This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

My refurbished Dell computer becoming increasingly sluggish [Solved]

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My refurbished Dell desktop has been getting increasingly slower and slower, now to the point that anything video is stop and start. Admittedly it wasn't the fastest in the world, but it's getting ridiculous. I've run Malwarebytes Antimalware and JRT, but neither found anything. I was hoping that I could get someone to take a look so that I can positively rule out some kind of malware/junkware dragging my computer down like a Mafia cinder block. I'm at the point where I feel like just reformatting my hard drive and starting over.

 

Do I need to run Hijack this or something? Thanks.

Please print out or make a copy in notepad of any instructions given, as sometimes it is necessary to go offline and you will lose access to them.

Please download and run the following tool to help allow other programs to run. (courtesy of BleepingComputer.com)
There are 6 different versions. If one of them won't run then download and try to run the other one.
Vista and Win7 users need to right click and choose Run as Admin
You only need to get one of them to run, not all of them.
  • rkill.exe
  • rkill.com
  • rkill.scr
  • rkill.pif
  • WiNlOgOn.exe
  • uSeRiNiT.exe
~~~~~~~~~~~~~~~~~~~~~`

[external image: xlK5Hdb.png]Farbar Recovery Scan Tool (FRST) Scan
  • Please download Farbar Recovery Scan Tool (x32) or Farbar Recovery Scan Tool (x64) and save the file to your Desktop.
  • Note: Download and run the version compatible with your system (32 or 64-bit). Download both if you're unsure; only one will run.
  • Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg]Run as administrator to run the programme.
  • Click Yes to the disclaimer.
  • Ensure the Addition.txt box is checked.
  • Click the Scan button and let the programme run.
  • Upon completion, click OK, then OK on the Addition.txt pop up screen.
  • Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.

~~~~
aswMBR Log

Important! Please do NOT perform any fix options offered in aswMBR, we just need to see the report.

Please download aswMBR to your desktop.
  • Double click the aswMBR icon to run it.
  • If a prompt stating: The computer supports "Virtualization Technology" appears select Yes
  • Click the Scan button to start scan.
  • If you are asked to update the Avast Virus database please allow it to do so.
  • When it finishes, press the Save Log button, save the logfile to your desktop and post its contents in your reply with the Farbar (FRST) log and Addition.txt.

I was unable to get the Farbar scan to complete - I tried three times and each time it froze, even after rebooting. Other programs like Word are beginning to freeze now, too. I'm providing the other logs, though.

 

Thanks!

 

—

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-01-2017
Ran by [removed] (administrator) on DYKES-FAMILY-PC (01-02-2017 21:14:56)
Running from C:\Users\[removed]\Downloads\Security-Malware Protection
[removed] Platform: Windows 10 Pro Version 1511 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel) C:\Program Files (x86)\Intel\AMT\LMS.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\AMT\atchksrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Intel) C:\Program Files (x86)\Intel\AMT\UNS.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Motorola) C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe
(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Motorola Mobility LLC) C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\AMT\atchk.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater Beta\ksu.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avBugReport.exe
(Farbar) C:\Users\Dykes-family\Downloads\Security-Malware Protection\Farbar-scan-tool.exe

==================== Registry (Whitelisted) ====================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [atchk] => C:\Program Files (x86)\Intel\AMT\atchk.exe [401408 2009-12-01] (Intel Corporation)
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508240 2015-08-05] (Adobe Systems Incorporated)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-12-06] (Apple Inc.)
HKLM-x32\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [9080768 2016-11-15] (AVAST Software)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [840592 2015-09-24] (Adobe Systems Inc.)
HKLM-x32\…\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [41360 2015-09-24] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [139776 2014-11-12] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [4517376 2014-11-11] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [BrHelp] => C:\Program Files (x86)\Brother\Brother Help\BrotherHelp.exe [1939968 2014-10-22] (Brother Industries, Ltd.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [596504 2016-04-01] (Oracle Corporation)
HKLM-x32\…\Run: [PowerDVD16Agent] => C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD16Agent.exe [525352 2016-05-13] (CyberLink Corp.)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [2900560 2015-10-08] (Valve Corporation)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [Google Update] => C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.32.7\GoogleUpdateCore.exe [601752 2016-12-16] (Google Inc.)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [Creative WebCam Tray] => C:\Program Files (x86)\Creative\Shared Files\CamTray.exe [299008 2005-10-27] (Creative Technology Ltd)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [GoogleDriveSync] => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [Icecream_Screen_Recorder_Prefetcher] => C:\Program Files (x86)\Icecream Screen Recorder\recorder.exe [3472384 2016-03-24] (Icecream)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29547136 2016-08-17] (Skype Technologies S.A.)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\Run: [KSS] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe [1556448 2015-12-15] (AO Kaspersky Lab)
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019_1"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6201.1019\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6281.1202\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6301.0127\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6302.0225\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6386.0412\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\RunOnce: [Uninstall C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Dykes-family\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\MountPoints2: {a1f26f5a-790d-11e4-add0-001e4fddf430} - "E:\VZW_Software_upgrade_assistant.exe"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\MountPoints2: {dc7331a9-49d6-11e6-9c12-001e4fddf430} - "E:\VerizonWirelessUpgradeAssistantSetup.exe" -a
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\MountPoints2: {dc73324a-49d6-11e6-9c12-001e4fddf430} - "E:\VerizonWirelessUpgradeAssistantSetup.exe" -a
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2016-09-26] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2016-09-07]
ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAHConsole.exe (WinZip Computing, S.L.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Kaspersky Software Updater Beta.lnk [2016-12-27]
ShortcutTarget: Kaspersky Software Updater Beta.lnk -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater Beta\ksu.exe (AO Kaspersky Lab)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Update Notifier.lnk [2016-09-07]
ShortcutTarget: Update Notifier.lnk -> C:\Program Files\WinZip\WZUpdateNotifier.exe (WinZip Computing, S.L.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2016-09-07]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{57d1d93b-eaf8-4091-a16e-59282cb5cfc4}: [DhcpNameServer] [removed] [removed]

Internet Explorer:
==================
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-05-13] (RealDownloader)
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-04-25] (Oracle Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-25] (Oracle Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus64.dll [2014-12-16] (Adblock Plus)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2012-09-23] (Adobe Systems Incorporated)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-05-13] (RealDownloader)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-25] (Oracle Corporation)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-25] (Oracle Corporation)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)
BHO-x32: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2014-12-16] (Adblock Plus)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2015-09-24] (Adobe Systems Incorporated)

FireFox:
========
FF ProfilePath: C:\Users\Dykes-family\AppData\Roaming\Mozilla\Firefox\Profiles\i12gxvos.default [2017-02-01]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\i12gxvos.default -> Google
FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\i12gxvos.default -> Google
FF Homepage: Mozilla\Firefox\Profiles\i12gxvos.default -> www.google.com
FF Extension: (LastPass) - C:\Users\Dykes-family\AppData\Roaming\Mozilla\Firefox\Profiles\i12gxvos.default\Extensions\[removed] [2017-01-11]
FF Extension: (Flashblock) - C:\Users\Dykes-family\AppData\Roaming\Mozilla\Firefox\Profiles\i12gxvos.default\Extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a} [2016-01-01]
FF Extension: (Adblock Plus) - C:\Users\Dykes-family\AppData\Roaming\Mozilla\Firefox\Profiles\i12gxvos.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23]
FF Extension: (Bitdefender QuickScan) - C:\Users\Dykes-family\AppData\Roaming\Mozilla\Firefox\Profiles\i12gxvos.default\Extensions\{e001c731-5e37-4538-a5cb-8168736a2360} [2016-12-11]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-09-26]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-09-26]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF HKLM-x32\…\Firefox\Extensions: [{7ADCCCD0-FDEC-4A18-A329-550A87710223}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-06-02] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: (Adobe Acrobat - Create PDF) - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2015-11-18] [not signed]
FF HKLM-x32\…\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-10] ()
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2015-08-06] (Adobe Systems)
FF Plugin: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\Win64Plugin\npAdobeExManDetectX64.dll [2013-12-02] (Adobe Systems)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-10] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw_1217157.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-25] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @real.com/nppl3260;version=17.0.10.8 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2014-06-02] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=17.0.10 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll [2014-05-13] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.10 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-05-13] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=17.0.10 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll [2014-05-13] (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=17.0.10.8 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2014-06-02] (RealPlayer Cloud)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-01-17] (Adobe Systems Inc.)
FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2015-08-06] (Adobe Systems)
FF Plugin-x32: adobe.com/AdobeExManDetect -> C:\Program Files (x86)\Adobe\Adobe Extension Manager CS6\npAdobeExManDetectX86.dll [2013-12-02] (Adobe Systems)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @nsroblox.roblox.com/launcher -> C:\Users\Dykes-family\AppData\Local\Roblox\Versions\version-ecedadb4b6824712\\NPRobloxProxy.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @nsroblox.roblox.com/launcher64 -> C:\Users\Dykes-family\AppData\Local\Roblox\Versions\version-ecedadb4b6824712\\NPRobloxProxy64.dll [2013-01-01] ( ROBLOX Corporation)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @talk.google.com/GoogleTalkPlugin -> C:\Users\Dykes-family\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @talk.google.com/O1DPlugin -> C:\Users\Dykes-family\AppData\Roaming\Mozilla\plugins\npo1d.dll [2015-12-08] (Google)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin HKU\S-1-5-21-3670747094-3822527020-2124027705-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\Dykes-family\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-06-27] (Unity Technologies ApS)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2014-03-20] (Coupons, Inc.)
FF Plugin ProgramFiles/Appdata: C:\Users\Dykes-family\AppData\Roaming\mozilla\plugins\npgoogletalk.dll [2015-12-08] (Google)
FF Plugin ProgramFiles/Appdata: C:\Users\Dykes-family\AppData\Roaming\mozilla\plugins\npo1d.dll [2015-12-08] (Google)

