I had done the retry as well but it took 3 restarts to get it to boot up correctly.
Computer running slow [Solved]
29 min read
Running this next tool can take quite a while to run. It checks for system errors and hard drive problems.
Tweaking.com - Windows Repair All-In-One (Portable)
- Download Windows Repair All-In-One (Portable Version) from here.
- Extract tweaking.com_windows_repair_aio.zip to your Desktop.
- Disable all your antivirus and antimalware software - see how to do that here.
- Right click on Click to load external image (QfBzvq1.png) and select Run as Administrator (XP users just double click) to start Windows Repair All-In-One.
(Windows Vista/7/8 users: Accept UAC warning if it is enabled.)
- A window will appear. Click Step 2.
[external image: 2f8o60N.png]
- Click the Open Pre-Scan button, then click Start Scan. Wait for Windows Repair to finish scanning.
- Depending on which error Windows Repair found, click Repair Reparse Point or Repair Environment Variable accordingly. When the button changes to "Done!", click the close button to return to Windows Repair.
- Go to Step 3, then click Check in the See If Check Disk Is Needed.
- If Windows Repair stated that errors are found, click Open Check Disk At Next Boot. Choose (/R) Fixes errors on the disk also locate bad sectors and recovers readable information, then click Add To Next Boot. Reboot the computer to let Windows check the disk.
[external image: Ymy7crZ.png]
- Go to Step 4, then click Do It.
[external image: zDtdN75.png]
- Go to Step 5. Under System Restore click Create.
[external image: f7lEe1N.png]
- Go to Repairs and click Open Repairs. Leave all checkmarks as they are, then click Start Repairs.
[external image: PGv2vtD.png]
- By default Windows Repair All-In-One will create a "Logs" folder in its folder on the Desktop. Please post the contents of the log in your next reply.
Good morming,
Please pardon my delay in greeting you this morning as well as my delay in following through with your March 15 instructions. Yes I'm still with you. I will start the March 15 instructions now. I also forgot to mention that I keep getting notifications saying that I need to "Reconnect my drive."
https://www.tenforums.com/performance-maintenance/46326-reconnect-your-drive-notification.html
https://support.microsoft.com/en-us/instantanswers/b9f8b902-b891-2f9c-ca31-8f3eda7c5b2b/reconnect-your-file-history-drive
https://answers.microsoft.com/en-us/windows/forum/windows_8/how-do-i-reconnect-my-drive-in-windows/74b0c974-8159-4186-bb72-abd4e26439d7
Hi!
I'm super frustrated. I apologize for taking so long to get back to you. I was blocked out of this site for 2 days. For 2 days, I entered this website in my browser and received messages that the site was not safe. I was never redirected. It was as if I had been hacked and wasn't allowed to access this website. I tried msn.com and was the page never loaded;however, I didn't get that same message. I would eventually end up with a warning to check my proxy settings.
I also had gotten to Step 3 of the tweaking,com process.
Which browser is doing this?Hi!
I'm super frustrated. I apologize for taking so long to get back to you. I was blocked out of this site for 2 days. For 2 days, I entered this website in my browser and received messages that the site was not safe. I was never redirected. It was as if I had been hacked and wasn't allowed to access this website. I tried msn.com and was the page never loaded;however, I didn't get that same message. I would eventually end up with a warning to check my proxy settings.
Somewhat sounds like security tools interfering
Instructions on how to backup your Favourites/Bookmarks and other data can be found below.
- Backup Internet Explorer Favourites
- Backup Firefox Bookmarks
- Backup Chrome Bookmarks
- Internet Explorer: How to reset Internet Explorer settings
- Firefox: Reset Firefox
- Chrome: Chrome - Reset browser settings
If you don't mind I would like to see a new FRST log.
- Right-Click FRST.exe / FRST64.exe and select [external image: AVOiBNU.jpg]Run as administrator to run the programme.
- Click Yes to the disclaimer.
- Ensure the Addition.txt box is checked.
- Click the Scan button and let the programme run.
- Upon completion, click OK, then OK on the Addition.txt pop up screen.
- Two logs (FRST.txt & Addition.txt) will now be open on your Desktop. Copy the contents of both logs and paste in your next reply.
Here is the new FRST log.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by [removed] (administrator) on MRSJOHNSON (24-03-2017 23:01:24)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 8.1 (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
() C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
(Softex Inc.) C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
() C:\Program Files\ATI Technologies\ATI.ACE\a4\AdaptiveSleepService.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(AO Kaspersky Lab) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avpui.exe
() C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
(Microsoft Corporation) C:\Windows\System32\SkyDrive.exe
(CyberLink Corp.) C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe
(Hewlett-Packard) C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(CenturyLink Inc) C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE15\CSISYNCCLIENT.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office15\MSOSYNC.EXE
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [SimplePass] => C:\Program Files\Hewlett-Packard\SimplePass\HPSmplPass.exe [2755640 2013-09-26] (Hewlett-Packard)
HKLM\…\Run: [OPBHOBroker] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBroker.exe [155704 2013-09-26] (Hewlett-Packard)
HKLM\…\Run: [OPBHOBrokerDesktop] => C:\Program Files\Hewlett-Packard\SimplePass\OPBHOBrokerDsktop.exe [155704 2013-09-26] (Hewlett-Packard)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2771184 2013-07-26] (Synaptics Incorporated)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8843520 2016-02-19] (Realtek Semiconductor)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766208 2013-09-25] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [507776 2014-10-07] (Oracle Corporation)
HKLM-x32\…\Run: [BCSSync] => C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe [89184 2012-11-05] (Microsoft Corporation)
HKLM-x32\…\Run: [CenturyLinkTouchPointAgent] => C:\Program Files (x86)\CenturyLink\Desktop\CenturyLinkTouchPointAgent.exe [48904 2014-11-04] (CenturyLink Inc)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [657424 2015-09-03] (Hewlett-Packard Development Company, L.P.)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\Run: [GoogleChromeAutoLaunch_0C9337CDD31A557C75EB2CDF52C45A5A] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [945496 2017-02-01] (Google Inc.)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\MountPoints2: {ed76fc77-6b0a-11e5-8270-3863bb8eae0e} - "F:\AutoRun.exe"
Startup: C:\Users\Jacquelyn\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2016-05-14]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files (x86)\Microsoft Office\Office15\ONENOTEM.EXE (Microsoft Corporation)
BootExecute: autocheck autochk /r \??\Z:autocheck autochk *
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 208.67.222.222 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{2BE7FA48-E3A9-4398-8011-4CBB02E6ACC5}: [DhcpNameServer] 208.67.222.222 8.8.8.8 8.8.4.4
Tcpip\..\Interfaces\{8E02059E-EC13-441B-AFD6-CD70C258610A}: [DhcpNameServer] 192.168.0.1 [removed]
Internet Explorer:
==================
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
BHO: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-03-08] (AO Kaspersky Lab)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-02-19] (Microsoft Corporation)
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-02-19] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)
BHO-x32: Kaspersky Protection -> {2E38825B-8815-42CF-9126-C58BC28D4591} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\IEExt\ie_plugin.dll [2017-03-08] (AO Kaspersky Lab)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-02-19] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Javaâ„¢ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-12-01] (Oracle Corporation)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-02-19] (Microsoft Corporation)
BHO-x32: Javaâ„¢ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-12-01] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
Toolbar: HKLM - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\IEExt\ie_plugin.dll [2017-03-08] (AO Kaspersky Lab)
Toolbar: HKLM-x32 - Kaspersky Protection Toolbar - {093F479D-712E-46CD-9E06-62E734A05F68} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\IEExt\ie_plugin.dll [2017-03-08] (AO Kaspersky Lab)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-08] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-08] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-08] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-03-08] (Microsoft Corporation)
FireFox:
========
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi [2017-03-08]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1204144.dll [2013-09-05] (Adobe Systems, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-12-01] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-12-01] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-02-19] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-02-19] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-06] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll [2014-11-22] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll [2016-07-19] (Microsoft Corporation)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://intra.rdale.org/
CHR NewTab: Default -> Not-active:"chrome-extension://laookkfknpbbblfpciffpaejjkokdgca/dashboard.html"
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default [2017-03-24]
CHR Extension: (Google Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-10-04]
CHR Extension: (Google Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-10-04]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-22]
CHR Extension: (Google Groups) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfmbadcfdhiklafcdohpfphhhakmiakk [2015-10-07]
CHR Extension: (Newsela) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bfpeiapdhnegnfcfkdfihabadngjagfj [2016-05-16]
CHR Extension: (Audiotool) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkgoccjhfjgjedhkiefaclppgbmoobnk [2015-10-07]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-04]
CHR Extension: (Honey) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2017-03-19]
CHR Extension: (GeoGebra Math Apps) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnbaboaihhkjoaolfnfoablhllahjnee [2016-06-06]
CHR Extension: (Bible) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\boljbeanmjklkbfnppfedajbgeongccb [2015-10-07]
CHR Extension: (Tab Scissors) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdochbecpfdpjobpgnacnbepkgcfhoek [2016-01-19]
CHR Extension: (Adblock Plus) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-03-23]
CHR Extension: (Ebates Cash Back) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\chhjbpecpncaggjpdakmflnfcopglcmi [2017-03-23]
CHR Extension: (EasyBib for Google Apps) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\cmfcdeceemokhabkjfdfmafnhpebponb [2015-10-07]
CHR Extension: (Google Search) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-12]
CHR Extension: (Drive Template Gallery) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\edccfahmoapjmcaahncgcekjodejmhkg [2015-10-07]
CHR Extension: (Adobe Acrobat) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-08]
CHR Extension: (Google Calendar) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejjicmeblgpmajnghnpcppodonldlgfn [2017-01-21]
CHR Extension: (Google Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-10-04]
CHR Extension: (Kaspersky Protection) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2017-03-08]
CHR Extension: (Office Editing for Docs, Sheets & Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\gbkeegbaiigmenfmjfclcdgdpimamgkj [2017-02-20]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-19]
CHR Extension: (SwagButton) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\gngocbkfmikdgphklgmmehbjjlfgdemm [2017-03-23]
CHR Extension: (G Suite Training) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\idkloemkmldbemijiamdiolojbffnjlh [2016-12-02]
CHR Extension: (Knok
Family Travel) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\iehdddmijbgofffjjmhkodckmnombhmf [2015-10-07]
CHR Extension: (MeeGenius! Children's Books) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhfhmaajajcjoijfaceafiembkmhcddc [2015-10-07]
CHR Extension: (HP Network Check Launcher) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\jkfpchpiljkaemlpmpebnglgkomamfeo [2017-02-20]
CHR Extension: (MackinVIA Reader) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkmkfkljmoipnaglegphplpihaigjnlc [2017-03-24]
CHR Extension: (Personal Trainer) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\kmgohkgndpahjklgpdihieeedjeneoke [2015-10-07]
CHR Extension: (Interior inspiration) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\koiigheakcgfhkijmpihjkngcnlkhbbd [2015-10-07]
CHR Extension: (Momentum) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\laookkfknpbbblfpciffpaejjkokdgca [2017-01-07]
CHR Extension: (Boomerang for Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdanidgdpmkimeiiojknlnekblgmpdll [2017-01-07]
CHR Extension: (Tab Glue) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\mfedioikeigljhjfpghdejnogniddhna [2016-01-19]
CHR Extension: (Finance41 Personal Finance Manager) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbgkhncobohkmgdjdiijlbgjidpnnkcd [2016-08-15]
CHR Extension: (Free Book Search) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\ncpnlnbcklbhdangaffeldjmmgmjjncl [2015-10-07]
CHR Extension: (Awesome Screenshot: Screen capture, Annotate) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlipoenfbbikpbjkfpfillcgkoblgpmj [2017-03-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-08]
CHR Extension: (Mission to Mars) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\oajieiehcnfnihdoginchdhfgceijgdm [2015-10-07]
CHR Extension: (TypingClub) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\obdbgibnhfcjmmpfijkpcihjieedpfah [2017-03-08]
CHR Extension: (PeofjASvJAwrZid) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\oedkmhdiokckdlnnphoebbnflkjjnhmo [2017-03-12]
CHR Extension: (PDF Viewer) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\oemmndcbldboiebfnladdacbdfmadadm [2016-11-13]
CHR Extension: (WeVideo - Video Editor and Maker) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\okgjbfikepgflmlelgfgecmgjnmnmnnb [2015-10-14]
CHR Extension: (Khan Academy) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pahdiadnidmaaoohjmlkcjffbfcapgko [2015-10-07]
CHR Extension: (Send from Gmail (by Google)) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc [2015-10-07]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-10-07]
CHR Extension: (Chrome Media Router) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-23]
CHR Extension: (Hapara Dashboard for Google Apps) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkimffcemlhioogdhaflfefoklamojgh [2015-11-25]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-03-08]
CHR Extension: (Google Slides) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-02-15]
CHR Extension: (Google Docs) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\aohghmighlieiainnegkcijnfilokake [2016-02-15]
CHR Extension: (Google Drive) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-02-15]
CHR Extension: (YouTube) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-02-15]
CHR Extension: (Google Search) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-02-15]
CHR Extension: (Google Sheets) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-02-15]
CHR Extension: (Google Docs Offline) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-02-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-02-15]
CHR Extension: (Gmail) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Profile 1\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-02-15]
CHR Profile: C:\Users\Annette\AppData\Local\Google\Chrome\User Data\System Profile [2017-03-08]
CHR HKLM\…\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKLM-x32\…\Chrome\Extension: [jkfpchpiljkaemlpmpebnglgkomamfeo] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdaptiveSleepService; C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe [99328 2013-09-25] () [File not signed]
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2013-09-25] (Advanced Micro Devices, Inc.) [File not signed]
R2 AVP17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe [241544 2016-06-28] (AO Kaspersky Lab)
R2 Cachedrv server; C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe [109568 2013-09-26] () [File not signed]
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3294920 2017-02-19] (Microsoft Corporation)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 HPWMISVC; C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [606224 2015-09-03] (Hewlett-Packard Development Company, L.P.)
S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\vssbridge64.exe [77328 2016-06-28] (AO Kaspersky Lab)
S2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (AO Kaspersky Lab)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [4278112 2013-08-02] (Symantec Corporation)
R2 omniserv; C:\Program Files\Hewlett-Packard\SimplePass\OmniServ.exe [87552 2013-09-26] (Softex Inc.) [File not signed]
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [310016 2016-02-19] (Realtek Semiconductor)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [366552 2015-07-07] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2015-07-07] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 AmdAS4; C:\Windows\System32\drivers\AmdAS4.sys [17504 2013-02-07] (Advanced Micro Devices, INC.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWB6.sys [138240 2013-06-23] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [100624 2015-06-08] (CyberLink)
R0 cm_km; C:\Windows\System32\DRIVERS\cm_km.sys [238936 2016-06-10] (AO Kaspersky Lab)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [129152 2016-04-25] (Samsung Electronics Co., Ltd.)
R1 epp; C:\Users\Annette\Desktop\bin64\epp.sys [115216 2017-01-03] (Emsisoft Ltd)
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [554416 2016-06-02] (AO Kaspersky Lab)
R0 klbackupdisk; C:\Windows\System32\DRIVERS\klbackupdisk.sys [63920 2016-06-08] (AO Kaspersky Lab)
R1 klbackupflt; C:\Windows\System32\DRIVERS\klbackupflt.sys [86352 2016-06-15] (AO Kaspersky Lab)
R2 kldisk; C:\Windows\system32\DRIVERS\kldisk.sys [78216 2016-06-01] (AO Kaspersky Lab)
S0 klelam; C:\Windows\System32\DRIVERS\klelam.sys [28792 2016-03-31] (AO Kaspersky Lab)
R3 klflt; C:\Windows\system32\DRIVERS\klflt.sys [196376 2017-03-23] (AO Kaspersky Lab)
R1 klhk; C:\Windows\System32\drivers\klhk.sys [435032 2017-03-08] (AO Kaspersky Lab)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [1017624 2017-03-23] (AO Kaspersky Lab)
R1 KLIM6; C:\Windows\system32\DRIVERS\klim6.sys [57424 2017-03-08] (AO Kaspersky Lab)
R3 klkbdflt; C:\Windows\system32\DRIVERS\klkbdflt.sys [52136 2016-05-19] (AO Kaspersky Lab)
R3 klmouflt; C:\Windows\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [45488 2016-06-01] (AO Kaspersky Lab)
R3 kltap; C:\Windows\system32\DRIVERS\kltap.sys [52152 2016-06-07] (The OpenVPN Project)
R1 klwfp; C:\Windows\system32\DRIVERS\klwfp.sys [85320 2016-06-18] (AO Kaspersky Lab)
R1 Klwtp; C:\Windows\system32\DRIVERS\klwtp.sys [136416 2017-03-23] (AO Kaspersky Lab)
R1 kneps; C:\Windows\system32\DRIVERS\kneps.sys [199392 2017-03-23] (AO Kaspersky Lab)
R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [294104 2014-11-28] (Realtek Semiconductor Corp.)
R3 RTWlanE; C:\Windows\system32\DRIVERS\rtwlane.sys [3636440 2014-12-22] (Realtek Semiconductor Corporation )
R3 RTWlanE; C:\Windows\SysWOW64\DRIVERS\rtwlane.sys [2945240 2013-09-12] (Realtek Semiconductor Corporation )
S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [30448 2013-07-26] (Synaptics Incorporated)
S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [34544 2013-07-26] (Synaptics Incorporated)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [221824 2016-04-25] (Samsung Electronics Co., Ltd.)
S3 usbrndis6; C:\Windows\system32\DRIVERS\usb80236.sys [20992 2015-04-24] (Microsoft Corporation)
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44560 2015-07-07] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [270168 2015-07-07] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114520 2015-07-07] (Microsoft Corporation)
R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [30384 2015-06-23] (HP Inc.)
S0 mnbb; System32\drivers\ftumiyt.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-24 23:01 - 2017-03-24 23:02 - 00030176 _____ C:\Users\Annette\Desktop\FRST.txt
2017-03-23 22:14 - 2017-03-23 22:14 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2017-03-23 20:11 - 2017-03-23 20:11 - 00298008 _____ C:\Windows\Minidump\032317-25734-01.dmp
2017-03-23 19:52 - 2017-03-23 19:52 - 00293880 _____ C:\Windows\Minidump\032317-37296-01.dmp
2017-03-23 19:50 - 2017-03-23 19:50 - 00289752 _____ C:\Windows\Minidump\032317-33515-01.dmp
2017-03-23 19:32 - 2017-03-23 19:32 - 00289752 _____ C:\Windows\Minidump\032317-34781-01.dmp
2017-03-19 19:43 - 2017-03-23 17:28 - 00000000 ____D C:\Users\Annette\Desktop\color_presets
2017-03-19 19:43 - 2017-03-19 19:43 - 00000000 ____D C:\Users\Annette\Desktop\repairs_info
2017-03-19 19:43 - 2017-03-19 19:43 - 00000000 ____D C:\Users\Annette\Desktop\CustomScripts
2017-03-19 19:43 - 2017-03-19 19:43 - 00000000 ____D C:\Users\Annette\Desktop\CleanMgrScripts
2017-03-19 19:42 - 2017-03-23 17:28 - 00000000 ____D C:\Users\Annette\Desktop\files
2017-03-19 19:42 - 2017-03-19 19:43 - 00000000 ____D C:\Users\Annette\Desktop\Uninstall
2017-03-14 21:51 - 2017-03-04 02:59 - 02895360 ____N (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-03-14 21:51 - 2017-03-04 02:48 - 25746944 ____N (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-03-14 21:51 - 2017-03-04 02:44 - 00817664 ____N (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-03-14 21:51 - 2017-03-04 02:31 - 06045696 ____N (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-03-14 21:51 - 2017-03-04 01:26 - 15259648 ____N (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-03-14 21:51 - 2017-03-04 01:25 - 03241984 ____N (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-03-14 21:51 - 2017-03-04 01:12 - 01545728 ____N (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-03-14 21:51 - 2017-02-11 00:12 - 00315392 ____N (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-03-14 21:50 - 2017-02-09 19:12 - 01375960 ____N (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-03-14 21:50 - 2017-02-09 10:28 - 01987584 ____N (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-03-14 21:50 - 2017-02-09 10:16 - 01094656 ____N (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-03-14 21:50 - 2017-02-09 09:59 - 00658432 ____N (Microsoft Corporation) C:\Windows\system32\dnsapi.dll
2017-03-14 21:50 - 2017-02-04 14:30 - 00285184 ____N (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-03-14 21:50 - 2017-02-04 12:40 - 01754112 ____N (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll
2017-03-14 21:50 - 2017-02-04 12:10 - 01491456 ____N (Microsoft Corporation) C:\Windows\SysWOW64\GdiPlus.dll
2017-03-14 21:50 - 2017-01-21 12:48 - 01437696 ____N (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-03-14 21:50 - 2017-01-14 12:49 - 00146944 ____N (Microsoft Corporation) C:\Windows\system32\wininit.exe
2017-03-14 21:50 - 2017-01-11 14:37 - 02345984 ____N (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2017-03-14 21:40 - 2017-02-22 09:35 - 00233984 ____N (Microsoft Corporation) C:\Windows\system32\aepic.dll
2017-03-14 21:40 - 2016-06-03 12:11 - 00472576 ____N (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2017-03-12 11:23 - 2017-03-12 11:24 - 00000000 ____D C:\Users\Annette\Documents\NACA
2017-03-12 08:09 - 2017-03-12 08:10 - 00000000 ____D C:\Users\Annette\Documents\Equifax
2017-03-12 06:38 - 2017-03-12 06:38 - 00289752 _____ C:\Windows\Minidump\031217-19843-01.dmp
2017-03-11 22:43 - 2017-03-11 22:43 - 00000954 _____ C:\Users\Annette\Desktop\EEK scan_170311-083605.txt
2017-03-11 09:50 - 2017-03-11 22:41 - 00000000 ____D C:\Users\Annette\Desktop\Reports
2017-03-11 09:31 - 2017-03-11 09:31 - 00000000 ____D C:\ProgramData\Emsisoft
2017-03-11 09:30 - 2017-03-11 09:50 - 00002604 _____ C:\Users\Annette\Desktop\a2settings.ini
2017-03-11 09:30 - 2017-03-11 09:30 - 00000000 ____D C:\Users\Annette\Desktop\Quarantine
2017-03-11 09:27 - 2017-03-11 09:31 - 00000000 ____D C:\Users\Annette\Desktop\bin64
2017-03-11 09:27 - 2017-03-11 03:06 - 00000000 ____D C:\Users\Annette\Desktop\bin32
2017-03-11 09:27 - 2017-02-27 22:00 - 00514920 _____ (Emsisoft Ltd) C:\Users\Annette\Desktop\start emergency kit scanner.exe
2017-03-11 09:27 - 2017-02-27 22:00 - 00468184 _____ (Emsisoft Ltd) C:\Users\Annette\Desktop\start commandline scanner.exe
2017-03-11 09:27 - 2015-12-09 09:23 - 00004314 _____ C:\Users\Annette\Desktop\readme.txt
2017-03-11 09:25 - 2017-03-11 09:26 - 281463608 _____ C:\Users\Annette\Downloads\EmsisoftEmergencyKit (1).exe
2017-03-11 09:24 - 2017-03-11 09:24 - 00000000 ____D C:\EEK
2017-03-10 19:51 - 2017-03-10 19:51 - 00289752 _____ C:\Windows\Minidump\031017-30625-01.dmp
2017-03-10 19:49 - 2017-03-10 19:49 - 00293880 _____ C:\Windows\Minidump\031017-30171-01.dmp
2017-03-10 19:25 - 2017-03-10 19:25 - 00289752 _____ C:\Windows\Minidump\031017-31265-01.dmp
2017-03-10 19:14 - 2017-03-10 19:14 - 00289752 _____ C:\Windows\Minidump\031017-31453-01.dmp
2017-03-08 22:14 - 2017-03-08 22:14 - 00001490 _____ C:\Users\Annette\Desktop\JRT.txt
2017-03-08 22:09 - 2017-03-08 22:09 - 01663736 _____ (Malwarebytes) C:\Users\Annette\Downloads\JRT.exe
2017-03-08 22:06 - 2017-03-08 22:06 - 00009376 _____ C:\Users\Annette\Desktop\AdwCleaner[C0].txt
2017-03-08 21:26 - 2017-03-08 21:51 - 00000000 ____D C:\AdwCleaner
2017-03-08 21:25 - 2017-03-08 21:25 - 04031440 _____ C:\Users\Annette\Downloads\AdwCleaner.exe
2017-03-08 21:02 - 2017-03-23 17:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2017-03-08 21:02 - 2017-03-08 21:51 - 00001397 _____ C:\Users\Public\Desktop\Kaspersky Secure Connection.lnk
2017-03-08 21:01 - 2017-03-24 20:38 - 00003032 _____ C:\Windows\System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901}
2017-03-08 21:01 - 2017-03-23 16:51 - 00000000 ____D C:\Program Files\Common Files\AV
2017-03-08 21:01 - 2017-03-08 21:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2017-03-08 21:01 - 2017-03-08 21:00 - 00002158 _____ C:\Users\Public\Desktop\Safe Money.lnk
2017-03-08 21:01 - 2017-03-08 21:00 - 00002134 _____ C:\Users\Public\Desktop\Kaspersky Total Security.lnk
2017-03-08 20:59 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2017-03-08 20:56 - 2017-03-24 23:01 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2017-03-08 20:56 - 2017-03-23 17:30 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2017-03-08 20:55 - 2017-03-23 22:02 - 01017624 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klif.sys
2017-03-08 20:55 - 2017-03-23 22:02 - 00196376 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klflt.sys
2017-03-08 20:30 - 2017-03-08 20:41 - 00009782 _____ C:\Users\Annette\Desktop\Fixlog.txt
2017-03-08 20:29 - 2017-03-24 23:01 - 00000000 ____D C:\Users\Annette\Desktop\FRST-OlderVersion
2017-03-06 23:07 - 2017-03-06 23:09 - 00047394 _____ C:\Users\Annette\Downloads\Addition.txt
2017-03-06 23:05 - 2017-03-06 23:09 - 00038092 _____ C:\Users\Annette\Downloads\FRST.txt
2017-03-06 23:03 - 2017-03-24 23:01 - 00000000 ____D C:\FRST
2017-03-06 23:01 - 2017-03-24 23:01 - 02424832 _____ (Farbar) C:\Users\Annette\Desktop\FRST64.exe
2017-03-06 23:00 - 2017-03-06 23:00 - 00000555 _____ C:\Users\Annette\Desktop\aswMBR.txt
2017-03-06 22:47 - 2017-03-06 22:48 - 05198336 _____ (AVAST Software) C:\Users\Annette\Downloads\aswMBR.exe
2017-03-06 13:43 - 2017-03-06 13:43 - 00677587 _____ C:\Users\Annette\Desktop\16 Success Drivers
2017-03-06 12:40 - 2017-03-06 12:40 - 00002352 _____ C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2017-02-25 07:46 - 2017-03-24 20:51 - 00003180 _____ C:\Windows\System32\Tasks\HPCeeScheduleForAnnette
2017-02-25 07:46 - 2017-03-24 20:51 - 00000362 _____ C:\Windows\Tasks\HPCeeScheduleForAnnette.job
2017-02-23 21:01 - 2017-02-23 21:32 - 00225822 _____ C:\TDSSKiller.3.1.0.12_23.02.2017_20.01.43_log.txt
2017-02-23 20:19 - 2017-02-23 20:19 - 00002171 _____ C:\Users\Public\Desktop\Google Earth.lnk
2017-02-23 20:19 - 2017-02-23 20:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-24 22:59 - 2013-08-22 10:36 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-24 22:59 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\AppReadiness
2017-03-24 22:51 - 2015-09-14 16:49 - 00000000 ___DO C:\Users\Annette\OneDrive
2017-03-24 22:49 - 2015-11-17 17:45 - 00003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3464BE36-788D-4EB3-890E-849F1DD7BE9F}
2017-03-24 20:29 - 2015-09-14 16:50 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1409944621-189731363-133459071-1005
2017-03-24 20:26 - 2014-03-18 04:53 - 00956476 _____ C:\Windows\system32\PerfStringBackup.INI
2017-03-24 20:26 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\Inf
2017-03-24 20:25 - 2015-09-14 16:49 - 00000000 ____D C:\Users\Annette\Documents\Youcam
2017-03-24 20:22 - 2015-03-19 15:56 - 00000000 ____D C:\ProgramData\boost_interprocess
2017-03-24 20:20 - 2016-05-05 21:41 - 00000600 _____ C:\Windows\Tasks\AVG-SSU_0516tb.job
2017-03-24 20:20 - 2016-05-05 21:41 - 00000462 _____ C:\Windows\Tasks\AVG-SSU_0516tb_DELETE.job
2017-03-24 20:18 - 2013-08-22 09:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-03-24 20:17 - 2013-08-22 08:25 - 00524288 ___SH C:\Windows\system32\config\BBI
2017-03-23 22:02 - 2016-06-14 18:47 - 00199392 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\kneps.sys
2017-03-23 22:02 - 2016-06-02 23:39 - 00136416 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klwtp.sys
2017-03-23 20:52 - 2013-08-22 10:20 - 00000000 ____D C:\Windows\CbsTemp
2017-03-23 20:11 - 2015-03-09 11:55 - 561742672 _____ C:\Windows\MEMORY.DMP
2017-03-23 20:11 - 2015-03-09 11:55 - 00000000 ____D C:\Windows\Minidump
2017-03-23 17:55 - 2015-04-07 21:03 - 00000000 ____D C:\Users\Annette
2017-03-23 17:54 - 2013-08-22 08:25 - 00262144 ___SH C:\Windows\system32\config\ELAM
2017-03-23 17:36 - 2014-11-19 16:48 - 00000000 ____D C:\Users\Jacquelyn
2017-03-23 17:35 - 2014-12-17 21:22 - 00000000 ____D C:\Windows\system32\appraiser
2017-03-23 17:35 - 2014-11-26 22:52 - 00000000 ___SD C:\Windows\system32\CompatTel
2017-03-23 17:35 - 2013-08-22 10:36 - 00000000 __RSD C:\Windows\Media
2017-03-23 17:35 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\rescache
2017-03-23 17:35 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\PolicyDefinitions
2017-03-23 17:34 - 2014-04-22 12:41 - 00000000 ____D C:\Windows\System32\Tasks\Hewlett-Packard
2017-03-23 17:34 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-03-23 17:34 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-03-23 17:34 - 2013-08-22 08:36 - 00000000 ____D C:\Windows\system32\Sysprep
2017-03-23 17:33 - 2016-03-24 09:59 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2017-03-23 17:33 - 2015-01-23 04:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-03-23 17:33 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\ADFS
2017-03-23 17:32 - 2015-01-23 04:11 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-03-23 17:32 - 2015-01-23 04:11 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-03-23 17:32 - 2013-08-22 10:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-03-23 17:04 - 2013-08-22 10:36 - 00000000 ____D C:\Windows\registration
2017-03-23 16:44 - 2014-04-22 12:28 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-03-18 08:22 - 2014-11-23 19:05 - 00000000 ____D C:\Windows\system32\MRT
2017-03-11 09:45 - 2016-08-21 23:56 - 00014848 ___SH C:\Users\Annette\Desktop\Thumbs.db
2017-03-10 20:14 - 2016-08-14 23:04 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-03-10 19:11 - 2013-08-22 08:25 - 00524288 ___SH C:\Windows\system32\config\BBI(273)
2017-03-10 19:09 - 2017-01-18 20:22 - 00000000 ___HD C:\ProgramData\{0897014C-63E3-47DF-8A5F-4399CC5D61B9}
2017-03-08 21:39 - 2016-06-21 00:41 - 00057424 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klim6.sys
2017-03-08 21:30 - 2016-06-20 18:54 - 00435032 _____ (AO Kaspersky Lab) C:\Windows\system32\Drivers\klhk.sys
2017-03-08 21:17 - 2013-08-22 10:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-03-08 20:57 - 2013-08-22 10:36 - 00000000 ___HD C:\Windows\ELAMBKUP
2017-03-08 20:33 - 2015-10-07 18:34 - 00000000 ____D C:\Users\Annette\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
2017-03-08 20:33 - 2015-09-14 16:42 - 00002265 _____ C:\Users\Annette\Desktop\Annette - Chrome.lnk
2017-03-06 12:40 - 2016-12-16 07:08 - 00003180 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2
2017-03-06 12:40 - 2016-08-19 12:29 - 00003188 _____ C:\Windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-1409944621-189731363-133459071-1005
2017-03-06 12:11 - 2014-11-23 19:05 - 138020592 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-03-04 01:24 - 2014-09-09 21:21 - 00065536 _____ C:\Windows\system32\spu_storage.bin
2017-02-27 10:30 - 2014-04-25 12:57 - 00032140 _____ C:\Users\Annette\Desktop\file_list.txt
2017-02-27 10:30 - 2013-07-18 18:22 - 00107396 _____ C:\Users\Annette\Desktop\changelog.txt
2017-02-23 22:15 - 2017-02-20 10:56 - 00000000 ____D C:\Users\Annette\Documents\Customer Serive PSA
2017-02-23 21:16 - 2015-12-12 14:20 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-23 20:18 - 2014-11-19 18:47 - 00000000 ____D C:\Program Files (x86)\Google
==================== Files in the root of some directories =======
2016-10-15 00:04 - 2016-10-15 00:17 - 0000469 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe
[2017-03-14 21:50] - [2017-01-14 12:49] - 0146944 ____N (Microsoft Corporation) D9516405E05F24EDCD90B1988FAF3948
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll
[2017-03-14 21:50] - [2017-02-09 09:59] - 0658432 ____N (Microsoft Corporation) CF5FA7E4FB587B0F09BB0C143EB49797
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-20 21:40
==================== End of FRST.txt ============================
Here is the new Addition report.
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by [removed] (24-03-2017 23:03:50)
Running from C:\Users\[removed]\Desktop
Windows 8.1 (Update) (X64) (2014-11-19 21:48:55)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1409944621-189731363-133459071-500 - Administrator - Disabled)
Annette (S-1-5-21-1409944621-189731363-133459071-1005 - Administrator - Enabled) => C:\Users\Annette
Guest (S-1-5-21-1409944621-189731363-133459071-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1409944621-189731363-133459071-1004 - Limited - Enabled)
Jacquelyn (S-1-5-21-1409944621-189731363-133459071-1002 - Administrator - Enabled) => C:\Users\Jacquelyn
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Kaspersky Total Security (Disabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Total Security (Disabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Disabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
4 Elements II (x32 Version: 2.2.0.98 - WildTangent) Hidden
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.)
Airport Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
AMD Catalyst Install Manager (HKLM\…\{301D3AA1-5DCC-FCFD-622E-3C7CBA87C80F}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Azkend 2: The World Beneath (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bounce Symphony (x32 Version: 2.2.0.97 - WildTangent) Hidden
Build-a-lot (x32 Version: 2.2.0.98 - WildTangent) Hidden
CenturyLink Installer (HKLM-x32\…\{C96FF998-45BD-411E-9253-B7F2660FE280}) (Version: 1.0 - CenturyLink, Inc.)
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Cradle of Rome 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Crescendo Music Notation Editor (HKLM-x32\…\Crescendo) (Version: 1.86 - NCH Software)
Curse at Twilight (x32 Version: 3.0.2.32 - WildTangent) Hidden
CyberLink LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6902 - CyberLink Corp.)
CyberLink Media Suite 10 (HKLM-x32\…\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.9.4928 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\…\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.4.4824 - CyberLink Corp.)
CyberLink Power Media Player 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.6.5104 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\…\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.10.5422 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.6.3912 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 5.0.5.4628 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Delicious: Emily's Childhood Memories Premium Edition (x32 Version: 3.0.2.32 - WildTangent) Hidden
DisableMSDefender (Version: 1.0.0 - Hewlett-Packard Company) Hidden
Energy Star (HKLM-x32\…\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Farkle 3.0.13.10 (HKLM-x32\…\Farkle_is1) (Version: - )
Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Fishdom 3: Collector's Edition (x32 Version: 3.0.2.38 - WildTangent) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Earth (HKLM-x32\…\{F6430171-B86B-4639-839E-374913E7911D}) (Version: 7.1.8.3036 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
House of 1000 Doors: Family Secrets (x32 Version: 2.2.0.98 - WildTangent) Hidden
HP Documentation (HKLM-x32\…\{2C0CCB21-5ED3-4417-93D2-CC6BEEB3C7CF}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Registration Service (HKLM\…\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7127.4628 - Hewlett-Packard)
HP SimplePass (HKLM-x32\…\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.54 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\…\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.3.50.9 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\…\{55065080-504F-43BB-BE00-36B80D7D39A5}) (Version: 12.5.32.203 - Hewlett-Packard Company)
HP System Event Utility (HKLM-x32\…\{6B1ECC61-B581-400D-BFAF-101B1AAEA5AB}) (Version: 1.4.7 - Hewlett-Packard Company)
HP Utility Center (HKLM\…\{7A75E042-0D30-43C2-BD2A-684F4BE38FF7}) (Version: 2.3.1 - Hewlett-Packard Company)
HP Wireless Button Driver (HKLM-x32\…\{EFA01423-3857-468C-B7B6-F30AA08E50BC}) (Version: 1.1.5.1 - Hewlett-Packard)
Inst5675 (Version: 8.00.54 - Softex Inc.) Hidden
Inst5676 (Version: 8.00.54 - Softex Inc.) Hidden
Java 8 Update 25 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Kaspersky Secure Connection (HKLM-x32\…\InstallWIX_{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab)
Kaspersky Secure Connection (x32 Version: 17.0.0.611 - Kaspersky Lab) Hidden
Kaspersky Total Security (HKLM-x32\…\InstallWIX_{E27B1D7B-3B34-43A2-9FC0-9828D5DF46E2}) (Version: 17.0.0.611 - Kaspersky Lab)
Kaspersky Total Security (x32 Version: 17.0.0.611 - Kaspersky Lab) Hidden
King Oddball (x32 Version: 3.0.2.48 - WildTangent) Hidden
Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Mahjongg Dimensions Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 16.0.7369.2118 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-0081-0409-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\…\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\OneDriveSetup.exe) (Version: 17.3.6798.0207 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Monopoly® (x32 Version: 3.0.2.51 - WildTangent) Hidden
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mystery P.I. - Curious Case of Counterfeit Cove (x32 Version: 2.2.0.98 - WildTangent) Hidden
NCH Tone Generator (HKLM-x32\…\ToneGen) (Version: 3.26 - NCH Software)
Norton Online Backup (HKLM-x32\…\{1969BD50-331D-4B7A-8116-29A7DC6D45B4}) (Version: 2.8.0.44 - Symantec Corporation)
OEM Application Profile (HKLM-x32\…\{70D5F822-F4C4-33D9-7EEC-2A4AF4EA7BDC}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7369.2118 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7369.2118 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7369.2118 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7369.2118 - Microsoft Corporation) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
Pinger (HKLM-x32\…\Pinger 1.4.0.1) (Version: 1.4.0.1 - Pinger Inc.)
Pinger (x32 Version: 1.4.0.1 - Pinger Inc.) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29080 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.32.508.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7730 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\…\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.0.0.41 - REALTEK Semiconductor Corp.)
Roads of Rome 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\…\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.6.2 - Synaptics Incorporated)
Tales of Lagoona (x32 Version: 2.2.0.110 - WildTangent) Hidden
TurboTax 2014 (HKLM-x32\…\TurboTax 2014) (Version: 2014.0 - Intuit, Inc)
Update for Skype for Business 2015 (KB3039776) 32-Bit Edition (HKLM-x32\…\{90150000-012B-0409-0000-0000000FF1CE}_Office15.PROPLUSR_{9F6B3627-AF9E-40A5-AAD5-3497C4327616}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3161988) 32-Bit Edition (HKLM-x32\…\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{245EB15F-A90C-422B-9D3F-3AEEDF028CCC}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3161988) 32-Bit Edition (HKLM-x32\…\{90150000-012B-0409-0000-0000000FF1CE}_Office15.PROPLUSR_{245EB15F-A90C-422B-9D3F-3AEEDF028CCC}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3161988) 32-Bit Edition (HKLM-x32\…\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{245EB15F-A90C-422B-9D3F-3AEEDF028CCC}) (Version: - Microsoft)
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Vacation Questâ„¢ - Australia (x32 Version: 3.0.2.32 - WildTangent) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WavePad Sound Editor (HKLM-x32\…\WavePad) (Version: 7.00 - NCH Software)
WhatsApp (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\WhatsApp) (Version: 0.2.1455 - WhatsApp)
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (HP Games) (x32 Version: 4.0.10.15 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Youda Jewel Shop (x32 Version: 3.0.2.32 - WildTangent) Hidden
Zulu DJ Software (HKLM-x32\…\Zulu) (Version: 3.70 - NCH Software)
Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Annette\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileCoAuthLib64.dll (Microsoft Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {014769DA-BE7F-4F02-9B58-34329401B70B} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {10A0396E-4397-432D-A61A-B29936C98279} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-27] (Google Inc.)
Task: {19BBD166-C964-43E3-B34D-187A7E62E5C1} - System32\Tasks\AVG-SSU_0516tb_RML => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: {1A39E007-12BB-4FCE-B21B-FF3D69A7BF99} - System32\Tasks\0915tbUpdateInfo => C:\ProgramData\Avg_Update_0915tb\0915tb_{82320DFB-27EB-4C68-8903-9D72AB169A0B}.exe
Task: {2FE82A44-7615-47C1-88DD-E0D568E5D0F2} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => %ProgramFiles%\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {3165798A-F44B-4387-8B96-BD947DFDF94F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {35B33F54-DE13-47B9-BE64-FC38E4A16DE5} - System32\Tasks\AVG-SSU_0516tb_DELETE => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: {3E898CDD-32F4-47D1-A2F4-BCF33E88AEBC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {422808BD-6F70-41BF-945D-E13AA06AE45A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
Task: {468B13AD-B541-4A27-B004-9B018EEA3275} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07] (Oracle Corporation)
Task: {55DCE214-7F3F-463F-BECE-5A67E73B6324} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
Task: {5B7B1C4A-9A07-4CAC-869E-5279651131BE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {657B0631-CFC6-4D97-9BBB-D64EA3A67056} - System32\Tasks\AVG-SSU_0516tb => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: {69D3BA23-D578-4DE2-AFDE-D9EF27762CEC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-27] (Google Inc.)
Task: {6CC93A74-62F2-4910-A4FC-A40536BC93CE} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [2016-07-11] (AO Kaspersky Lab)
Task: {7096DF25-3B68-4C03-84FD-DD056A6478FC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-03-10] (HP Inc.)
Task: {7CE5B9ED-BBEF-4FA0-BAB5-C5D42E3475BC} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-19] (Microsoft Corporation)
Task: {8AEFBD24-B736-48AC-8C72-6522466A99DE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-02-19] (Microsoft Corporation)
Task: {8B512A54-342F-4730-ADEC-CBA51071C650} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2017-03-06] (Microsoft Corporation)
Task: {A30614CC-919B-432A-A18E-DC51DEBD08F0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {AD039A2B-990C-47B8-ABDA-3597CE2D288C} - System32\Tasks\HPCeeScheduleForAnnette => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {B46771D0-89A1-4B43-9AF1-2EB5AAF264C1} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-02-19] (Microsoft Corporation)
Task: {B73A7C7B-CF7F-4A7E-A613-BFBB8A73789D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {C2AE1DC2-5E00-418C-9CB1-D4E263229737} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-02-19] (Microsoft Corporation)
Task: {CC822724-6442-4F48-B1A5-EB51857BE53E} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {CD39A3B5-0980-4947-BD6C-3D87425A7FCE} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-07-26] (Synaptics Incorporated)
Task: {D0F920D8-40AD-4B42-9F6C-ADA01607FCCD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-02-10] (HP Inc.)
Task: {DCEFA36E-E149-4C02-99DB-E3F29CC3066E} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [2014-10-28] (CyberLink Corp.)
Task: {E6B7EE15-0DF8-473B-AA30-3C92EDE7356E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
Task: {EC860F0E-1C8E-4761-BA2C-9ACF03169D98} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
Task: {FC28F289-DC07-41F7-A432-5D92E184B45F} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-19] (Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\0915tbUpdateInfo.job => C:\ProgramData\Avg_Update_0915tb\0915tb_{82320DFB-27EB-4C68-8903-9D72AB169A0B}.exe
Task: C:\Windows\Tasks\AVG-SSU_0516tb.job => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: C:\Windows\Tasks\AVG-SSU_0516tb_DELETE.job => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: C:\Windows\Tasks\AVG-SSU_0516tb_RML.job => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: C:\Windows\Tasks\HPCeeScheduleForAnnette.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Annette\AppData\Local\Microsoft\Windows\ConnectedSearch\History\site_2989506396_en-us.lnk -> hxxp://www.windowssearch.com:80/suggestions?qry=minneapolis+radiology&cc;=US&setlang;=en-US&inlang;=en-US&adlt;=moderate&scale;=100&contrast;=none&hw;=768%2C1366&CVID;=A87F048B1716477D94308BC9F119B97
==================== Loaded Modules (Whitelisted) ==============
2013-09-26 13:26 - 2013-09-26 13:26 - 00109568 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
2013-09-26 13:32 - 2013-09-26 13:32 - 00627200 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachedrv.dll
2013-09-26 13:28 - 2013-09-26 13:28 - 02540544 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 00035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 00055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 00021504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 00306064 _____ () C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 01298832 _____ () C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll
2013-09-25 08:49 - 2013-09-25 08:49 - 00099328 _____ () C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
2013-09-25 08:48 - 2013-09-25 08:48 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2016-08-19 12:07 - 2017-02-19 16:54 - 08923848 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:23 - 2010-10-20 16:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-09-26 13:34 - 2013-09-26 13:34 - 00064000 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
2013-09-25 08:48 - 2013-09-25 08:48 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2013-09-25 08:49 - 2013-09-25 08:49 - 00016896 _____ () C:\Program Files\ATI Technologies\ATI.ACE\a4\AS4.NativeProxy.dll
2016-06-28 01:19 - 2016-06-28 01:19 - 00865232 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\kpcengine.2.3.dll
2017-02-11 11:01 - 2017-02-01 04:01 - 01870168 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-02-11 11:01 - 2017-02-01 04:01 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\sharepoint.com -> hxxps://liveedurdale-files.sharepoint.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 08:25 - 2017-03-08 20:33 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Hewlett-Packard Backgrounds\backgroundDefault.jpg
DNS Servers: 208.67.222.222 - 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
HKLM\…\StartupApproved\Run32: => "YouCam Service"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{8D444952-FDB7-4FA5-901C-2462C1A37F99}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{AF3331A2-97B7-4313-AC3F-01DBA6B2C4FE}] => (Allow) LPort=2869
FirewallRules: [{150FBC6F-7AB5-4063-A0FB-EAC794994B93}] => (Allow) LPort=1900
FirewallRules: [{E39BD188-517F-4E06-97D0-5C42D5838F7E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{F1948981-D69A-4ED2-8B17-9EFB0572B092}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1402E48A-D816-4233-BC99-5439A3F6EDF5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8F1DB3E0-F2A7-42ED-91C7-FB0C90AC0852}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BAB834BF-B807-4BB0-9914-BEB323488AC5}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{B4EC793D-9BBE-49AF-B2AF-C979A6135B15}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{711CA439-540E-400F-96B4-03755DDF5D83}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{A58108F8-825B-42DE-A8B0-03908ED19304}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{37B0BF0A-6A5B-4084-8C13-81F803B4FF7C}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{7281462C-F67B-4492-905D-4C4B321E723A}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{A5A52445-92E8-42E2-A32A-0836A405AB0F}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{3B61AE1B-6103-477A-8F0D-4BAE585A8645}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPSOCKSVC.exe
FirewallRules: [{A4D5D120-EF07-4D46-A751-2106EBA65128}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{05E02CB2-DD6F-4010-A83B-A512473814C6}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{EFA066DD-C059-4586-ABDF-A21118A3F404}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{6A275A23-CBA3-45C2-B294-6F06F6C0848D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [TCP Query User{ACBD9CE9-88F2-4D23-8571-2E3C7E52DE4E}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [UDP Query User{02717F8A-ABC2-4205-9C6C-6DD19E9FB7DF}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [{D7AA5C63-D072-4153-8525-465AED706750}] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [{ED315B61-5CAE-477B-92D2-6F17C887849E}] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [{A42A81CB-243D-424B-A1D2-E662EB7A79B5}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe
FirewallRules: [{7878122C-021D-4A6D-A0EB-284AB08B8B7E}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe
FirewallRules: [TCP Query User{07B278D4-21FF-4CD2-A965-9B4438E8948A}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe
FirewallRules: [UDP Query User{F79BB37B-92F4-474B-AD1B-CF9F1568C6B7}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe
FirewallRules: [TCP Query User{FEEB000C-3527-4656-972D-BD975F70038B}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe
FirewallRules: [UDP Query User{AA76E5A5-6069-49D6-B878-FDBD28329607}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe
FirewallRules: [{5407BD3E-4D9F-460E-A8AA-0B2BD11CE977}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{C767F0A0-DC9F-430D-81AC-BA6847226F1E}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [{6C0E44BE-0BDE-4BBC-A1D5-7E0B514B8E10}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{80803E9F-BC54-40E5-A2AC-C160843F37F5}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{91BE1D7A-7F5E-4888-8C7B-7A4FB2833155}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{85591B93-2B77-4228-ACD3-3663078EA1C8}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D228A34F-3AF9-41F6-AA7B-3579CF041A48}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{BD1FD5D4-E5B0-44EF-A5F2-0CC6D6F8A3E3}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{DF2CC86E-9A5F-4831-B378-C0A56490E11E}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [UDP Query User{BEB80554-9B9D-4AB0-90E7-0640D3A57881}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [TCP Query User{136FA891-6E6C-483B-8803-A3420AA28CD3}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [UDP Query User{11852EA3-54FD-4B1C-96D7-470540C49779}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [{9830404C-9584-4B5A-AAA7-37464D53161D}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{5BCD7EEB-5882-4C2B-8864-78E37C461F11}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{D1E14E70-55FD-433A-BA10-0FDA73C5FA47}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{702D7745-DB5D-4710-8D92-015A472B9C96}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{CB1CDFB6-8E46-4267-A529-C2D1099F4180}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{0CDC5D99-44C4-49B6-8130-528ED1F07E26}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{83F18E26-E83F-4F9C-A56D-8B5D7A93C367}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{BD161ADE-0A7C-44D3-8915-BB5980B4305B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{A6A9097C-7008-48A2-AD29-13120F59BAAF}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{7F39D004-385E-48B2-9AC7-02CFC9CB9DF9}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{4767A3CC-2571-4160-8DAD-E9C5D341B5A2}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{188AD522-CA2C-4096-B0C6-73A7377F1EDC}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{3C9E1994-A54A-4741-9505-6142A9097317}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{B3EFC034-FD60-4DDF-B0F1-5837E7FA5375}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{F71E818A-A294-41B8-BD37-D13C81FA5F53}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{6B914922-3E76-4FEC-A515-4105D6FDC28F}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{F5E466D7-9CCD-4E00-B99F-B4B6D6F4D8D7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{F9FCBDA4-2E6B-4828-932D-AD998122FFB7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{6C701C59-B17B-486B-9D50-93844C0B482F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{1890F277-1738-49F9-8AA6-01CBDDF0C720}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{FD5590CC-017D-44AE-86A9-00E3FE28FB6D}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{C66BD5C9-1AB8-46C3-BC95-4795126CAECB}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{071AC728-7D57-4B67-BAD1-F2BF4D1009DC}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{75E91A46-1BBE-4E2D-A34A-3E22273BBB32}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{B4F8DCE1-4FF7-4C1F-BC65-B49B02A489B3}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{C3F65FC8-FCC0-4EDC-841B-E344B116F68B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{F92EFA33-3CBA-4D48-A37F-EAA5C3B85EAC}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{7F0BE56E-50CB-4D65-BA66-69B59B4E5837}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{5BDC7800-C619-4DAF-9158-04EC99DFB02E}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{BD129EA8-910D-4761-95EF-F4BD429148F1}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{1FA56378-6A82-4A35-99DE-8725DADA7EE5}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{B5A22037-BC5A-4720-A169-8A51A0B6DD94}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{BF006074-C97D-40B6-B4D7-875815699F4E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
23-03-2017 16:30:15 Restore Operation
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/24/2017 06:44:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 64813156
Error: (03/24/2017 06:44:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 64813156
Error: (03/24/2017 06:44:27 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (03/23/2017 07:17:39 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: An unspecified error occurred during System Restore: (Windows Update). Additional information: 0xc0000022.
Error: (03/23/2017 06:00:00 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1756) SRUJet: Error -1811 (0xfffff8ed) occurred while opening logfile C:\Windows\system32\SRU\SRU011D2.log.
Error: (03/23/2017 05:58:10 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (03/23/2017 05:41:10 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: )
Description: The Cryptographic Services service failed to initialize the Catalog Database. The ESENT error was: -528.
Error: (03/23/2017 05:41:10 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Catalog Database (1468) Catalog Database: Error -1811 (0xfffff8ed) occurred while opening logfile C:\Windows\system32\CatRoot2\edb0004F.log.
Error: (03/23/2017 04:23:53 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wwahost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 24fc
Start Time: 01d2a35034d5b2f8
Termination Time: 4294967295
Application Path: C:\Windows\system32\wwahost.exe
Report Id: 7c630ee7-0f43-11e7-82b1-3863bb8eae0e
Faulting package full name: Microsoft.BingWeather_3.0.4.350_x64__8wekyb3d8bbwe
Faulting package-relative application ID: App
Error: (03/23/2017 04:21:57 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
System errors:
=============
Error: (03/24/2017 10:46:48 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
Error: (03/24/2017 10:46:48 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
Error: (03/24/2017 10:46:29 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
Error: (03/24/2017 10:46:29 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
Error: (03/24/2017 10:46:29 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
Error: (03/24/2017 10:46:29 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
Error: (03/24/2017 10:46:28 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
Error: (03/24/2017 10:46:28 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
Error: (03/24/2017 08:48:52 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
Error: (03/24/2017 08:48:52 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
CodeIntegrity:
===================================
Date: 2017-03-24 22:52:11.355
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-24 22:52:10.324
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-24 22:52:09.243
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-24 22:52:08.165
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-23 23:04:17.762
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-20 21:43:47.532
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-18 10:44:53.927
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-23 20:57:46.980
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-23 20:57:46.022
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-23 20:13:27.689
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: AMD A6-5200 APU with Radeon(TM) HD Graphics
Percentage of memory in use: 58%
Total physical RAM: 3554.01 MB
Available physical RAM: 1473.14 MB
Total Virtual: 8418.01 MB
Available Virtual: 5466.17 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:677.63 GB) (Free:437.87 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:19.99 GB) (Free:1.28 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive f: () (Removable) (Total:7.4 GB) (Free:0.06 GB) FAT32
Drive z: () (Fixed) (Total:0.25 GB) (Free:0.14 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: A9A16C4F)
Partition: GPT.
========================================================
Disk: 1 (Size: 7.4 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by [removed] (24-03-2017 23:03:50)
Running from C:\Users\[removed]\Desktop
Windows 8.1 (Update) (X64) (2014-11-19 21:48:55)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1409944621-189731363-133459071-500 - Administrator - Disabled)
Annette (S-1-5-21-1409944621-189731363-133459071-1005 - Administrator - Enabled) => C:\Users\Annette
Guest (S-1-5-21-1409944621-189731363-133459071-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1409944621-189731363-133459071-1004 - Limited - Enabled)
Jacquelyn (S-1-5-21-1409944621-189731363-133459071-1002 - Administrator - Enabled) => C:\Users\Jacquelyn
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Kaspersky Total Security (Disabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Kaspersky Total Security (Disabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Total Security (Disabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
4 Elements II (x32 Version: 2.2.0.98 - WildTangent) Hidden
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.0.4.144 - Adobe Systems, Inc.)
Airport Mania (x32 Version: 2.2.0.95 - WildTangent) Hidden
AMD Catalyst Install Manager (HKLM\…\{301D3AA1-5DCC-FCFD-622E-3C7CBA87C80F}) (Version: 8.0.915.0 - Advanced Micro Devices, Inc.)
Azkend 2: The World Beneath (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bounce Symphony (x32 Version: 2.2.0.97 - WildTangent) Hidden
Build-a-lot (x32 Version: 2.2.0.98 - WildTangent) Hidden
CenturyLink Installer (HKLM-x32\…\{C96FF998-45BD-411E-9253-B7F2660FE280}) (Version: 1.0 - CenturyLink, Inc.)
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{AF312B06-5C5C-468E-89B3-BE6DE2645722}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{0A4EF0E6-A912-4CDE-A7F3-6E56E7C13A2F}) (Version: 1.1.6 - Cisco Systems, Inc.)
Cradle Of Egypt Collector's Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Cradle of Rome 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Crescendo Music Notation Editor (HKLM-x32\…\Crescendo) (Version: 1.86 - NCH Software)
Curse at Twilight (x32 Version: 3.0.2.32 - WildTangent) Hidden
CyberLink LabelPrint (HKLM-x32\…\InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}) (Version: 2.5.5.6902 - CyberLink Corp.)
CyberLink Media Suite 10 (HKLM-x32\…\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.9.4928 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\…\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.4.4824 - CyberLink Corp.)
CyberLink Power Media Player 12 (HKLM-x32\…\InstallShield_{B46BEA36-0B71-4A4E-AE41-87241643FA0A}) (Version: 12.0.6.5104 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\…\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.10.5422 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.6.3912 - CyberLink Corp.)
CyberLink YouCam (HKLM-x32\…\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 5.0.5.4628 - CyberLink Corp.)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Delicious: Emily's Childhood Memories Premium Edition (x32 Version: 3.0.2.32 - WildTangent) Hidden
DisableMSDefender (Version: 1.0.0 - Hewlett-Packard Company) Hidden
Energy Star (HKLM-x32\…\{FC0ADA4D-8FA5-4452-8AFF-F0A0BAC97EF7}) (Version: 1.0.9 - Hewlett-Packard Company)
Farkle 3.0.13.10 (HKLM-x32\…\Farkle_is1) (Version: - )
Farm Frenzy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Fishdom 3: Collector's Edition (x32 Version: 3.0.2.38 - WildTangent) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Earth (HKLM-x32\…\{F6430171-B86B-4639-839E-374913E7911D}) (Version: 7.1.8.3036 - Google)
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (x32 Version: 2.2.0.110 - WildTangent) Hidden
Hewlett-Packard ACLM.NET v1.2.2.3 (x32 Version: 1.00.0000 - Hewlett-Packard Company) Hidden
House of 1000 Doors: Family Secrets (x32 Version: 2.2.0.98 - WildTangent) Hidden
HP Documentation (HKLM-x32\…\{2C0CCB21-5ED3-4417-93D2-CC6BEEB3C7CF}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Registration Service (HKLM\…\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.7127.4628 - Hewlett-Packard)
HP SimplePass (HKLM-x32\…\InstallShield_{314FAD12-F785-4471-BCE8-AB506642B9A1}) (Version: 8.00.54 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\…\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.3.50.9 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\…\{55065080-504F-43BB-BE00-36B80D7D39A5}) (Version: 12.5.32.203 - Hewlett-Packard Company)
HP System Event Utility (HKLM-x32\…\{6B1ECC61-B581-400D-BFAF-101B1AAEA5AB}) (Version: 1.4.7 - Hewlett-Packard Company)
HP Utility Center (HKLM\…\{7A75E042-0D30-43C2-BD2A-684F4BE38FF7}) (Version: 2.3.1 - Hewlett-Packard Company)
HP Wireless Button Driver (HKLM-x32\…\{EFA01423-3857-468C-B7B6-F30AA08E50BC}) (Version: 1.1.5.1 - Hewlett-Packard)
Inst5675 (Version: 8.00.54 - Softex Inc.) Hidden
Inst5676 (Version: 8.00.54 - Softex Inc.) Hidden
Java 8 Update 25 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Jewel Match 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (x32 Version: 2.2.0.95 - WildTangent) Hidden
Kaspersky Secure Connection (HKLM-x32\…\InstallWIX_{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab)
Kaspersky Secure Connection (x32 Version: 17.0.0.611 - Kaspersky Lab) Hidden
Kaspersky Total Security (HKLM-x32\…\InstallWIX_{E27B1D7B-3B34-43A2-9FC0-9828D5DF46E2}) (Version: 17.0.0.611 - Kaspersky Lab)
Kaspersky Total Security (x32 Version: 17.0.0.611 - Kaspersky Lab) Hidden
King Oddball (x32 Version: 3.0.2.48 - WildTangent) Hidden
Luxor Evolved (x32 Version: 2.2.0.98 - WildTangent) Hidden
Mahjongg Dimensions Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office 365 ProPlus - en-us (HKLM\…\O365ProPlusRetail - en-us) (Version: 16.0.7369.2118 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\…\{95140000-0081-0409-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM-x32\…\Office15.PROPLUSR) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\OneDriveSetup.exe) (Version: 17.3.6798.0207 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\…\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\…\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Monopoly® (x32 Version: 3.0.2.51 - WildTangent) Hidden
Movie Maker (x32 Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mystery P.I. - Curious Case of Counterfeit Cove (x32 Version: 2.2.0.98 - WildTangent) Hidden
NCH Tone Generator (HKLM-x32\…\ToneGen) (Version: 3.26 - NCH Software)
Norton Online Backup (HKLM-x32\…\{1969BD50-331D-4B7A-8116-29A7DC6D45B4}) (Version: 2.8.0.44 - Symantec Corporation)
OEM Application Profile (HKLM-x32\…\{70D5F822-F4C4-33D9-7EEC-2A4AF4EA7BDC}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.7369.2118 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.7369.2118 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.7369.2118 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7369.2118 - Microsoft Corporation) Hidden
Outils de vérification linguistique 2013 de Microsoft Office - Français (x32 Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
Pinger (HKLM-x32\…\Pinger 1.4.0.1) (Version: 1.4.0.1 - Pinger Inc.)
Pinger (x32 Version: 1.4.0.1 - Pinger Inc.) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.3.9600.29080 - Realtek Semiconductor Corp.)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 8.32.508.2014 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7730 - Realtek Semiconductor Corp.)
REALTEK Wireless LAN Driver (HKLM-x32\…\{A5107464-AA9B-4177-8129-5FF2F42DD322}) (Version: 1.0.0.41 - REALTEK Semiconductor Corp.)
Roads of Rome 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Service Pack 1 for Microsoft Office 2013 (KB2850036) 32-Bit Edition (HKLM-x32\…\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{7F6C4883-A18C-459A-82C1-A2F9403F2DA6}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 17.0.6.2 - Synaptics Incorporated)
Tales of Lagoona (x32 Version: 2.2.0.110 - WildTangent) Hidden
TurboTax 2014 (HKLM-x32\…\TurboTax 2014) (Version: 2014.0 - Intuit, Inc)
Update for Skype for Business 2015 (KB3039776) 32-Bit Edition (HKLM-x32\…\{90150000-012B-0409-0000-0000000FF1CE}_Office15.PROPLUSR_{9F6B3627-AF9E-40A5-AAD5-3497C4327616}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3161988) 32-Bit Edition (HKLM-x32\…\{90150000-002A-0000-1000-0000000FF1CE}_Office15.PROPLUSR_{245EB15F-A90C-422B-9D3F-3AEEDF028CCC}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3161988) 32-Bit Edition (HKLM-x32\…\{90150000-012B-0409-0000-0000000FF1CE}_Office15.PROPLUSR_{245EB15F-A90C-422B-9D3F-3AEEDF028CCC}) (Version: - Microsoft)
Update for Skype for Business 2015 (KB3161988) 32-Bit Edition (HKLM-x32\…\{91150000-0011-0000-0000-0000000FF1CE}_Office15.PROPLUSR_{245EB15F-A90C-422B-9D3F-3AEEDF028CCC}) (Version: - Microsoft)
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Vacation Questâ„¢ - Australia (x32 Version: 3.0.2.32 - WildTangent) Hidden
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
WavePad Sound Editor (HKLM-x32\…\WavePad) (Version: 7.00 - NCH Software)
WhatsApp (HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\WhatsApp) (Version: 0.2.1455 - WhatsApp)
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (HP Games) (x32 Version: 4.0.10.15 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Youda Jewel Shop (x32 Version: 3.0.2.32 - WildTangent) Hidden
Zulu DJ Software (HKLM-x32\…\Zulu) (Version: 3.70 - NCH Software)
Zuma's Revenge (x32 Version: 2.2.0.98 - WildTangent) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1409944621-189731363-133459071-1005_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Annette\AppData\Local\Microsoft\OneDrive\17.3.6798.0207\amd64\FileCoAuthLib64.dll (Microsoft Corporation)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {014769DA-BE7F-4F02-9B58-34329401B70B} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {10A0396E-4397-432D-A61A-B29936C98279} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-27] (Google Inc.)
Task: {19BBD166-C964-43E3-B34D-187A7E62E5C1} - System32\Tasks\AVG-SSU_0516tb_RML => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: {1A39E007-12BB-4FCE-B21B-FF3D69A7BF99} - System32\Tasks\0915tbUpdateInfo => C:\ProgramData\Avg_Update_0915tb\0915tb_{82320DFB-27EB-4C68-8903-9D72AB169A0B}.exe
Task: {2FE82A44-7615-47C1-88DD-E0D568E5D0F2} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => %ProgramFiles%\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe
Task: {3165798A-F44B-4387-8B96-BD947DFDF94F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {35B33F54-DE13-47B9-BE64-FC38E4A16DE5} - System32\Tasks\AVG-SSU_0516tb_DELETE => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: {3E898CDD-32F4-47D1-A2F4-BCF33E88AEBC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {422808BD-6F70-41BF-945D-E13AA06AE45A} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis Install => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
Task: {468B13AD-B541-4A27-B004-9B018EEA3275} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2014-10-07] (Oracle Corporation)
Task: {55DCE214-7F3F-463F-BECE-5A67E73B6324} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
Task: {5B7B1C4A-9A07-4CAC-869E-5279651131BE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-22] (Microsoft Corporation)
Task: {657B0631-CFC6-4D97-9BBB-D64EA3A67056} - System32\Tasks\AVG-SSU_0516tb => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: {69D3BA23-D578-4DE2-AFDE-D9EF27762CEC} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-27] (Google Inc.)
Task: {6CC93A74-62F2-4910-A4FC-A40536BC93CE} - System32\Tasks\Kaspersky_Upgrade_Launcher_{278ADC42-419D-4547-A6CA-5B74BE0AD901} => C:\Program Files\Common Files\AV\Kaspersky Lab\upgrade_launcher.exe [2016-07-11] (AO Kaspersky Lab)
Task: {7096DF25-3B68-4C03-84FD-DD056A6478FC} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-03-10] (HP Inc.)
Task: {7CE5B9ED-BBEF-4FA0-BAB5-C5D42E3475BC} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-19] (Microsoft Corporation)
Task: {8AEFBD24-B736-48AC-8C72-6522466A99DE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-02-19] (Microsoft Corporation)
Task: {8B512A54-342F-4730-ADEC-CBA51071C650} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2017-03-06] (Microsoft Corporation)
Task: {A30614CC-919B-432A-A18E-DC51DEBD08F0} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {AD039A2B-990C-47B8-ABDA-3597CE2D288C} - System32\Tasks\HPCeeScheduleForAnnette => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {B46771D0-89A1-4B43-9AF1-2EB5AAF264C1} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-02-19] (Microsoft Corporation)
Task: {B73A7C7B-CF7F-4A7E-A613-BFBB8A73789D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {C2AE1DC2-5E00-418C-9CB1-D4E263229737} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-02-19] (Microsoft Corporation)
Task: {CC822724-6442-4F48-B1A5-EB51857BE53E} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {CD39A3B5-0980-4947-BD6C-3D87425A7FCE} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-07-26] (Synaptics Incorporated)
Task: {D0F920D8-40AD-4B42-9F6C-ADA01607FCCD} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-02-10] (HP Inc.)
Task: {DCEFA36E-E149-4C02-99DB-E3F29CC3066E} - System32\Tasks\YCMServiceAgent => C:\Program Files (x86)\CyberLink\YouCam\YouCamService.exe [2014-10-28] (CyberLink Corp.)
Task: {E6B7EE15-0DF8-473B-AA30-3C92EDE7356E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
Task: {EC860F0E-1C8E-4761-BA2C-9ACF03169D98} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
Task: {FC28F289-DC07-41F7-A432-5D92E184B45F} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-02-19] (Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\0915tbUpdateInfo.job => C:\ProgramData\Avg_Update_0915tb\0915tb_{82320DFB-27EB-4C68-8903-9D72AB169A0B}.exe
Task: C:\Windows\Tasks\AVG-SSU_0516tb.job => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: C:\Windows\Tasks\AVG-SSU_0516tb_DELETE.job => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: C:\Windows\Tasks\AVG-SSU_0516tb_RML.job => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: C:\Windows\Tasks\HPCeeScheduleForAnnette.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
Shortcut: C:\Users\Annette\AppData\Local\Microsoft\Windows\ConnectedSearch\History\site_2989506396_en-us.lnk -> hxxp://www.windowssearch.com:80/suggestions?qry=minneapolis+radiology&cc;=US&setlang;=en-US&inlang;=en-US&adlt;=moderate&scale;=100&contrast;=none&hw;=768%2C1366&CVID;=A87F048B1716477D94308BC9F119B97
==================== Loaded Modules (Whitelisted) ==============
2013-09-26 13:26 - 2013-09-26 13:26 - 00109568 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachesrvr.exe
2013-09-26 13:32 - 2013-09-26 13:32 - 00627200 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cachedrv.dll
2013-09-26 13:28 - 2013-09-26 13:28 - 02540544 _____ () C:\Program Files\Hewlett-Packard\SimplePass\autheng.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 00035328 _____ () C:\Program Files\Hewlett-Packard\SimplePass\ssplogon.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 00055296 _____ () C:\Program Files\Hewlett-Packard\SimplePass\RandomPass.dll
2013-09-26 13:25 - 2013-09-26 13:25 - 00021504 _____ () C:\Program Files\Hewlett-Packard\SimplePass\cryptodll.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 00306064 _____ () C:\Program Files\Hewlett-Packard\SimplePass\mstrpwd.dll
2013-09-26 13:39 - 2013-09-26 13:39 - 01298832 _____ () C:\Program Files\Hewlett-Packard\SimplePass\GraphicalPwd.dll
2013-09-25 08:49 - 2013-09-25 08:49 - 00099328 _____ () C:\Program Files\ATI Technologies\ATI.ACE\A4\AdaptiveSleepService.exe
2013-09-25 08:48 - 2013-09-25 08:48 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2016-08-19 12:07 - 2017-02-19 16:54 - 08923848 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:23 - 2010-10-20 16:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-09-26 13:34 - 2013-09-26 13:34 - 00064000 _____ () C:\Program Files\Hewlett-Packard\SimplePass\opvapp.exe
2013-09-25 08:48 - 2013-09-25 08:48 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
2013-09-25 08:49 - 2013-09-25 08:49 - 00016896 _____ () C:\Program Files\ATI Technologies\ATI.ACE\a4\AS4.NativeProxy.dll
2016-06-28 01:19 - 2016-06-28 01:19 - 00865232 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\kpcengine.2.3.dll
2017-02-11 11:01 - 2017-02-01 04:01 - 01870168 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-02-11 11:01 - 2017-02-01 04:01 - 00085848 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1409944621-189731363-133459071-1005\…\sharepoint.com -> hxxps://liveedurdale-files.sharepoint.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 08:25 - 2017-03-08 20:33 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1409944621-189731363-133459071-1005\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Hewlett-Packard Backgrounds\backgroundDefault.jpg
DNS Servers: 208.67.222.222 - 8.8.8.8
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
HKLM\…\StartupApproved\Run32: => "YouCam Service"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{8D444952-FDB7-4FA5-901C-2462C1A37F99}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{AF3331A2-97B7-4313-AC3F-01DBA6B2C4FE}] => (Allow) LPort=2869
FirewallRules: [{150FBC6F-7AB5-4063-A0FB-EAC794994B93}] => (Allow) LPort=1900
FirewallRules: [{E39BD188-517F-4E06-97D0-5C42D5838F7E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{F1948981-D69A-4ED2-8B17-9EFB0572B092}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1402E48A-D816-4233-BC99-5439A3F6EDF5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{8F1DB3E0-F2A7-42ED-91C7-FB0C90AC0852}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{BAB834BF-B807-4BB0-9914-BEB323488AC5}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{B4EC793D-9BBE-49AF-B2AF-C979A6135B15}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{711CA439-540E-400F-96B4-03755DDF5D83}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{A58108F8-825B-42DE-A8B0-03908ED19304}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{37B0BF0A-6A5B-4084-8C13-81F803B4FF7C}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{7281462C-F67B-4492-905D-4C4B321E723A}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{A5A52445-92E8-42E2-A32A-0836A405AB0F}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{3B61AE1B-6103-477A-8F0D-4BAE585A8645}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP System Event\HPSOCKSVC.exe
FirewallRules: [{A4D5D120-EF07-4D46-A751-2106EBA65128}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{05E02CB2-DD6F-4010-A83B-A512473814C6}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{EFA066DD-C059-4586-ABDF-A21118A3F404}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{6A275A23-CBA3-45C2-B294-6F06F6C0848D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [TCP Query User{ACBD9CE9-88F2-4D23-8571-2E3C7E52DE4E}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [UDP Query User{02717F8A-ABC2-4205-9C6C-6DD19E9FB7DF}C:\program files (x86)\symantec\norton online backup\nobuclient.exe] => (Allow) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [{D7AA5C63-D072-4153-8525-465AED706750}] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [{ED315B61-5CAE-477B-92D2-6F17C887849E}] => (Block) C:\program files (x86)\symantec\norton online backup\nobuclient.exe
FirewallRules: [{A42A81CB-243D-424B-A1D2-E662EB7A79B5}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe
FirewallRules: [{7878122C-021D-4A6D-A0EB-284AB08B8B7E}] => (Allow) C:\Program Files (x86)\Tango\Tango.exe
FirewallRules: [TCP Query User{07B278D4-21FF-4CD2-A965-9B4438E8948A}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe
FirewallRules: [UDP Query User{F79BB37B-92F4-474B-AD1B-CF9F1568C6B7}C:\windows\system32\settingsynchost.exe] => (Block) C:\windows\system32\settingsynchost.exe
FirewallRules: [TCP Query User{FEEB000C-3527-4656-972D-BD975F70038B}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe
FirewallRules: [UDP Query User{AA76E5A5-6069-49D6-B878-FDBD28329607}C:\program files (x86)\tango\tango.exe] => (Block) C:\program files (x86)\tango\tango.exe
FirewallRules: [{5407BD3E-4D9F-460E-A8AA-0B2BD11CE977}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{C767F0A0-DC9F-430D-81AC-BA6847226F1E}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [{6C0E44BE-0BDE-4BBC-A1D5-7E0B514B8E10}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{80803E9F-BC54-40E5-A2AC-C160843F37F5}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{91BE1D7A-7F5E-4888-8C7B-7A4FB2833155}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{85591B93-2B77-4228-ACD3-3663078EA1C8}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{D228A34F-3AF9-41F6-AA7B-3579CF041A48}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{BD1FD5D4-E5B0-44EF-A5F2-0CC6D6F8A3E3}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [TCP Query User{DF2CC86E-9A5F-4831-B378-C0A56490E11E}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [UDP Query User{BEB80554-9B9D-4AB0-90E7-0640D3A57881}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [TCP Query User{136FA891-6E6C-483B-8803-A3420AA28CD3}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [UDP Query User{11852EA3-54FD-4B1C-96D7-470540C49779}C:\program files (x86)\tams11\games\farkle\farkle.exe] => (Allow) C:\program files (x86)\tams11\games\farkle\farkle.exe
FirewallRules: [{9830404C-9584-4B5A-AAA7-37464D53161D}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{5BCD7EEB-5882-4C2B-8864-78E37C461F11}] => (Allow) C:\Users\Jacquelyn\AppData\Local\Maelstrom\Application\chrome.native.torrent.exe
FirewallRules: [{D1E14E70-55FD-433A-BA10-0FDA73C5FA47}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{702D7745-DB5D-4710-8D92-015A472B9C96}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{CB1CDFB6-8E46-4267-A529-C2D1099F4180}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{0CDC5D99-44C4-49B6-8130-528ED1F07E26}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{83F18E26-E83F-4F9C-A56D-8B5D7A93C367}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{BD161ADE-0A7C-44D3-8915-BB5980B4305B}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\lync.exe
FirewallRules: [{A6A9097C-7008-48A2-AD29-13120F59BAAF}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{7F39D004-385E-48B2-9AC7-02CFC9CB9DF9}] => (Allow) C:\Program Files (x86)\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{4767A3CC-2571-4160-8DAD-E9C5D341B5A2}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{188AD522-CA2C-4096-B0C6-73A7377F1EDC}] => (Allow) C:\Users\Jacquelyn\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{3C9E1994-A54A-4741-9505-6142A9097317}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{B3EFC034-FD60-4DDF-B0F1-5837E7FA5375}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgnsa.exe
FirewallRules: [{F71E818A-A294-41B8-BD37-D13C81FA5F53}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{6B914922-3E76-4FEC-A515-4105D6FDC28F}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgdiagex.exe
FirewallRules: [{F5E466D7-9CCD-4E00-B99F-B4B6D6F4D8D7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{F9FCBDA4-2E6B-4828-932D-AD998122FFB7}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{6C701C59-B17B-486B-9D50-93844C0B482F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{1890F277-1738-49F9-8AA6-01CBDDF0C720}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{FD5590CC-017D-44AE-86A9-00E3FE28FB6D}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{C66BD5C9-1AB8-46C3-BC95-4795126CAECB}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{071AC728-7D57-4B67-BAD1-F2BF4D1009DC}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{75E91A46-1BBE-4E2D-A34A-3E22273BBB32}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{B4F8DCE1-4FF7-4C1F-BC65-B49B02A489B3}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{C3F65FC8-FCC0-4EDC-841B-E344B116F68B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{F92EFA33-3CBA-4D48-A37F-EAA5C3B85EAC}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{7F0BE56E-50CB-4D65-BA66-69B59B4E5837}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{5BDC7800-C619-4DAF-9158-04EC99DFB02E}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{BD129EA8-910D-4761-95EF-F4BD429148F1}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{1FA56378-6A82-4A35-99DE-8725DADA7EE5}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{B5A22037-BC5A-4720-A169-8A51A0B6DD94}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{BF006074-C97D-40B6-B4D7-875815699F4E}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
23-03-2017 16:30:15 Restore Operation
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/24/2017 06:44:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 64813156
Error: (03/24/2017 06:44:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 64813156
Error: (03/24/2017 06:44:27 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (03/23/2017 07:17:39 PM) (Source: System Restore) (EventID: 8210) (User: )
Description: An unspecified error occurred during System Restore: (Windows Update). Additional information: 0xc0000022.
Error: (03/23/2017 06:00:00 PM) (Source: ESENT) (EventID: 455) (User: )
Description: svchost (1756) SRUJet: Error -1811 (0xfffff8ed) occurred while opening logfile C:\Windows\system32\SRU\SRU011D2.log.
Error: (03/23/2017 05:58:10 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
Error: (03/23/2017 05:41:10 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 257) (User: )
Description: The Cryptographic Services service failed to initialize the Catalog Database. The ESENT error was: -528.
Error: (03/23/2017 05:41:10 PM) (Source: ESENT) (EventID: 455) (User: )
Description: Catalog Database (1468) Catalog Database: Error -1811 (0xfffff8ed) occurred while opening logfile C:\Windows\system32\CatRoot2\edb0004F.log.
Error: (03/23/2017 04:23:53 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wwahost.exe version 6.3.9600.17415 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 24fc
Start Time: 01d2a35034d5b2f8
Termination Time: 4294967295
Application Path: C:\Windows\system32\wwahost.exe
Report Id: 7c630ee7-0f43-11e7-82b1-3863bb8eae0e
Faulting package full name: Microsoft.BingWeather_3.0.4.350_x64__8wekyb3d8bbwe
Faulting package-relative application ID: App
Error: (03/23/2017 04:21:57 PM) (Source: Office 2016 Licensing Service) (EventID: 0) (User: )
Description: Event-ID 0
System errors:
=============
Error: (03/24/2017 10:46:48 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
Error: (03/24/2017 10:46:48 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
Error: (03/24/2017 10:46:29 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
Error: (03/24/2017 10:46:29 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
Error: (03/24/2017 10:46:29 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
Error: (03/24/2017 10:46:29 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
Error: (03/24/2017 10:46:28 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
Error: (03/24/2017 10:46:28 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
Error: (03/24/2017 08:48:52 PM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 107.
Error: (03/24/2017 08:48:52 PM) (Source: Schannel) (EventID: 4106) (User: NT AUTHORITY)
Description: An TLS 1.0 connection request was received from a remote client application, but none of the cipher suites supported by the client application are supported by the server. The SSL connection request has failed.
CodeIntegrity:
===================================
Date: 2017-03-24 22:52:11.355
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-24 22:52:10.324
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-24 22:52:09.243
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-24 22:52:08.165
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-23 23:04:17.762
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-20 21:43:47.532
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-18 10:44:53.927
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-23 20:57:46.980
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-23 20:57:46.022
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-02-23 20:13:27.689
Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume4\Program Files\Microsoft Silverlight\xapauthenticodesip.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: AMD A6-5200 APU with Radeon(TM) HD Graphics
Percentage of memory in use: 58%
Total physical RAM: 3554.01 MB
Available physical RAM: 1473.14 MB
Total Virtual: 8418.01 MB
Available Virtual: 5466.17 MB
==================== Drives ================================
Drive c: (Windows) (Fixed) (Total:677.63 GB) (Free:437.87 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:19.99 GB) (Free:1.28 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive f: () (Removable) (Total:7.4 GB) (Free:0.06 GB) FAT32
Drive z: () (Fixed) (Total:0.25 GB) (Free:0.14 GB) FAT32
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: A9A16C4F)
Partition: GPT.
========================================================
Disk: 1 (Size: 7.4 GB) (Disk ID: 00000000)
Partition: GPT.
==================== End of Addition.txt ============================
Or use this method Press the windows key [external image: Windows_Logo_key.gif]+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.
To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)
[external image: x1lWQRS.gif]
start
CreateRestorePoint:
CloseProcesses:
CHR NewTab: Default -> Not-active:"chrome-extension://laookkfknpbbblfpciffpaejjkokdgca/dashboard.html"
CHR Extension: (Ebates Cash Back) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\chhjbpecpncaggjpdakmflnfcopglcmi [2017-03-23]
CHR Extension: (PeofjASvJAwrZid) - C:\Users\Annette\AppData\Local\Google\Chrome\User Data\Default\Extensions\oedkmhdiokckdlnnphoebbnflkjjnhmo [2017-03-12]
S0 mnbb; System32\drivers\ftumiyt.sys [X]
C:\Windows\Tasks\AVG-SSU_0516tb.job
C:\Windows\Tasks\AVG-SSU_0516tb_DELETE.job
Task: {014769DA-BE7F-4F02-9B58-34329401B70B} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe
Task: {19BBD166-C964-43E3-B34D-187A7E62E5C1} - System32\Tasks\AVG-SSU_0516tb_RML => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: {1A39E007-12BB-4FCE-B21B-FF3D69A7BF99} - System32\Tasks\0915tbUpdateInfo => C:\ProgramData\Avg_Update_0915tb\0915tb_{82320DFB-27EB-4C68-8903-9D72AB169A0B}.exe
Task: {35B33F54-DE13-47B9-BE64-FC38E4A16DE5} - System32\Tasks\AVG-SSU_0516tb_DELETE => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: {657B0631-CFC6-4D97-9BBB-D64EA3A67056} - System32\Tasks\AVG-SSU_0516tb => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: C:\Windows\Tasks\0915tbUpdateInfo.job => C:\ProgramData\Avg_Update_0915tb\0915tb_{82320DFB-27EB-4C68-8903-9D72AB169A0B}.exe
Task: C:\Windows\Tasks\AVG-SSU_0516tb.job => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: C:\Windows\Tasks\AVG-SSU_0516tb_DELETE.job => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Task: C:\Windows\Tasks\AVG-SSU_0516tb_RML.job => C:\ProgramData\Avg_Update_0516tb\AVG-Secure-Search-Update_0516tb.exe
Shortcut: C:\Users\Annette\AppData\Local\Microsoft\Windows\ConnectedSearch\History\site_2989506396_en-us.lnk -> hxxp://www.windowssearch.com:80/suggestions?qry=minneapolis+radiology&cc=US&setlang=en-US&inlang=en-US&adlt=moderate&scale=100&contrast=none&hw=768%2C1366&CVID=A87F048B1716477D94308BC9F119B97
FirewallRules: [{A4D5D120-EF07-4D46-A751-2106EBA65128}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{05E02CB2-DD6F-4010-A83B-A512473814C6}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgmfapx.exe
FirewallRules: [{EFA066DD-C059-4586-ABDF-A21118A3F404}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
FirewallRules: [{6A275A23-CBA3-45C2-B294-6F06F6C0848D}] => (Allow) C:\Program Files (x86)\AVG\AVG2015\avgemca.exe
CMD: ipconfig /flushdns
CMD: netsh winsock reset all
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
Hosts:
End
Open FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.
~~~~~~~~~~~~~~~~~~~~~~~~
Download Zeok tool from here
When the download appears, save to the Desktop.
On the Desktop, right-click the Zoek.exe file and select: Run as Administrator
(Give it a few seconds to appear.)
Next, copy/paste the entire script inside the code box below to the input field of Zoek:
createsrpoint; autoclean; emptyclsid; emptyffcache; FFdefaults; emptyiecache; iedefaults; emptychrcache; CHRdefaults; emptyalltemp; emptyfolderscheck;delete ipconfig /flushdns;bNow…
Close any open Browsers.
Click the Run script button, and wait. It takes a few minutes to run all the script.
When the tool finishes, the zoek-results.log is opened in Notepad.
The log is also found on the systemdrive, normally C:\
If a reboot is needed, the log is opened after the reboot.
Please attach the zoek-results.log in your reply.
~~~~~~~~~~~~~~~~~`
Click to load external image (a6csRll.png)Malwarebytes Anti-Rootkit Beta
- Download Malwarebytes Anti-Rootkit Beta and extract it to your desktop (MBAR will be launched shortly after the extraction);
Click to load external image (HTCF1SV.png) - Click on Next, and then on the Update button to let it update its database. Once the database has been successfully updated, click on Next;
Click to load external image (UJCQPAS.png) - Make sure all the checkboxes are checked, then click on the Scan button, and let it completes its scan (this can take a while);
Click to load external image (v4lJKL5.png) - Once the scan is done, make sure that every item is checked, and click on the Cleanup button (a reboot might be required);
- After that (and the reboot, if one was required), go back in the mbar folder and look for a text file called mbar-log-TODAY'S-DATE.txt;
- Copy/paste the content of that log in your next reply;
After restarting from the zeok scan, my laptop got 2 blue screen error messages.
":( Your PC ran into a problem and needs to restart . We're just collecting some error info, and then we'll restart for you. It did that twice."
Next I got the blue screen RECOVERY message/
"It looks like Windows didn't load correctly. If you'd like to restart and try again, choose "Restart my PC" below. Otherwise, choose "See advanced repair options" for troubleshooting tools and advanced options. If you don't know which options is right for you, contact someone you trust to help with this. I chose the advanced repair button. It went to "Choose an option". I attempted to click on the "Continue" button that said to Exit and continue to Windows 8.1. After waiting 3 minutes for it to respond, I ended up powering off my laptop and turning it back on. Then that's when I started the Malware update/scan.
After malware update and scan, it came back congratulations, scan finished and not cleanup required.
After running this scan, it did reboot right up. Got no error message upon start.
How is the computer now?
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI