I was unable to get the Farbar scan to complete - I tried three times and each time it froze, even after rebooting. Other programs like Word are beginning to freeze now, too. I'm providing the other logs, though.
Thanks!
—
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-01-2017
Ran by [removed] (administrator) on DYKES-FAMILY-PC (01-02-2017 21:14:56)
Running from C:\Users\[removed]\Downloads\Security-Malware Protection
[removed]
Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel) C:\Program Files (x86)\Intel\AMT\LMS.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\AMT\atchksrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel) C:\Program Files (x86)\Intel\AMT\UNS.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\AMT\atchk.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater Beta\ksu.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avBugReport.exe
(Farbar) C:\Users\Dykes-family\Downloads\Security-Malware Protection\Farbar-scan-tool.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [atchk] => C:\Program Files (x86)\Intel\AMT\atchk.exe [401408 2009-12-01] (Intel Corporation)
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-12-06] (Apple Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-11-15] (AVAST Software)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.)
HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-11-12] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4517376 2014-11-11] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [1939968 2014-10-22] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation)
HKLM-x32\…\Run: [PowerDVD16Agent] => C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD16Agent.exe [525352 2016-05-13] (CyberLink Corp.)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2900560 2015-10-08] (Valve Corporation)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [Google Update] => C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-16] (Google Inc.)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [Creative WebCam Tray] => C:\Program Files (x86)\Creative\Shared Files\CamTray.exe [299008 2005-10-27] (Creative Technology Ltd)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [GoogleDriveSync] => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [Icecream_Screen_Recorder_Prefetcher] => C:\Program Files (x86)\Icecream Screen Recorder\recorder.exe [3472384 2016-03-24] (Icecream)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29547136 2016-08-17] (Skype Technologies S.A.)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [KSS] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe [1556448 2015-12-15] (AO Kaspersky Lab)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\MountPoints2: {a1f26f5a-790d-11e4-add0-001e4fddf430} - "E:\VZW_Software_upgrade_assistant.exe"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\MountPoints2: {dc7331a9-49d6-11e6-9c12-001e4fddf430} - "E:\VerizonWirelessUpgradeAssistantSetup.exe" -a
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\MountPoints2: {dc73324a-49d6-11e6-9c12-001e4fddf430} - "E:\VerizonWirelessUpgradeAssistantSetup.exe" -a
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-09-26] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2016-09-07]
ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (WinZip Computing, S.L.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Kaspersky Software Updater Beta.lnk [2016-12-27]
ShortcutTarget: Kaspersky Software Updater Beta.lnk -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater Beta\ksu.exe (AO Kaspersky Lab)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Notifier.lnk [2016-09-07]
ShortcutTarget: Update Notifier.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (WinZip Computing, S.L.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2016-09-07]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{57d1d93b-eaf8-4091-a16e-59282cb5cfc4}: [DhcpNameServer] [removed] [removed]
Internet Explorer:
==================
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-05-13] (RealDownloader)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-04-25] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-25] (Oracle Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2014-12-16] (Adblock Plus)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-05-13] (RealDownloader)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-25] (Oracle Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-25] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2014-12-16] (Adblock Plus)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
FireFox:
========
FF ProfilePath: C:\Users\Dykes-family\AppData\Roaming\Mozilla\Firefox\Profiles\i12gxvos.default [2017-02-01]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\i12gxvos.default -> Google
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\i12gxvos.default -> Google
FF Homepage: Mozilla\Firefox\Profiles\i12gxvos.default -> www.google.com
FF Extension: (LastPass) - C:\Users\Dykes-family\AppData\Roaming\Mozilla\Firefox\Profiles\i12gxvos.default\Extensions\[removed] [2017-01-11]
FF Extension: (Flashblock) - C:\Users\Dykes-family\AppData\Roaming\Mozilla\Firefox\Profiles\i12gxvos.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2016-01-01]
FF Extension: (Adblock Plus) - C:\Users\Dykes-family\AppData\Roaming\Mozilla\Firefox\Profiles\i12gxvos.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23]
FF Extension: (Bitdefender QuickScan) - C:\Users\Dykes-family\AppData\Roaming\Mozilla\Firefox\Profiles\i12gxvos.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2016-12-11]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-26]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-09-26]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\…\Firefox\Extensions: [{7ADCCCD0-FDEC-4A18-A329-550A87710223}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-06-02] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-11-18] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-10] ()
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1217157.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-25] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=17.0.10.8 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2014-06-02] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=17.0.10 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2014-05-13] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.10 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-05-13] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=17.0.10 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2014-05-13] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.10.8 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2014-06-02] (RealPlayer Cloud)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-01-17] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @nsroblox.roblox.com/launcher -> C:\Users\Dykes-family\AppData\Local\Roblox\Versions\version-ecedadb4b6824712\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\Dykes-family\AppData\Local\Roblox\Versions\version-ecedadb4b6824712\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Dykes-family\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @talk.google.com/O1DPlugin -> C:\Users\Dykes-family\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Dykes-family\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-27] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2014-03-20] (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Dykes-family\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Dykes-family\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)
Chrome:
=======
CHR DefaultProfile: Default
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\pdf.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\gcswf32.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll => No File
CHR Profile: C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default [2017-01-25]
CHR Extension: (YouTube) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-23]
CHR Extension: (Adobe Acrobat) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-25]
CHR Extension: (Avast SafePrice) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-12-23]
CHR Extension: (RealPlayer Downloader) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2016-04-02]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2016-12-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-25]
CHR Extension: (Gmail) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-02]
CHR Extension: (Chrome Media Router) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-23]
CHR HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\DYKES-~1\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-01-2017
Ran by [removed] (01-02-2017 21:17:18)
Running from C:\Users\[removed]\Downloads\Security-Malware Protection
Windows 10 Pro Version 1511 (X64) (2015-12-06 09:35:37)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3670747094-3822527020-2124027705-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3670747094-3822527020-2124027705-503 - Limited - Disabled)
Dykes-family (S-1-5-21-3670747094-3822527020-2124027705-1001 - Administrator - Enabled) => C:\Users\Dykes-family
Guest (S-1-5-21-3670747094-3822527020-2124027705-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3670747094-3822527020-2124027705-1002 - Limited - Enabled)
legen (S-1-5-21-3670747094-3822527020-2124027705-1004 - Limited - Enabled) => C:\Users\legen
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adblock Plus for IE (32-bit and 64-bit) (HKLM\…\{C5D8EEB2-EDBC-4375-829D-BE50547C8890}) (Version: 1.3 - Eyeo GmbH)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20056 - Adobe Systems Incorporated)
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\…\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.16 - Adobe Systems)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 16.0.0.273 - Adobe Systems Incorporated)
Adobe Creative Suite 6 Master Collection (HKLM-x32\…\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.)
Adobe Widget Browser (HKLM-x32\…\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
Adobe® Content Viewer (HKLM-x32\…\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated)
AKVIS Retoucher (HKLM-x32\…\{D77DBB31-D3EB-4405-8785-488CA60ECE46}) (Version: 3.5 - AKVIS Software Inc)
Apple Application Support (32-bit) (HKLM-x32\…\{D079CAAD-0C31-47A2-9AF5-A82F9CD9B221}) (Version: 5.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{64E6007B-1DA9-42CD-BBE4-D5FA67A7C71D}) (Version: 5.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
AppLogLibSetup (x32 Version: 1.0.1.0 - Brother Industries Ltd.) Hidden
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)
AviSynth 2.5 (HKLM-x32\…\AviSynth) (Version: - )
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
BrLauncher (x32 Version: 1.1.6.0 - Brother Industries Ltd.) Hidden
BrLogRx (x32 Version: 1.0.1.1 - Brother Industries Ltd.) Hidden
Brother PCFax Driver (x32 Version: 1.4.0.0 - Brother Industries Ltd.) Hidden
Brother Port Driver (x32 Version: 1.0.11.11 - Brother Industries Ltd.) Hidden
Brother Printer Driver (x32 Version: 1.5.0.0 - Brother Industries Ltd.) Hidden
Brother Scanner Driver (x32 Version: 1.0.15.10 - Brother Industries Ltd.) Hidden
BrotherHelpInstaller (x32 Version: 1.0.0.0 - Brother) Hidden
BrSupportTools (x32 Version: 1.0.9.0 - Brother Industries Ltd.) Hidden
Canon CanoScan LiDE 110 User Registration (HKLM-x32\…\Canon CanoScan LiDE 110 User Registration) (Version: - )
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\…\CANONIJPLM100) (Version: - )
Canon MP Navigator EX 4.0 (HKLM-x32\…\MP Navigator EX 4.0) (Version: - )
Canon Solution Menu EX (HKLM-x32\…\CanonSolutionMenuEX) (Version: - )
CanoScan LiDE 110 Scanner Driver (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_cnq2414) (Version: - Canon Inc.)
Cisco Configuration Professional (HKLM-x32\…\{29342492-9F4F-4089-866A-10D801B610FD}) (Version: 2.5 - Cisco Systems)
Clone2Go Video Converter Free Version 1.7.7 (HKLM-x32\…\Clone2Go Video Converter Free Version_is1) (Version: - Clone2Go.com)
Cobalt (HKLM-x32\…\Cobalt) (Version: - )
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
ControlCenter4 (x32 Version: 4.2.435.1 - Brother Insutries Ltd.) Hidden
ControlCenter4 CSDK (x32 Version: 4.2.3.1 - Brother Insutries Ltd.) Hidden
Coupon Printer for Windows (HKLM-x32\…\Coupon Printer for Windows5.0.0.9) (Version: 5.0.0.9 - Coupons.com Incorporated)
Creative WebCam Center (HKLM-x32\…\Creative WebCam Center) (Version: - )
CyberLink PowerDVD 16 (HKLM-x32\…\{7CD1ACC0-3DD0-4894-90C7-BF2A136C074D}) (Version: 16.0.1713.60 - CyberLink Corp.)
DeviceDetect (x32 Version: 1.0.3.3 - Brother Industries Ltd.) Hidden
Disney Infinity PC (HKLM-x32\…\{11CB229E-8A2B-40FD-8670-4EC92D3DDAD5}) (Version: 1.85.4161 - Disney Interactive)
ExtractNow (HKLM-x32\…\ExtractNow_is1) (Version: - Nathan Moinvaziri)
EZ CD Audio Converter (HKLM-x32\…\EZ CD Audio Converter) (Version: 2.4 - Poikosoft)
FileZilla Client 3.23.0.2 (HKLM-x32\…\FileZilla Client) (Version: 3.23.0.2 - Tim Kosse)
Free Video to DVD Converter version 5.0.56.128 (HKLM-x32\…\Free Video to DVD Converter_is1) (Version: 5.0.56.128 - DVDVideoSoft Ltd.)
Freemake Audio Converter version 1.1.4 (HKLM-x32\…\Freemake Audio Converter_is1) (Version: 1.1.4 - Ellora Assets Corporation)
Freemake Video Converter version 4.1.5 (HKLM-x32\…\Freemake Video Converter_is1) (Version: 4.1.5 - Ellora Assets Corporation)
FreeRIP MP3 Converter 4.7.0 (HKLM-x32\…\{501451DE-5808-4599-B544-8BD0915B6B24}_is1) (Version: 4.7.0 - GreenTree Applications SRL)
GNS3-ER 1.0-beta1 (HKLM-x32\…\GNS3-ER) (Version: 1.0-beta1 - )
GOM Player (HKLM-x32\…\GOM Player) (Version: 2.2.57.5189 - Gretech Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
Google Talk Plugin (HKLM-x32\…\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
HandBrake 0.10.0 (HKLM-x32\…\HandBrake) (Version: 0.10.0 - )
HowToGuide (x32 Version: 1.0.1.0 - Brother Industries Ltd.) Hidden
HP Photosmart 6510 series Basic Device Software (HKLM\…\{1952AED6-2908-418F-B9D8-AC359651F92D}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Support Solutions Framework (HKLM-x32\…\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.5.32.203 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Icecream Screen Recorder version 3.61 (HKLM-x32\…\{7ADEC622-3230-4C9A-9DCE-9BD462B74095}_is1) (Version: 3.61 - Icecream Apps)
Intel Driver Update Utility (HKLM-x32\…\{ca4bc3a8-b99c-4416-90d8-351a8ceab458}) (Version: 2.2.0.2 - Intel)
Intel(R) Driver Update Utility 2.2 (x32 Version: 2.2.0.1 - Intel) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
Intel(R) Management Engine Interface (HKLM\…\HECI) (Version: - Intel Corporation)
Intel® Active Management Technology (HKLM\…\MESOL) (Version: - Intel Corporation)
iTunes (HKLM\…\{81C96689-EA5B-4B7D-A04F-16326EC51BC2}) (Version: 12.5.4.42 - Apple Inc.)
Java 8 Update 91 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.14 - Oracle Corporation)
Java 8 Update 91 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation)
Java SE Development Kit 8 Update 51 (64-bit) (HKLM\…\{64A3A4F4-B792-11D6-A78A-00B0D0180510}) (Version: 8.0.510.16 - Oracle Corporation)
Kaspersky Security Scan (HKLM-x32\…\InstallWIX_{D1282694-0693-41A8-ABC1-6D1FFC1F65C5}) (Version: 16.0.0.1344 - Kaspersky Lab)
Kaspersky Security Scan (x32 Version: 16.0.0.1344 - Kaspersky Lab) Hidden
Kaspersky Software Updater Beta (HKLM-x32\…\InstallWIX_{94C8D443-1D07-4E6D-A9EB-FDBA45A839D8}) (Version: 1.5.2.228 - Kaspersky Lab)
Kaspersky Software Updater Beta (x32 Version: 1.5.2.228 - Kaspersky Lab) Hidden
K-Lite Codec Pack 9.2.0 (Basic) (HKLM-x32\…\KLiteCodecPack_is1) (Version: 9.2.0 - )
LEGO Digital Designer (HKLM-x32\…\New LEGO Digital Designer) (Version: - LEGO A/S)
LEGO MINDSTORMS NXT - English Language Pack (HKLM-x32\…\{53753510-7620-4D2B-9C0B-111F871615D9}) (Version: 2.0.100.0 - The LEGO Group)
LEGO MINDSTORMS NXT Driver for x64 (HKLM\…\{74E85F31-573F-45BF-8939-4D2BCDCC2083}) (Version: 1.17.770 - LEGO)
LEGO MINDSTORMS NXT Migration Package (HKLM-x32\…\{6C1D47CC-682C-4673-8CA8-DEE659628599}) (Version: 1.2.8.0 - LEGO)
LEGO MINDSTORMS NXT Software v2.0 (HKLM-x32\…\{CB263F8D-EF2D-4EB5-A368-A27056EE92D4}) (Version: 2.0.108.0 - LEGO)
LEGO Minifigures Online (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\423b93224c69643b) (Version: 1.0.0.0 - Funcom)
MakeMKV v1.8.10 (HKLM-x32\…\MakeMKV) (Version: v1.8.10 - GuinpinSoft inc)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Media Foundation FLAC Codec (HKLM-x32\…\{5B47D5CC-38D3-4853-9A9E-AD1C7C717D40}) (Version: 1.4.1.0 - Alexander Demidov)
Microcular (HKLM-x32\…\InstallShield_{2CBD0ADE-0EB2-491A-BDF8-17A738CFE264}) (Version: 0.1.3.5.0 - PC Camera)
Microcular (x32 Version: 0.1.3.5.0 - PC Camera) Hidden
Microsoft Office XP Standard for Students and Teachers (HKLM-x32\…\{913D0409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\…\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Minecraft (HKLM-x32\…\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Motorola Mobile Drivers Installation 6.4.0 (HKLM\…\{27986EDD-C9EC-4B52-B92F-06D073F0AA52}) (Version: 6.4.0 - Motorola Mobility LLC)
Movavi Video Converter 15 (HKLM-x32\…\Movavi Video Converter 15) (Version: 15.3.0 - Movavi)
Mozilla Firefox 51.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 51.0.1 (x86 en-US)) (Version: 51.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 51.0.1.6234 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
NetworkRepairTool (x32 Version: 1.2.11.0 - Brother Insutries Ltd.) Hidden
Next Video Converter version 4.0.3 (HKLM-x32\…\{752EC6FD-1CEB-409B-AEF5-A297943102EA}_is1) (Version: 4.0.3 - NextVideoSoft Inc.)
Open Broadcaster Software (HKLM-x32\…\Open Broadcaster Software) (Version: - )
OpenAL (HKLM-x32\…\OpenAL) (Version: - )
OpenOffice.org 3.4 (HKLM-x32\…\{51071D66-D034-4239-94E0-723FCA10B6FE}) (Version: 3.4.9590 - OpenOffice.org)
Origin (HKLM-x32\…\Origin) (Version: 9.10.1.1501 - Electronic Arts, Inc.)
PC-FAXReceive (x32 Version: 1.3.5 - Brother) Hidden
PCFaxTx (x32 Version: 1.0.4.5 - Brother Industries Ltd.) Hidden
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
PhoneTrans 3.8.0 (HKLM-x32\…\{F0B50B3A-0C1F-43D8-BE90-70241B473114}}_is1) (Version: 3.8.0 - iMobie Inc.)
Pirate101 (HKLM-x32\…\{662140BE-138C-4DC1-B4CD-B62C6C855A25}) (Version: 1.0.0 - KingsIsle Entertainment, Inc.)
Pokémon Trading Card Game Online (HKLM-x32\…\{0D9304CD-1C83-4703-AFEF-0C46D1DB21F2}) (Version: 2.27.0 - The Pokémon Company International)
PrimoPDF – brought to you by Nitro PDF Software (HKLM-x32\…\PrimoPDF) (Version: 5 - Nitro PDF Software)
QuickTime (HKLM-x32\…\{0E64B098-8018-4256-BA23-C316A43AD9B0}) (Version: 7.72.80.56 - Apple Inc.)
RealDownloader (x32 Version: 17.0.10 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\…\RealPlayer 17.0) (Version: 17.0.10 - RealNetworks)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
RemoteSetup (x32 Version: 3.8.0.0 - Brother Industries Ltd.) Hidden
ROBLOX Player for Dykes-family (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - ROBLOX Corporation)
ROBLOX Studio for Dykes-family (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version: - ROBLOX Corporation)
SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden
ScannerUtilityInstaller (x32 Version: 1.0.0.0 - Brother) Hidden
Scrolls (HKLM-x32\…\{F7F74F7F-C458-4B7C-A6F4-80A28ED7AF0B}) (Version: 1.0.2.0 - Mojang)
SimCity™ (HKLM-x32\…\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
Skype™ 7.27 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.27.101 - Skype Technologies S.A.)
Snagit 12 (HKLM-x32\…\{8f4df1fe-49bb-4295-99d2-0e29ad8f99c6}) (Version: 12.2.0.1656 - TechSmith Corporation)
Snagit 12 (x32 Version: 12.2.0 - TechSmith Corporation) Hidden
SolarWinds Response Time Viewer (HKLM-x32\…\{5B415E10-D1C1-4E54-9061-AE0FB3D7F2B2}) (Version: 1.0.0.162 - SolarWinds)
Speccy (HKLM\…\Speccy) (Version: 1.30 - Piriform)
StatusMonitor (x32 Version: 1.12.4.0 - Brother Insutries Ltd.) Hidden
Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
Swivel (HKLM-x32\…\Swivel) (Version: 1.11 - Newgrounds.com, Inc.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Tachyon (HKLM-x32\…\Tachyon) (Version: - )
TSview (HKLM-x32\…\TSview6.0.1.1) (Version: 6.0.1.1 - Tucsen)
Unity Web Player (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\UnityWebPlayer) (Version: - Unity Technologies ApS)
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
UsbRepairTool (x32 Version: 1.4.0.0 - Brother Insutries Ltd.) Hidden
Verizon Software Upgrade Assistant (x32 Version: 15.05.0601 - Motorola Mobility) Hidden
Verizon Wireless Software Upgrade Assistant for Motorola (HKLM-x32\…\{9BEDD987-AC68-44D2-8803-EC0650F6C43F}) (Version: 1.4.8 - Motorola Mobility)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.4 - VideoLAN)
VSO ConvertXToDVD (HKLM-x32\…\{CE1F93C0-4353-4C9D-84DA-AB4E7C63ED32}_is1) (Version: 5.2.0.13 - VSO Software)
VSO ConvertXToDVD 6 (HKLM-x32\…\{8FC36FA6-C508-44FB-B137-1CB46D8258B2}_is1) (Version: 6.0.0.20 - VSO Software)
War Thunder (HKLM-x32\…\Steam App 236390) (Version: - Gaijin Entertainment)
War Thunder Launcher 1.0.1.542 (HKLM-x32\…\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version: - Gaijin Entertainment)
WebM Project Directshow Filters (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\webmdshow) (Version: 1.0.4.1 - WebM Project)
WinPcap 4.1.3 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinZip (HKLM-x32\…\WinZip) (Version: - )
WinZip 20.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C24105}) (Version: 20.5.12118 - WinZip Computing, S.L. )
Wireshark 1.10.8 (64-bit) (HKLM-x32\…\Wireshark) (Version: 1.10.8 - The Wireshark developer community, hxxp://www.wireshark.org)
WM Capture 7 (HKLM-x32\…\WM Capture 7) (Version: 7.2 - AllAlex, Inc.)
Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\…\Open Codecs) (Version: 0.85.17777 - Xiph.Org)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.29.2\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Roblox\Versions\version-ecedadb4b6824712\RobloxProxy64.dll (ROBLOX Corporation)
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0139817E-2129-4236-9767-A5FF602A4F86} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {022D831C-4C79-4DDA-9F46-CF0371090367} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {065474CC-462A-4655-AD08-DC636D9942E0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-10] (Adobe Systems Incorporated)
Task: {08847825-9E6B-4B60-9817-73E64A1366B9} - System32\Tasks\AdobeAAMUpdater-1.0-Dykes-family-PC-Dykes-family => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-08-05] (Adobe Systems Incorporated)
Task: {0DC1A74E-306A-49C1-A678-580AC24991A7} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {18F0FD4E-D27F-4AE1-9B83-67653E9FC8D7} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {1E43DC1F-C70B-49A8-89B2-614E6E97139D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {1F58AFFF-5592-43A4-9B78-40388A4F0A5B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-02] (Google Inc.)
Task: {27DCA93B-AEDC-4D90-84FB-5EF7EBAD80AD} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {2D6F92CB-856F-425A-97F5-5D2C52D01D6F} - System32\Tasks\{6BE163AC-EDCD-48B5-A135-C3F5B45D5D1A} => pcalua.exe -a C:\Users\Dykes-family\Desktop\forge-1.7.2-10.12.2.1147-installer-win.exe -d C:\Users\Dykes-family\Desktop
Task: {320BDC0A-EF88-4FD3-BAB6-FC598F9EA88F} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-09-26] (AVAST Software)
Task: {37A2592A-D481-4CB8-B9E8-AE25DB788E5F} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {3C535FA3-F3C8-4192-A9B9-0C96F7BC35F3} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {406C39D4-BA2D-42B1-832E-7AB9A006C855} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {4E39BF1F-2B0E-47CE-9AC5-7629DD54C78E} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4EB7F5C1-1A88-4F85-B684-55AB9B7C33B9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {4EC0EEDB-2A66-48AB-A3F2-695EEF71AC8F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-500UA => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {52D96370-488D-42B6-B271-1F1A0C5B112C} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [2014-07-31] (TechSmith Corporation)
Task: {57DB7453-8984-4E9E-9DCC-404B4C344DBF} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {5AA49963-F35F-442E-8881-741CAFD090EC} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-01-11] (Microsoft Corporation)
Task: {5CF9FE4C-751A-436C-AA89-B6B2566BDDCF} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5D171B64-96B8-4580-AE31-EEC926E9F0A5} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-1001UA => C:\Users\Dykes-family\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {6737F9A0-A06E-4C6E-AD98-CA5F71F902E0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
Task: {6B97F6B8-A0D0-4887-8F24-8E98F5251554} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-1001Core => C:\Users\Dykes-family\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {6F003481-05BD-4A88-92CD-C13CB03669E5} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7921FE4E-B137-4317-B8D7-B7E4B1DAD97E} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {7BD0F194-9BA0-4699-8686-C9F6D5F80BF1} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {7C5A8F71-B8B1-419E-AFDD-658F0E54B672} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-500Core => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {7F76106B-0A90-4685-9A0B-4350E5337EFF} - System32\Tasks\{263B73C8-4A13-4C80-9636-BECB24C98E9B} => pcalua.exe -a C:\Users\Dykes-family\Desktop\forge-1.7.10-10.13.2.1230-installer-win.exe -d C:\Users\Dykes-family\Desktop
Task: {7FCE95EF-BCB4-408E-8160-9A8BB6B9107B} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {82567FCD-E4FC-44F2-B11E-0C888D335A80} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3670747094-3822527020-2124027705-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-05-13] (RealNetworks, Inc.)
Task: {8B1AF5AF-FC9F-4A09-902A-14790701122C} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {8B6DC2BD-2B4B-482E-A8C4-1B6C976F6B69} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {9295111F-83F3-49D9-A822-2AD953A165D2} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {92AEEA2D-3B57-4643-B244-07E8911BAA9B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {94A9047D-2E3E-4906-A746-D5C3A844018E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {9AAA0900-423D-4A14-BC4F-36F088BF5473} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {A2D856CB-39DD-4598-ADA7-FF17DA9757A3} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A5753665-D293-450B-A5C2-D912643B0FB3} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {AAF3522D-11DB-4702-A2CA-5FDF5FC6557C} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {B1AAD89D-A96B-4389-A134-A00B2F2508A9} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B662F054-CF05-4746-AA0E-2CBBF8D8156F} - System32\Tasks\Verizon Wireless Upgrade Assistant Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\VerizonWirelessUpgradeAssistantUpdate.exe [2016-03-21] ()
Task: {BAF9FB83-BB19-4DB8-B7A0-21323ACB18A0} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BDA538FA-68DB-43F8-9A5E-7BB7622D916F} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {BE406590-1253-4020-8048-372BBB336DEF} - System32\Tasks\Verizon Wireless Upgrade Assistant Update Initial Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\VerizonWirelessUpgradeAssistantUpdate.exe [2016-03-21] ()
Task: {C221E675-9579-4BD4-97EB-0A763EE3E67E} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {C24ABE6C-BEA7-4CF5-941E-B6CB443FCC20} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3670747094-3822527020-2124027705-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-05-13] (RealNetworks, Inc.)
Task: {C3D3E5ED-C8CC-4BAA-9694-C789E2EB67DA} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3670747094-3822527020-2124027705-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-05-23] (RealNetworks, Inc.)
Task: {C612880E-7624-4F85-9819-7C7445260FF4} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3670747094-3822527020-2124027705-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-05-23] (RealNetworks, Inc.)
Task: {C739DADD-36F9-4FA9-ADC3-AB0144329D46} - System32\Tasks\arp_flush => C:\Program Files (x86)\hide.me VPN\FlushArpCache.exe
Task: {C8CA7CA5-EBBD-476F-818D-E27A76508C4F} - System32\Tasks\SafeZone scheduled Autoupdate 1462969116 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software)
Task: {CC136BC3-F63E-4563-9FA8-68F95C50B565} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {CECD283B-CEA2-4142-8A9E-60BFF7897A40} - System32\Tasks\{5C7ED580-D17B-441B-9CFC-D9071077D042} => pcalua.exe -a "C:\Users\Dykes-family\Desktop\New folder (2)\forge-1.8-11.14.0.1299-installer-win.exe" -d "C:\Users\Dykes-family\Desktop\New folder (2)"
Task: {D718FB89-0E45-4DD1-B6D6-B9594C909310} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D7B33869-F1A8-426D-9627-8624CBD8DCA7} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D893E8D2-D852-490C-96FC-83EAC9DDE087} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {DC62D376-60E0-4B4D-871C-ADA3204BBDE1} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {E0B88179-7894-4408-8C41-1FC44AAD136A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E2E7A0AB-7800-4F6B-A123-2AB2A632479E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-02] (Google Inc.)
Task: {E402D9F8-A3EF-4E2C-AAB7-82CEBED954A4} - \WinSATService -> No File <==== ATTENTION
Task: {E5674698-9C34-4E86-8E6E-C05B1E96920F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {F396A6E3-9E65-4BEC-AE3D-B2E5E02535CA} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-345625499-1670360406-2532865610-500Core.job => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-345625499-1670360406-2532865610-500UA.job => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-500Core.job => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-500UA.job => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2015-10-30 02:17 - 2015-10-30 02:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll
2015-10-30 02:18 - 2015-10-30 02:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-07-17 11:39 - 2015-09-01 08:41 - 00095008 _____ () C:\WINDOWS\System32\Primomonnt.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-11-17 01:28 - 2016-11-17 01:28 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-05-24 13:30 - 2010-04-05 14:55 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2014-05-23 00:34 - 2014-05-23 00:34 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
2014-05-13 12:10 - 2014-05-13 12:10 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2016-11-08 16:28 - 2016-10-25 04:42 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-11-08 16:28 - 2016-10-25 04:42 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-01-11 15:55 - 2014-10-24 14:16 - 00721263 _____ () C:\Windows\SysWOW64\WSCM64.dll
2016-11-08 16:28 - 2016-10-24 23:44 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-12-17 15:48 - 2015-12-06 23:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-07-13 13:11 - 2016-06-30 22:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-11-08 16:28 - 2016-10-24 23:49 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-11-08 16:28 - 2016-10-24 23:46 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-11-08 16:28 - 2016-10-24 23:45 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-11-08 16:28 - 2016-10-24 23:48 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-09-26 06:55 - 2016-09-26 06:55 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-02-01 17:22 - 2017-02-01 17:22 - 04459608 _____ () C:\Program Files\AVAST Software\Avast\defs\17020101\algo.dll
2016-09-26 06:55 - 2016-09-26 06:55 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2015-12-15 13:38 - 2015-12-15 13:38 - 00326112 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\dblite.dll
2015-10-27 16:44 - 2015-10-27 16:44 - 00404952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\ipm_service.dll
2015-04-15 08:11 - 2015-04-15 08:11 - 00162816 _____ () C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\css_core.dll
2016-06-02 18:06 - 2016-06-02 18:06 - 45077376 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\libcef.dll
2016-09-26 06:55 - 2016-09-26 06:55 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:B3ED3AFF [290]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 21:34 - 2014-12-28 22:05 - 00001028 ____A C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 lmlicenses.wip4.adobe.com
127.0.0.1 lm.licenses.adobe.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Dykes-family\Pictures\Wallpaper\whale_sperm_whale.jpg
HKU\S-1-5-21-3670747094-3822527020-2124027705-1004\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Control Panel\Desktop\\Wallpaper ->
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RealPlayer Cloud Service UI.lnk => C:\Windows\pss\RealPlayer Cloud Service UI.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snagit 12.lnk => C:\Windows\pss\Snagit 12.lnk.CommonStartup
MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
MSCONFIG\startupreg: DelaypluginInstall => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
MSCONFIG\startupreg: DriveTheLife2013 => "C:\Program Files (x86)\DTLSoft\DriveTheLife\DriveTheLife.exe" /start
MSCONFIG\startupreg: Google Update => "C:\Users\Dykes-family\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
MSCONFIG\startupreg: uTorrent => "C:\Users\Dykes-family\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED
MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM\…\StartupApproved\StartupFolder: => "FAH.lnk"
HKLM\…\StartupApproved\StartupFolder: => "WinZip Preloader.lnk"
HKLM\…\StartupApproved\StartupFolder: => "Update Notifier.lnk"
HKLM\…\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\…\StartupApproved\Run: => "iTunesHelper"
HKLM\…\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\…\StartupApproved\Run32: => "Adobe Acrobat Speed Launcher"
HKLM\…\StartupApproved\Run32: => "BrHelp"
HKLM\…\StartupApproved\Run32: => "ControlCenter4"
HKLM\…\StartupApproved\Run32: => "ProductUpdater"
HKLM\…\StartupApproved\Run32: => "BrStsMon00"
HKLM\…\StartupApproved\Run32: => "PowerDVD16Agent"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "Creative WebCam Tray"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "GoogleDriveSync"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "Icecream_Screen_Recorder_Prefetcher"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1004\…\StartupApproved\Run: => "Steam"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => LPort=139
FirewallRules: [MSMQ-In-TCP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => LPort=808
FirewallRules: [{93CB8957-282E-4F00-98A3-62B796079D9C}] => c:\program files (x86)\pc-faxreceive\brengineprocess.exe
FirewallRules: [{8414DDD4-F84A-42F2-ADF2-5E2C70F00D05}] => c:\program files (x86)\pc-faxreceive\brengineprocess.exe
FirewallRules: [{22358ADE-58E7-4E60-AADD-AFA280131246}] => C:\Users\Dykes-family\AppData\Local\Temp\7zS156B\HPDiagnosticCoreUI.exe
FirewallRules: [{891531CA-F0DF-40FA-81D9-FD71DDA6E1C0}] => C:\Users\Dykes-family\AppData\Local\Temp\7zS156B\HPDiagnosticCoreUI.exe
FirewallRules: [{640CA6B2-5D3A-425A-ACA5-20340E77E652}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{CA7AC0A9-6FF9-4067-8B42-C48431DD1682}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{55B78628-311F-4950-83DF-40B2E66CA14E}] => C:\WarThunder\bpreport.exe
FirewallRules: [{C1A0EDE0-9BA8-4401-B544-D0ED6AD3BEC2}] => C:\WarThunder\bpreport.exe
FirewallRules: [{11870A34-94DC-4C1A-B669-015F096F0B36}] => C:\WarThunder\aces.exe
FirewallRules: [{17C55341-3723-4250-9745-F314BBBB5201}] => C:\WarThunder\aces.exe
FirewallRules: [{3DA07D15-9FDF-4547-84AC-8D904ED15335}] => C:\WarThunder\launcher.exe
FirewallRules: [{4256A970-570A-4470-83F2-3D3ACEBAD6F4}] => C:\WarThunder\launcher.exe
FirewallRules: [UDP Query User{626EEEFD-EAA8-4A84-B7FA-3D63C8D7966E}C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe] => C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe
FirewallRules: [TCP Query User{975E3E53-282D-4E91-A674-DD998EF4851B}C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe] => C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe
FirewallRules: [UDP Query User{A1AD25C2-AFDF-4C5D-97CC-E66FD3411130}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => C:\program files\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [TCP Query User{B5878C78-573C-404A-9991-489EFD57D3D1}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => C:\program files\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [UDP Query User{6B1F324E-5863-4339-A767-A2920B74098E}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [TCP Query User{2F0125C2-C8AF-497D-9F19-C3BE7352F570}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [{10C67387-6A88-4E96-BE85-C60F69154762}] => C:\Program Files\HP\HP Photosmart 6510 series\Bin\DeviceSetup.exe
FirewallRules: [{195B4DFF-C4D9-44C3-AA27-B2823F6F0ABD}] => C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{7C5BBEB5-3312-4751-B92A-AA8309895A12}] => C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{D1DA57C6-8F68-47F8-BE29-751CFE515C1A}] => c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [TCP Query User{3279BD8A-6CF7-4195-B26E-9A21D2790878}C:\users\dykes-family\appdata\local\apps\2.0\70bgzxml.hjv\tjcjyw9d.02h\lego…app_8c161902ccf9ca2a_0001.0000_1277cc1e021b3644\lmo.exe] => C:\users\dykes-family\appdata\local\apps\2.0\70bgzxml.hjv\tjcjyw9d.02h\lego…app_8c161902ccf9ca2a_0001.0000_1277cc1e021b3644\lmo.exe
FirewallRules: [UDP Query User{2C7ED095-2D24-46AB-A166-6E8AD6742EED}C:\users\dykes-family\appdata\local\apps\2.0\70bgzxml.hjv\tjcjyw9d.02h\lego…app_8c161902ccf9ca2a_0001.0000_1277cc1e021b3644\lmo.exe] => C:\users\dykes-family\appdata\local\apps\2.0\70bgzxml.hjv\tjcjyw9d.02h\lego…app_8c161902ccf9ca2a_0001.0000_1277cc1e021b3644\lmo.exe
FirewallRules: [{C89F6907-27D2-4E7C-B388-5A92FBB8674F}] => C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{244303D6-F0AD-4D3A-AAEA-6C492991A937}] => C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{44DBD89C-1F2F-4C00-9275-3D2C3D80C2D7}] => LPort=7935
FirewallRules: [TCP Query User{2BEBF0D7-7ECD-42EB-B153-84D354DF6F8D}C:\program files\gns3-er\gns3server.exe] => C:\program files\gns3-er\gns3server.exe
FirewallRules: [UDP Query User{BDA1B462-AD21-440D-BA13-C5A3232C6CA4}C:\program files\gns3-er\gns3server.exe] => C:\program files\gns3-er\gns3server.exe
FirewallRules: [{E6100552-B05E-46C8-B032-A3D056644D53}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C44F31EF-E6D7-494F-A934-E90A6EC97D8D}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3DBED0E6-4736-4EE1-8113-1F56CD3749F7}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8240F37C-EACE-4FE7-93BA-89DB64D9CC55}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{2120A7C7-6484-4D6F-94AB-E8F612870FDA}] => C:\Users\Dykes-family\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{BF34CF2A-DA6E-44D0-B556-FE60D8D3726D}] => C:\Users\Dykes-family\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{BC16E2C4-40F1-4C49-AF00-FC4AD75C1D4A}C:\users\dykes-family\desktop\seths stuff\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\dykes-family\desktop\seths stuff\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{DA451EFC-7E7C-4AE2-84FE-0FFC52571015}C:\users\dykes-family\desktop\seths stuff\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\dykes-family\desktop\seths stuff\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{C39D127C-9B67-4C26-A01B-AFD741D9F7DD}] => LPort=8298
FirewallRules: [TCP Query User{CB5E9AF7-FD1E-4FD1-B17E-90C995589E2F}C:\program files (x86)\wondershare\video converter ultimate\dscheck.exe] => C:\program files (x86)\wondershare\video converter ultimate\dscheck.exe
FirewallRules: [UDP Query User{4E1F072A-4708-4493-A7A3-AD7C44EDC666}C:\program files (x86)\wondershare\video converter ultimate\dscheck.exe] => C:\program files (x86)\wondershare\video converter ultimate\dscheck.exe
FirewallRules: [{5B94D5FF-CA15-47BD-8141-37409FECDF2C}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{610069C6-9906-4652-99D4-A9498B68E2A4}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{80DC156E-D699-46B8-A750-E05CB3609C86}C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe] => C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe
FirewallRules: [UDP Query User{AE76B06D-C6F6-40B4-B621-790C35EC236D}C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe] => C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe
FirewallRules: [TCP Query User{9680A60F-BC7B-4580-B0DA-EEA9617BAEFB}C:\program files (x86)\java\jre1.8.0_31\bin\jp2launcher.exe] => C:\program files (x86)\java\jre1.8.0_31\bin\jp2launcher.exe
FirewallRules: [UDP Query User{EEAA9A59-21DB-477C-AD1B-D9467481769C}C:\program files (x86)\java\jre1.8.0_31\bin\jp2launcher.exe] => C:\program files (x86)\java\jre1.8.0_31\bin\jp2launcher.exe
FirewallRules: [TCP Query User{55B8E8A5-FAF6-480B-8F91-3B1CDB10DF72}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{6166A3F0-EA04-4910-8AC5-6A19F084C128}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{8851F2C4-026D-482C-BE7F-D0C100478D4E}] => C:\Program Files (x86)\DTLSoft\DriveTheLife\DriveTheLife.exe
FirewallRules: [{E3C1D997-B158-4911-8D62-3C9F3915E65C}] => C:\Program Files (x86)\DTLSoft\DriveTheLife\DTLService.exe
FirewallRules: [{873261E8-10A7-4EFF-8F6C-197F77A5109F}] => C:\Program Files (x86)\DTLSoft\DriveTheLife\download\MiniThunderPlatform.exe
FirewallRules: [TCP Query User{0CFD8F0E-AE65-4BF8-A995-B781C328D926}C:\users\dykes-family\desktop\seths stuff\music\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\dykes-family\desktop\seths stuff\music\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{2EC94120-BC54-428A-90DA-E753C17A674D}C:\users\dykes-family\desktop\seths stuff\music\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\dykes-family\desktop\seths stuff\music\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{DD3E71B0-65A8-4E2D-9921-96B17A48A7D2}D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe] => D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe
FirewallRules: [UDP Query User{DDE7BBD4-5E56-41D2-AD2D-E0612204BEBC}D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe] => D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe
FirewallRules: [{02C41359-3DDE-404D-BA97-B0FA80742415}] => D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe
FirewallRules: [{6381D3D2-AB5C-4C86-8C1C-F5F05DA69E43}] => D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe
FirewallRules: [{865E393D-5AB9-412F-9CE0-4C0A5538A8F6}] => LPort=80
FirewallRules: [{AA75C8A6-47E3-4AD5-A1D8-48A79D2E7331}] => LPort=443
FirewallRules: [{D9D099F3-C8EA-4B26-B093-FC7F61B69A3E}] => LPort=20010
FirewallRules: [{80229565-E031-435B-9B6C-9A259CFB299C}] => LPort=3478
FirewallRules: [{914A9E68-EC11-4034-BBC4-4A6C4E4F7EF2}] => LPort=7850
FirewallRules: [{310B075D-FF80-41F0-BF31-0596A45C0917}] => LPort=7852
FirewallRules: [{807A6E80-C588-4797-AEA1-5A027C07F440}] => LPort=7853
FirewallRules: [{8E3FD9F2-3ACD-41B9-BFEE-EF4A036A63DA}] => LPort=27022
FirewallRules: [{91891ED2-DA7A-4919-8C1B-C147BC6483B9}] => LPort=6881
FirewallRules: [{0D90B2A6-94CD-4098-BF7B-DD5693F11C66}] => LPort=33333
FirewallRules: [{57C9EF02-3E86-4248-AEFA-C6159386CC5B}] => LPort=20443
FirewallRules: [{4F7F518E-A93A-45EB-B6A6-3BC6A1960FAB}] => LPort=8090
FirewallRules: [TCP Query User{20E6541F-E596-4A54-A54C-00E8D6C93255}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [UDP Query User{C502801E-9DA3-4F65-9E91-E97D80B5E8C3}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [{92906DE0-F1B0-4648-8D4E-2E3D78A10F22}] => C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{86996E66-E9A1-432A-945B-B338E10A353A}] => C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{65E5CFE6-5768-42A7-9F82-59629DFD20E3}] => C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{6D6B164F-D148-4B4C-9988-4DA791202945}] => C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{70DAAA0F-CC2B-4D21-8AB9-FEFACA764741}] => C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{ED454976-1DF5-433C-8F97-2D747416E6DC}] => C:\Program Files (x86)\Steam\steamapps\common\War Thunder\launcher.exe
FirewallRules: [{B81D17EF-FCC3-41F8-869C-F8658351628D}] => C:\Program Files (x86)\Steam\steamapps\common\War Thunder\launcher.exe
FirewallRules: [TCP Query User{51B22E85-3F01-4951-A5F5-5F1B2875BE05}C:\users\dykes-family\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe] => C:\users\dykes-family\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe
FirewallRules: [UDP Query User{49000193-E041-4F08-BF0C-6C79A947DA38}C:\users\dykes-family\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe] => C:\users\dykes-family\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe
FirewallRules: [{82A884C7-3FFC-4438-A3CB-2D4F65587996}] => C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{82B68183-1E01-4F8A-BDFE-97766F3B0184}] => C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{1B642415-0FAB-46AD-A201-018112283132}] => C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD.exe
FirewallRules: [{7A756677-0870-4605-96B7-E56AFD1C9F5A}] => C:\Program Files (x86)\CyberLink\PowerDVD16\Kernel\DMS\CLMSServerPDVD16.exe
FirewallRules: [{CE3BBDFD-BFDC-41BB-AB41-269DCC225EA2}] => C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD16Agent.exe
FirewallRules: [{58DAB53E-255C-4046-A3F4-69627B6FAB30}] => C:\Program Files (x86)\CyberLink\PowerDVD16\Movie\PowerDVDMovie.exe
FirewallRules: [{483C7A19-8F63-4D3B-AC27-7DE031973DAA}] => C:\Program Files (x86)\CyberLink\PowerDVD16\CastingStation.exe
FirewallRules: [{987BFF37-FFA2-4947-9FFD-DBBD88DD37C3}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7EF3FD59-278F-40B1-905B-D7134A1C3623}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{21FDE955-2857-4801-A151-BAEE2B2EE3C9}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CCD7BADC-AD6D-4F5E-A236-9A5CEED7F43A}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{72AF883C-6CA0-471B-B2B6-6CE72B1C03A5}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{383F7CA9-72EC-4BCF-B229-B3B4BD6BA33C}] => C:\Program Files\iTunes\iTunes.exe
==================== Restore Points =========================
20-01-2017 16:59:07 Scheduled Checkpoint
29-01-2017 05:37:54 Scheduled Checkpoint
31-01-2017 18:08:26 JRT Pre-Junkware Removal
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/31/2017 06:11:16 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\CyberLink\PowerDVD16\Kernel\DMS\CLMSMediaInfoPDVD16.exe".
Dependent Assembly CLMSMediaInfo.X,type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/31/2017 06:10:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 51.0.1.6234, time stamp: 0x5888f707
Faulting module name: mozglue.dll, version: 51.0.1.6234, time stamp: 0x5888f27e
Exception code: 0x80000003
Fault offset: 0x0000ec83
Faulting process id: 0x2e4
Faulting application start time: 0x01d27c16296b1ad2
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
Report Id: dc7491b1-2aef-45b9-accb-72bd9c5c2b41
Faulting package full name:
Faulting package-relative application ID:
Error: (01/31/2017 06:08:59 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (01/31/2017 06:07:53 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\CyberLink\PowerDVD16\Kernel\DMS\CLMSMediaInfoPDVD16.exe".
Dependent Assembly CLMSMediaInfo.X,type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/31/2017 06:04:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Speccy-setup.exe version 1.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
Process ID: 153c
Start Time: 01d27c164136e745
Termination Time: 4294967295
Application Path: C:\Users\Dykes-family\Downloads\Speccy-setup.exe
Report Id: 8e19f170-e809-11e6-9c3a-001e4fddf430
Faulting package full name:
Faulting package-relative application ID:
Error: (01/31/2017 11:49:23 AM) (Source: LMS) (EventID: 2) (User: NT AUTHORITY)
Description: LMS Service lost connection to HECI driver
Error: (01/31/2017 11:47:23 AM) (Source: LMS) (EventID: 2) (User: NT AUTHORITY)
Description: LMS Service lost connection to HECI driver
Error: (01/31/2017 11:43:28 AM) (Source: LMS) (EventID: 2) (User: NT AUTHORITY)
Description: LMS Service lost connection to HECI driver
Error: (01/30/2017 03:32:32 PM) (Source: LMS) (EventID: 2) (User: NT AUTHORITY)
Description: LMS Service lost connection to HECI driver
Error: (01/29/2017 08:04:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ksu.exe, version: 1.5.2.228, time stamp: 0x57447574
Faulting module name: ksu.exe, version: 1.5.2.228, time stamp: 0x57447574
Exception code: 0xc000041d
Fault offset: 0x00045146
Faulting process id: 0x27d8
Faulting application start time: 0x01d27a77bbd96b45
Faulting application path: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater Beta\ksu.exe
Faulting module path: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater Beta\ksu.exe
Report Id: d7c83343-25a8-411a-8d65-23f0cec7df03
Faulting package full name:
Faulting package-relative application ID:
System errors:
=============
Error: (02/01/2017 09:19:21 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/01/2017 09:19:15 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/01/2017 09:19:09 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/01/2017 09:19:03 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/01/2017 09:18:57 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/01/2017 09:18:51 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/01/2017 09:18:48 PM) (Source: Service Control Manager) (EventID: 7046) (User: )
Description: The following service has repeatedly stopped responding to service control requests: Windows Search
Contact the service vendor or the system administrator about whether to disable this service until the problem is identified.
You may have to restart the computer in safe mode before you can disable the service.
Error: (02/01/2017 09:18:45 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/01/2017 09:18:39 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (02/01/2017 09:18:33 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
CodeIntegrity:
===================================
Date: 2017-01-13 03:50:09.567
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-12 03:22:43.782
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2017-01-12 03:07:14.870
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-12-15 03:24:16.253
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-12-14 05:39:19.255
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-12-14 04:28:37.390
Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.
Date: 2016-12-02 09:18:32.288
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-02 09:18:32.243
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-02 09:18:32.183
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2016-12-02 09:18:31.921
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz
Percentage of memory in use: 30%
Total physical RAM: 8052.61 MB
Available physical RAM: 5624.51 MB
Total Virtual: 8052.61 MB
Available Virtual: 5850.47 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:463.73 GB) (Free:9.1 GB) NTFS
—
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-02-01 21:21:10
—————————–
21:21:10.847 OS Version: Windows x64 6.2.9200
21:21:10.847 Number of processors: 2 586 0xF0D
21:21:10.847 ComputerName: DYKES-FAMILY-PC UserName: Dykes-family
21:21:12.034 Initialize success
21:21:12.159 VM: initialized successfully
21:21:12.159 VM: Intel CPU virtualization not supported
21:21:21.351 AVAST engine defs: 17020101
21:21:34.947 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3
21:21:34.947 Disk 0 Vendor: HITACHI_HUA7250SBSUN500G_0814J84K7F GK6OA90A Size: 476940MB BusType: 3
21:21:35.103 Disk 0 MBR read successfully
21:21:35.103 Disk 0 MBR scan
21:21:35.118 Disk 0 Windows 7 default MBR code
21:21:35.134 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 1177 MB offset 2048
21:21:35.134 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 474862 MB offset 2412544
21:21:35.165 Disk 0 Partition 3 00 27 Hidden NTFS WinRE NTFS 450 MB offset 974929920
21:21:35.306 Disk 0 scanning C:\WINDOWS\system32\drivers
21:21:47.213 Service scanning
21:22:14.936 Modules scanning
21:22:14.936 Disk 0 trace - called modules:
21:22:14.952 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS pciide.sys hal.dll PCIIDEX.SYS atapi.sys
21:22:14.952 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe001ccaf2300]
21:22:14.968 3 CLASSPNP.SYS[fffff801da717d95] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-3[0xffffe001cc5ff060]
21:22:15.781 AVAST engine scan C:\WINDOWS
21:22:18.609 AVAST engine scan C:\WINDOWS\system32
21:25:13.427 AVAST engine scan C:\WINDOWS\system32\drivers
21:25:28.678 AVAST engine scan C:\Users\Dykes-family
22:45:38.045 File: C:\Users\Dykes-family\Documents\Kingston Drive\Centurylink\Downloads\PDFReaderSetup.exe **INFECTED** Win32:Evo-gen [Susp]
22:55:17.553 AVAST engine scan C:\ProgramData
23:06:40.190 Disk 0 statistics 11605672/0/0 @ 1.51 MB/s
23:06:40.198 Scan finished successfully
06:41:15.911 Disk 0 MBR has been saved successfully to "C:\Users\Dykes-family\Downloads\Security-Malware Protection\MBR.dat"
06:41:15.985 The log file has been saved successfully to "C:\Users\Dykes-family\Downloads\Security-Malware Protection\aswMBR-2-2-17.txt"