Chrome:
=======
CHR DefaultProfile: Default
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\pdf.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\gcswf32.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll => No File
CHR Plugin: (Java(TM) Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll => No File
CHR Profile: C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default [2017-01-25]
CHR Extension: (YouTube) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-12-23]
CHR Extension: (Adobe Acrobat) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-01-25]
CHR Extension: (Avast SafePrice) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2016-12-23]
CHR Extension: (RealPlayer Downloader) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2016-04-02]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2016-12-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-01-25]
CHR Extension: (Gmail) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-04-02]
CHR Extension: (Chrome Media Router) - C:\Users\Dykes-family\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-12-23]
CHR HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\DYKES-~1\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-01-2017
Ran by [removed] (01-02-2017 21:17:18)
Running from C:\Users\[removed]\Downloads\Security-Malware Protection
Windows 10 Pro Version 1511 (X64) (2015-12-06 09:35:37)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3670747094-3822527020-2124027705-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-3670747094-3822527020-2124027705-503 - Limited - Disabled)
Dykes-family (S-1-5-21-3670747094-3822527020-2124027705-1001 - Administrator - Enabled) => C:\Users\Dykes-family
Guest (S-1-5-21-3670747094-3822527020-2124027705-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3670747094-3822527020-2124027705-1002 - Limited - Enabled)
legen (S-1-5-21-3670747094-3822527020-2124027705-1004 - Limited - Enabled) => C:\Users\legen

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Disabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adblock Plus for IE (32-bit and 64-bit) (HKLM\…\{C5D8EEB2-EDBC-4375-829D-BE50547C8890}) (Version: 1.3 - Eyeo GmbH)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20056 - Adobe Systems Incorporated)
Adobe Acrobat X Pro - English, Français, Deutsch (HKLM-x32\…\{AC76BA86-1033-F400-7760-000000000005}) (Version: 10.1.16 - Adobe Systems)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 16.0.0.273 - Adobe Systems Incorporated)
Adobe Creative Suite 6 Master Collection (HKLM-x32\…\{E8AD3069-9EB7-4BA8-8BFE-83F4E69355C0}) (Version: 6 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.)
Adobe Widget Browser (HKLM-x32\…\com.adobe.WidgetBrowser) (Version: 2.0 Build 348 - Adobe Systems Incorporated.)
Adobe® Content Viewer (HKLM-x32\…\com.adobe.dmp.contentviewer) (Version: 3.4.3 - Adobe Systems, Incorporated)
AKVIS Retoucher (HKLM-x32\…\{D77DBB31-D3EB-4405-8785-488CA60ECE46}) (Version: 3.5 - AKVIS Software Inc)
Apple Application Support (32-bit) (HKLM-x32\…\{D079CAAD-0C31-47A2-9AF5-A82F9CD9B221}) (Version: 5.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{64E6007B-1DA9-42CD-BBE4-D5FA67A7C71D}) (Version: 5.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
AppLogLibSetup (x32 Version: 1.0.1.0 - Brother Industries Ltd.) Hidden
Avast Free Antivirus (HKLM-x32\…\Avast) (Version: 12.3.2280 - AVAST Software)
AviSynth 2.5 (HKLM-x32\…\AviSynth) (Version:  - )
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
BrLauncher (x32 Version: 1.1.6.0 - Brother Industries Ltd.) Hidden
BrLogRx (x32 Version: 1.0.1.1 - Brother Industries Ltd.) Hidden
Brother PCFax Driver (x32 Version: 1.4.0.0 - Brother Industries Ltd.) Hidden
Brother Port Driver (x32 Version: 1.0.11.11 - Brother Industries Ltd.) Hidden
Brother Printer Driver (x32 Version: 1.5.0.0 - Brother Industries Ltd.) Hidden
Brother Scanner Driver (x32 Version: 1.0.15.10 - Brother Industries Ltd.) Hidden
BrotherHelpInstaller (x32 Version: 1.0.0.0 - Brother) Hidden
BrSupportTools (x32 Version: 1.0.9.0 - Brother Industries Ltd.) Hidden
Canon CanoScan LiDE 110 User Registration (HKLM-x32\…\Canon CanoScan LiDE 110 User Registration) (Version:  - )
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\…\CANONIJPLM100) (Version:  - )
Canon MP Navigator EX 4.0 (HKLM-x32\…\MP Navigator EX 4.0) (Version:  - )
Canon Solution Menu EX (HKLM-x32\…\CanonSolutionMenuEX) (Version:  - )
CanoScan LiDE 110 Scanner Driver (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_cnq2414) (Version:  - Canon Inc.)
Cisco Configuration Professional (HKLM-x32\…\{29342492-9F4F-4089-866A-10D801B610FD}) (Version: 2.5 - Cisco Systems)
Clone2Go Video Converter Free Version 1.7.7 (HKLM-x32\…\Clone2Go Video Converter Free Version_is1) (Version:  - Clone2Go.com)
Cobalt (HKLM-x32\…\Cobalt) (Version:  - )
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
ControlCenter4 (x32 Version: 4.2.435.1 - Brother Insutries Ltd.) Hidden
ControlCenter4 CSDK (x32 Version: 4.2.3.1 - Brother Insutries Ltd.) Hidden
Coupon Printer for Windows (HKLM-x32\…\Coupon Printer for Windows5.0.0.9) (Version: 5.0.0.9 - Coupons.com Incorporated)
Creative WebCam Center (HKLM-x32\…\Creative WebCam Center) (Version:  - )
CyberLink PowerDVD 16 (HKLM-x32\…\{7CD1ACC0-3DD0-4894-90C7-BF2A136C074D}) (Version: 16.0.1713.60 - CyberLink Corp.)
DeviceDetect (x32 Version: 1.0.3.3 - Brother Industries Ltd.) Hidden
Disney Infinity PC (HKLM-x32\…\{11CB229E-8A2B-40FD-8670-4EC92D3DDAD5}) (Version: 1.85.4161 - Disney Interactive)
ExtractNow (HKLM-x32\…\ExtractNow_is1) (Version:  - Nathan Moinvaziri)
EZ CD Audio Converter (HKLM-x32\…\EZ CD Audio Converter) (Version: 2.4 - Poikosoft)
FileZilla Client 3.23.0.2 (HKLM-x32\…\FileZilla Client) (Version: 3.23.0.2 - Tim Kosse)
Free Video to DVD Converter version 5.0.56.128 (HKLM-x32\…\Free Video to DVD Converter_is1) (Version: 5.0.56.128 - DVDVideoSoft Ltd.)
Freemake Audio Converter version 1.1.4 (HKLM-x32\…\Freemake Audio Converter_is1) (Version: 1.1.4 - Ellora Assets Corporation)
Freemake Video Converter version 4.1.5 (HKLM-x32\…\Freemake Video Converter_is1) (Version: 4.1.5 - Ellora Assets Corporation)
FreeRIP MP3 Converter 4.7.0 (HKLM-x32\…\{501451DE-5808-4599-B544-8BD0915B6B24}_is1) (Version: 4.7.0 - GreenTree Applications SRL)
GNS3-ER 1.0-beta1 (HKLM-x32\…\GNS3-ER) (Version: 1.0-beta1 - )
GOM Player (HKLM-x32\…\GOM Player) (Version: 2.2.57.5189 - Gretech Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 55.0.2883.87 - Google Inc.)
Google Talk Plugin (HKLM-x32\…\{F9B579C2-D854-300A-BE62-A09EB9D722E4}) (Version: 5.41.3.0 - Google)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
HandBrake 0.10.0 (HKLM-x32\…\HandBrake) (Version: 0.10.0 - )
HowToGuide (x32 Version: 1.0.1.0 - Brother Industries Ltd.) Hidden
HP Photosmart 6510 series Basic Device Software (HKLM\…\{1952AED6-2908-418F-B9D8-AC359651F92D}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Support Solutions Framework (HKLM-x32\…\{F6A11738-3EE4-4573-AEA5-6CD5D491C167}) (Version: 12.5.32.203 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Icecream Screen Recorder version 3.61 (HKLM-x32\…\{7ADEC622-3230-4C9A-9DCE-9BD462B74095}_is1) (Version: 3.61 - Icecream Apps)
Intel Driver Update Utility (HKLM-x32\…\{ca4bc3a8-b99c-4416-90d8-351a8ceab458}) (Version: 2.2.0.2 - Intel)
Intel(R) Driver Update Utility 2.2 (x32 Version: 2.2.0.1 - Intel) Hidden
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.1930 - Intel Corporation)
Intel(R) Management Engine Interface (HKLM\…\HECI) (Version:  - Intel Corporation)
Intel® Active Management Technology (HKLM\…\MESOL) (Version:  - Intel Corporation)
iTunes (HKLM\…\{81C96689-EA5B-4B7D-A04F-16326EC51BC2}) (Version: 12.5.4.42 - Apple Inc.)
Java 8 Update 91 (64-bit) (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F86418091F0}) (Version: 8.0.910.14 - Oracle Corporation)
Java 8 Update 91 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.14 - Oracle Corporation)
Java SE Development Kit 8 Update 51 (64-bit) (HKLM\…\{64A3A4F4-B792-11D6-A78A-00B0D0180510}) (Version: 8.0.510.16 - Oracle Corporation)
Kaspersky Security Scan (HKLM-x32\…\InstallWIX_{D1282694-0693-41A8-ABC1-6D1FFC1F65C5}) (Version: 16.0.0.1344 - Kaspersky Lab)
Kaspersky Security Scan (x32 Version: 16.0.0.1344 - Kaspersky Lab) Hidden
Kaspersky Software Updater Beta (HKLM-x32\…\InstallWIX_{94C8D443-1D07-4E6D-A9EB-FDBA45A839D8}) (Version: 1.5.2.228 - Kaspersky Lab)
Kaspersky Software Updater Beta (x32 Version: 1.5.2.228 - Kaspersky Lab) Hidden
K-Lite Codec Pack 9.2.0 (Basic) (HKLM-x32\…\KLiteCodecPack_is1) (Version: 9.2.0 - )
LEGO Digital Designer (HKLM-x32\…\New LEGO Digital Designer) (Version:  - LEGO A/S)
LEGO MINDSTORMS NXT - English Language Pack (HKLM-x32\…\{53753510-7620-4D2B-9C0B-111F871615D9}) (Version: 2.0.100.0 - The LEGO Group)
LEGO MINDSTORMS NXT Driver for x64 (HKLM\…\{74E85F31-573F-45BF-8939-4D2BCDCC2083}) (Version: 1.17.770 - LEGO)
LEGO MINDSTORMS NXT Migration Package (HKLM-x32\…\{6C1D47CC-682C-4673-8CA8-DEE659628599}) (Version: 1.2.8.0 - LEGO)
LEGO MINDSTORMS NXT Software v2.0 (HKLM-x32\…\{CB263F8D-EF2D-4EB5-A368-A27056EE92D4}) (Version: 2.0.108.0 - LEGO)
LEGO Minifigures Online (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\423b93224c69643b) (Version: 1.0.0.0 - Funcom)
MakeMKV v1.8.10 (HKLM-x32\…\MakeMKV) (Version: v1.8.10 - GuinpinSoft inc)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Media Foundation FLAC Codec (HKLM-x32\…\{5B47D5CC-38D3-4853-9A9E-AD1C7C717D40}) (Version: 1.4.1.0 - Alexander Demidov)
Microcular (HKLM-x32\…\InstallShield_{2CBD0ADE-0EB2-491A-BDF8-17A738CFE264}) (Version: 0.1.3.5.0 - PC Camera)
Microcular (x32 Version: 0.1.3.5.0 - PC Camera) Hidden
Microsoft Office XP Standard for Students and Teachers (HKLM-x32\…\{913D0409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411 (HKLM-x32\…\{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}) (Version: 9.0.30411 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Minecraft (HKLM-x32\…\{1C16BCA3-EBC1-49F6-8623-8FBFB9CCC872}) (Version: 1.0.3.0 - Mojang)
Motorola Mobile Drivers Installation 6.4.0 (HKLM\…\{27986EDD-C9EC-4B52-B92F-06D073F0AA52}) (Version: 6.4.0 - Motorola Mobility LLC)
Movavi Video Converter 15 (HKLM-x32\…\Movavi Video Converter 15) (Version: 15.3.0 - Movavi)
Mozilla Firefox 51.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 51.0.1 (x86 en-US)) (Version: 51.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 51.0.1.6234 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
NetworkRepairTool (x32 Version: 1.2.11.0 - Brother Insutries Ltd.) Hidden
Next Video Converter version 4.0.3 (HKLM-x32\…\{752EC6FD-1CEB-409B-AEF5-A297943102EA}_is1) (Version: 4.0.3 - NextVideoSoft Inc.)
Open Broadcaster Software (HKLM-x32\…\Open Broadcaster Software) (Version:  - )
OpenAL (HKLM-x32\…\OpenAL) (Version:  - )
OpenOffice.org 3.4 (HKLM-x32\…\{51071D66-D034-4239-94E0-723FCA10B6FE}) (Version: 3.4.9590 - OpenOffice.org)
Origin (HKLM-x32\…\Origin) (Version: 9.10.1.1501 - Electronic Arts, Inc.)
PC-FAXReceive (x32 Version: 1.3.5 - Brother) Hidden
PCFaxTx (x32 Version: 1.0.4.5 - Brother Industries Ltd.) Hidden
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
PhoneTrans 3.8.0 (HKLM-x32\…\{F0B50B3A-0C1F-43D8-BE90-70241B473114}}_is1) (Version: 3.8.0 - iMobie Inc.)
Pirate101 (HKLM-x32\…\{662140BE-138C-4DC1-B4CD-B62C6C855A25}) (Version: 1.0.0 - KingsIsle Entertainment, Inc.)
Pokémon Trading Card Game Online (HKLM-x32\…\{0D9304CD-1C83-4703-AFEF-0C46D1DB21F2}) (Version: 2.27.0 - The Pokémon Company International)
PrimoPDF – brought to you by Nitro PDF Software (HKLM-x32\…\PrimoPDF) (Version: 5 - Nitro PDF Software)
QuickTime (HKLM-x32\…\{0E64B098-8018-4256-BA23-C316A43AD9B0}) (Version: 7.72.80.56 - Apple Inc.)
RealDownloader (x32 Version: 17.0.10 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer Cloud (HKLM-x32\…\RealPlayer 17.0) (Version: 17.0.10 - RealNetworks)
RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden
RemoteSetup (x32 Version: 3.8.0.0 - Brother Industries Ltd.) Hidden
ROBLOX Player for Dykes-family (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version:  - ROBLOX Corporation)
ROBLOX Studio for Dykes-family (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version:  - ROBLOX Corporation)
SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden
ScannerUtilityInstaller (x32 Version: 1.0.0.0 - Brother) Hidden
Scrolls (HKLM-x32\…\{F7F74F7F-C458-4B7C-A6F4-80A28ED7AF0B}) (Version: 1.0.2.0 - Mojang)
SimCity™ (HKLM-x32\…\{F70FDE4B-8F86-4eb6-8C8E-636EC89F6419}) (Version: 4.0.86.0859 - Electronic Arts)
Skype™ 7.27 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.27.101 - Skype Technologies S.A.)
Snagit 12 (HKLM-x32\…\{8f4df1fe-49bb-4295-99d2-0e29ad8f99c6}) (Version: 12.2.0.1656 - TechSmith Corporation)
Snagit 12 (x32 Version: 12.2.0 - TechSmith Corporation) Hidden
SolarWinds Response Time Viewer (HKLM-x32\…\{5B415E10-D1C1-4E54-9061-AE0FB3D7F2B2}) (Version: 1.0.0.162 - SolarWinds)
Speccy (HKLM\…\Speccy) (Version: 1.30 - Piriform)
StatusMonitor (x32 Version: 1.12.4.0 - Brother Insutries Ltd.) Hidden
Steam (HKLM-x32\…\Steam) (Version: 2.10.91.91 - Valve Corporation)
Swivel (HKLM-x32\…\Swivel) (Version: 1.11 - Newgrounds.com, Inc.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Tachyon (HKLM-x32\…\Tachyon) (Version:  - )
TSview (HKLM-x32\…\TSview6.0.1.1) (Version: 6.0.1.1 - Tucsen)
Unity Web Player (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\UnityWebPlayer) (Version:  - Unity Technologies ApS)
UpdateService (x32 Version: 1.0.0 - RealNetworks, Inc.) Hidden
UsbRepairTool (x32 Version: 1.4.0.0 - Brother Insutries Ltd.) Hidden
Verizon Software Upgrade Assistant (x32 Version: 15.05.0601 - Motorola Mobility) Hidden
Verizon Wireless Software Upgrade Assistant for Motorola (HKLM-x32\…\{9BEDD987-AC68-44D2-8803-EC0650F6C43F}) (Version: 1.4.8 - Motorola Mobility)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.4 - VideoLAN)
VSO ConvertXToDVD (HKLM-x32\…\{CE1F93C0-4353-4C9D-84DA-AB4E7C63ED32}_is1) (Version: 5.2.0.13 - VSO Software)
VSO ConvertXToDVD 6 (HKLM-x32\…\{8FC36FA6-C508-44FB-B137-1CB46D8258B2}_is1) (Version: 6.0.0.20 - VSO Software)
War Thunder (HKLM-x32\…\Steam App 236390) (Version:  - Gaijin Entertainment)
War Thunder Launcher 1.0.1.542 (HKLM-x32\…\{ed8deea4-29fa-3932-9612-e2122d8a62d9}}_is1) (Version:  - Gaijin Entertainment)
WebM Project Directshow Filters (HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\webmdshow) (Version: 1.0.4.1 - WebM Project)
WinPcap 4.1.3 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2980 - Riverbed Technology, Inc.)
WinZip (HKLM-x32\…\WinZip) (Version:  - )
WinZip 20.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C24105}) (Version: 20.5.12118 - WinZip Computing, S.L. )
Wireshark 1.10.8 (64-bit) (HKLM-x32\…\Wireshark) (Version: 1.10.8 - The Wireshark developer community, hxxp://www.wireshark.org)
WM Capture 7 (HKLM-x32\…\WM Capture 7) (Version: 7.2 - AllAlex, Inc.)
Xiph.Org Open Codecs 0.85.17777 (HKLM-x32\…\Open Codecs) (Version: 0.85.17777 - Xiph.Org)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{0F22A205-CFB0-4679-8499-A6F44A80A208}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.25.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{1423F872-3F7F-4E57-B621-8B1A9D49B448}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.27.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{355EC88A-02E2-4547-9DEE-F87426484BD1}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.23.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{5C8C2A98-6133-4EBA-BBCC-34D9EA01FC2E}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.28.1\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{78550997-5DEF-4A8A-BAF9-D5774E87AC98}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.28.13\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{793EE463-1304-471C-ADF1-68C2FFB01247}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.29.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{90B3DFBF-AF6A-4EA0-8899-F332194690F8}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.24.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{C3BC25C0-FCD3-4F01-AFDD-41373F017C9A}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.26.9\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{CC182BE1-84CE-4A57-B85C-FD4BBDF78CB2}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.29.2\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{D0336C0B-7919-4C04-8CCE-2EBAE2ECE8C9}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.25.11\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{D1EDC4F5-7F4D-4B12-906A-614ECF66DDAF}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.28.15\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{DEE03C2B-0C0C-41A9-9877-FD4B4D7B6EA3}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Roblox\Versions\version-ecedadb4b6824712\RobloxProxy64.dll (ROBLOX Corporation)
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-3670747094-3822527020-2124027705-1001_Classes\CLSID\{FE498BAB-CB4C-4F88-AC3F-3641AAAF5E9E}\InprocServer32 -> C:\Users\Dykes-family\AppData\Local\Google\Update\1.3.24.7\psuser_64.dll => No File

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {0139817E-2129-4236-9767-A5FF602A4F86} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {022D831C-4C79-4DDA-9F46-CF0371090367} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {065474CC-462A-4655-AD08-DC636D9942E0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-10] (Adobe Systems Incorporated)
Task: {08847825-9E6B-4B60-9817-73E64A1366B9} - System32\Tasks\AdobeAAMUpdater-1.0-Dykes-family-PC-Dykes-family => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2015-08-05] (Adobe Systems Incorporated)
Task: {0DC1A74E-306A-49C1-A678-580AC24991A7} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {18F0FD4E-D27F-4AE1-9B83-67653E9FC8D7} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {1E43DC1F-C70B-49A8-89B2-614E6E97139D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {1F58AFFF-5592-43A4-9B78-40388A4F0A5B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-02] (Google Inc.)
Task: {27DCA93B-AEDC-4D90-84FB-5EF7EBAD80AD} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {2D6F92CB-856F-425A-97F5-5D2C52D01D6F} - System32\Tasks\{6BE163AC-EDCD-48B5-A135-C3F5B45D5D1A} => pcalua.exe -a C:\Users\Dykes-family\Desktop\forge-1.7.2-10.12.2.1147-installer-win.exe -d C:\Users\Dykes-family\Desktop
Task: {320BDC0A-EF88-4FD3-BAB6-FC598F9EA88F} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2016-09-26] (AVAST Software)
Task: {37A2592A-D481-4CB8-B9E8-AE25DB788E5F} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {3C535FA3-F3C8-4192-A9B9-0C96F7BC35F3} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {406C39D4-BA2D-42B1-832E-7AB9A006C855} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {4E39BF1F-2B0E-47CE-9AC5-7629DD54C78E} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {4EB7F5C1-1A88-4F85-B684-55AB9B7C33B9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {4EC0EEDB-2A66-48AB-A3F2-695EEF71AC8F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-500UA => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {52D96370-488D-42B6-B271-1F1A0C5B112C} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [2014-07-31] (TechSmith Corporation)
Task: {57DB7453-8984-4E9E-9DCC-404B4C344DBF} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {5AA49963-F35F-442E-8881-741CAFD090EC} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-01-11] (Microsoft Corporation)
Task: {5CF9FE4C-751A-436C-AA89-B6B2566BDDCF} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5D171B64-96B8-4580-AE31-EEC926E9F0A5} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-1001UA => C:\Users\Dykes-family\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {6737F9A0-A06E-4C6E-AD98-CA5F71F902E0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
Task: {6B97F6B8-A0D0-4887-8F24-8E98F5251554} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-1001Core => C:\Users\Dykes-family\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-29] (Google Inc.)
Task: {6F003481-05BD-4A88-92CD-C13CB03669E5} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {7921FE4E-B137-4317-B8D7-B7E4B1DAD97E} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {7BD0F194-9BA0-4699-8686-C9F6D5F80BF1} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {7C5A8F71-B8B1-419E-AFDD-658F0E54B672} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-500Core => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Task: {7F76106B-0A90-4685-9A0B-4350E5337EFF} - System32\Tasks\{263B73C8-4A13-4C80-9636-BECB24C98E9B} => pcalua.exe -a C:\Users\Dykes-family\Desktop\forge-1.7.10-10.13.2.1230-installer-win.exe -d C:\Users\Dykes-family\Desktop
Task: {7FCE95EF-BCB4-408E-8160-9A8BB6B9107B} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {82567FCD-E4FC-44F2-B11E-0C888D335A80} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3670747094-3822527020-2124027705-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-05-13] (RealNetworks, Inc.)
Task: {8B1AF5AF-FC9F-4A09-902A-14790701122C} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {8B6DC2BD-2B4B-482E-A8C4-1B6C976F6B69} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {9295111F-83F3-49D9-A822-2AD953A165D2} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {92AEEA2D-3B57-4643-B244-07E8911BAA9B} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {94A9047D-2E3E-4906-A746-D5C3A844018E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {9AAA0900-423D-4A14-BC4F-36F088BF5473} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {A2D856CB-39DD-4598-ADA7-FF17DA9757A3} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {A5753665-D293-450B-A5C2-D912643B0FB3} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {AAF3522D-11DB-4702-A2CA-5FDF5FC6557C} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {B1AAD89D-A96B-4389-A134-A00B2F2508A9} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {B662F054-CF05-4746-AA0E-2CBBF8D8156F} - System32\Tasks\Verizon Wireless Upgrade Assistant Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\VerizonWirelessUpgradeAssistantUpdate.exe [2016-03-21] ()
Task: {BAF9FB83-BB19-4DB8-B7A0-21323ACB18A0} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {BDA538FA-68DB-43F8-9A5E-7BB7622D916F} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {BE406590-1253-4020-8048-372BBB336DEF} - System32\Tasks\Verizon Wireless Upgrade Assistant Update Initial Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\VerizonWirelessUpgradeAssistantUpdate.exe [2016-03-21] ()
Task: {C221E675-9579-4BD4-97EB-0A763EE3E67E} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {C24ABE6C-BEA7-4CF5-941E-B6CB443FCC20} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3670747094-3822527020-2124027705-1001 => C:\Program Files (x86)\RealNetworks\RealDownloader\realupgrade.exe [2014-05-13] (RealNetworks, Inc.)
Task: {C3D3E5ED-C8CC-4BAA-9694-C789E2EB67DA} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3670747094-3822527020-2124027705-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-05-23] (RealNetworks, Inc.)
Task: {C612880E-7624-4F85-9819-7C7445260FF4} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3670747094-3822527020-2124027705-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2014-05-23] (RealNetworks, Inc.)
Task: {C739DADD-36F9-4FA9-ADC3-AB0144329D46} - System32\Tasks\arp_flush => C:\Program Files (x86)\hide.me VPN\FlushArpCache.exe
Task: {C8CA7CA5-EBBD-476F-818D-E27A76508C4F} - System32\Tasks\SafeZone scheduled Autoupdate 1462969116 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2016-09-06] (Avast Software)
Task: {CC136BC3-F63E-4563-9FA8-68F95C50B565} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {CECD283B-CEA2-4142-8A9E-60BFF7897A40} - System32\Tasks\{5C7ED580-D17B-441B-9CFC-D9071077D042} => pcalua.exe -a "C:\Users\Dykes-family\Desktop\New folder (2)\forge-1.8-11.14.0.1299-installer-win.exe" -d "C:\Users\Dykes-family\Desktop\New folder (2)"
Task: {D718FB89-0E45-4DD1-B6D6-B9594C909310} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D7B33869-F1A8-426D-9627-8624CBD8DCA7} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D893E8D2-D852-490C-96FC-83EAC9DDE087} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {DC62D376-60E0-4B4D-871C-ADA3204BBDE1} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {E0B88179-7894-4408-8C41-1FC44AAD136A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E2E7A0AB-7800-4F6B-A123-2AB2A632479E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-02] (Google Inc.)
Task: {E402D9F8-A3EF-4E2C-AAB7-82CEBED954A4} - \WinSATService -> No File <==== ATTENTION
Task: {E5674698-9C34-4E86-8E6E-C05B1E96920F} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {F396A6E3-9E65-4BEC-AE3D-B2E5E02535CA} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-345625499-1670360406-2532865610-500Core.job => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-345625499-1670360406-2532865610-500UA.job => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-500Core.job => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskUserS-1-5-21-3670747094-3822527020-2124027705-500UA.job => C:\Users\Administrator\AppData\Local\Google\Update\GoogleUpdate.exe

==================== Shortcuts =============================

(The entries could be listed to be restored or removed.)

==================== Loaded Modules (Whitelisted) ==============

2015-10-30 02:17 - 2015-10-30 02:17 - 00028672 _____ () C:\WINDOWS\SYSTEM32\efsext.dll
2015-10-30 02:18 - 2015-10-30 02:18 - 00185856 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-07-17 11:39 - 2015-09-01 08:41 - 00095008 _____ () C:\WINDOWS\System32\Primomonnt.dll
2016-10-05 18:17 - 2016-10-05 18:17 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-11-17 01:28 - 2016-11-17 01:28 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-05-24 13:30 - 2010-04-05 14:55 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2014-05-23 00:34 - 2014-05-23 00:34 - 00023552 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe
2014-05-13 12:10 - 2014-05-13 12:10 - 00039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
2016-11-08 16:28 - 2016-10-25 04:42 - 02656952 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-11-08 16:28 - 2016-10-25 04:42 - 02656952 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-01-11 15:55 - 2014-10-24 14:16 - 00721263 _____ () C:\Windows\SysWOW64\WSCM64.dll
2016-11-08 16:28 - 2016-10-24 23:44 - 00591360 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-12-17 15:48 - 2015-12-06 23:14 - 00093696 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\Windows.UI.Shell.SharedUtilities.dll
2016-07-13 13:11 - 2016-06-30 22:48 - 00472064 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2016-11-08 16:28 - 2016-10-24 23:49 - 07992832 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2016-11-08 16:28 - 2016-10-24 23:46 - 00936960 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2016-11-08 16:28 - 2016-10-24 23:45 - 02483200 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2016-11-08 16:28 - 2016-10-24 23:48 - 04089856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-09-26 06:55 - 2016-09-26 06:55 - 00169064 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-02-01 17:22 - 2017-02-01 17:22 - 04459608 _____ () C:\Program Files\AVAST Software\Avast\defs\17020101\algo.dll
2016-09-26 06:55 - 2016-09-26 06:55 - 00482928 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2015-12-15 13:38 - 2015-12-15 13:38 - 00326112 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\dblite.dll
2015-10-27 16:44 - 2015-10-27 16:44 - 00404952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\ipm_service.dll
2015-04-15 08:11 - 2015-04-15 08:11 - 00162816 _____ () C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\css_core.dll
2016-06-02 18:06 - 2016-06-02 18:06 - 45077376 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\libcef.dll
2016-09-26 06:55 - 2016-09-26 06:55 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:B3ED3AFF [290]

==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 21:34 - 2014-12-28 22:05 - 00001028 ____A C:\WINDOWS\system32\Drivers\etc\hosts

127.0.0.1                   activate.adobe.com
127.0.0.1                   practivate.adobe.com
127.0.0.1                   lmlicenses.wip4.adobe.com
127.0.0.1                   lm.licenses.adobe.com

==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Dykes-family\Pictures\Wallpaper\whale_sperm_whale.jpg
HKU\S-1-5-21-3670747094-3822527020-2124027705-1004\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Control Panel\Desktop\\Wallpaper ->
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Microsoft Office.lnk => C:\Windows\pss\Microsoft Office.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^RealPlayer Cloud Service UI.lnk => C:\Windows\pss\RealPlayer Cloud Service UI.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snagit 12.lnk => C:\Windows\pss\Snagit 12.lnk.CommonStartup
MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe"
MSCONFIG\startupreg: AdobeCS6ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
MSCONFIG\startupreg: DelaypluginInstall => C:\ProgramData\Wondershare\Video Converter Ultimate\DelayPluginI.exe
MSCONFIG\startupreg: DriveTheLife2013 => "C:\Program Files (x86)\DTLSoft\DriveTheLife\DriveTheLife.exe" /start
MSCONFIG\startupreg: Google Update => "C:\Users\Dykes-family\AppData\Local\Google\Update\GoogleUpdate.exe" /c
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: MSC => "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
MSCONFIG\startupreg: uTorrent => "C:\Users\Dykes-family\AppData\Roaming\uTorrent\uTorrent.exe"  /MINIMIZED
MSCONFIG\startupreg: Wondershare Helper Compact.exe => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe
HKLM\…\StartupApproved\StartupFolder: => "FAH.lnk"
HKLM\…\StartupApproved\StartupFolder: => "WinZip Preloader.lnk"
HKLM\…\StartupApproved\StartupFolder: => "Update Notifier.lnk"
HKLM\…\StartupApproved\Run: => "AdobeAAMUpdater-1.0"
HKLM\…\StartupApproved\Run: => "iTunesHelper"
HKLM\…\StartupApproved\Run32: => "Acrobat Assistant 8.0"
HKLM\…\StartupApproved\Run32: => "Adobe Acrobat Speed Launcher"
HKLM\…\StartupApproved\Run32: => "BrHelp"
HKLM\…\StartupApproved\Run32: => "ControlCenter4"
HKLM\…\StartupApproved\Run32: => "ProductUpdater"
HKLM\…\StartupApproved\Run32: => "BrStsMon00"
HKLM\…\StartupApproved\Run32: => "PowerDVD16Agent"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "Google Update"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "Steam"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "Creative WebCam Tray"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "GoogleDriveSync"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "Icecream_Screen_Recorder_Prefetcher"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\…\StartupApproved\Run: => "Skype"
HKU\S-1-5-21-3670747094-3822527020-2124027705-1004\…\StartupApproved\Run: => "Steam"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [vm-monitoring-nb-session] => LPort=139
FirewallRules: [MSMQ-In-TCP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => LPort=808
FirewallRules: [{93CB8957-282E-4F00-98A3-62B796079D9C}] => c:\program files (x86)\pc-faxreceive\brengineprocess.exe
FirewallRules: [{8414DDD4-F84A-42F2-ADF2-5E2C70F00D05}] => c:\program files (x86)\pc-faxreceive\brengineprocess.exe
FirewallRules: [{22358ADE-58E7-4E60-AADD-AFA280131246}] => C:\Users\Dykes-family\AppData\Local\Temp\7zS156B\HPDiagnosticCoreUI.exe
FirewallRules: [{891531CA-F0DF-40FA-81D9-FD71DDA6E1C0}] => C:\Users\Dykes-family\AppData\Local\Temp\7zS156B\HPDiagnosticCoreUI.exe
FirewallRules: [{640CA6B2-5D3A-425A-ACA5-20340E77E652}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{CA7AC0A9-6FF9-4067-8B42-C48431DD1682}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{55B78628-311F-4950-83DF-40B2E66CA14E}] => C:\WarThunder\bpreport.exe
FirewallRules: [{C1A0EDE0-9BA8-4401-B544-D0ED6AD3BEC2}] => C:\WarThunder\bpreport.exe
FirewallRules: [{11870A34-94DC-4C1A-B669-015F096F0B36}] => C:\WarThunder\aces.exe
FirewallRules: [{17C55341-3723-4250-9745-F314BBBB5201}] => C:\WarThunder\aces.exe
FirewallRules: [{3DA07D15-9FDF-4547-84AC-8D904ED15335}] => C:\WarThunder\launcher.exe
FirewallRules: [{4256A970-570A-4470-83F2-3D3ACEBAD6F4}] => C:\WarThunder\launcher.exe
FirewallRules: [UDP Query User{626EEEFD-EAA8-4A84-B7FA-3D63C8D7966E}C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe] => C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe
FirewallRules: [TCP Query User{975E3E53-282D-4E91-A674-DD998EF4851B}C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe] => C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe
FirewallRules: [UDP Query User{A1AD25C2-AFDF-4C5D-97CC-E66FD3411130}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => C:\program files\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [TCP Query User{B5878C78-573C-404A-9991-489EFD57D3D1}C:\program files\java\jre1.8.0_51\bin\javaw.exe] => C:\program files\java\jre1.8.0_51\bin\javaw.exe
FirewallRules: [UDP Query User{6B1F324E-5863-4339-A767-A2920B74098E}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [TCP Query User{2F0125C2-C8AF-497D-9F19-C3BE7352F570}C:\program files (x86)\java\jre1.8.0_45\bin\java.exe] => C:\program files (x86)\java\jre1.8.0_45\bin\java.exe
FirewallRules: [{10C67387-6A88-4E96-BE85-C60F69154762}] => C:\Program Files\HP\HP Photosmart 6510 series\Bin\DeviceSetup.exe
FirewallRules: [{195B4DFF-C4D9-44C3-AA27-B2823F6F0ABD}] => C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{7C5BBEB5-3312-4751-B92A-AA8309895A12}] => C:\Program Files\HP\HP Photosmart 6510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{D1DA57C6-8F68-47F8-BE29-751CFE515C1A}] => c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe
FirewallRules: [TCP Query User{3279BD8A-6CF7-4195-B26E-9A21D2790878}C:\users\dykes-family\appdata\local\apps\2.0\70bgzxml.hjv\tjcjyw9d.02h\lego…app_8c161902ccf9ca2a_0001.0000_1277cc1e021b3644\lmo.exe] => C:\users\dykes-family\appdata\local\apps\2.0\70bgzxml.hjv\tjcjyw9d.02h\lego…app_8c161902ccf9ca2a_0001.0000_1277cc1e021b3644\lmo.exe
FirewallRules: [UDP Query User{2C7ED095-2D24-46AB-A166-6E8AD6742EED}C:\users\dykes-family\appdata\local\apps\2.0\70bgzxml.hjv\tjcjyw9d.02h\lego…app_8c161902ccf9ca2a_0001.0000_1277cc1e021b3644\lmo.exe] => C:\users\dykes-family\appdata\local\apps\2.0\70bgzxml.hjv\tjcjyw9d.02h\lego…app_8c161902ccf9ca2a_0001.0000_1277cc1e021b3644\lmo.exe
FirewallRules: [{C89F6907-27D2-4E7C-B388-5A92FBB8674F}] => C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{244303D6-F0AD-4D3A-AAEA-6C492991A937}] => C:\Program Files (x86)\Adobe\Adobe Flash Builder 4.6\FlashBuilder.exe
FirewallRules: [{44DBD89C-1F2F-4C00-9275-3D2C3D80C2D7}] => LPort=7935
FirewallRules: [TCP Query User{2BEBF0D7-7ECD-42EB-B153-84D354DF6F8D}C:\program files\gns3-er\gns3server.exe] => C:\program files\gns3-er\gns3server.exe
FirewallRules: [UDP Query User{BDA1B462-AD21-440D-BA13-C5A3232C6CA4}C:\program files\gns3-er\gns3server.exe] => C:\program files\gns3-er\gns3server.exe
FirewallRules: [{E6100552-B05E-46C8-B032-A3D056644D53}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{C44F31EF-E6D7-494F-A934-E90A6EC97D8D}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{3DBED0E6-4736-4EE1-8113-1F56CD3749F7}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8240F37C-EACE-4FE7-93BA-89DB64D9CC55}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{2120A7C7-6484-4D6F-94AB-E8F612870FDA}] => C:\Users\Dykes-family\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{BF34CF2A-DA6E-44D0-B556-FE60D8D3726D}] => C:\Users\Dykes-family\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{BC16E2C4-40F1-4C49-AF00-FC4AD75C1D4A}C:\users\dykes-family\desktop\seths stuff\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\dykes-family\desktop\seths stuff\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{DA451EFC-7E7C-4AE2-84FE-0FFC52571015}C:\users\dykes-family\desktop\seths stuff\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\dykes-family\desktop\seths stuff\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [{C39D127C-9B67-4C26-A01B-AFD741D9F7DD}] => LPort=8298
FirewallRules: [TCP Query User{CB5E9AF7-FD1E-4FD1-B17E-90C995589E2F}C:\program files (x86)\wondershare\video converter ultimate\dscheck.exe] => C:\program files (x86)\wondershare\video converter ultimate\dscheck.exe
FirewallRules: [UDP Query User{4E1F072A-4708-4493-A7A3-AD7C44EDC666}C:\program files (x86)\wondershare\video converter ultimate\dscheck.exe] => C:\program files (x86)\wondershare\video converter ultimate\dscheck.exe
FirewallRules: [{5B94D5FF-CA15-47BD-8141-37409FECDF2C}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{610069C6-9906-4652-99D4-A9498B68E2A4}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{80DC156E-D699-46B8-A750-E05CB3609C86}C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe] => C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe
FirewallRules: [UDP Query User{AE76B06D-C6F6-40B4-B621-790C35EC236D}C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe] => C:\program files (x86)\cisco systems\ciscocp\tools\jre6\bin\ciscocpengine.exe
FirewallRules: [TCP Query User{9680A60F-BC7B-4580-B0DA-EEA9617BAEFB}C:\program files (x86)\java\jre1.8.0_31\bin\jp2launcher.exe] => C:\program files (x86)\java\jre1.8.0_31\bin\jp2launcher.exe
FirewallRules: [UDP Query User{EEAA9A59-21DB-477C-AD1B-D9467481769C}C:\program files (x86)\java\jre1.8.0_31\bin\jp2launcher.exe] => C:\program files (x86)\java\jre1.8.0_31\bin\jp2launcher.exe
FirewallRules: [TCP Query User{55B8E8A5-FAF6-480B-8F91-3B1CDB10DF72}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{6166A3F0-EA04-4910-8AC5-6A19F084C128}C:\program files (x86)\mozilla firefox\firefox.exe] => C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{8851F2C4-026D-482C-BE7F-D0C100478D4E}] => C:\Program Files (x86)\DTLSoft\DriveTheLife\DriveTheLife.exe
FirewallRules: [{E3C1D997-B158-4911-8D62-3C9F3915E65C}] => C:\Program Files (x86)\DTLSoft\DriveTheLife\DTLService.exe
FirewallRules: [{873261E8-10A7-4EFF-8F6C-197F77A5109F}] => C:\Program Files (x86)\DTLSoft\DriveTheLife\download\MiniThunderPlatform.exe
FirewallRules: [TCP Query User{0CFD8F0E-AE65-4BF8-A995-B781C328D926}C:\users\dykes-family\desktop\seths stuff\music\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\dykes-family\desktop\seths stuff\music\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [UDP Query User{2EC94120-BC54-428A-90DA-E753C17A674D}C:\users\dykes-family\desktop\seths stuff\music\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => C:\users\dykes-family\desktop\seths stuff\music\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe
FirewallRules: [TCP Query User{DD3E71B0-65A8-4E2D-9921-96B17A48A7D2}D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe] => D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe
FirewallRules: [UDP Query User{DDE7BBD4-5E56-41D2-AD2D-E0612204BEBC}D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe] => D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe
FirewallRules: [{02C41359-3DDE-404D-BA97-B0FA80742415}] => D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe
FirewallRules: [{6381D3D2-AB5C-4C86-8C1C-F5F05DA69E43}] => D:\easysetupassistant\tl-wdr3600\easysetupassistant.exe
FirewallRules: [{865E393D-5AB9-412F-9CE0-4C0A5538A8F6}] => LPort=80
FirewallRules: [{AA75C8A6-47E3-4AD5-A1D8-48A79D2E7331}] => LPort=443
FirewallRules: [{D9D099F3-C8EA-4B26-B093-FC7F61B69A3E}] => LPort=20010
FirewallRules: [{80229565-E031-435B-9B6C-9A259CFB299C}] => LPort=3478
FirewallRules: [{914A9E68-EC11-4034-BBC4-4A6C4E4F7EF2}] => LPort=7850
FirewallRules: [{310B075D-FF80-41F0-BF31-0596A45C0917}] => LPort=7852
FirewallRules: [{807A6E80-C588-4797-AEA1-5A027C07F440}] => LPort=7853
FirewallRules: [{8E3FD9F2-3ACD-41B9-BFEE-EF4A036A63DA}] => LPort=27022
FirewallRules: [{91891ED2-DA7A-4919-8C1B-C147BC6483B9}] => LPort=6881
FirewallRules: [{0D90B2A6-94CD-4098-BF7B-DD5693F11C66}] => LPort=33333
FirewallRules: [{57C9EF02-3E86-4248-AEFA-C6159386CC5B}] => LPort=20443
FirewallRules: [{4F7F518E-A93A-45EB-B6A6-3BC6A1960FAB}] => LPort=8090
FirewallRules: [TCP Query User{20E6541F-E596-4A54-A54C-00E8D6C93255}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [UDP Query User{C502801E-9DA3-4F65-9E91-E97D80B5E8C3}C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe] => C:\program files (x86)\java\jre1.8.0_45\bin\javaw.exe
FirewallRules: [{92906DE0-F1B0-4648-8D4E-2E3D78A10F22}] => C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{86996E66-E9A1-432A-945B-B338E10A353A}] => C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{65E5CFE6-5768-42A7-9F82-59629DFD20E3}] => C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{6D6B164F-D148-4B4C-9988-4DA791202945}] => C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{70DAAA0F-CC2B-4D21-8AB9-FEFACA764741}] => C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{ED454976-1DF5-433C-8F97-2D747416E6DC}] => C:\Program Files (x86)\Steam\steamapps\common\War Thunder\launcher.exe
FirewallRules: [{B81D17EF-FCC3-41F8-869C-F8658351628D}] => C:\Program Files (x86)\Steam\steamapps\common\War Thunder\launcher.exe
FirewallRules: [TCP Query User{51B22E85-3F01-4951-A5F5-5F1B2875BE05}C:\users\dykes-family\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe] => C:\users\dykes-family\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe
FirewallRules: [UDP Query User{49000193-E041-4F08-BF0C-6C79A947DA38}C:\users\dykes-family\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe] => C:\users\dykes-family\appdata\local\roblox\versions\version-337f2aa823bb4833\robloxstudiobeta.exe
FirewallRules: [{82A884C7-3FFC-4438-A3CB-2D4F65587996}] => C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{82B68183-1E01-4F8A-BDFE-97766F3B0184}] => C:\Program Files (x86)\Origin Games\SimCity\SimCity\SimCity.exe
FirewallRules: [{1B642415-0FAB-46AD-A201-018112283132}] => C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD.exe
FirewallRules: [{7A756677-0870-4605-96B7-E56AFD1C9F5A}] => C:\Program Files (x86)\CyberLink\PowerDVD16\Kernel\DMS\CLMSServerPDVD16.exe
FirewallRules: [{CE3BBDFD-BFDC-41BB-AB41-269DCC225EA2}] => C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD16Agent.exe
FirewallRules: [{58DAB53E-255C-4046-A3F4-69627B6FAB30}] => C:\Program Files (x86)\CyberLink\PowerDVD16\Movie\PowerDVDMovie.exe
FirewallRules: [{483C7A19-8F63-4D3B-AC27-7DE031973DAA}] => C:\Program Files (x86)\CyberLink\PowerDVD16\CastingStation.exe
FirewallRules: [{987BFF37-FFA2-4947-9FFD-DBBD88DD37C3}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7EF3FD59-278F-40B1-905B-D7134A1C3623}] => C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{21FDE955-2857-4801-A151-BAEE2B2EE3C9}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CCD7BADC-AD6D-4F5E-A236-9A5CEED7F43A}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{72AF883C-6CA0-471B-B2B6-6CE72B1C03A5}] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{383F7CA9-72EC-4BCF-B229-B3B4BD6BA33C}] => C:\Program Files\iTunes\iTunes.exe

==================== Restore Points =========================

20-01-2017 16:59:07 Scheduled Checkpoint
29-01-2017 05:37:54 Scheduled Checkpoint
31-01-2017 18:08:26 JRT Pre-Junkware Removal

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/31/2017 06:11:16 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\CyberLink\PowerDVD16\Kernel\DMS\CLMSMediaInfoPDVD16.exe".
Dependent Assembly CLMSMediaInfo.X,type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (01/31/2017 06:10:58 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: plugin-container.exe, version: 51.0.1.6234, time stamp: 0x5888f707
Faulting module name: mozglue.dll, version: 51.0.1.6234, time stamp: 0x5888f27e
Exception code: 0x80000003
Fault offset: 0x0000ec83
Faulting process id: 0x2e4
Faulting application start time: 0x01d27c16296b1ad2
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\mozglue.dll
Report Id: dc7491b1-2aef-45b9-accb-72bd9c5c2b41
Faulting package full name:
Faulting package-relative application ID:

Error: (01/31/2017 06:08:59 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.

System Error:
Access is denied.
.

Error: (01/31/2017 06:07:53 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\CyberLink\PowerDVD16\Kernel\DMS\CLMSMediaInfoPDVD16.exe".
Dependent Assembly CLMSMediaInfo.X,type="win32",version="1.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.

Error: (01/31/2017 06:04:05 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program Speccy-setup.exe version 1.0.0.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.

Process ID: 153c

Start Time: 01d27c164136e745

Termination Time: 4294967295

Application Path: C:\Users\Dykes-family\Downloads\Speccy-setup.exe

Report Id: 8e19f170-e809-11e6-9c3a-001e4fddf430

Faulting package full name:

Faulting package-relative application ID:

Error: (01/31/2017 11:49:23 AM) (Source: LMS) (EventID: 2) (User: NT AUTHORITY)
Description: LMS Service lost connection to HECI driver

Error: (01/31/2017 11:47:23 AM) (Source: LMS) (EventID: 2) (User: NT AUTHORITY)
Description: LMS Service lost connection to HECI driver

Error: (01/31/2017 11:43:28 AM) (Source: LMS) (EventID: 2) (User: NT AUTHORITY)
Description: LMS Service lost connection to HECI driver

Error: (01/30/2017 03:32:32 PM) (Source: LMS) (EventID: 2) (User: NT AUTHORITY)
Description: LMS Service lost connection to HECI driver

Error: (01/29/2017 08:04:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: ksu.exe, version: 1.5.2.228, time stamp: 0x57447574
Faulting module name: ksu.exe, version: 1.5.2.228, time stamp: 0x57447574
Exception code: 0xc000041d
Fault offset: 0x00045146
Faulting process id: 0x27d8
Faulting application start time: 0x01d27a77bbd96b45
Faulting application path: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater Beta\ksu.exe
Faulting module path: C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater Beta\ksu.exe
Report Id: d7c83343-25a8-411a-8d65-23f0cec7df03
Faulting package full name:
Faulting package-relative application ID:


System errors:
=============
Error: (02/01/2017 09:19:21 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (02/01/2017 09:19:15 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (02/01/2017 09:19:09 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (02/01/2017 09:19:03 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (02/01/2017 09:18:57 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (02/01/2017 09:18:51 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (02/01/2017 09:18:48 PM) (Source: Service Control Manager) (EventID: 7046) (User: )
Description: The following service has repeatedly stopped responding to service control requests: Windows Search

Contact the service vendor or the system administrator about whether to disable this service until the problem is identified.

You may have to restart the computer in safe mode before you can disable the service.

Error: (02/01/2017 09:18:45 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (02/01/2017 09:18:39 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.

Error: (02/01/2017 09:18:33 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.


CodeIntegrity:
===================================
  Date: 2017-01-13 03:50:09.567
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2017-01-12 03:22:43.782
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2017-01-12 03:07:14.870
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-15 03:24:16.253
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-14 05:39:19.255
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-14 04:28:37.390
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\efswrt.dll because the set of per-page image hashes could not be found on the system.

  Date: 2016-12-02 09:18:32.288
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-12-02 09:18:32.243
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-12-02 09:18:32.183
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.

  Date: 2016-12-02 09:18:31.921
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM)2 Duo CPU E4500 @ 2.20GHz
Percentage of memory in use: 30%
Total physical RAM: 8052.61 MB
Available physical RAM: 5624.51 MB
Total Virtual: 8052.61 MB
Available Virtual: 5850.47 MB

==================== Drives ================================

Drive c: (Windows) (Fixed) (Total:463.73 GB) (Free:9.1 GB) NTFS
 

—

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-02-01 21:21:10
—————————–
21:21:10.847    OS Version: Windows x64 6.2.9200
21:21:10.847    Number of processors: 2 586 0xF0D
21:21:10.847    ComputerName: DYKES-FAMILY-PC  UserName: Dykes-family
21:21:12.034    Initialize success
21:21:12.159    VM: initialized successfully
21:21:12.159    VM: Intel CPU virtualization not supported
21:21:21.351    AVAST engine defs: 17020101
21:21:34.947    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3
21:21:34.947    Disk 0 Vendor: HITACHI_HUA7250SBSUN500G_0814J84K7F GK6OA90A Size: 476940MB BusType: 3
21:21:35.103    Disk 0 MBR read successfully
21:21:35.103    Disk 0 MBR scan
21:21:35.118    Disk 0 Windows 7 default MBR code
21:21:35.134    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS         1177 MB offset 2048
21:21:35.134    Disk 0 Partition 2 00     07    HPFS/NTFS NTFS       474862 MB offset 2412544
21:21:35.165    Disk 0 Partition 3 00     27 Hidden NTFS WinRE NTFS          450 MB offset 974929920
21:21:35.306    Disk 0 scanning C:\WINDOWS\system32\drivers
21:21:47.213    Service scanning
21:22:14.936    Modules scanning
21:22:14.936    Disk 0 trace - called modules:
21:22:14.952    ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS pciide.sys hal.dll PCIIDEX.SYS atapi.sys
21:22:14.952    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffe001ccaf2300]
21:22:14.968    3 CLASSPNP.SYS[fffff801da717d95] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP2T0L0-3[0xffffe001cc5ff060]
21:22:15.781    AVAST engine scan C:\WINDOWS
21:22:18.609    AVAST engine scan C:\WINDOWS\system32
21:25:13.427    AVAST engine scan C:\WINDOWS\system32\drivers
21:25:28.678    AVAST engine scan C:\Users\Dykes-family
22:45:38.045    File: C:\Users\Dykes-family\Documents\Kingston Drive\Centurylink\Downloads\PDFReaderSetup.exe  **INFECTED** Win32:Evo-gen [Susp]
22:55:17.553    AVAST engine scan C:\ProgramData
23:06:40.190    Disk 0 statistics 11605672/0/0 @ 1.51 MB/s
23:06:40.198    Scan finished successfully
06:41:15.911    Disk 0 MBR has been saved successfully to "C:\Users\Dykes-family\Downloads\Security-Malware Protection\MBR.dat"
06:41:15.985    The log file has been saved successfully to "C:\Users\Dykes-family\Downloads\Security-Malware Protection\aswMBR-2-2-17.txt"


 

The scans did fine….we'll continue

Looking at the logs it appears that AVAST and Kaspersky are both on the machine. I can't tell if Kaspersky is just a online scanner at this point so I think it best we remove it unless, this is a tool you paid for
If it is, then please uninstall Avast. We can only have 1 antivirus on the computer.

Kaspersky Security Scan (HKLM-x32\…\InstallWIX_{D1282694-0693-41A8-ABC1-6D1FFC1F65C5}) (Version: 16.0.0.1344 - Kaspersky Lab)
Kaspersky Security Scan (x32 Version: 16.0.0.1344 - Kaspersky Lab) Hidden
Kaspersky Software Updater Beta (HKLM-x32\…\InstallWIX_{94C8D443-1D07-4E6D-A9EB-FDBA45A839D8}) (Version: 1.5.2.228 - Kaspersky Lab)
Kaspersky Software Updater Beta (x32 Version: 1.5.2.228 - Kaspersky Lab) Hidden

~~

C:\Users\Dykes-family\Downloads\Security-Malware Protection
We're going to have to move FRST to desktop.
~~
Please go to your downloads folder, locate Security-Malware Protection next locate Farbar Recovery Scan Tool, right click and select CUT
Go to an open spot on your desktop, right click and select PASTE
You should now have Farbar Recovery Scan Tool on your desktop.


Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK)
or this way ==> Press the windows key [external image: Windows_Logo_key.gif]+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

and copy and paste the text present inside the quote box below:
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)


[external image: FRSTfix.JPG]

 

start
CreateRestorePoint:
CloseProcesses:
HKLM-x32\…\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-04-25] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-25] (Oracle Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-25] (Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-25] (Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-25] (Oracle Corporation)
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\pdf.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\gcswf32.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll => No File
CHR Plugin: (Java Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
HR HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\DYKES-~1\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx


Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
~~~~~~~~~~~~~~~~~~~~~~~~

[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
    In order to use AdwCleaner, you have to agree the Eula:
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
– File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Please download Junkware Removal Tool
or from here http://downloads.malwarebytes.org/file/jrt
to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
~~
please post
Fixlog.txt
AdwCleaner[C1].txt
JRT.txt

Here are the logs you asked for.

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 29-01-2017
Ran by [removed] (02-02-2017 19:20:34) Run:2
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
HKLM-x32\…\Run: [ProductUpdater] => C:\Program Files (x86)\Common Files\Freemake Shared\ProductUpdater\ProductUpdater.exe
BHO: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_91\bin\ssv.dll [2016-04-25] (Oracle Corporation)
BHO: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-25] (Oracle Corporation)
BHO-x32: Java Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-04-25] (Oracle Corporation)
BHO-x32: Java Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-25] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-25] (Oracle Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-04-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-04-25] (Oracle Corporation)
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\ppGoogleNaClPluginChrome.dll => No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\pdf.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\55.0.2883.87\gcswf32.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_43.dll => No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll => No File
CHR Plugin: (Java Deployment Toolkit 7.0.510.13) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll => No File
CHR Plugin: (Java Platform SE 7 U51) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll => No File
HR HKU\S-1-5-21-3670747094-3822527020-2124027705-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [apdfllckaahabafndbhieahigkjlhalf] - C:\Users\DYKES-~1\AppData\Local\Google\Drive\user_default\apdfllckaahabafndbhieahigkjlhalf_live.crx

 

 

 

 

# AdwCleaner v6.043 - Logfile created 02/02/2017 at 20:08:52
# Updated on 27/01/2017 by Malwarebytes
# Database : 2017-02-02.4 [Local]
# Operating System : Windows 10 Pro  (X64)
# Username : Dykes-family - DYKES-FAMILY-PC
# Running from : C:\Users\Dykes-family\Desktop\adwcleaner_6.043.exe
# Mode: Scan
# Support : https://www.malwarebytes.com/support



***** [ Services ] *****

No malicious services found.


***** [ Folders ] *****

No malicious folders found.


***** [ Files ] *****

No malicious files found.


***** [ DLL ] *****

No malicious DLLs found.


***** [ WMI ] *****

No malicious keys found.


***** [ Shortcuts ] *****

No infected shortcut found.


***** [ Scheduled Tasks ] *****

No malicious task found.


***** [ Registry ] *****

No malicious registry entries found.


***** [ Web browsers ] *****

No malicious Firefox based browser items found.
No malicious Chromium based browser items found.

*************************

C:\AdwCleaner\AdwCleaner[C0].txt - [2775 Bytes] - [14/08/2016 18:29:03]
C:\AdwCleaner\AdwCleaner[C2].txt - [5115 Bytes] - [10/12/2016 11:49:30]
C:\AdwCleaner\AdwCleaner[C3].txt - [1598 Bytes] - [02/02/2017 19:46:36]
C:\AdwCleaner\AdwCleaner[R0].txt - [1663 Bytes] - [18/05/2015 20:11:53]
C:\AdwCleaner\AdwCleaner[S0].txt - [2888 Bytes] - [14/08/2016 18:26:40]
C:\AdwCleaner\AdwCleaner[S1].txt - [4819 Bytes] - [09/12/2016 14:48:36]
C:\AdwCleaner\AdwCleaner[S2].txt - [1697 Bytes] - [02/02/2017 19:39:43]
C:\AdwCleaner\AdwCleaner[S3].txt - [1520 Bytes] - [02/02/2017 20:08:52]

########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1593 Bytes] ##########
 

 

 

 

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.0 (12.05.2016)
Operating System: Windows 10 Pro x64
Ran by [removed] (Administrator) on Thu 02/02/2017 at 19:54:37.74
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




File System: 2

Failed to delete: C:\Program Files (x86)\coupons (Folder)
Failed to delete: C:\Program Files (x86)\freerip (Folder)



Registry: 0





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 02/02/2017 at 19:58:46.69
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

Ran by [removed] (02-02-2017 19:20:34) Run:2
Hope run 1 worked better then run 2

Since you already have Malwarebytes Anti-Malware on the machine
let's update it and run a scan

Open MalwareBytes
  • On the Dashboard click on Update Now
  • Under SETTINGS…..APPLICATIONS leave everything at default
  • Under SETTINGS…..PROTECTION make sure AUTOMATIC QUARANTINE is on.
  • Then go to the Dashboard and click on SCAN NOW
  • When the scan is finished click on EXPORT SUMMARY……COPY TO CLIPBOARD
  • Then come back to this thread and and under REPLY TO THIS TOPIC, right click in the reply and select Paste
  • Then click on POST
  • Exit Malwarebytes
  • ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`
How is the computer now?

It's doing poorly. Although I already have Malwarebytes Antimalware on my computer, it won't open. A window pops up and asks me if i want this program to make changes to the computer, and I click yes, then it goes away and for a moment I see an hourglass; then it disappears and nothing else happens. I see its small icon appear by the clock, but clicking on it does nothing, nor does trying to access it though Apps or any other way. I turned off my virus protection - Avast - but that didn't help. I was going to uninstall it, then reinstall it, but I also can't get Uninstall to open - and this was after a fresh reboot!

 

The only other thing I can think of is to start in safe mode. If you want me to do that, remind me how to do it in Windows 10? Thanks.

Well, when I selected safe mode with networking, I had no Internet access - ? Weird. I ran Malwarebytes Anti-Malware and it said that it didn't find anything. I didn't see an "export summary" button, so I clicked another tab hoping to see it; all that did was just ask if I wanted to run another scan. I didn't see a log output or anything. Sorry.

 

A friend had suggested that I looking into doing a disk defragmentation, which I don't think I've ever run on this computer. It wouldn't let me do it for some reason - until I discovered that the account we've been using wasn't even the administrator account! That's an account my son set up some time ago and which has almost nothing set up on it. It may have something to do with some of my issues in getting things to open. As far as software causes to my problems, should I run another kind of scan? Or would you suggest I defragment my computer?

 

Thanks again.

If MalwareBytes didn't find anything no log needed.

I searched back through the logs and found the account we have been using
Dykes-family (S-1-5-21-3670747094-3822527020-2124027705-1001 - Administrator - Enabled) => C:\Users\Dykes-family
So it's confusing why things wont run using this account since it is setup as administrator and enabled.

Early on I had asked about Kaspersky being on the computer, did you go to add/remove programs to remove that?


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`
  • Download Emsisoft Emergency Kit and save it to your desktop.
  • Double-click icon then click Install
  • A Window should open highlighting Start Emergency Kit Scanner
  • Right click on the icon and select Run as administrator
  • Click 1. Update now!
  • Once the update is completed select Settings under Scan
  • Uncheck Join the Emsisoft Anti-Malware Network
  • Click Scan at the top
  • Click On scan completion
  • Click Quarantine detected objects, then click OK
  • Click Malware Scan
  • Once completed click View Report
  • Save the file to your Desktop using the default file name
  • Copy and paste the report in your reply

I ran the scan, and the report is below. I don't know what the "couponprinter" thing is; the Adobe Master collection was given to me by a friend years ago. It's also on my laptop, which runs fine.

 

 

Emsisoft Emergency Kit - Version 12.0
Last update: 2/5/2017 3:35:24 PM
User account: Dykes-family-PC\Dykes-family
Computer name: DYKES-FAMILY-PC
OS version: Windows 10x64

Scan settings:

Scan type: Malware Scan
Objects: Rootkits, Memory, Traces, Files

Detect PUPs: On
Scan archives: Off
ADS Scan: On
File extension filter: Off
Direct disk access: Off

Scan start:    2/5/2017 3:40:01 PM
C:\Users\Dykes-family\Downloads\Adobe Master Collection\xf-mccs6.exe     detected: Application.GenericKD.4124021 (B) [krnl.xmd]
C:\Users\Dykes-family\Pictures\couponprinter.exe     detected: Application.AdOffer (A) [285399]

Scanned    109521
Found    2

Scan end:    2/5/2017 5:51:01 PM
Scan time:    2:11:00

C:\Users\Dykes-family\Pictures\couponprinter.exe     Application.AdOffer (A)
C:\Users\Dykes-family\Downloads\Adobe Master Collection\xf-mccs6.exe     Application.GenericKD.4124021 (B)

Quarantined    2
 

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI