [File not signed]
S3 AndnetBus; C:\Windows\System32\DRIVERS\lgandnetbus64.sys [20992 2014-05-27] (LG Electronics Inc.) [File not signed]
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2014-07-07] (LG Electronics Inc.) [File not signed]
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2014-07-07] (LG Electronics Inc.) [File not signed]
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [37656 2016-08-28] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [37144 2016-08-28] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [108816 2016-08-28] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [103064 2016-08-28] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [74544 2016-08-28] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [969184 2016-10-27] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [513632 2016-10-27] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [163416 2016-08-28] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [293352 2016-10-27] (AVAST Software)
S3 DigiartyVirtualCDBus; C:\Windows\System32\drivers\DigiartyVirtualCDBus.sys [276256 2015-10-25] (Digiarty Software, Inc.)
S0 eorclc; no ImagePath
U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-04] (Microsoft Corporation)
R3 hsCDFiDrv; C:\Windows\System32\DRIVERS\hsCDFiDrv.sys [7168 2010-07-16] ()
S3 MDA_NTDRV; C:\Windows\system32\MDA_NTDRV.sys [21208 2013-02-25] ()
R2 mfmonitor; C:\Windows\System32\DRIVERS\mfmonitor_x64.sys [20696 2015-03-23] (Windows (R) Win 7 DDK provider)
R2 npf; C:\Windows\System32\drivers\npf.sys [36600 2015-11-15] (Riverbed Technology, Inc.)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-01-15] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2014-11-28] (Secunia)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [92848 2016-08-19] ()
R1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [26800 2016-08-19] ()
R1 Uim_IM; C:\Windows\System32\DRIVERS\uim_im.sys [484528 2016-08-19] ()
S3 uvhid; C:\Windows\System32\DRIVERS\uvhid.sys [25592 2015-07-25] (Windows (R) Win 7 DDK provider)
R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [117768 2015-08-13] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [146072 2015-08-13] (Oracle Corporation)
S3 avchv; system32\DRIVERS\avchv.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-11-23 06:41 - 2016-11-23 06:41 - 00001081 _____ C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
2016-11-23 06:41 - 2016-11-23 06:41 - 00000000 ____D C:\Users\Bryan\AppData\Local\VS Revo Group
2016-11-23 06:41 - 2016-11-23 06:41 - 00000000 ____D C:\ProgramData\VS Revo Group
2016-11-23 06:41 - 2016-11-23 06:41 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller Pro
2016-11-23 06:41 - 2009-12-30 11:21 - 00031800 _____ (VS Revo Group) C:\Windows\system32\Drivers\revoflt.sys
2016-11-23 06:40 - 2016-11-23 06:40 - 11432112 _____ (VS Revo Group ) C:\Users\Bryan\Downloads\RevoUninProSetup.exe
2016-11-23 06:39 - 2016-11-23 06:40 - 07100088 _____ (VS Revo Group ) C:\Users\Bryan\Downloads\revosetup (3).exe
2016-11-23 06:37 - 2016-11-23 06:41 - 00000000 ____D C:\Program Files\VS Revo Group
2016-11-23 06:37 - 2016-11-23 06:37 - 07100088 _____ (VS Revo Group ) C:\Users\Bryan\Downloads\revosetup (2).exe
2016-11-23 06:37 - 2016-11-23 06:37 - 00001038 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2016-11-23 06:37 - 2016-11-23 06:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2016-11-22 17:40 - 2016-11-22 17:40 - 00071473 _____ C:\malware bytes scan.txt
2016-11-22 16:58 - 2016-11-22 16:58 - 00003638 _____ C:\Users\Bryan\Desktop\JRT.txt
2016-11-22 16:30 - 2016-11-22 16:30 - 03910208 _____ C:\Users\Bryan\Desktop\AdwCleaner.exe
2016-11-22 16:30 - 2016-11-22 16:30 - 01631928 _____ (Malwarebytes) C:\Users\Bryan\Desktop\JRT.exe
2016-11-22 16:06 - 2016-11-22 16:06 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\EasyDuplicateFinder
2016-11-22 10:29 - 2016-11-22 10:32 - 00048674 _____ C:\Users\Bryan\Desktop\Addition.txt
2016-11-22 10:27 - 2016-11-23 07:32 - 00028085 _____ C:\Users\Bryan\Desktop\FRST.txt
2016-11-22 10:27 - 2016-11-23 07:31 - 00000000 ____D C:\FRST
2016-11-22 10:15 - 2016-11-22 10:15 - 00000565 _____ C:\Users\Bryan\Documents\aswMBR.txt
2016-11-22 09:54 - 2016-11-22 09:54 - 02412544 _____ (Farbar) C:\Users\Bryan\Desktop\FRST64.exe
2016-11-22 09:53 - 2016-11-22 09:53 - 05198336 _____ (AVAST Software) C:\Users\Bryan\Desktop\aswMBR.exe
2016-11-13 15:30 - 2016-11-02 07:36 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2016-11-13 15:30 - 2016-11-02 07:32 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2016-11-13 15:30 - 2016-11-02 07:32 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2016-11-13 15:30 - 2016-11-02 07:32 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2016-11-13 15:30 - 2016-11-02 07:32 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2016-11-13 15:30 - 2016-11-02 07:22 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2016-11-13 15:30 - 2016-11-02 07:16 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2016-11-13 15:30 - 2016-11-02 07:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2016-11-13 15:30 - 2016-11-02 07:16 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2016-11-13 15:30 - 2016-11-02 06:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2016-11-13 15:30 - 2016-10-27 19:59 - 00394440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-11-13 15:30 - 2016-10-27 19:14 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-11-13 15:30 - 2016-10-27 11:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-11-13 15:30 - 2016-10-27 11:13 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-11-13 15:30 - 2016-10-27 10:55 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-11-13 15:30 - 2016-10-27 10:54 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-11-13 15:30 - 2016-10-27 10:54 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-11-13 15:30 - 2016-10-27 10:53 - 00576000 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-11-13 15:30 - 2016-10-27 10:53 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-11-13 15:30 - 2016-10-27 10:51 - 02896384 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-11-13 15:30 - 2016-10-27 10:44 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-11-13 15:30 - 2016-10-27 10:43 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-11-13 15:30 - 2016-10-27 10:38 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-11-13 15:30 - 2016-10-27 10:37 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-11-13 15:30 - 2016-10-27 10:37 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-11-13 15:30 - 2016-10-27 10:37 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-11-13 15:30 - 2016-10-27 10:37 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-11-13 15:30 - 2016-10-27 10:28 - 25763328 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-11-13 15:30 - 2016-10-27 10:28 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-11-13 15:30 - 2016-10-27 10:24 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-11-13 15:30 - 2016-10-27 10:19 - 06047744 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-11-13 15:30 - 2016-10-27 10:15 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-11-13 15:30 - 2016-10-27 10:13 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-11-13 15:30 - 2016-10-27 10:09 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-11-13 15:30 - 2016-10-27 10:08 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-11-13 15:30 - 2016-10-27 10:05 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-11-13 15:30 - 2016-10-27 10:02 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-11-13 15:30 - 2016-10-27 09:49 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-11-13 15:30 - 2016-10-27 09:46 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-11-13 15:30 - 2016-10-27 09:46 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-11-13 15:30 - 2016-10-27 09:44 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-11-13 15:30 - 2016-10-27 09:44 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-11-13 15:30 - 2016-10-27 09:17 - 15257088 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-11-13 15:30 - 2016-10-27 09:16 - 02920448 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-11-13 15:30 - 2016-10-27 09:03 - 01543680 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-11-13 15:30 - 2016-10-27 08:54 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-11-13 15:30 - 2016-10-27 07:05 - 20304896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-11-13 15:30 - 2016-10-25 07:02 - 03219456 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-11-13 15:30 - 2016-10-22 09:54 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-11-13 15:30 - 2016-10-22 09:36 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-11-13 15:30 - 2016-10-22 09:36 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-11-13 15:30 - 2016-10-22 09:35 - 00498688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-11-13 15:30 - 2016-10-22 09:35 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-11-13 15:30 - 2016-10-22 09:34 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-11-13 15:30 - 2016-10-22 09:27 - 02287616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-11-13 15:30 - 2016-10-22 09:27 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-11-13 15:30 - 2016-10-22 09:26 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-11-13 15:30 - 2016-10-22 09:22 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-11-13 15:30 - 2016-10-22 09:21 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-11-13 15:30 - 2016-10-22 09:21 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-11-13 15:30 - 2016-10-22 09:20 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-11-13 15:30 - 2016-10-22 09:09 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-11-13 15:30 - 2016-10-22 09:04 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-11-13 15:30 - 2016-10-22 09:03 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-11-13 15:30 - 2016-10-22 08:59 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-11-13 15:30 - 2016-10-22 08:58 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-11-13 15:30 - 2016-10-22 08:56 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-11-13 15:30 - 2016-10-22 08:54 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-11-13 15:30 - 2016-10-22 08:46 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-11-13 15:30 - 2016-10-22 08:45 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-11-13 15:30 - 2016-10-22 08:44 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-11-13 15:30 - 2016-10-22 08:43 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-11-13 15:30 - 2016-10-22 08:43 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-11-13 15:30 - 2016-10-22 08:30 - 13654016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-11-13 15:30 - 2016-10-22 08:12 - 02444800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-11-13 15:30 - 2016-10-22 08:09 - 01312256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-11-13 15:30 - 2016-10-22 08:09 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-11-13 15:30 - 2016-10-15 07:31 - 00976896 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2016-11-13 15:30 - 2016-10-15 07:31 - 00084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2016-11-13 15:30 - 2016-10-15 07:13 - 00741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2016-11-13 15:30 - 2016-10-15 07:13 - 00084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2016-11-13 15:30 - 2016-10-11 07:37 - 00370920 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2016-11-13 15:30 - 2016-10-11 07:31 - 01148416 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10.IME
2016-11-13 15:30 - 2016-10-11 07:31 - 01068544 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll
2016-11-13 15:30 - 2016-10-11 07:31 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\IMJP10K.DLL
2016-11-13 15:30 - 2016-10-11 07:31 - 00457216 _____ (Microsoft Corporation) C:\Windows\system32\imkr80.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00246784 _____ (Microsoft Corporation) C:\Windows\system32\input.dll
2016-11-13 15:30 - 2016-10-11 07:31 - 00176128 _____ (Microsoft Corporation) C:\Windows\system32\tintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\quick.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\qintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\phon.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\cintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00175104 _____ (Microsoft Corporation) C:\Windows\system32\chajei.ime
2016-11-13 15:30 - 2016-10-11 07:31 - 00132608 _____ (Microsoft Corporation) C:\Windows\system32\pintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 01027584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10.IME
2016-11-13 15:30 - 2016-10-11 07:18 - 00829952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll
2016-11-13 15:30 - 2016-10-11 07:18 - 00701440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IMJP10K.DLL
2016-11-13 15:30 - 2016-10-11 07:18 - 00430080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imkr80.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00202240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\input.dll
2016-11-13 15:30 - 2016-10-11 07:18 - 00126976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quick.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\phon.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cintlgnt.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00125952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\chajei.ime
2016-11-13 15:30 - 2016-10-11 07:18 - 00090112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pintlgnt.ime
2016-11-13 15:30 - 2016-10-11 05:33 - 00187392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAnimation.dll
2016-11-13 15:30 - 2016-10-11 05:06 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\UIAnimation.dll
2016-11-13 15:30 - 2016-10-10 07:38 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-11-13 15:30 - 2016-10-10 07:38 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-11-13 15:30 - 2016-10-10 07:34 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-11-13 15:30 - 2016-10-10 07:34 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-11-13 15:30 - 2016-10-10 07:34 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-11-13 15:30 - 2016-10-10 07:34 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 01462272 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-11-13 15:30 - 2016-10-10 07:33 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-11-13 15:30 - 2016-10-10 07:16 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-11-13 15:30 - 2016-10-10 07:02 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-11-13 15:30 - 2016-10-10 06:56 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-11-13 15:30 - 2016-10-10 06:55 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-11-13 15:30 - 2016-10-10 06:55 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-11-13 15:30 - 2016-10-10 06:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-11-13 15:30 - 2016-10-10 06:54 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-11-13 15:30 - 2016-10-10 06:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-11-13 15:30 - 2016-10-07 07:40 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2016-11-13 15:30 - 2016-10-07 07:37 - 05547752 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2016-11-13 15:30 - 2016-10-07 07:37 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2016-11-13 15:30 - 2016-10-07 07:35 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 03649536 _____ (Microsoft Corporation) C:\Windows\system32\MSVidCtl.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00877056 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:32 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:18 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2016-11-13 15:30 - 2016-10-07 07:18 - 03944680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2016-11-13 15:30 - 2016-10-07 07:15 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 02291712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVidCtl.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00581632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:12 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 07:04 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2016-11-13 15:30 - 2016-10-07 07:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2016-11-13 15:30 - 2016-10-07 07:04 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2016-11-13 15:30 - 2016-10-07 07:01 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2016-11-13 15:30 - 2016-10-07 07:00 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2016-11-13 15:30 - 2016-10-07 06:56 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2016-11-13 15:30 - 2016-10-07 06:50 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2016-11-13 15:30 - 2016-10-07 06:50 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2016-11-13 15:30 - 2016-10-07 06:50 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2016-11-13 15:30 - 2016-10-07 06:50 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2016-11-13 15:30 - 2016-10-07 06:49 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 06:49 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 06:49 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2016-11-13 15:30 - 2016-10-07 06:49 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2016-11-13 15:30 - 2016-10-05 06:54 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\bowser.sys
2016-11-13 15:30 - 2016-09-15 06:56 - 00041984 _____ (Microsoft Corporation) C:\Windows\system32\UtcResources.dll
2016-11-13 15:30 - 2016-09-13 07:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-11-13 15:30 - 2016-09-13 07:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-11-13 15:30 - 2016-09-09 10:20 - 00756736 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2016-11-13 15:30 - 2016-09-09 10:00 - 00497152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2016-11-13 15:30 - 2016-08-22 08:19 - 01386496 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll
2016-11-09 07:29 - 2016-11-09 07:31 - 00870704 _____ C:\Windows\Minidump\110916-32822-01.dmp
2016-11-09 07:29 - 2016-11-09 07:29 - 654737022 _____ C:\Windows\MEMORY.DMP
2016-11-02 09:50 - 2016-11-02 09:50 - 00000063 _____ C:\Users\Bryan\Desktop\Terms of Use.url
2016-11-01 17:49 - 2016-11-01 17:49 - 00002864 _____ C:\Users\Ashanthe\Downloads\graph.pdf
2016-10-28 19:44 - 2016-10-28 19:44 - 00167296 _____ (Gibson Research Corp.) C:\Users\Bryan\Downloads\DNSBench.exe
2016-10-27 11:07 - 2016-10-27 11:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
2016-10-27 10:52 - 2016-10-27 10:52 - 00001926 _____ C:\Users\Public\Desktop\Avast Pro Antivirus.lnk
2016-10-27 10:52 - 2016-10-27 10:52 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2016-10-27 10:51 - 2016-10-27 10:51 - 00044952 _____ () C:\Windows\system32\Drivers\staport.sys
2016-10-27 10:50 - 2016-08-28 10:50 - 00391496 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2016-10-27 08:00 - 2016-10-27 08:00 - 06306112 _____ (AVAST Software) C:\Users\Bryan\Downloads\avast_pro_antivirus_setup_online.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2016-11-23 07:27 - 2016-05-08 14:47 - 00018944 ___SH C:\Users\Bryan\Thumbs.db
2016-11-23 07:23 - 2016-08-04 17:37 - 00000706 _____ C:\Windows\Tasks\WpsKtpcntrQingTask_Bryan.job
2016-11-23 06:59 - 2015-02-18 04:38 - 00000908 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA.job
2016-11-23 06:50 - 2016-07-28 14:45 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2016-11-23 06:49 - 2009-07-13 20:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-11-23 06:49 - 2009-07-13 20:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-11-23 06:42 - 2016-08-04 17:37 - 00000412 _____ C:\Windows\Tasks\WpsExternal_20160804183703.job
2016-11-23 06:33 - 2014-09-16 21:13 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2016-11-22 16:41 - 2016-07-28 14:45 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2016-11-22 16:39 - 2014-09-12 18:01 - 00000000 ____D C:\ProgramData\NVIDIA
2016-11-22 16:39 - 2009-07-13 21:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-11-22 16:38 - 2015-01-21 15:16 - 00000000 ____D C:\AdwCleaner
2016-11-22 16:03 - 2016-08-20 10:17 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\IObit
2016-11-22 15:59 - 2015-02-18 04:38 - 00000856 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001Core.job
2016-11-22 11:49 - 2016-07-30 09:39 - 00000000 ____D C:\ProgramData\panda_url_filtering
2016-11-22 10:26 - 2016-05-24 11:14 - 00000000 ____D C:\Users\Bryan\AppData\Local\CrashDumps
2016-11-22 07:13 - 2016-08-28 10:51 - 00004180 _____ C:\Windows\System32\Tasks\avast! Emergency Update
2016-11-19 19:51 - 2009-10-27 22:10 - 00000000 ____D C:\ProgramData\Google
2016-11-18 01:07 - 2009-07-13 21:13 - 00781790 _____ C:\Windows\system32\PerfStringBackup.INI
2016-11-18 01:07 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\inf
2016-11-15 06:23 - 2015-02-15 01:17 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2016-11-15 06:21 - 2015-02-15 01:15 - 00000000 ____D C:\Program Files\Microsoft Office 15
2016-11-14 14:52 - 2014-09-12 19:37 - 00002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-11-14 11:40 - 2009-07-13 19:20 - 00000000 ____D C:\Windows\rescache
2016-11-14 03:22 - 2016-07-31 05:06 - 00374816 _____ C:\Windows\system32\FNTCACHE.DAT
2016-11-11 03:16 - 2014-09-12 20:01 - 00000000 ____D C:\Windows\system32\MRT
2016-11-11 03:04 - 2014-09-12 20:01 - 141011376 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2016-11-09 07:33 - 2016-08-20 10:17 - 00000000 ____D C:\ProgramData\IObit
2016-11-09 07:29 - 2015-11-17 00:58 - 00000000 ____D C:\Windows\Minidump
2016-11-08 17:24 - 2015-07-11 09:04 - 00000000 ____D C:\Users\Ashanthe\AppData\Local\Google
2016-11-07 20:06 - 2015-07-26 15:33 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2016-11-01 17:46 - 2015-07-11 09:05 - 00085192 _____ C:\Users\Ashanthe\AppData\Local\GDIPFONTCACHEV1.DAT
2016-11-01 09:52 - 2016-08-28 13:38 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2016-10-28 18:16 - 2014-09-12 19:28 - 00000000 ____D C:\Users\Bryan\AppData\Local\Google
2016-10-27 11:07 - 2016-04-16 16:36 - 00000000 ____D C:\Program Files (x86)\7-Zip
2016-10-27 11:06 - 2015-07-16 02:52 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-10-27 11:06 - 2015-07-16 02:52 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-10-27 11:06 - 2015-07-16 02:52 - 00003770 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2016-10-27 11:06 - 2014-09-15 17:46 - 00000000 ____D C:\Windows\system32\Macromed
2016-10-27 11:06 - 2009-10-27 22:25 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2016-10-27 11:05 - 2014-09-13 10:28 - 00000000 ____D C:\Program Files\7-Zip
2016-10-27 11:03 - 2016-08-28 11:05 - 00003892 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1472411119
2016-10-27 10:51 - 2016-08-28 10:51 - 00969184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys
2016-10-27 10:51 - 2016-08-28 10:51 - 00513632 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys
2016-10-27 10:51 - 2016-08-28 10:51 - 00293352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2016-10-27 10:50 - 2016-08-28 10:51 - 00513496 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.147759427456810
2016-10-27 10:50 - 2016-08-28 10:51 - 00292704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.147759427419212
2016-10-27 10:49 - 2016-08-28 10:51 - 00969560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.147759427235107
 
==================== Files in the root of some directories =======
 
2016-08-28 13:52 - 2016-08-28 14:17 - 0000120 _____ () C:\Users\Bryan\AppData\Roaming\wklnhst.dat
2016-05-24 08:42 - 2016-05-24 08:42 - 0000017 _____ () C:\Users\Bryan\AppData\Local\resmon.resmoncfg
2016-01-11 22:28 - 2016-01-11 22:28 - 0986063 _____ () C:\Users\Bryan\AppData\Local\Zip-File-Opener_1706.rar
2015-01-02 21:38 - 2015-01-02 21:38 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-18 12:30 - 2015-12-18 12:38 - 0000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
 
Some files in TEMP:
====================
C:\Users\Bryan\AppData\Local\Temp\libeay32.dll
C:\Users\Bryan\AppData\Local\Temp\msvcr120.dll
C:\Users\Bryan\AppData\Local\Temp\safezone_installer_201610275131460.dll
C:\Users\Bryan\AppData\Local\Temp\sqlite3.dll
C:\Users\Bryan\AppData\Local\Temp\{87FE1528-560C-4FE1-A94F-B7E25C825A42}.exe
C:\Users\Zanthia\AppData\Local\Temp\avgnt.exe
 
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
 
LastRegBack: 2016-11-14 00:38
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-11-2016 01
Ran by [removed] (23-11-2016 07:32:49)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2014-09-13 02:47:10)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1069211171-1032678597-3133260682-500 - Administrator - Disabled)
Ashanthe (S-1-5-21-1069211171-1032678597-3133260682-1005 - Limited - Enabled) => C:\Users\Ashanthe
Bryan (S-1-5-21-1069211171-1032678597-3133260682-1001 - Administrator - Enabled) => C:\Users\Bryan
danbear11 (S-1-5-21-1069211171-1032678597-3133260682-1004 - Limited - Enabled) => C:\Users\danbear11
Guest (S-1-5-21-1069211171-1032678597-3133260682-501 - Limited - Enabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-1069211171-1032678597-3133260682-1002 - Limited - Enabled)
SophosSAUARTADI-PC0 (S-1-5-21-1069211171-1032678597-3133260682-1006 - Limited - Enabled)
Zanthia (S-1-5-21-1069211171-1032678597-3133260682-1003 - Administrator - Enabled) => C:\Users\Zanthia
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 16.01 (HKLM-x32\…\7-Zip) (Version: 16.01 - Igor Pavlov)
7-Zip 16.02 (x64) (HKLM\…\7-Zip) (Version: 16.02 - Igor Pavlov)
7-Zip 16.04 (HKLM-x32\…\{23170F69-40C1-2701-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
7-Zip 16.04 (x64 edition) (HKLM\…\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
Acer Assist (HKLM-x32\…\Acer Assist) (Version:  - Acer Incorporated)
Acer Backup Manager (HKLM-x32\…\InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}) (Version: 2.0.2.19 - NewTech Infosystems)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Acer Incorporated)
Acer Games (HKLM-x32\…\WildTangent acer Master Uninstall) (Version: 1.0.0.71 - WildTangent)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.02.3006 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\…\Acer Screensaver) (Version: 1.2.0812 - Acer Incorporated)
Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 23.0.0.257 - Adobe Systems Incorporated)
Adobe Flash Player 23 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Adobe Flash Player 23 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 23.0.0.185 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.17) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.17 - Adobe Systems Incorporated)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
Amazon Music (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Amazon Amazon Music) (Version: 3.8.1.754 - Amazon Services LLC)
Avast Pro Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)
Backup Manager Advance (x32 Version: 2.0.2.19 - NewTech Infosystems) Hidden
Box Sync (HKLM\…\{8706624B-B498-455D-9606-3130782C20B3}) (Version: 4.0.6621.0 - Box, Inc.)
Box Sync (x32 Version: 4.0.5253.0 - Box Inc.) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.15 - Piriform)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Core Temp 1.1 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.1 - Alcpu)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Defraggler (HKLM\…\Defraggler) (Version: 2.21 - Piriform)
Dropbox (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Dropbox) (Version: 3.16.1 - Dropbox, Inc.)
EaseUS Data Recovery Wizard 9.5 (HKLM\…\EaseUS Data Recovery Wizard 9.5_is1) (Version:  - EaseUS)
eSobi v2 (HKLM-x32\…\InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.4.000274 - esobi Inc.)
eSobi v2 (x32 Version: 2.0.4.000274 - esobi Inc.) Hidden
f.lux (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Flux) (Version:  - )
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 54.0.2840.99 - Google Inc.)
Google Earth Pro (HKLM-x32\…\{44FC61F0-2F8A-11E3-8CAE-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Photos Backup (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
HostsMan 4.1.96 (HKLM-x32\…\{1A3DD1A9-7B7B-4ECA-AD2F-98466F49F62C}_is1) (Version: 4.1.96.0 - abelhadigital.com)
Hotkey Utility (HKLM-x32\…\Hotkey Utility) (Version: 1.00.3004 - Acer Incorporated)
HP Dropbox Plugin (HKLM-x32\…\{23617173-F935-4C17-A323-EB1207F3ED49}) (Version: 36.0.31.53050 - Hewlett-Packard Co.)
HP ENVY 4510 series Basic Device Software (HKLM\…\{E9FE2E2C-FF62-4C23-B816-62B6EEA1A772}) (Version: 36.0.72.54013 - Hewlett-Packard Co.)
HP ENVY 4510 series Help (HKLM-x32\…\{CB5C9CB2-B471-42CC-93E6-D0E15021D5C2}) (Version: 36.0.0 - Hewlett Packard)
HP FWUpdateEDO2 (HKLM-x32\…\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Google Drive Plugin (HKLM-x32\…\{AFF80405-E56A-48E7-98FC-8E46E261949F}) (Version: 36.0.31.53050 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Support Solutions Framework (HKLM-x32\…\{A772EA32-AE5B-4474-BFC0-4C69C04AFF6A}) (Version: 12.4.18.7 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3002 - Acer Incorporated)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
Jarte (HKLM-x32\…\Jarte_is1) (Version: 5.4 - Carolina Road Software L.L.C.)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
LG United Mobile Driver (HKLM-x32\…\{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}) (Version: 3.12.3.0 - LG Electronics)
LGFlashTool 1.8.1.1023 (HKLM-x32\…\LGFlashTool) (Version: 1.8.1.1023 - LGE)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MediaFire Desktop (HKLM-x32\…\MediaFire Desktop 1.4.25.10813) (Version: 1.4.26.10815 - MediaFire)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\OneDriveSetup.exe) (Version: 17.3.6390.0509 - Microsoft Corporation)
Microsoft OneNote 2013 - en-us (HKLM\…\OneNoteFreeRetail - en-us) (Version: 15.0.4875.1001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\…\{E4A1FDA3-689D-44DA-9B39-86BD2270F522}) (Version: 11.2.5058.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\…\{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\…\{99AC7F47-A4E0-4706-9C65-8948775C2652}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Works (HKLM-x32\…\{67E03279-F703-408F-B4BF-46B5FC8D70CD}) (Version: 9.7.0621 - Microsoft Corporation)
MiniTool Partition Wizard Professional Edition 9.1 (HKLM\…\{69237D97-3063-450F-AE49-2357B191EA5D}_is1) (Version:  - MiniTool Solution Ltd.)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 38.0.5 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 38.0.5 (x86 en-US)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 38.0.5 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyWinLocker (HKLM-x32\…\{68301905-2DEA-41CE-A4D4-E8B443B099BA}) (Version: 3.1.76.0 - Egis Technology Inc.)
Nero 9 Essentials (HKLM-x32\…\{0b739e85-e796-499c-98fe-3be76860dfd0}) (Version:  - Nero AG)
Nmap 7.00 (HKLM-x32\…\Nmap) (Version:  - )
NVIDIA 3D Vision Controller Driver 340.50 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 341.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 341.44 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation)
NVIDIA ForceWare Network Access Manager (HKLM-x32\…\InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}) (Version:  - )
NVIDIA GeForce Experience 2.2.2 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)
NVIDIA Graphics Driver 341.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.44 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\…\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4875.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4875.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4875.1001 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\…\OpenAL) (Version:  - )
OpenDNS Updater 2.2.1 (HKLM-x32\…\OpenDNS Updater) (Version: 2.2.1 - )
Oracle VM VirtualBox 5.0.2 (HKLM\…\{6CB00039-29CC-42A1-8ED2-820821DA2B8A}) (Version: 5.0.2 - Oracle Corporation)
Paragon Backup and Recovery™ 16 (HKLM\…\{DADAA9CF-36B6-11E6-B0B5-005056C00008}) (Version: 10.28.101 - Paragon Software)
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9.140.248 - Google, Inc.)
PokerStars (HKLM-x32\…\PokerStars) (Version:  - PokerStars)
Product Improvement Study for HP ENVY 4510 series (HKLM\…\{CE8D3871-0B4C-45A8-8380-1F1BBD4AD33D}) (Version: 36.0.72.54013 - Hewlett-Packard Co.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5898 - Realtek Semiconductor Corp.)
Recuva (HKLM\…\Recuva) (Version: 1.52 - Piriform)
Revo Uninstaller 2.0.1 (HKLM\…\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.1 - VS Revo Group, Ltd.)
Revo Uninstaller Pro 3.1.7 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.7 - VS Revo Group, Ltd.)
SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden
Serif PanoramaPlus Starter Edition (HKLM-x32\…\{64AEB598-E518-4AD0-B02B-99F365B8054C}) (Version: 2.0.0.001 - Serif (Europe) Ltd)
SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden
System Requirements Lab Detection (HKLM-x32\…\{B9C5A961-B5D5-4F55-9E9E-006FE3A85227}) (Version: 2.2.1.0 - Husdawg, LLC)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Watermark Software 8.1 (HKLM-x32\…\Watermark Software) (Version: 8.1 - watermark-software.com)
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.00.3008 - Acer Incorporated)
Windows Driver Package - Hisense Corporation hsCDFiDrv CDROM  (07/12/2010 1.01.00) (HKLM\…\D6CCB3CCE9E8F1119A58ECAB8CE0B3B24A78942E) (Version: 07/12/2010 1.01.00 - Hisense Corporation)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2980 - CACE Technologies)
WinX DVD Copy Pro 3.6.5 (HKLM\…\WinX DVD Copy Pro_is1) (Version:  - Digiarty Software,Inc.)
WinX DVD Ripper Platinum 7.5.11 (HKLM-x32\…\WinX DVD Ripper Platinum_is1) (Version:  - Digiarty Software, Inc.)
WinX HD Video Converter Deluxe 5.6.2 (HKLM-x32\…\WinX HD Video Converter Deluxe_is1) (Version:  - Digiarty Software, Inc.)
Wireshark 2.0.1 (64-bit) (HKLM-x32\…\Wireshark) (Version: 2.0.1 - The Wireshark developer community, hxxps://www.wireshark.org)
WPS Office (10.1.0.5656) (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Kingsoft Office) (Version: 10.1.0.5656 - Kingsoft Corp.)
Zynewave Podium Free 3.2.1 (x64) (HKLM\…\{EFA46A5D-4ACD-4665-A074-1B7CF713A9BB}) (Version: 3.2.1 - Zynewave)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll ()
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll (Google Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {064EE1AB-DBC2-458B-AB6E-5384536BCF1D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-02-12] (Piriform Ltd)
Task: {0BD32A31-137B-4365-945B-BA45E90EC8D4} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-10-21] (Adobe Systems Incorporated)
Task: {0D30B4CF-2B59-4B0E-AFD1-8E7F32225BF5} - System32\Tasks\HPCustParticipation HP ENVY 4510 series => C:\Program Files\HP\HP ENVY 4510 series\Bin\HPCustPartic.exe [2015-03-09] (Hewlett-Packard Development Company, LP)
Task: {16C7614F-D73D-4768-9C12-E865A2B1D45B} - System32\Tasks\Acer\Acer Assist\New Message Check - Ashanthe => C:\Program Files (x86)\Acer\Acer Assist\AcerAssist.exe [2007-11-19] (Acer Incorporated)
Task: {29A91802-4F76-47C9-B845-647A97387C4A} - System32\Tasks\SafeZone scheduled Autoupdate 1472411119 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software)
Task: {2A84CF68-5A68-418E-9C27-DC135EC32E85} - System32\Tasks\googleupdatetaskmachinecore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {2BC2695E-8B0A-4AD2-AB6C-20EC1AD53AB7} - System32\Tasks\WpsKtpcntrQingTask_Bryan => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exe [2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {325D5EEC-A3D8-4FCE-92A8-417092DCF0A5} - System32\Tasks\WpsExternal_20160804183703 => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\ksolaunch.exe [2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {3C5FF15A-D333-4AE9-8AAD-A696E1ADDB0D} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-08-28] (AVAST Software)
Task: {3FE34152-9031-4426-AB0D-73A87CB472E3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-05-09] (Hewlett-Packard)
Task: {591201AC-6F77-4EE9-9330-4ADDC8F7D1E6} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-10-04] (Microsoft Corporation)
Task: {7330AB6F-E50C-47E3-BE07-62C22864CF88} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2016-08-28] (AVAST Software)
Task: {79C9FB33-975A-4580-9897-6E8615E55720} - System32\Tasks\{486A61CF-7BE3-4D52-81C7-6AE86E41C66E} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.3.73.105.457/en/abandoninstall?page=tsWLM
Task: {79E3E16F-73E3-4D37-B7DA-975698283354} - System32\Tasks\googleupdatetaskmachineua => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {885DF136-CC62-42EA-8722-CA0D7A03CB15} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2016-10-04] (Microsoft Corporation)
Task: {89A88E6B-9624-4C8F-9ABB-92125ED0B39A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-10-27] (Adobe Systems Incorporated)
Task: {9E5D32EE-277C-4623-810F-C69B3A0E5978} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {AA6D2334-BA38-4774-91D4-64A432DAE773} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001Core => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {B3CEDE53-F48D-4FF5-A3C0-8E94190DF8DC} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA => C:\Users\Bryan\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-14] (Dropbox, Inc.)
Task: {C6BFBECF-A713-4CBE-9CE3-36C96C805246} - System32\Tasks\Acer Registration Data Sending => C:\Program Files (x86)\Acer\Registration\GREG.exe [2009-08-28] (Acer Incorporated)
Task: {E0B01958-B00F-4779-A383-FDA5C239721E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-05-04] (Hewlett-Packard)
Task: {FDCCDC42-8A37-4C52-A163-A5AF0DEDCF96} - System32\Tasks\dropboxupdatetaskusers-1-5-21-1069211171-1032678597-3133260682-1001core => C:\Users\Bryan\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-14] (Dropbox, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001Core.job => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA.job => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\WpsExternal_20160804183703.job => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\ksolaunch.exe
Task: C:\Windows\Tasks\WpsKtpcntrQingTask_Bryan.job => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exeÃqing 10.1.0.5656 xxx server_url=hxxp:/kdl1.cache.wps.com/ksodl/wpscfg/client/____client____html____service____bubble.html ic_server_url=hxxp:/info.kingsoftstore.com/wpsv6internet/infos.ads
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Public\Desktop\Netflix.lnk -> C:\ProgramData\OEM_E471269A730D\Netflix\StartURL.exe () -> hxxp://homepage.acer.com/redirect.aspx?rid=09000001
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-02-15 01:15 - 2016-05-24 09:51 - 00116416 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2016-05-24 21:18 - 2016-05-24 21:27 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2009-04-19 07:34 - 2009-04-19 07:34 - 00625184 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
2009-04-19 07:34 - 2009-04-19 07:34 - 00070176 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll
2009-04-19 07:34 - 2009-04-19 07:34 - 00578080 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll
2009-04-19 07:34 - 2009-04-19 07:34 - 00207904 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
2016-05-21 13:12 - 2016-05-21 13:12 - 00959168 _____ () C:\Users\Bryan\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2016-07-24 02:24 - 2016-05-24 08:43 - 08909504 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2016-08-28 10:50 - 2016-08-28 10:50 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2016-11-22 13:39 - 2016-11-22 13:39 - 03129808 _____ () C:\Program Files\AVAST Software\Avast\defs\16112201\algo.dll
2016-08-28 10:50 - 2016-08-28 10:50 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-11-23 06:43 - 2016-11-23 06:43 - 03134984 _____ () C:\Program Files\AVAST Software\Avast\defs\16112300\algo.dll
2009-02-02 16:33 - 2009-02-02 16:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2008-09-28 16:55 - 2008-09-28 16:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
2016-08-28 10:50 - 2016-08-28 10:50 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com
 
There are 7865 more sites.
 
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\facebook.com -> hxxps://staticxx.facebook.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\facebook.net -> hxxps://connect.facebook.net
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\fbcdn.net -> hxxps://static.xx.fbcdn.net
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\google-analytics.com -> hxxps://www.google-analytics.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\hosts -> hxxps://hosts
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\paragon-software.com -> hxxps://bo4-fe.paragon-software.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\pch.com -> hxxps://pch.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\pga.com -> hxxps://pga.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123simsen.com -> www.123simsen.com
 
There are 7865 more sites.
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 18:34 - 2016-09-05 20:15 - 00948898 ____R C:\Windows\system32\Drivers\etc\hosts
 
127.0.0.1 www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1 www.008k.com
127.0.0.1 008k.com
127.0.0.1 www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1 www.032439.com
127.0.0.1 032439.com
127.0.0.1 www.0scan.com
127.0.0.1 0scan.com
127.0.0.1 1000gratisproben.com
127.0.0.1 www.1000gratisproben.com
127.0.0.1 1001namen.com
127.0.0.1 www.1001namen.com
127.0.0.1 100888290cs.com
127.0.0.1 www.100888290cs.com
127.0.0.1 www.100sexlinks.com
127.0.0.1 100sexlinks.com
127.0.0.1 10sek.com
127.0.0.1 www.10sek.com
127.0.0.1 www.1-2005-search.com
127.0.0.1 1-2005-search.com
127.0.0.1 123fporn.info
127.0.0.1 www.123fporn.info
127.0.0.1 123haustiereundmehr.com
127.0.0.1 www.123haustiereundmehr.com
127.0.0.1 123moviedownload.com
127.0.0.1 www.123moviedownload.com
 
There are 27258 more lines.
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is disabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: AdobeARMservice => 3
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{8C3230A9-3B37-4AB0-BF07-F92E56E6D000}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [UDP Query User{C5ECB86D-D992-4133-85A8-E2375ADBE977}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [{C1131851-AE0D-47EC-985D-3B54FFB37410}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A2186EEF-31C0-4771-8F5C-20057A62313F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{1F0A2EEF-2338-4C46-B282-735BCF6E757B}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [UDP Query User{EEF57E84-7427-4683-9F0A-911AF23E417E}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [TCP Query User{022FA091-367D-4079-A8A2-ED2592DD7D24}C:\program files (x86)\frostwire\frostwire.exe] => (Block) C:\program files (x86)\frostwire\frostwire.exe
FirewallRules: [UDP Query User{09F60FA5-71A9-473F-8B6A-E4D4253CEA95}C:\program files (x86)\frostwire\frostwire.exe] => (Block) C:\program files (x86)\frostwire\frostwire.exe
FirewallRules: [{B3DA051D-830C-4383-97B3-86C0DDE059B8}] => (Allow) C:\Users\Bryan\Downloads\solutoinstaller.exe
FirewallRules: [{012249DF-E899-4E68-ADA6-4099377F6DD7}] => (Allow) C:\Users\Bryan\Downloads\solutoinstaller.exe
FirewallRules: [{044001A0-E716-4D0D-81B1-70E9FD015F95}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9283772B-511B-4821-B133-BED4BF4AB2AC}] => (Allow) LPort=2869
FirewallRules: [{DCDC16A6-6A0C-4C05-AA19-AFE390FD2405}] => (Allow) LPort=1900
FirewallRules: [{2260B718-D95B-4B4D-95FA-609C9FBB7636}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{695FD75E-C711-464D-BAB3-B87FFB5CB693}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{39F77321-AFFB-49F6-9E20-BB09C6108758}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{5FE532DA-7DCE-4498-B1D7-2EA7839AA5AE}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{8C3A945E-2263-4351-957B-7DB970A38D0C}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{A7F95135-CCD5-473A-839D-E4F426AB21F8}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS09EB\HP.EasyStart.exe
FirewallRules: [{984BB3F6-E964-4B8E-9BA2-E6A1510F0A5E}] => (Allow) C:\Program Files\HP\HP ENVY 4510 series\Bin\DeviceSetup.exe
FirewallRules: [{3BDD8F22-9012-4F6D-9C1A-BED6890F1F1F}] => (Allow) LPort=5357
FirewallRules: [{C7ED9287-EAE5-4029-85CD-CBC94782DC03}] => (Allow) C:\Program Files\HP\HP ENVY 4510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{57ED47F0-4F49-456A-929B-2E775595F985}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2E65\HPDiagnosticCoreUI.exe
FirewallRules: [{539324E4-FE1E-4767-8DC0-C08D87D50E71}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2E65\HPDiagnosticCoreUI.exe
FirewallRules: [{D51CA84B-F225-4D3E-98D5-0E86499BA40A}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2EAD\HPDiagnosticCoreUI.exe
FirewallRules: [{574DA190-38B0-4004-BBAC-4C39E5F47175}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2EAD\HPDiagnosticCoreUI.exe
FirewallRules: [{A00F1B2E-031B-480F-AE27-B72AF2D5E08A}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
FirewallRules: [{AEF819C4-15BE-4827-A80D-FEFD9DAD7A9A}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
FirewallRules: [{65ABF914-9DF7-4667-940A-D38951B87F6C}] => (Allow) C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{57E388FA-A5E9-44F8-8988-CF70A5ECAF01}] => (Allow) C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{F2301F04-2268-4612-B640-411F080B6C2A}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS5761\HPDiagnosticCoreUI.exe
FirewallRules: [{BA79D814-7ED2-49B5-ACE1-BF9408D60E3A}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS5761\HPDiagnosticCoreUI.exe
FirewallRules: [{40DE9545-9D62-4219-8336-F7C9D640F5AE}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS6D1A\HPDiagnosticCoreUI.exe
FirewallRules: [{57991DE4-5A64-4175-AB5C-8C993868D41E}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS6D1A\HPDiagnosticCoreUI.exe
FirewallRules: [{610620A6-A213-4C59-AA61-47EDA9D1CC90}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS57A1\HPDiagnosticCoreUI.exe
FirewallRules: [{EBE92228-91A5-4A53-8D86-A7EF6CD77ED4}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS57A1\HPDiagnosticCoreUI.exe
FirewallRules: [{677AB390-0B4C-4ED8-9ADB-8A1E7BAD8891}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
02-11-2016 15:17:13 Removed HP ENVY 4510 series Basic Device Software
11-11-2016 03:01:23 Windows Update
14-11-2016 03:00:13 Windows Update
22-11-2016 16:54:19 JRT Pre-Junkware Removal
23-11-2016 06:41:40 Revo Uninstaller's restore point - EasyDuplicateFinder v4.7
23-11-2016 06:44:54 Revo Uninstaller's restore point - Duplicate File Finder
 
==================== Faulty Device Manager Devices =============
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (11/22/2016 11:54:24 PM) (Source: MsiInstaller) (EventID: 1024) (User: Artadi-PC)
Description: Product: Adobe Reader XI (11.0.18) - Update 'Adobe Reader XI (11.0.18)' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
 
Error: (11/22/2016 11:54:23 PM) (Source: MsiInstaller) (EventID: 11311) (User: Artadi-PC)
Description: Product: Adobe Reader XI (11.0.18) – Error 1311.Source file not found(cabinet): C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AB0000000001}\Data1.cab.  Verify that the file exists and that you can access it.
 
Error: (11/22/2016 04:42:11 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (3268) WebCacheLocal: An attempt to open the file "C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.chk" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (11/22/2016 10:26:07 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: aswMBR.exe, version: 1.0.1.2252, time stamp: 0x5465ba64
Faulting module name: ntdll.dll, version: 6.1.7601.23569, time stamp: 0x57f7bb79
Exception code: 0xc0000005
Fault offset: 0x0002e43e
Faulting process id: 0x1370
Faulting application start time: 0x01d244eda90b3a88
Faulting application path: C:\Users\Bryan\Desktop\aswMBR.exe
Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report Id: 2209f578-b0e1-11e6-b836-00262d289fc4
 
Error: (11/22/2016 10:16:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: aswMBR.exe, version: 1.0.1.2252, time stamp: 0x5465ba64
Faulting module name: ntdll.dll, version: 6.1.7601.23569, time stamp: 0x57f7bb79
Exception code: 0xc0000005
Fault offset: 0x0002e43e
Faulting process id: 0x1b28
Faulting application start time: 0x01d244ec4ffaa678
Faulting application path: C:\Users\Bryan\Desktop\aswMBR.exe
Faulting module path: C:\Windows\SysWOW64\ntdll.dll
Report Id: db81bc18-b0df-11e6-b836-00262d289fc4
 
Error: (11/20/2016 01:02:01 PM) (Source: ESENT) (EventID: 490) (User: )
Description: taskhost (2768) WebCacheLocal: An attempt to open the file "C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.chk" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (11/20/2016 12:06:28 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (11/20/2016 07:56:25 AM) (Source: ESENT) (EventID: 439) (User: )
Description: Windows (3820) Windows: Unable to write a shadowed header for file C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk. Error -1032.
 
Error: (11/20/2016 07:56:25 AM) (Source: ESENT) (EventID: 490) (User: )
Description: Windows (3820) Windows: An attempt to open the file "C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS.chk" for read / write access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ".  The open file operation will fail with error -1032 (0xfffffbf8).
 
Error: (11/18/2016 02:31:34 PM) (Source: MsiInstaller) (EventID: 1024) (User: Artadi-PC)
Description: Product: Adobe Reader XI (11.0.18) - Update 'Adobe Reader XI (11.0.18)' could not be installed. Error code 1603. Windows Installer can create logs to help troubleshoot issues with installing software packages. Use the following link for instructions on turning on logging support: http://go.microsoft.com/fwlink/?LinkId=23127
 
 
System errors:
=============
Error: (11/22/2016 04:55:16 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NVIDIA Display Driver Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (11/22/2016 04:42:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Media Player Network Sharing Service service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (11/22/2016 04:42:16 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Media Player Network Sharing Service service to connect.
 
Error: (11/22/2016 04:40:55 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
eorclc
 
Error: (11/22/2016 04:40:04 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NetDrive2_Service_NetDrive2 service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (11/22/2016 04:38:18 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
An instance of the service is already running.
 
Error: (11/22/2016 04:37:49 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (11/22/2016 04:37:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (11/22/2016 04:37:48 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The ForceWare IP service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (11/22/2016 04:37:48 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The ForceWare Intelligent Application Manager (IAM) service terminated unexpectedly.  It has done this 1 time(s).
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ II X2 215 Processor 
Percentage of memory in use: 40%
Total physical RAM: 3838.55 MB
Available physical RAM: 2298.8 MB
Total Virtual: 7675.29 MB
Available Virtual: 6093 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:698.63 GB) (Free:609.2 GB) NTFS ==>[drive with boot components (obtained from BCD)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 698.6 GB) (Disk ID: 6E286E28)
Partition 1: (Active) - (Size=698.6 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 
 

I am going to work you up a quick fix with FRST, but before I do let me know about these

 

Zhuhai Kingsoft Office  <– Do you use this along with Microsoft Office ? The reason I am asking is that there both running as a task and using system resources

 

Panda  <– Did you get rid of this one

 

Frostwire <– Are you sure you want to keep this one. I would not allow File Sharing in any form on any of my PCs

I ran Revo and could not find panda, which I had uninstalled when you asked me to along with Frostwire, neither one shows up on a search in Revo. Are both still showing in the FRST scan? As to the office programs, I rarely use them, I use Jarta when I need to write anything, actually its my grand daughter who uses it much more than me. So please let me know how to get rid of Frostwire and Panda if they are indeed hiding somewhere in the system.

Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 
 
Post the FIXLOG and let me know how your system is behaving now ??

heres the fixlog

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 23-11-2016
Ran by [removed] (23-11-2016 13:47:09) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
CMD: ipconfig /flushdns
Hosts:
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => value restored successfully
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => key removed successfully
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Could not flush the DNS Resolver Cache: Function failed during execution.
 
 
========= End of CMD: =========
 
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 17207490 B
Java, Flash, Steam htmlcache => 336097304 B
Windows/system/drivers => 213926904 B
Edge => 0 B
Chrome => 722703911 B
Firefox => 3663473 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 66228 B
Public => 0 B
ProgramData => 0 B
systemprofile => 56325731 B
systemprofile32 => 7113917 B
LocalService => 132244 B
NetworkService => 4646772 B
Bryan => 266709528 B
Zanthia => 30046324 B
danbear11 => 5503768 B
Ashanthe => 22620454 B
Guest => 3187559 B
 
RecycleBin => 14179879 B
EmptyTemp: => 1.6 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 13:48:40 ====

It is much more responsive, and so far I haven't had it lock up on me. I want to Thank You for the help you've given. If there are any more instructions please let me know.

Glad things are better.  You may want to think about upgrading Malwarebytes to the Premium version, it has a Protection Module that blocks known bad websites , the cost is minimall but this is entirely up to you

 

https://support.malwarebytes.com/customer/portal/articles/1835309-what-s-the-difference-between-the-malwarebytes-anti-malware-free-and-premium-?b_id=6438

 

 

 

Double click on AdwCleaner.exe to run the tool again.
  •  
  • Click on the Uninstall button.
  • Click Yes when asked are you sure you want to uninstall.
  • Both AdwCleaner.exe, its folder and all logs will be removed.
 
 
 
==========================================================
 
 
Open up Malwarebytes
  •  
  • On the Dashboard…click on History
  • Then click on Quarantine
  • Make everything is checked
  • Then click on Delete All
  • Close out Malwarebytes
 
 
 
==========================================================
 
 
Please download DelFix and save the file to your Desktop.
 
[external image: DelFix_zps139e2ea1.jpg]
 
  •  
  • Windows XP Double Click DelFix.exe to run the program. 
  • Windows Vista > Win 7 > Win 8 Right Click on DelFix.exe and select RUN AS ADMINISTRATOR 
  • Checkmark " Remove Disinfection Tools"
  • Click the Run button
 
 
This will remove the specialised tools we used to clean your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually
 
 
 
 
So How did I get infected in the first place <– Some reading for you to keep yourself safe online
 
 
Safe Surfn
Ken
 
 
 
 
 
 
 
 
 
 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI