This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

trojan win32/vigorf.a [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Keep getting windows defender notifications that trojan win32/vigorf.a has been detected and removed.  I haven't downloaded anything today.  How do I permanently get rid of it?  It popped up a few times in windows defender.  I removed it several times and now it isn't popping up any more.  Malwarebytes isn't finding anything.

:welcome:

 

Lets run a few scans and see if we can determine whats going on

 

 

[external image: 1QYkxTZ.jpg] Please download aswMBR to your DESKTOP <<<<<
 
  •  
  • Right click the aswMBR icon and select Run as Administrator
  • XP users just Double Click it to run
  • If it says that this computer supports VIRTUALIZATION TECHNOLOGY do you want to use it say Yes
  • Click the Scan button to start scan.
  • Select Quickscan on the dropdown list
  • If you are asked to update the Avast Virus database please allow it to do so.
  • The scan could take 20 minutes or more , please be patient and let it finish
  • It will say Scan Finished when its done.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.
 
 
I just want to see the report….Please Do Not Fix Anything
 
============================================================================
 
 
Please download Farbar Recovery Scan Tool and save it to your DESKTOP<<<<<<
 
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
 
How to determine whether a computer is running a 32-bit version or 64-bit version of the Windows operating system
A simple way to check your system: Start –> Computer (right click) –> Properties
 
[external image: FRST_zps5d956a1a.jpg]
 
 
  •  
  • Right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • Just keep the defaults as in the picture checkmarked
  • Press Scan button.
  • It will produce a log called FRST.txt in the same directory the tool is run from.
  • Please copy and paste log back here.
  • The first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-03-10 08:09:49
—————————–
08:09:49.034    OS Version: Windows x64 6.2.9200 
08:09:49.034    Number of processors: 4 586 0x2A07
08:09:49.050    ComputerName: NANCY-PC  UserName: Nancy
08:09:56.018    Initialze error C0000043 - driver not loaded
08:13:06.814    The log file has been saved successfully to "C:\Users\Nancy\Documents\aswMBR.txt"
 
 
aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-03-10 08:14:08
—————————–
08:14:08.075    OS Version: Windows x64 6.2.9200 
08:14:08.075    Number of processors: 4 586 0x2A07
08:14:08.075    ComputerName: NANCY-PC  UserName: Nancy
08:14:10.057    Initialze error C000010E - driver not loaded
08:17:49.910    AVAST engine defs: 17030301
08:19:25.626    Service scanning
08:20:18.386    Modules scanning
08:20:18.398    Disk 0 trace - called modules:
08:20:18.403    
08:20:20.375    AVAST engine scan C:\WINDOWS
08:20:25.483    AVAST engine scan C:\WINDOWS\system32
08:24:28.777    AVAST engine scan C:\WINDOWS\system32\drivers
08:24:54.354    AVAST engine scan C:\Users\Nancy
08:40:28.809    File: C:\Users\Nancy\AppData\Local\updanager\upd.exe  **INFECTED** Win32:Malware-gen
09:27:19.841    AVAST engine scan C:\ProgramData
09:36:33.359    Scan finished successfully
09:42:46.117    The log file has been saved successfully to "C:\Users\Nancy\Documents\aswMBR.txt"
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2017
Ran by [removed] (10-03-2017 09:48:26)
Running from C:\Users\[removed]\Downloads
Windows 10 Home Version 1607 (X64) (2016-10-29 20:23:59)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1846905553-2082907679-4278756267-500 - Administrator - Disabled)
ASPNET (S-1-5-21-1846905553-2082907679-4278756267-1004 - Limited - Enabled)
DefaultAccount (S-1-5-21-1846905553-2082907679-4278756267-503 - Limited - Disabled)
Guest (S-1-5-21-1846905553-2082907679-4278756267-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1846905553-2082907679-4278756267-1002 - Limited - Enabled)
Nancy (S-1-5-21-1846905553-2082907679-4278756267-1001 - Administrator - Enabled) => C:\Users\Nancy
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
AddrBk 473 (HKLM-x32\…\Address Book_is1) (Version:  - )
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe Flash Player 24 PPAPI (HKLM-x32\…\Adobe Flash Player PPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe Photoshop Elements 8.0 (HKLM-x32\…\Adobe Photoshop Elements 8.0) (Version: 8.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.2.2.172 - Adobe Systems, Inc.)
Amazon Music (HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Amazon Amazon Music) (Version: 5.3.2.1634 - Amazon Services LLC)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{9BA1A894-B42F-4805-BC8C-349C905A3930}) (Version: 5.3.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{7EAC8A42-9FAC-4F6B-AABF-C08C9F2E0F13}) (Version: 5.3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
BigOven (HKLM-x32\…\{98C4F0D9-3C09-4BD9-B835-29744B94931A}) (Version: 1.9.1 - Lakefront Software)
BigOven (x32 Version: 1.8.999 - Lakefront Software) Hidden
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 5.27 - Piriform)
CleanUp! (HKLM-x32\…\CleanUp!) (Version:  - )
Coupon Printer for Windows (HKLM-x32\…\Coupon Printer for Windows5.0.1.7) (Version: 5.0.1.7 - Coupons.com Incorporated)
Digital Coupon Printer (HKLM-x32\…\{2CDD20A5-DFDE-4AC0-97DD-F60B1196BF98}) (Version: 3.50.0.0 - Hopster, Inc. an Inmar company)
ELAN Touchpad 11.15.0.18_X64 (HKLM\…\Elantech) (Version: 11.15.0.18 - ELAN Microelectronic Corp.)
Elevated Installer (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
EPSON WorkForce 545 Series Printer Uninstall (HKLM\…\EPSON WorkForce 545 Series) (Version:  - SEIKO EPSON Corporation)
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
Evernote v. 6.4.2 (HKLM-x32\…\{E74F0DCA-9FC8-11E6-9D98-005056950253}) (Version: 6.4.2.3788 - Evernote Corp.)
Garmin Express (HKLM-x32\…\{9fbf4745-0038-4ed3-aee1-87af9b9ef8f1}) (Version: 5.1.1.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
GoodSync (HKLM\…\{B26B00DA-2E5D-4CF2-83C5-911198C0F009}) (Version: 9.9.45.8 - Siber Systems)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
HP ENVY 4500 series Basic Device Software (HKLM\…\{6915424E-704F-4F5D-9057-9C7B406B36DB}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
HP ENVY 4500 series Help (HKLM-x32\…\{95BECC50-22B4-4FCA-8A2E-BF77713E6D3A}) (Version: 30.0.0 - Hewlett Packard)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Support Assistant (HKLM-x32\…\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.3.50.9 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\…\{55065080-504F-43BB-BE00-36B80D7D39A5}) (Version: 12.5.32.203 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\…\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation)
iTunes (HKLM\…\{9D0D2A8B-7E7B-4D88-8D50-24286ED6A5EB}) (Version: 12.5.5.5 - Apple Inc.)
LIFX Bulb Update (HKLM-x32\…\{AA0C44A9-01EB-44F7-BE71-72EEC9805D2A}) (Version: 2.0.0 - LIFX)
Living Cookbook 2015 (HKLM-x32\…\Living Cookbook 2015) (Version: 5.0.85 - Radium Technologies, Inc.)
Living Cookbook 2015 (x32 Version: 5.0.85 - Radium Technologies) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Money Plus (HKLM-x32\…\Money2008b) (Version: 17 - Microsoft)
Microsoft OneDrive (HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 46.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 46.0.1 (x86 en-US)) (Version: 46.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 46.0.1.5966 - Mozilla)
OpenOffice 4.1.3 (HKLM-x32\…\{EEA30AEB-8BA7-465B-85D4-098BB99733E7}) (Version: 4.13.9783 - Apache Software Foundation)
P@H-Protocol (HKLM-x32\…\{14F936AB-5D31-410E-A4E2-70AE504712F2}) (Version: 3.0.8.6 - Valassis)
Product Improvement Study for HP ENVY 4500 series (HKLM\…\{58139103-BACF-4BDC-B71C-955F9164ADA6}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
QuickTime 7 (HKLM-x32\…\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
RoboForm 7-9-28-8 (All Users) (HKLM-x32\…\AI RoboForm) (Version: 7-9-28-8 - Siber Systems)
SpywareBlaster 5.5 (HKLM-x32\…\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\…\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\…\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {1F6E2644-9468-D082-12B6-1FEE85889A47} => No File
CustomCLSID: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {5B37C4F4-9468-D082-A254-46AA85889A47} => No File
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {022C9A37-0F0F-4E20-8450-B83957241C24} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
Task: {0FF0FC1B-B2F7-4411-92B4-FDF864AEF8DB} - System32\Tasks\Updanager_1443125228 => C:\Users\Nancy\AppData\Local\updanager\upd.exe [2015-08-27] ()
Task: {197F1288-EFE1-4B5B-B544-5D06D728AE96} - no filepath
Task: {1FF1059A-15BE-4E17-B2B9-9304236DF372} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {2937C4D3-5CA8-4B9C-8CF8-9572D233E75F} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2017-03-01] (Siber Systems)
Task: {2C332323-1941-421E-B32B-14684BFCCC0E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {36668100-3F13-4176-8031-6C00D3DCFF27} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-03-02] (HP Inc.)
Task: {37AA8B3D-591B-45A9-8452-BAA457420507} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_CN57A324CZ => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-02-08] (HP Inc.)
Task: {3C746049-BFD0-4E9D-8DBD-ACF5824F10E1} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-06-24] (Realtek Semiconductor)
Task: {66ABD524-B4FA-4A79-9A45-69501E56E0B3} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe [2017-02-23] (Adobe Systems Incorporated)
Task: {697D14F0-C76B-42AF-B080-77E75E88A63A} - System32\Tasks\HPCeeScheduleForNancy => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {6FDBD80A-D2BA-4CDC-A582-412690BF8389} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-02-07] (Piriform Ltd)
Task: {73AE5C14-FD2D-4D12-8E06-1C4468596143} - System32\Tasks\{B0569A02-899F-4FA8-9C53-EE1C79427AAE} => pcalua.exe -a C:\Users\Nancy\Downloads\3500-4500(1).exe -d C:\Users\Nancy\Downloads
Task: {8891EC3B-83E5-4F0D-89A1-155442F6B9BC} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-24] (Realtek Semiconductor)
Task: {8FD0DE1C-2C53-4FE1-ACF6-CF37CCE5A1D0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-12] (Google Inc.)
Task: {91456B91-D4AE-4403-987A-D83F5103B138} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-24] (Realtek Semiconductor)
Task: {927DD210-4912-4CC0-85F2-93B160042419} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxamon.exe -unregister 
Task: {96B9C065-14B5-4E0E-AF5C-B71FFED45F3C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-12] (Google Inc.)
Task: {9C7C4400-BBFA-44FF-90D4-D33DB6EA4A98} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {C1F6AEE8-357A-46B6-B2E7-5E0C341755F2} - System32\Tasks\HPCustParticipation HP ENVY 4500 series => C:\Program Files\HP\HP ENVY 4500 series\Bin\HPCustPartic.exe [2014-07-21] (Hewlett-Packard Development Company, LP)
Task: {CE6F81D4-3DF4-42B6-9347-D2924290D6F3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
Task: {D4A452B0-E8FC-4F18-9067-18248E714286} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-02-24] (Microsoft Corporation)
Task: {D7DB135C-1E06-4413-A4DC-CBB5E80002A8} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/test-pass.html?aaa=KICMKJKMKJMJNMKMGMKMCNNJGMIMLJCNLMKMOMLJCNOJLJKJGMCNJMHMJJMJKJIMOJJJJJOMOMPMJNJICMIMCNGMCNNMHMFMOMOMCNKMIMJMCNOMLMMMGMMMFMPMCNPMCNOMLMMMGMMMCNNMJNPICMOMFMEKMICNJJCKFMOMHMKMHMJNHICMMJBJKJLIMJJNBJCMBLOJBJMJGIJNKJCMJNNICMJNDJCMKJB (the data entry has 58 more characters).
Task: {DAF8A2CE-C90E-487C-AE59-A11BA25700C1} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Nancy\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe 
Task: {E1A1B839-5141-4517-B4C1-70234BA57E06} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-01-16] ()
Task: {E2799DBD-560C-4669-B12F-01A33873A4B5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-02-08] (HP Inc.)
Task: {E504A4A4-6CEC-4CB8-83D7-7647F30FB278} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {EC1C7EB2-D7A6-446C-BBB6-0B155DA43003} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForNancy.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-07-16 06:42 - 2016-07-16 06:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-12-14 07:00 - 2016-12-09 05:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-04-08 19:45 - 2016-04-08 19:45 - 08844000 _____ () C:\Program Files\Siber Systems\GoodSync\gs-server.exe
2016-10-05 17:17 - 2016-10-05 17:17 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2017-01-13 13:56 - 2017-01-13 13:56 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-12-14 07:00 - 2016-12-09 05:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2016-10-29 17:29 - 2016-10-29 17:29 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-01-11 05:43 - 2016-12-21 02:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-06-01 20:00 - 2017-03-09 01:16 - 00112264 _____ () C:\Windows\System32\IccLibDll_x64.dll
2017-01-01 12:10 - 2016-12-14 16:41 - 03494376 _____ () C:\Users\Nancy\AppData\Local\Amazon Music\Amazon Music Helper.exe
2017-02-07 05:22 - 2017-02-01 04:47 - 02459992 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-02-07 05:22 - 2017-02-01 04:47 - 00099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll
2017-02-22 04:59 - 2017-02-22 04:59 - 00073728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-02-22 04:59 - 2017-02-22 04:59 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-02-22 04:59 - 2017-02-22 04:59 - 42895360 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-02-07 05:24 - 2017-02-07 05:24 - 02215424 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\roottools.dll
2017-01-11 05:43 - 2016-12-21 01:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-01-11 05:43 - 2016-12-21 01:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-12-16 06:31 - 2016-12-16 06:31 - 00017408 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
2016-12-16 06:31 - 2016-12-16 06:31 - 12163072 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Msn.Weather.dll
2016-12-16 06:29 - 2016-12-16 06:29 - 00958464 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\SQLite3Wrapper.dll
2015-09-09 10:27 - 2015-09-09 10:27 - 00645120 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Aria.ClientTelemetry.dll
2016-08-23 04:48 - 2016-08-23 04:48 - 03312024 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Advertising.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\webcompanion.com -> hxxp://webcompanion.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1001movie.com -> 1001movie.com
 
There are 6091 more sites.
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-07-30 11:06 - 2015-07-30 11:04 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Nancy\Pictures\PC_50th-WIDE.png
DNS Servers: 10.0.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\StartupApproved\StartupFolder: => "EvernoteClipper.lnk"
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\StartupApproved\Run: => "EPLTarget\P0000000000000000"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{5C18B0BF-9961-440E-AE06-C27BF28F6D55}] => (Allow) C:\Program Files\Siber Systems\GoodSync\gs-server.exe
FirewallRules: [UDP Query User{828761B7-1CD5-4627-9C6C-617E3E39B65A}C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe
FirewallRules: [TCP Query User{1D5D90F6-4274-4E08-A226-FB077C472EA7}C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe
FirewallRules: [UDP Query User{F56D4608-DF62-4639-91DD-862B8A646B38}C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe
FirewallRules: [TCP Query User{D0226AF5-22A6-490D-BE19-98E28F54A27E}C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe
FirewallRules: [UDP Query User{07BF3F83-DBCA-4A9F-99FA-50644EFF9660}C:\program files (x86)\amcrest ip config\amcrest ip config.exe] => (Allow) C:\program files (x86)\amcrest ip config\amcrest ip config.exe
FirewallRules: [TCP Query User{1C163188-3DC8-4C1B-B9F3-9AA883823D3B}C:\program files (x86)\amcrest ip config\amcrest ip config.exe] => (Allow) C:\program files (x86)\amcrest ip config\amcrest ip config.exe
FirewallRules: [{0593ED53-9B60-4457-A780-46E4F8BEF194}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{656F195E-4A4E-45DC-BB5B-E74FB78DD581}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FD9D7C6F-62A4-4050-8CE7-732A2C2E3597}] => (Allow) LPort=15600
FirewallRules: [{4F362F99-6171-4C90-8070-508D6DFCF5C2}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS520D\HPDiagnosticCoreUI.exe
FirewallRules: [{C62E4E86-71CA-41EA-A64A-34F164462736}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS520D\HPDiagnosticCoreUI.exe
FirewallRules: [{CB6F60BA-6BE0-4A70-9BCE-1290C1DB1425}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS45FF\HPDiagnosticCoreUI.exe
FirewallRules: [{6AC06B51-5D29-41B0-958B-76B252E54098}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS45FF\HPDiagnosticCoreUI.exe
FirewallRules: [{40D60FED-B41B-4495-AB41-C036DBB14685}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8BC01190-2CD0-4D0C-BC1B-9F848915393F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E2C9FE14-33E2-4A6D-9C02-67D3FDA606D9}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxamon.exe
FirewallRules: [{E9D6BCFE-2A3D-4B7A-A1C5-169FF318C8E1}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxamon.exe
FirewallRules: [{7A83B6B7-EB3B-4C9F-98EA-8F0993B1B2A2}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\frun.exe
FirewallRules: [{2B693B3B-79F3-44CC-AB3E-8BEB028877F7}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\frun.exe
FirewallRules: [{1B3BF916-1BC3-41D4-B672-D6697D233420}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{96FDF443-1DBD-42A8-AB95-2741FD888FB6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{88076CD8-92BC-45F2-A35D-026DDECD32EA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AB815C1C-F965-4AA7-93A9-298F7B8A2CCB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{C1E26AEA-A3A3-47B6-9E63-BE5271A60D09}C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe] => (Allow) C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe
FirewallRules: [UDP Query User{317E2EC3-F485-48C7-AA8B-9F46EE5553F2}C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe] => (Allow) C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe
FirewallRules: [{C45C1D30-2C02-4D88-AC9C-246B5EC83CC0}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\DeviceSetup.exe
FirewallRules: [{77691047-7821-4B4E-94CE-2A1696654552}] => (Allow) LPort=5357
FirewallRules: [{B6874F85-42BD-4AFA-9464-4B1C6A3A1BAA}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{48281AEC-C60D-485E-AE0A-8485E35C412D}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS738E\HPDiagnosticCoreUI.exe
FirewallRules: [{A9894A93-F173-406B-83DB-EDAE5F494E1A}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS738E\HPDiagnosticCoreUI.exe
FirewallRules: [TCP Query User{7E2B4FA6-721F-4C85-B776-ADDD5C358A04}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Allow) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [UDP Query User{B59D4F0E-6268-4D6F-9A20-00920349E7A4}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Allow) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [TCP Query User{0FFF73B0-6134-483E-BD24-78C7AE6F4063}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Block) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [UDP Query User{AAA4988D-5713-4CBF-9141-DAF13927348F}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Block) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [{9A865A28-AA24-4CF7-A160-D6404402FA65}] => (Allow) C:\Program Files (x86)\LIFX Bulb Updater\LIFX Firmware Updater.exe
FirewallRules: [{3E660921-44CD-4EBA-940A-FEACDEF612A2}] => (Allow) C:\Program Files (x86)\LIFX Bulb Updater\LIFX Firmware Updater.exe
FirewallRules: [{8E6D0701-80AC-4869-B427-DF04CB3F246A}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{F9BBC5CE-2617-454E-8B94-563C7823A551}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
22-02-2017 11:39:23 Windows Backup
04-03-2017 09:39:36 Scheduled Checkpoint
09-03-2017 08:40:58 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/10/2017 08:10:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.14393.0, time stamp: 0x57899bb2
Faulting module name: twinapi.appcore.dll, version: 10.0.14393.206, time stamp: 0x57daca78
Exception code: 0xc000027b
Fault offset: 0x000000000006d1c4
Faulting process id: 0x1db8
Faulting application start time: 0x01d2999f902d5e76
Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe
Faulting module path: C:\Windows\System32\twinapi.appcore.dll
Report Id: a3e28789-2217-499b-8737-fba0acc784ef
Faulting package full name: 60986LythixDesigns.BatteryLevel_1.1.42.0_x64__qrx3rfbhcdp2p
Faulting package-relative application ID: App
 
Error: (03/09/2017 08:41:26 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (03/08/2017 06:36:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.14393.0, time stamp: 0x57899bb2
Faulting module name: twinapi.appcore.dll, version: 10.0.14393.206, time stamp: 0x57daca78
Exception code: 0xc000027b
Fault offset: 0x000000000006d1c4
Faulting process id: 0x2198
Faulting application start time: 0x01d2980016f4fcae
Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe
Faulting module path: C:\Windows\System32\twinapi.appcore.dll
Report Id: 2b2a007e-e591-47e5-a3ba-d370b8afdd48
Faulting package full name: 60986LythixDesigns.BatteryLevel_1.1.42.0_x64__qrx3rfbhcdp2p
Faulting package-relative application ID: App
 
Error: (03/06/2017 11:51:29 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2842765
 
Error: (03/06/2017 11:51:29 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2842765
 
Error: (03/06/2017 11:51:29 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (03/06/2017 06:19:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.14393.0, time stamp: 0x57899bb2
Faulting module name: twinapi.appcore.dll, version: 10.0.14393.206, time stamp: 0x57daca78
Exception code: 0xc000027b
Fault offset: 0x000000000006d1c4
Faulting process id: 0x207c
Faulting application start time: 0x01d2966b42778ab7
Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe
Faulting module path: C:\Windows\System32\twinapi.appcore.dll
Report Id: 86589b64-5b47-4f0a-9fe1-6e8a53efa233
Faulting package full name: 60986LythixDesigns.BatteryLevel_1.1.42.0_x64__qrx3rfbhcdp2p
Faulting package-relative application ID: App
 
Error: (03/04/2017 10:34:23 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1203
 
Error: (03/04/2017 10:34:23 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1203
 
Error: (03/04/2017 10:34:23 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
 
System errors:
=============
Error: (03/10/2017 08:12:52 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {B91D5831-B1BD-4608-8198-D72E155020F7} did not register with DCOM within the required timeout.
 
Error: (03/10/2017 08:10:52 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {B91D5831-B1BD-4608-8198-D72E155020F7} did not register with DCOM within the required timeout.
 
Error: (03/10/2017 08:06:29 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (03/10/2017 08:06:29 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (03/10/2017 08:06:27 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (03/10/2017 08:06:19 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Garmin Device Interaction Service service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (03/10/2017 08:06:18 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Garmin Device Interaction Service service to connect.
 
Error: (03/10/2017 08:06:03 AM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000050 (0xfffff6fb7dbedca0, 0x0000000000000000, 0xfffff809f23578be, 0x0000000000000002). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 6482e16f-ff75-421f-95c7-3fde5b46daf4.
 
Error: (03/10/2017 08:05:39 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:00:01 AM on ‎3/‎10/‎2017 was unexpected.
 
Error: (03/10/2017 08:01:02 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
 
CodeIntegrity:
===================================
  Date: 2017-03-10 09:18:11.301
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:18:11.296
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:16:08.269
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:16:08.264
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:15:05.005
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:15:05.002
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:14:34.858
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:14:34.853
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:14:29.747
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:14:29.738
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i7-2640M CPU @ 2.80GHz
Percentage of memory in use: 35%
Total physical RAM: 8102.75 MB
Available physical RAM: 5188.84 MB
Total Virtual: 9382.75 MB
Available Virtual: 6320.87 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:279.01 GB) (Free:46.05 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:394.18 GB) (Free:393.99 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: E3102A4B)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=279 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=451 MB) - (Type=27)
Partition 4: (Not Active) - (Size=394.2 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-03-2017
Ran by [removed] (administrator) on NANCY-PC (10-03-2017 09:45:22)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe2\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
() C:\Program Files\Siber Systems\GoodSync\Gs-Server.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe
() C:\Users\Nancy\AppData\Local\Amazon Music\Amazon Music Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Inmar, Inc.) C:\Program Files (x86)\Digital Coupon Printer\DigitalCouponPrinter.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Siber Systems Inc.) C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome-nm-host.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(AVAST Software) C:\Users\Nancy\Downloads\aswmbr.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Coupons.com Inc.) C:\Program Files (x86)\Coupons\CouponPrinterService.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(AVAST Software) C:\Users\Nancy\Downloads\aswMBR (1).exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Nancy\Downloads\FRST64 (2).exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-10] (ELAN Microelectronics Corp.)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\…\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-10-29] (Microsoft Corporation)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2017-01-19] (Apple Inc.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-16] (Apple Inc.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Digital Coupon Print Driver] => C:\Program Files (x86)\Digital Coupon Printer\DigitalCouponPrinter.exe [90048 2015-09-22] (Inmar, Inc.)
HKLM-x32\…\Run: [PDFVPrinter] => C:\Program Files (x86)\Classic PDF Editor\PDFVPrinter.exe
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE [241280 2015-01-06] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [HP ENVY 4500 series (NET)] => C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9363672 2017-02-07] (Piriform Ltd)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2017-01-16] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [Amazon Music] => C:\Users\Nancy\AppData\Local\Amazon Music\Amazon Music Helper.exe [3494376 2016-12-14] ()
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [GoogleChromeAutoLaunch_3312EA6C4F41A42564159DA1D2D4BD7F] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1116504 2017-02-01] (Google Inc.)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110376 2017-03-01] (Siber Systems)
HKU\S-1-5-18\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2017-01-16] (Garmin Ltd. or its subsidiaries)
Startup: C:\Users\Nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2016-05-08]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
GroupPolicy: Restriction - Chrome <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{2b11abdc-a83c-4d6f-b508-6c1b0077fde2}: [DhcpNameServer] 10.0.1.1
 
Internet Explorer:
==================
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-03-01] (Siber Systems Inc.)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-03-01] (Siber Systems Inc.)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2016-10-31] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Toolbar: HKLM - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-03-01] (Siber Systems Inc.)
Toolbar: HKLM-x32 - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-03-01] (Siber Systems Inc.)
 
FireFox:
========
FF ProfilePath: C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605 [2017-03-01]
FF DefaultSearchEngine: Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605 -> SafeSearch
FF SearchEngineOrder.1: Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605 -> SafeSearch
FF SelectedSearchEngine: Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605 -> SafeSearch
FF Homepage: Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605 -> hxxps://us-mg6.mail.yahoo.com/neo/launch?.rand=8oagsi4fh2shd
FF Keyword.URL: Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605 -> hxxp://www.safesear.ch/web/?type=ss-ff-kw&q;=
FF Extension: (Firefox Hotfix) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\[removed] [2016-12-26]
FF Extension: (Youtube MP3 Downloader using youtube-mp3.org) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\[removed] [2016-05-14]
FF Extension: (Pin It button) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\[removed] [2015-08-27]
FF Extension: (1-Click YouTube Video Downloader) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\[removed] [2017-01-02]
FF Extension: (All-in-One Sidebar) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi [2016-05-16]
FF Extension: (web_clipper) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}.xpi [2016-05-14]
FF Extension: (Greasemonkey) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2017-01-02]
FF Extension: (Youtube Unblocker Remediation) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\features\{b1de51fa-66e6-45f6-823b-05ba6726d6da}\[removed] [2016-12-26]
FF HKLM-x32\…\Firefox\Extensions: [{jid1-vS7biDmom8YxhA@jetpack}] - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\extensions\{jid1-vS7biDmom8YxhA@jetpack} => not found
FF HKLM-x32\…\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Extension: (RoboForm Toolbar) - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi [2017-03-01]
FF HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-26] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-26] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1222172.dll [2015-11-19] (Adobe Systems, Inc.)
FF Plugin-x32: @IPC/npmedia3.0.0.3,version=3.0.0.3 -> C:\Program Files\webrec\Torch\3.0.0.3\npmedia3.0.0.3.dll [2015-11-20] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2015-09-18] (Coupons, Inc.)
 
Chrome: 
=======
CHR DefaultSearchURL: Default -> hxxp://www.swagbucks.com/?f=55&t;=w&p;=1&q;={searchTerms}
CHR DefaultSearchKeyword: Default -> swagbucks.com
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.866\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\PepperFlash\21.0.0.182\pepflashplayer.dll => No File
CHR Profile: C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default [2017-03-10]
CHR Extension: (Perk for Chrome) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\edpaeddemekchnbmjmcjplbbeeheionp [2016-12-31]
CHR Extension: (Pinterest Save Button) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2017-02-28]
CHR Extension: (Evernote Web) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2015-09-25]
CHR Extension: (tampermonkey) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpeahjkbempddijjinnoppjbdegiggba [2016-04-04]
CHR Extension: (Tampermonkey) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mchbmglgiiijnmpdhcbepaefgljhigdi [2016-01-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10]
CHR Extension: (Amazon Assistant for Chrome) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2016-12-22]
CHR Extension: (Evernote Web Clipper) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2017-02-15]
CHR Extension: (Chrome Media Router) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-15]
CHR Extension: (RoboForm Password Manager) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2017-02-15]
CHR HKLM\…\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2015-07-30]
CHR HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [gdfjhiclilbjdpeejgcgebmmihkkofji] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gdfjhiclilbjdpeejgcgebmmihkkofji] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2015-07-30]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeActiveFileMonitor8.0; C:\Program Files (x86)\Adobe2\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [169312 2009-09-06] (Adobe Systems Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [1413736 2015-09-18] (Coupons.com Inc.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-10] (ELAN Microelectronics Corp.)
S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1039376 2017-01-16] (Garmin Ltd. or its subsidiaries)
R2 GsServer; C:\Program Files\Siber Systems\GoodSync\gs-server.exe [8844000 2016-04-08] ()
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 FLxHCIh; C:\WINDOWS\System32\drivers\FLxHCIh.sys [77040 2015-07-30] (Fresco Logic)
R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [15416 2009-07-20] ( )
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
U3 aswMBR; C:\Users\Nancy\AppData\Local\Temp\aswMBR.sys [62728 2017-03-10] () [File not signed] <==== ATTENTION
U3 aswVmm; C:\Users\Nancy\AppData\Local\Temp\aswVmm.sys [224896 2017-03-10] () <==== ATTENTION
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-03-10 08:20 - 2017-03-10 09:43 - 02423808 _____ (Farbar) C:\Users\Nancy\Downloads\FRST64 (2).exe
2017-03-10 08:18 - 2017-03-10 08:18 - 02423808 _____ (Farbar) C:\Users\Nancy\Downloads\FRST64 (1).exe
2017-03-10 08:13 - 2017-03-10 09:42 - 00001481 _____ C:\Users\Nancy\Documents\aswMBR.txt
2017-03-10 08:05 - 2017-03-10 08:06 - 00379220 _____ C:\WINDOWS\Minidump\031017-31156-01.dmp
2017-03-10 08:04 - 2017-03-10 08:04 - 00000000 _____ C:\Users\Nancy\AppData\Local\{8B3C75FB-BFB5-491E-9ECB-DD42A76A979A}
2017-03-10 08:04 - 2017-03-10 08:04 - 00000000 _____ C:\Users\Nancy\AppData\Local\{6702FBBD-5E40-404B-B581-07C5B697FC1E}
2017-03-10 07:59 - 2017-03-10 08:05 - 523190840 _____ C:\WINDOWS\MEMORY.DMP
2017-03-10 07:59 - 2017-03-10 08:00 - 00417412 _____ C:\WINDOWS\Minidump\031017-30140-01.dmp
2017-03-10 07:56 - 2017-03-10 07:57 - 05198336 _____ (AVAST Software) C:\Users\Nancy\Downloads\aswMBR (1).exe
2017-03-09 08:43 - 2017-03-09 08:44 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2017-03-09 01:17 - 2017-03-09 01:17 - 12935296 _____ (Intel Corporation) C:\WINDOWS\system32\igdumd64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 11460448 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10umd32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 11330576 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumd32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 01086408 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00975184 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00558728 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00553424 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00242800 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00206000 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00051184 _____ (Intel Corporation) C:\WINDOWS\system32\igfxexps.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 13046920 _____ (Intel Corporation) C:\WINDOWS\system32\ig4icd64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 10829448 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig4icd32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 05925984 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUI.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 03529352 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 03139208 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00593544 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00560776 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00536664 _____ (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00460936 _____ (Intel Corporation) C:\WINDOWS\system32\igfxdev.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00458376 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrell.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457864 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrfra.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457864 _____ (Intel Corporation) C:\WINDOWS\system32\igfxresn.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457352 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrrus.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457344 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrrom.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrsky.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrptg.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrplk.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrnld.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrita.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrhrv.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrdeu.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456328 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrhun.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456328 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrfin.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456328 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrcsy.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrtrk.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrsve.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrslv.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrptb.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrnor.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455304 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrtha.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455304 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrdan.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00453768 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrheb.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00453768 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrara.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00450184 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrjpn.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00449160 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrkor.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00447112 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrcht.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00446600 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrchs.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00428680 _____ (Intel Corporation) C:\WINDOWS\system32\igfxTMM.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00402568 _____ (Intel Corporation) C:\WINDOWS\system32\igfxpph.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00348808 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxdv32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00300128 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00276064 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00206944 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00193160 _____ (Intel Corporation) C:\WINDOWS\system32\gfxSrvc.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00160392 _____ (Intel Corporation) C:\WINDOWS\system32\igfxdo.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00145032 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcpl.cpl
2017-03-09 01:16 - 2017-03-09 01:16 - 00134280 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v4459.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00119432 _____ C:\WINDOWS\system32\igdde64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00099464 _____ C:\WINDOWS\SysWOW64\igdde32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00043144 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00027784 _____ ( ) C:\WINDOWS\system32\IGFXDEVLib.dll
2017-03-05 09:36 - 2017-03-05 09:36 - 02668573 _____ C:\Users\Nancy\Downloads\card.pdf
2017-02-28 07:05 - 2017-02-28 07:05 - 09261616 _____ (Piriform Ltd) C:\Users\Nancy\Downloads\ccsetup527 (1).exe
2017-02-26 08:16 - 2017-02-26 08:16 - 04291320 _____ (BrightFort LLC ) C:\Users\Nancy\Downloads\spywareblastersetup55.exe
2017-02-24 14:08 - 2017-02-24 14:08 - 00105675 _____ C:\Users\Nancy\Documents\declaration.pdf
2017-02-23 09:52 - 2017-02-23 09:52 - 00000000 ____D C:\Program Files\Common Files\Intel
2017-02-23 09:51 - 2017-03-01 06:54 - 00000000 ____D C:\Program Files\Common Files\McAfee
2017-02-23 09:51 - 2017-03-01 06:54 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-02-23 09:43 - 2017-02-23 09:42 - 00000030 _____ C:\AVScanner.ini
2017-02-23 06:07 - 2017-02-23 06:07 - 00758134 _____ C:\Users\Nancy\Downloads\FLW024084_20160729_20160727102658output (1).pdf
2017-02-21 07:04 - 2017-02-21 07:04 - 09261616 _____ (Piriform Ltd) C:\Users\Nancy\Downloads\ccsetup527.exe
2017-02-16 06:48 - 2017-02-16 06:48 - 00076854 _____ C:\Users\Nancy\Downloads\Mary Drake_MedicalClearance.pdf
2017-02-14 16:29 - 2017-02-14 16:29 - 00837472 _____ C:\Users\Nancy\Downloads\doc00510420170214145651.pdf
2017-02-14 16:26 - 2017-02-14 16:26 - 02085345 _____ C:\Users\Nancy\Downloads\doc00510320170214145053.pdf
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-03-10 09:45 - 2015-07-31 05:02 - 00019548 _____ C:\Users\Nancy\Downloads\FRST.txt
2017-03-10 09:45 - 2015-07-31 05:02 - 00000000 ____D C:\FRST
2017-03-10 09:22 - 2016-10-29 13:37 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-10 09:18 - 2012-12-31 13:14 - 00000000 ____D C:\Users\Nancy\Downloads\WinAVI_Video_Capture
2017-03-10 08:10 - 2015-07-30 07:45 - 01030638 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-10 08:05 - 2016-10-29 15:59 - 00000000 ____D C:\WINDOWS\Minidump
2017-03-10 08:05 - 2016-10-29 15:10 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-10 08:00 - 2017-01-13 07:06 - 00000892 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2017-03-10 08:00 - 2016-11-02 00:56 - 00000350 _____ C:\WINDOWS\Tasks\HPCeeScheduleForNancy.job
2017-03-10 08:00 - 2016-10-29 13:46 - 00000000 ____D C:\Users\Nancy
2017-03-10 07:59 - 2016-07-02 05:18 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-03-10 07:18 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-10 06:20 - 2016-07-16 06:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-10 06:14 - 2015-07-30 07:55 - 00000000 ____D C:\Users\Nancy\Desktop\sweep
2017-03-09 11:53 - 2015-07-30 07:51 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-03-09 09:44 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-03-09 08:44 - 2015-11-29 08:23 - 00000000 ____D C:\Program Files (x86)\Intel
2017-03-09 08:43 - 2016-07-16 06:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-09 08:33 - 2015-07-30 12:55 - 09211904 _____ C:\Users\Nancy\Documents\My Money.mny
2017-03-09 01:17 - 2015-06-01 20:01 - 13182528 _____ (Intel Corporation) C:\WINDOWS\system32\igd10umd64.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 09025672 _____ (Intel Corporation) C:\WINDOWS\system32\igfxress.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 05382856 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
2017-03-09 01:16 - 2015-06-01 20:00 - 00463960 _____ (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
2017-03-09 01:16 - 2015-06-01 20:00 - 00420960 _____ (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
2017-03-09 01:16 - 2015-06-01 20:00 - 00304264 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrenu.lrc
2017-03-09 01:16 - 2015-06-01 20:00 - 00193112 _____ (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
2017-03-09 01:16 - 2015-06-01 20:00 - 00128648 _____ (Intel Corporation) C:\WINDOWS\system32\hccutils.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 00112264 _____ C:\WINDOWS\system32\IccLibDll_x64.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 00082056 _____ (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.dll
2017-03-08 07:54 - 2016-11-02 00:56 - 00003242 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForNancy
2017-03-07 06:26 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-03-07 05:31 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-03-06 06:17 - 2015-07-30 08:47 - 00000085 _____ C:\WINDOWS\wininit.ini
2017-03-06 06:17 - 2015-07-30 08:30 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-03-05 09:47 - 2015-08-24 13:07 - 00000000 ____D C:\Users\Nancy\AppData\Local\ElevatedDiagnostics
2017-03-03 13:48 - 2016-07-16 01:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-03-01 06:50 - 2016-10-29 15:10 - 00004214 _____ C:\WINDOWS\System32\Tasks\Open URL by RoboForm
2017-03-01 06:50 - 2016-10-29 15:10 - 00003578 _____ C:\WINDOWS\System32\Tasks\Run RoboForm TaskBar Icon
2017-03-01 06:48 - 2015-07-30 08:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
2017-02-28 07:06 - 2015-12-11 12:11 - 00000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-02-26 19:33 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-26 08:17 - 2016-02-02 05:59 - 00000000 ____D C:\ProgramData\TEMP
2017-02-26 08:17 - 2015-09-24 06:46 - 00000258 __RSH C:\ProgramData\ntuser.pol
2017-02-26 08:16 - 2016-02-02 06:02 - 00001154 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2017-02-26 08:16 - 2016-02-02 06:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2017-02-26 08:16 - 2016-02-02 06:02 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2017-02-24 09:22 - 2015-08-18 14:47 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-24 09:16 - 2015-08-18 14:47 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-23 09:57 - 2015-07-31 06:17 - 00000000 ____D C:\ProgramData\McAfee
2017-02-23 09:51 - 2015-09-03 05:50 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-23 09:42 - 2017-01-13 07:06 - 00004032 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-02-23 09:42 - 2015-07-31 06:16 - 00000000 ____D C:\Users\Nancy\AppData\Local\Adobe
2017-02-23 08:57 - 2016-07-16 06:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-22 11:42 - 2015-11-30 09:29 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-22 11:31 - 2012-09-04 06:46 - 00000000 ___RD C:\Users\Nancy\Documents\Scanned Documents
 
==================== Files in the root of some directories =======
 
2015-09-01 07:34 - 2007-09-17 08:10 - 0024576 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series
2017-03-10 08:04 - 2017-03-10 08:04 - 0000000 _____ () C:\Users\Nancy\AppData\Local\{6702FBBD-5E40-404B-B581-07C5B697FC1E}
2017-03-10 08:04 - 2017-03-10 08:04 - 0000000 _____ () C:\Users\Nancy\AppData\Local\{8B3C75FB-BFB5-491E-9ECB-DD42A76A979A}
2015-10-15 06:07 - 2015-10-15 06:07 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-08-02 05:10 - 2015-08-02 05:10 - 0000252 _____ () C:\ProgramData\FastPics.log
2015-08-04 06:54 - 2015-10-15 04:57 - 0000445 _____ () C:\ProgramData\lxdx.log
2015-09-01 06:20 - 2015-09-01 06:28 - 0000248 _____ () C:\ProgramData\lxdxDiagnostics.log
2015-09-01 06:20 - 2015-09-01 06:20 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt
 
Files to move or delete:
====================
C:\Users\Nancy\CARDFILE.EXE
C:\Users\Nancy\DisneyTime.exe
C:\Users\Nancy\Sweep.dat
 
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-03-07 09:13
 
==================== End of FRST.txt ============================

Hi,

 

Just so you know that when you reply to this topic I am notified by email but when you edit the post and add to it I am not. 

 

 

Your running FRST64 from your Downloads folder, our tools and scanners work more efficiently when run from the Desktop in lieu of being buried in some folder, so go to your Downloads folder and look for FRST64, right click on it and select CUT, then come back to your Desktop and right click on a blank space and select PASTE, then we will have FRST64 exactly where we want it to be.

 

Lets see what these tools remove and see if we will have to remove some things manually after these programs are run

 

You already have Malawarebytes installed, I am providing the info for it because there is a new version just came out, no need to uninstall the older version, when you install this new version it will uninstall the old one in the process

 

 

 

All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  •  
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
 
 
 
===============================================================================
 
 
 
 
[external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
  •  
  • Download the one from Bleeping Computer
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
 
 
 
 
===============================================================================
 
 
 
Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
 
  •  
  • Windows XP : Double click on the icon to run it.
  • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
 
 
[external image: MBAM305Good_zps6urblsu9.jpg]
 
 
  •  
  • After the installation IS complete let it update if it asks.
  • Under SETTINGS…..APPLICATIONS leave everything at default
  • Under SETTINGS…..PROTECTION make sure AUTOMATIC QUARANTINE is on. 
  • Then go to the Dashboard and click on SCAN NOW
  • When the scan is finished click on EXPORT SUMMARY……COPY TO CLIPBOARD
  • Then come back to this thread and and under REPLY TO THIS TOPIC, right click in the reply and select Paste
  • Then click on POST
  • Exit Malwarebytes
 
# AdwCleaner v6.044 - Logfile created 10/03/2017 at 11:29:06
# Updated on 28/02/2017 by Malwarebytes
# Database : 2017-03-09.3 [Server]
# Operating System : Windows 10 Home  (X64)
# Username : Nancy - NANCY-PC
# Running from : C:\Users\Nancy\Desktop\AdwCleaner (1).exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support
 
 
 
***** [ Services ] *****
 
[-] Service deleted: CouponPrinterService
 
 
***** [ Folders ] *****
 
[-] Folder deleted: C:\Users\Nancy\AppData\Local\PackageAware
[-] Folder deleted: C:\Users\Nancy\Documents\DriverDoc
[-] Folder deleted: C:\ProgramData\Auslogics
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Auslogics
[-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Coupons
[-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
[-] Folder deleted: C:\Program Files (x86)\Coupons
[-] Folder deleted: C:\Program Files (x86)\Digital Coupon Printer
[-] Folder deleted: C:\Program Files (x86)\Auslogics
[-] Folder deleted: C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam
[-] Folder deleted: C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\pbjikboenpfhbbejgkoklgkhjpfogcam
 
 
***** [ Files ] *****
 
[-] File deleted: C:\WINDOWS\SysNative\LavasoftTcpService64.dll
[-] File deleted: C:\WINDOWS\SysNative\LavasoftTcpServiceOff.ini
[-] File deleted: C:\WINDOWS\SysWoW64\lavasofttcpservice.dll
[-] File deleted: C:\WINDOWS\SysWoW64\LavasoftTcpServiceOff.ini
[-] File deleted: C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_pbjikboenpfhbbejgkoklgkhjpfogcam_0.localstorage
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key deleted: HKLM\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{9522B3FB-7A2B-4646-8AF6-36E7F593073C}
[-] Key deleted: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\Software\Earth Networks
[#] Key deleted on reboot: HKCU\Software\Earth Networks
[-] Key deleted: HKLM\SOFTWARE\Lavasoft\Web Companion
[-] Key deleted: HKLM\SOFTWARE\Auslogics
[#] Key deleted on reboot: [x64] HKCU\Software\Earth Networks
[-] Data restored: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\Software\Microsoft\Internet Explorer\SearchUrl [Default] 
[-] Data restored: HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] 
[-] Data restored: [x64] HKCU\Software\Microsoft\Internet Explorer\SearchUrl [Default] 
[-] Value deleted: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [Web Companion]
[-] Value deleted: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run [WeatherBug]
[-] Value deleted: HKCU\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION [WeatherBug.exe]
[-] Key deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
 
 
***** [ Web browsers ] *****
 
[-] Firefox preferences cleaned: "keyword.url" -  "hxxp://www.safesear.ch/web/?type=ss-ff-kw&q="
[-] [C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
[-] [C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: pbjikboenpfhbbejgkoklgkhjpfogcam
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [3887 Bytes] - [10/03/2017 11:29:06]
C:\AdwCleaner\AdwCleaner[R0].txt - [17935 Bytes] - [29/05/2014 16:45:45]
C:\AdwCleaner\AdwCleaner[S0].txt - [17758 Bytes] - [29/05/2014 16:47:15]
C:\AdwCleaner\AdwCleaner[S2].txt - [2402 Bytes] - [15/11/2015 07:43:20]
C:\AdwCleaner\AdwCleaner[S3].txt - [4412 Bytes] - [10/03/2017 11:28:01]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [4254 Bytes] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.1 (02.11.2017)
Operating System: Windows 10 Home x64 
Ran by [removed] (Administrator) on Fri 03/10/2017 at 11:35:38.71
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 4 
 
Successfully deleted: C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol (Folder) 
Successfully deleted: C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\extensions\[removed] (File) 
Successfully deleted: C:\WINDOWS\couponprinter.ocx (File) 
Successfully deleted: C:\WINDOWS\wininit.ini (File) 
 
Deleted the following from C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\prefs.js
user_pref(browser.search.defaultenginename, SafeSearch);
user_pref(browser.search.order.1, SafeSearch);
user_pref(browser.search.selectedEngine, SafeSearch);
 
 
 
Registry: 3 
 
Successfully deleted: HKCU\Software\Google\Chrome\Extensions\gdfjhiclilbjdpeejgcgebmmihkkofji (Registry Key) 
Successfully deleted: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\\GoogleChromeAutoLaunch_3312EA6C4F41A42564159DA1D2D4BD7F (Registry Value) 
Successfully deleted: HKLM\Software\Google\Chrome\Extensions\gdfjhiclilbjdpeejgcgebmmihkkofji (Registry Key) 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Fri 03/10/2017 at 11:41:52.33
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Malwarebytes Anti-Malware
www.malwarebytes.org
 
Scan Date: 3/10/2017
Scan Time: 11:46 AM
Logfile: 
Administrator: Yes
 
Version: 2.2.1.1043
Malware Database: v2017.03.10.05
Rootkit Database: v2017.03.10.02
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled
 
OS: Windows 10
CPU: x64
File System: NTFS
User: Nancy
 
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 318848
Time Elapsed: 48 min, 22 sec
 
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
Processes: 0
(No malicious items detected)
 
Modules: 0
(No malicious items detected)
 
Registry Keys: 0
(No malicious items detected)
 
Registry Values: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Folders: 0
(No malicious items detected)
 
Files: 0
(No malicious items detected)
 
Physical Sectors: 0
(No malicious items detected)
 
 
(end)

:thumbup:

 

Open up FRST64 by right clicking on it and select RUN AS ADMINISTRATOR.  Make sure ADDITIONS IS CHECKED, leave everything else as is, click on Scan and post both new FRST64 and Additions logs please

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2017
Ran by [removed] (10-03-2017 14:09:46)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1607 (X64) (2016-10-29 20:23:59)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1846905553-2082907679-4278756267-500 - Administrator - Disabled)
ASPNET (S-1-5-21-1846905553-2082907679-4278756267-1004 - Limited - Enabled)
DefaultAccount (S-1-5-21-1846905553-2082907679-4278756267-503 - Limited - Disabled)
Guest (S-1-5-21-1846905553-2082907679-4278756267-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1846905553-2082907679-4278756267-1002 - Limited - Enabled)
Nancy (S-1-5-21-1846905553-2082907679-4278756267-1001 - Administrator - Enabled) => C:\Users\Nancy
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
AddrBk 473 (HKLM-x32\…\Address Book_is1) (Version:  - )
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe Flash Player 24 PPAPI (HKLM-x32\…\Adobe Flash Player PPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe Photoshop Elements 8.0 (HKLM-x32\…\Adobe Photoshop Elements 8.0) (Version: 8.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.2.2.172 - Adobe Systems, Inc.)
Amazon Music (HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Amazon Amazon Music) (Version: 5.3.2.1634 - Amazon Services LLC)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{9BA1A894-B42F-4805-BC8C-349C905A3930}) (Version: 5.3.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{7EAC8A42-9FAC-4F6B-AABF-C08C9F2E0F13}) (Version: 5.3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
BigOven (HKLM-x32\…\{98C4F0D9-3C09-4BD9-B835-29744B94931A}) (Version: 1.9.1 - Lakefront Software)
BigOven (x32 Version: 1.8.999 - Lakefront Software) Hidden
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 5.27 - Piriform)
CleanUp! (HKLM-x32\…\CleanUp!) (Version:  - )
Coupon Printer for Windows (HKLM-x32\…\Coupon Printer for Windows5.0.1.7) (Version: 5.0.1.7 - Coupons.com Incorporated)
Digital Coupon Printer (HKLM-x32\…\{2CDD20A5-DFDE-4AC0-97DD-F60B1196BF98}) (Version: 3.50.0.0 - Hopster, Inc. an Inmar company)
ELAN Touchpad 11.15.0.18_X64 (HKLM\…\Elantech) (Version: 11.15.0.18 - ELAN Microelectronic Corp.)
Elevated Installer (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
EPSON WorkForce 545 Series Printer Uninstall (HKLM\…\EPSON WorkForce 545 Series) (Version:  - SEIKO EPSON Corporation)
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version:  - )
Evernote v. 6.4.2 (HKLM-x32\…\{E74F0DCA-9FC8-11E6-9D98-005056950253}) (Version: 6.4.2.3788 - Evernote Corp.)
Garmin Express (HKLM-x32\…\{9fbf4745-0038-4ed3-aee1-87af9b9ef8f1}) (Version: 5.1.1.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
GoodSync (HKLM\…\{B26B00DA-2E5D-4CF2-83C5-911198C0F009}) (Version: 9.9.45.8 - Siber Systems)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
HP ENVY 4500 series Basic Device Software (HKLM\…\{6915424E-704F-4F5D-9057-9C7B406B36DB}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
HP ENVY 4500 series Help (HKLM-x32\…\{95BECC50-22B4-4FCA-8A2E-BF77713E6D3A}) (Version: 30.0.0 - Hewlett Packard)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Support Assistant (HKLM-x32\…\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.3.50.9 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\…\{55065080-504F-43BB-BE00-36B80D7D39A5}) (Version: 12.5.32.203 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\…\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation)
iTunes (HKLM\…\{9D0D2A8B-7E7B-4D88-8D50-24286ED6A5EB}) (Version: 12.5.5.5 - Apple Inc.)
LIFX Bulb Update (HKLM-x32\…\{AA0C44A9-01EB-44F7-BE71-72EEC9805D2A}) (Version: 2.0.0 - LIFX)
Living Cookbook 2015 (HKLM-x32\…\Living Cookbook 2015) (Version: 5.0.85 - Radium Technologies, Inc.)
Living Cookbook 2015 (x32 Version: 5.0.85 - Radium Technologies) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Money Plus (HKLM-x32\…\Money2008b) (Version: 17 - Microsoft)
Microsoft OneDrive (HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 46.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 46.0.1 (x86 en-US)) (Version: 46.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 46.0.1.5966 - Mozilla)
OpenOffice 4.1.3 (HKLM-x32\…\{EEA30AEB-8BA7-465B-85D4-098BB99733E7}) (Version: 4.13.9783 - Apache Software Foundation)
P@H-Protocol (HKLM-x32\…\{14F936AB-5D31-410E-A4E2-70AE504712F2}) (Version: 3.0.8.6 - Valassis)
Product Improvement Study for HP ENVY 4500 series (HKLM\…\{58139103-BACF-4BDC-B71C-955F9164ADA6}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
QuickTime 7 (HKLM-x32\…\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
RoboForm 7-9-28-8 (All Users) (HKLM-x32\…\AI RoboForm) (Version: 7-9-28-8 - Siber Systems)
SpywareBlaster 5.5 (HKLM-x32\…\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\…\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\…\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {1F6E2644-9468-D082-12B6-1FEE85889A47} => No File
CustomCLSID: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {5B37C4F4-9468-D082-A254-46AA85889A47} => No File
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {022C9A37-0F0F-4E20-8450-B83957241C24} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
Task: {0FF0FC1B-B2F7-4411-92B4-FDF864AEF8DB} - System32\Tasks\Updanager_1443125228 => C:\Users\Nancy\AppData\Local\updanager\upd.exe [2015-08-27] ()
Task: {197F1288-EFE1-4B5B-B544-5D06D728AE96} - no filepath
Task: {1FF1059A-15BE-4E17-B2B9-9304236DF372} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {2937C4D3-5CA8-4B9C-8CF8-9572D233E75F} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2017-03-01] (Siber Systems)
Task: {2C332323-1941-421E-B32B-14684BFCCC0E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {36668100-3F13-4176-8031-6C00D3DCFF27} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-03-02] (HP Inc.)
Task: {37AA8B3D-591B-45A9-8452-BAA457420507} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_CN57A324CZ => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-02-08] (HP Inc.)
Task: {3C746049-BFD0-4E9D-8DBD-ACF5824F10E1} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-06-24] (Realtek Semiconductor)
Task: {66ABD524-B4FA-4A79-9A45-69501E56E0B3} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe [2017-02-23] (Adobe Systems Incorporated)
Task: {697D14F0-C76B-42AF-B080-77E75E88A63A} - System32\Tasks\HPCeeScheduleForNancy => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {6FDBD80A-D2BA-4CDC-A582-412690BF8389} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-02-07] (Piriform Ltd)
Task: {73AE5C14-FD2D-4D12-8E06-1C4468596143} - System32\Tasks\{B0569A02-899F-4FA8-9C53-EE1C79427AAE} => pcalua.exe -a C:\Users\Nancy\Downloads\3500-4500(1).exe -d C:\Users\Nancy\Downloads
Task: {8891EC3B-83E5-4F0D-89A1-155442F6B9BC} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-24] (Realtek Semiconductor)
Task: {8FD0DE1C-2C53-4FE1-ACF6-CF37CCE5A1D0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-12] (Google Inc.)
Task: {91456B91-D4AE-4403-987A-D83F5103B138} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-24] (Realtek Semiconductor)
Task: {927DD210-4912-4CC0-85F2-93B160042419} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxamon.exe -unregister 
Task: {96B9C065-14B5-4E0E-AF5C-B71FFED45F3C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-12] (Google Inc.)
Task: {9C7C4400-BBFA-44FF-90D4-D33DB6EA4A98} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {C1F6AEE8-357A-46B6-B2E7-5E0C341755F2} - System32\Tasks\HPCustParticipation HP ENVY 4500 series => C:\Program Files\HP\HP ENVY 4500 series\Bin\HPCustPartic.exe [2014-07-21] (Hewlett-Packard Development Company, LP)
Task: {CE6F81D4-3DF4-42B6-9347-D2924290D6F3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
Task: {D4A452B0-E8FC-4F18-9067-18248E714286} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-02-24] (Microsoft Corporation)
Task: {D7DB135C-1E06-4413-A4DC-CBB5E80002A8} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/test-pass.html?aaa=KICMKJKMKJMJNMKMGMKMCNNJGMIMLJCNLMKMOMLJCNOJLJKJGMCNJMHMJJMJKJIMOJJJJJOMOMPMJNJICMIMCNGMCNNMHMFMOMOMCNKMIMJMCNOMLMMMGMMMFMPMCNPMCNOMLMMMGMMMCNNMJNPICMOMFMEKMICNJJCKFMOMHMKMHMJNHICMMJBJKJLIMJJNBJCMBLOJBJMJGIJNKJCMJNNICMJNDJCMKJB (the data entry has 58 more characters).
Task: {DAF8A2CE-C90E-487C-AE59-A11BA25700C1} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Nancy\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe 
Task: {E1A1B839-5141-4517-B4C1-70234BA57E06} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-01-16] ()
Task: {E2799DBD-560C-4669-B12F-01A33873A4B5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-02-08] (HP Inc.)
Task: {E504A4A4-6CEC-4CB8-83D7-7647F30FB278} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {EC1C7EB2-D7A6-446C-BBB6-0B155DA43003} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForNancy.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-07-16 06:42 - 2016-07-16 06:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-12-14 07:00 - 2016-12-09 05:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-10-05 17:17 - 2016-10-05 17:17 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2017-01-13 13:56 - 2017-01-13 13:56 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-04-08 19:45 - 2016-04-08 19:45 - 08844000 _____ () C:\Program Files\Siber Systems\GoodSync\gs-server.exe
2016-12-14 07:00 - 2016-12-09 05:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2017-01-11 05:43 - 2016-12-21 01:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-01-11 05:43 - 2016-12-21 01:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-10-29 17:29 - 2016-10-29 17:29 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-01-11 05:43 - 2016-12-21 02:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-02-07 05:22 - 2017-02-01 04:47 - 02459992 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-02-07 05:22 - 2017-02-01 04:47 - 00099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll
2017-02-22 04:59 - 2017-02-22 04:59 - 00073728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-02-22 04:59 - 2017-02-22 04:59 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-02-22 04:59 - 2017-02-22 04:59 - 42895360 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-02-07 05:24 - 2017-02-07 05:24 - 02215424 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\roottools.dll
2016-12-16 06:31 - 2016-12-16 06:31 - 00017408 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
2016-12-16 06:31 - 2016-12-16 06:31 - 12163072 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Msn.Weather.dll
2016-12-16 06:29 - 2016-12-16 06:29 - 00958464 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\SQLite3Wrapper.dll
2015-09-09 10:27 - 2015-09-09 10:27 - 00645120 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Aria.ClientTelemetry.dll
2016-08-23 04:48 - 2016-08-23 04:48 - 03312024 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Advertising.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\localhost -> localhost
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1001movie.com -> 1001movie.com
 
There are 6091 more sites.
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-07-30 11:06 - 2015-07-30 11:04 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Nancy\Pictures\PC_50th-WIDE.png
DNS Servers: 10.0.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\StartupApproved\StartupFolder: => "EvernoteClipper.lnk"
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\StartupApproved\Run: => "EPLTarget\P0000000000000000"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{5C18B0BF-9961-440E-AE06-C27BF28F6D55}] => (Allow) C:\Program Files\Siber Systems\GoodSync\gs-server.exe
FirewallRules: [UDP Query User{828761B7-1CD5-4627-9C6C-617E3E39B65A}C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe
FirewallRules: [TCP Query User{1D5D90F6-4274-4E08-A226-FB077C472EA7}C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe
FirewallRules: [UDP Query User{F56D4608-DF62-4639-91DD-862B8A646B38}C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe
FirewallRules: [TCP Query User{D0226AF5-22A6-490D-BE19-98E28F54A27E}C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe
FirewallRules: [UDP Query User{07BF3F83-DBCA-4A9F-99FA-50644EFF9660}C:\program files (x86)\amcrest ip config\amcrest ip config.exe] => (Allow) C:\program files (x86)\amcrest ip config\amcrest ip config.exe
FirewallRules: [TCP Query User{1C163188-3DC8-4C1B-B9F3-9AA883823D3B}C:\program files (x86)\amcrest ip config\amcrest ip config.exe] => (Allow) C:\program files (x86)\amcrest ip config\amcrest ip config.exe
FirewallRules: [{0593ED53-9B60-4457-A780-46E4F8BEF194}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{656F195E-4A4E-45DC-BB5B-E74FB78DD581}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FD9D7C6F-62A4-4050-8CE7-732A2C2E3597}] => (Allow) LPort=15600
FirewallRules: [{4F362F99-6171-4C90-8070-508D6DFCF5C2}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS520D\HPDiagnosticCoreUI.exe
FirewallRules: [{C62E4E86-71CA-41EA-A64A-34F164462736}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS520D\HPDiagnosticCoreUI.exe
FirewallRules: [{CB6F60BA-6BE0-4A70-9BCE-1290C1DB1425}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS45FF\HPDiagnosticCoreUI.exe
FirewallRules: [{6AC06B51-5D29-41B0-958B-76B252E54098}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS45FF\HPDiagnosticCoreUI.exe
FirewallRules: [{40D60FED-B41B-4495-AB41-C036DBB14685}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8BC01190-2CD0-4D0C-BC1B-9F848915393F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E2C9FE14-33E2-4A6D-9C02-67D3FDA606D9}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxamon.exe
FirewallRules: [{E9D6BCFE-2A3D-4B7A-A1C5-169FF318C8E1}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxamon.exe
FirewallRules: [{7A83B6B7-EB3B-4C9F-98EA-8F0993B1B2A2}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\frun.exe
FirewallRules: [{2B693B3B-79F3-44CC-AB3E-8BEB028877F7}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\frun.exe
FirewallRules: [{1B3BF916-1BC3-41D4-B672-D6697D233420}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{96FDF443-1DBD-42A8-AB95-2741FD888FB6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{88076CD8-92BC-45F2-A35D-026DDECD32EA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AB815C1C-F965-4AA7-93A9-298F7B8A2CCB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{C1E26AEA-A3A3-47B6-9E63-BE5271A60D09}C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe] => (Allow) C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe
FirewallRules: [UDP Query User{317E2EC3-F485-48C7-AA8B-9F46EE5553F2}C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe] => (Allow) C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe
FirewallRules: [{C45C1D30-2C02-4D88-AC9C-246B5EC83CC0}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\DeviceSetup.exe
FirewallRules: [{77691047-7821-4B4E-94CE-2A1696654552}] => (Allow) LPort=5357
FirewallRules: [{B6874F85-42BD-4AFA-9464-4B1C6A3A1BAA}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{48281AEC-C60D-485E-AE0A-8485E35C412D}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS738E\HPDiagnosticCoreUI.exe
FirewallRules: [{A9894A93-F173-406B-83DB-EDAE5F494E1A}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS738E\HPDiagnosticCoreUI.exe
FirewallRules: [TCP Query User{7E2B4FA6-721F-4C85-B776-ADDD5C358A04}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Allow) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [UDP Query User{B59D4F0E-6268-4D6F-9A20-00920349E7A4}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Allow) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [TCP Query User{0FFF73B0-6134-483E-BD24-78C7AE6F4063}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Block) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [UDP Query User{AAA4988D-5713-4CBF-9141-DAF13927348F}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Block) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [{9A865A28-AA24-4CF7-A160-D6404402FA65}] => (Allow) C:\Program Files (x86)\LIFX Bulb Updater\LIFX Firmware Updater.exe
FirewallRules: [{3E660921-44CD-4EBA-940A-FEACDEF612A2}] => (Allow) C:\Program Files (x86)\LIFX Bulb Updater\LIFX Firmware Updater.exe
FirewallRules: [{8E6D0701-80AC-4869-B427-DF04CB3F246A}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{F9BBC5CE-2617-454E-8B94-563C7823A551}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
22-02-2017 11:39:23 Windows Backup
04-03-2017 09:39:36 Scheduled Checkpoint
09-03-2017 08:40:58 Windows Update
10-03-2017 11:35:44 JRT Pre-Junkware Removal
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/10/2017 11:36:11 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (03/10/2017 08:10:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.14393.0, time stamp: 0x57899bb2
Faulting module name: twinapi.appcore.dll, version: 10.0.14393.206, time stamp: 0x57daca78
Exception code: 0xc000027b
Fault offset: 0x000000000006d1c4
Faulting process id: 0x1db8
Faulting application start time: 0x01d2999f902d5e76
Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe
Faulting module path: C:\Windows\System32\twinapi.appcore.dll
Report Id: a3e28789-2217-499b-8737-fba0acc784ef
Faulting package full name: 60986LythixDesigns.BatteryLevel_1.1.42.0_x64__qrx3rfbhcdp2p
Faulting package-relative application ID: App
 
Error: (03/09/2017 08:41:26 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
 
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
 
System Error:
Access is denied.
.
 
Error: (03/08/2017 06:36:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.14393.0, time stamp: 0x57899bb2
Faulting module name: twinapi.appcore.dll, version: 10.0.14393.206, time stamp: 0x57daca78
Exception code: 0xc000027b
Fault offset: 0x000000000006d1c4
Faulting process id: 0x2198
Faulting application start time: 0x01d2980016f4fcae
Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe
Faulting module path: C:\Windows\System32\twinapi.appcore.dll
Report Id: 2b2a007e-e591-47e5-a3ba-d370b8afdd48
Faulting package full name: 60986LythixDesigns.BatteryLevel_1.1.42.0_x64__qrx3rfbhcdp2p
Faulting package-relative application ID: App
 
Error: (03/06/2017 11:51:29 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2842765
 
Error: (03/06/2017 11:51:29 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2842765
 
Error: (03/06/2017 11:51:29 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (03/06/2017 06:19:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.14393.0, time stamp: 0x57899bb2
Faulting module name: twinapi.appcore.dll, version: 10.0.14393.206, time stamp: 0x57daca78
Exception code: 0xc000027b
Fault offset: 0x000000000006d1c4
Faulting process id: 0x207c
Faulting application start time: 0x01d2966b42778ab7
Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe
Faulting module path: C:\Windows\System32\twinapi.appcore.dll
Report Id: 86589b64-5b47-4f0a-9fe1-6e8a53efa233
Faulting package full name: 60986LythixDesigns.BatteryLevel_1.1.42.0_x64__qrx3rfbhcdp2p
Faulting package-relative application ID: App
 
Error: (03/04/2017 10:34:23 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1203
 
Error: (03/04/2017 10:34:23 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1203
 
 
System errors:
=============
Error: (03/10/2017 11:31:13 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
 and APPID 
{F72671A9-012C-4725-9D2F-2A4D32D65169}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (03/10/2017 11:30:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Garmin Device Interaction Service service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (03/10/2017 11:30:41 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Garmin Device Interaction Service service to connect.
 
Error: (03/10/2017 11:30:32 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (03/10/2017 11:30:32 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 and APPID 
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (03/10/2017 11:28:51 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
An instance of the service is already running.
 
Error: (03/10/2017 11:28:23 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The HP Support Solutions Framework Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/10/2017 11:28:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Coupon Printer Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
 
Error: (03/10/2017 11:28:22 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The iPod Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (03/10/2017 11:28:22 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Bluetooth OBEX Service service terminated unexpectedly.  It has done this 1 time(s).
 
 
CodeIntegrity:
===================================
  Date: 2017-03-10 09:18:11.301
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:18:11.296
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:16:08.269
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:16:08.264
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:15:05.005
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:15:05.002
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:14:34.858
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:14:34.853
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:14:29.747
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-03-10 09:14:29.738
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i7-2640M CPU @ 2.80GHz
Percentage of memory in use: 45%
Total physical RAM: 8102.75 MB
Available physical RAM: 4454.25 MB
Total Virtual: 9382.75 MB
Available Virtual: 5453.46 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:279.01 GB) (Free:46.04 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:394.18 GB) (Free:393.99 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: E3102A4B)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=279 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=451 MB) - (Type=27)
Partition 4: (Not Active) - (Size=394.2 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-03-2017
Ran by [removed] (administrator) on NANCY-PC (10-03-2017 14:06:45)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files\Siber Systems\GoodSync\Gs-Server.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe2\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Siber Systems Inc.) C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome-nm-host.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Farbar) C:\Users\Nancy\Desktop\FRST64 (2).exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-10] (ELAN Microelectronics Corp.)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\…\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-10-29] (Microsoft Corporation)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2017-01-19] (Apple Inc.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-16] (Apple Inc.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Digital Coupon Print Driver] => "C:\Program Files (x86)\Digital Coupon Printer\DigitalCouponPrinter.exe"
HKLM-x32\…\Run: [PDFVPrinter] => C:\Program Files (x86)\Classic PDF Editor\PDFVPrinter.exe
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE [241280 2015-01-06] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [HP ENVY 4500 series (NET)] => C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9363672 2017-02-07] (Piriform Ltd)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2017-01-16] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [Amazon Music] => C:\Users\Nancy\AppData\Local\Amazon Music\Amazon Music Helper.exe [3494376 2016-12-14] ()
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110376 2017-03-01] (Siber Systems)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [GoogleChromeAutoLaunch_3312EA6C4F41A42564159DA1D2D4BD7F] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1116504 2017-02-01] (Google Inc.)
HKU\S-1-5-18\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2017-01-16] (Garmin Ltd. or its subsidiaries)
Startup: C:\Users\Nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2016-05-08]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
GroupPolicy: Restriction - Chrome <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{2b11abdc-a83c-4d6f-b508-6c1b0077fde2}: [DhcpNameServer] 10.0.1.1
 
Internet Explorer:
==================
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-03-01] (Siber Systems Inc.)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-03-01] (Siber Systems Inc.)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2016-10-31] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Toolbar: HKLM - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-03-01] (Siber Systems Inc.)
Toolbar: HKLM-x32 - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-03-01] (Siber Systems Inc.)
 
FireFox:
========
FF ProfilePath: C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605 [2017-03-01]
FF Homepage: Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605 -> hxxps://us-mg6.mail.yahoo.com/neo/launch?.rand=8oagsi4fh2shd
FF Extension: (Firefox Hotfix) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\[removed] [2016-12-26]
FF Extension: (Pin It button) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\[removed] [2015-08-27]
FF Extension: (1-Click YouTube Video Downloader) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\[removed] [2017-01-02]
FF Extension: (All-in-One Sidebar) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi [2016-05-16]
FF Extension: (web_clipper) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}.xpi [2016-05-14]
FF Extension: (Greasemonkey) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2017-01-02]
FF Extension: (Youtube Unblocker Remediation) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\features\{b1de51fa-66e6-45f6-823b-05ba6726d6da}\[removed] [2016-12-26]
FF HKLM-x32\…\Firefox\Extensions: [{jid1-vS7biDmom8YxhA@jetpack}] - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\extensions\{jid1-vS7biDmom8YxhA@jetpack} => not found
FF HKLM-x32\…\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Extension: (RoboForm Toolbar) - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi [2017-03-01]
FF HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-26] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-26] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1222172.dll [2015-11-19] (Adobe Systems, Inc.)
FF Plugin-x32: @IPC/npmedia3.0.0.3,version=3.0.0.3 -> C:\Program Files\webrec\Torch\3.0.0.3\npmedia3.0.0.3.dll [2015-11-20] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2015-09-18] (Coupons, Inc.)
 
Chrome: 
=======
CHR DefaultSearchURL: Default -> hxxp://www.swagbucks.com/?f=55&t;=w&p;=1&q;={searchTerms}
CHR DefaultSearchKeyword: Default -> swagbucks.com
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.866\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\PepperFlash\21.0.0.182\pepflashplayer.dll => No File
CHR Profile: C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default [2017-03-10]
CHR Extension: (Perk for Chrome) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\edpaeddemekchnbmjmcjplbbeeheionp [2016-12-31]
CHR Extension: (Pinterest Save Button) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2017-02-28]
CHR Extension: (tampermonkey) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpeahjkbempddijjinnoppjbdegiggba [2016-04-04]
CHR Extension: (Tampermonkey) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mchbmglgiiijnmpdhcbepaefgljhigdi [2016-01-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10]
CHR Extension: (Evernote Web Clipper) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2017-02-15]
CHR Extension: (Chrome Media Router) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-15]
CHR Extension: (RoboForm Password Manager) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2017-02-15]
CHR HKLM\…\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2015-07-30]
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2015-07-30]
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeActiveFileMonitor8.0; C:\Program Files (x86)\Adobe2\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [169312 2009-09-06] (Adobe Systems Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-10] (ELAN Microelectronics Corp.)
S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1039376 2017-01-16] (Garmin Ltd. or its subsidiaries)
R2 GsServer; C:\Program Files\Siber Systems\GoodSync\gs-server.exe [8844000 2016-04-08] ()
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 FLxHCIh; C:\WINDOWS\System32\drivers\FLxHCIh.sys [77040 2015-07-30] (Fresco Logic)
R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [15416 2009-07-20] ( )
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-03-10 14:06 - 2017-03-10 14:08 - 00016595 _____ C:\Users\Nancy\Desktop\FRST.txt
2017-03-10 11:41 - 2017-03-10 11:41 - 00001626 _____ C:\Users\Nancy\Desktop\JRT.txt
2017-03-10 11:33 - 2017-03-10 11:35 - 01663736 _____ (Malwarebytes) C:\Users\Nancy\Desktop\JRT (1).exe
2017-03-10 11:21 - 2017-03-10 11:24 - 04031440 _____ C:\Users\Nancy\Desktop\AdwCleaner (1).exe
2017-03-10 08:20 - 2017-03-10 09:43 - 02423808 _____ (Farbar) C:\Users\Nancy\Desktop\FRST64 (2).exe
2017-03-10 08:18 - 2017-03-10 08:18 - 02423808 _____ (Farbar) C:\Users\Nancy\Downloads\FRST64 (1).exe
2017-03-10 08:13 - 2017-03-10 09:42 - 00001481 _____ C:\Users\Nancy\Documents\aswMBR.txt
2017-03-10 08:05 - 2017-03-10 08:06 - 00379220 _____ C:\WINDOWS\Minidump\031017-31156-01.dmp
2017-03-10 08:04 - 2017-03-10 08:04 - 00000000 _____ C:\Users\Nancy\AppData\Local\{8B3C75FB-BFB5-491E-9ECB-DD42A76A979A}
2017-03-10 08:04 - 2017-03-10 08:04 - 00000000 _____ C:\Users\Nancy\AppData\Local\{6702FBBD-5E40-404B-B581-07C5B697FC1E}
2017-03-10 07:59 - 2017-03-10 08:05 - 523190840 _____ C:\WINDOWS\MEMORY.DMP
2017-03-10 07:59 - 2017-03-10 08:00 - 00417412 _____ C:\WINDOWS\Minidump\031017-30140-01.dmp
2017-03-10 07:56 - 2017-03-10 07:57 - 05198336 _____ (AVAST Software) C:\Users\Nancy\Downloads\aswMBR (1).exe
2017-03-09 08:43 - 2017-03-09 08:44 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2017-03-09 01:17 - 2017-03-09 01:17 - 12935296 _____ (Intel Corporation) C:\WINDOWS\system32\igdumd64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 11460448 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10umd32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 11330576 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumd32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 01086408 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00975184 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00558728 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00553424 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00242800 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00206000 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00051184 _____ (Intel Corporation) C:\WINDOWS\system32\igfxexps.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 13046920 _____ (Intel Corporation) C:\WINDOWS\system32\ig4icd64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 10829448 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig4icd32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 05925984 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUI.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 03529352 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 03139208 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00593544 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00560776 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00536664 _____ (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00460936 _____ (Intel Corporation) C:\WINDOWS\system32\igfxdev.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00458376 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrell.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457864 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrfra.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457864 _____ (Intel Corporation) C:\WINDOWS\system32\igfxresn.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457352 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrrus.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457344 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrrom.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrsky.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrptg.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrplk.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrnld.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrita.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrhrv.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrdeu.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456328 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrhun.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456328 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrfin.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456328 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrcsy.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrtrk.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrsve.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrslv.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrptb.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrnor.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455304 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrtha.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455304 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrdan.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00453768 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrheb.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00453768 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrara.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00450184 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrjpn.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00449160 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrkor.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00447112 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrcht.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00446600 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrchs.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00428680 _____ (Intel Corporation) C:\WINDOWS\system32\igfxTMM.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00402568 _____ (Intel Corporation) C:\WINDOWS\system32\igfxpph.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00348808 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxdv32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00300128 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00276064 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00206944 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00193160 _____ (Intel Corporation) C:\WINDOWS\system32\gfxSrvc.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00160392 _____ (Intel Corporation) C:\WINDOWS\system32\igfxdo.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00145032 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcpl.cpl
2017-03-09 01:16 - 2017-03-09 01:16 - 00134280 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v4459.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00119432 _____ C:\WINDOWS\system32\igdde64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00099464 _____ C:\WINDOWS\SysWOW64\igdde32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00043144 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00027784 _____ ( ) C:\WINDOWS\system32\IGFXDEVLib.dll
2017-03-05 09:36 - 2017-03-05 09:36 - 02668573 _____ C:\Users\Nancy\Downloads\card.pdf
2017-02-28 07:05 - 2017-02-28 07:05 - 09261616 _____ (Piriform Ltd) C:\Users\Nancy\Downloads\ccsetup527 (1).exe
2017-02-26 08:16 - 2017-02-26 08:16 - 04291320 _____ (BrightFort LLC ) C:\Users\Nancy\Downloads\spywareblastersetup55.exe
2017-02-24 14:08 - 2017-02-24 14:08 - 00105675 _____ C:\Users\Nancy\Documents\declaration.pdf
2017-02-23 09:52 - 2017-02-23 09:52 - 00000000 ____D C:\Program Files\Common Files\Intel
2017-02-23 09:51 - 2017-03-01 06:54 - 00000000 ____D C:\Program Files\Common Files\McAfee
2017-02-23 09:51 - 2017-03-01 06:54 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-02-23 09:43 - 2017-02-23 09:42 - 00000030 _____ C:\AVScanner.ini
2017-02-23 06:07 - 2017-02-23 06:07 - 00758134 _____ C:\Users\Nancy\Downloads\FLW024084_20160729_20160727102658output (1).pdf
2017-02-21 07:04 - 2017-02-21 07:04 - 09261616 _____ (Piriform Ltd) C:\Users\Nancy\Downloads\ccsetup527.exe
2017-02-16 06:48 - 2017-02-16 06:48 - 00076854 _____ C:\Users\Nancy\Downloads\Mary Drake_MedicalClearance.pdf
2017-02-14 16:29 - 2017-02-14 16:29 - 00837472 _____ C:\Users\Nancy\Downloads\doc00510420170214145651.pdf
2017-02-14 16:26 - 2017-02-14 16:26 - 02085345 _____ C:\Users\Nancy\Downloads\doc00510320170214145053.pdf
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-03-10 14:06 - 2015-07-31 05:02 - 00000000 ____D C:\FRST
2017-03-10 13:03 - 2016-10-29 13:37 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-10 11:45 - 2015-07-30 07:51 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-03-10 11:30 - 2016-10-29 15:10 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-10 11:29 - 2016-10-29 13:46 - 00000000 ____D C:\Users\Nancy
2017-03-10 11:29 - 2016-07-16 01:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-03-10 11:29 - 2014-05-29 16:45 - 00000000 ____D C:\AdwCleaner
2017-03-10 09:51 - 2015-07-31 05:07 - 00041152 _____ C:\Users\Nancy\Downloads\Addition.txt
2017-03-10 09:51 - 2015-07-31 05:02 - 00035925 _____ C:\Users\Nancy\Downloads\FRST.txt
2017-03-10 09:18 - 2012-12-31 13:14 - 00000000 ____D C:\Users\Nancy\Downloads\WinAVI_Video_Capture
2017-03-10 08:10 - 2015-07-30 07:45 - 01030638 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-10 08:05 - 2016-10-29 15:59 - 00000000 ____D C:\WINDOWS\Minidump
2017-03-10 08:00 - 2017-01-13 07:06 - 00000892 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2017-03-10 08:00 - 2016-11-02 00:56 - 00000350 _____ C:\WINDOWS\Tasks\HPCeeScheduleForNancy.job
2017-03-10 07:59 - 2016-07-02 05:18 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-03-10 07:18 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-10 06:20 - 2016-07-16 06:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-10 06:14 - 2015-07-30 07:55 - 00000000 ____D C:\Users\Nancy\Desktop\sweep
2017-03-09 09:44 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-03-09 08:44 - 2015-11-29 08:23 - 00000000 ____D C:\Program Files (x86)\Intel
2017-03-09 08:43 - 2016-07-16 06:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-09 08:33 - 2015-07-30 12:55 - 09211904 _____ C:\Users\Nancy\Documents\My Money.mny
2017-03-09 01:17 - 2015-06-01 20:01 - 13182528 _____ (Intel Corporation) C:\WINDOWS\system32\igd10umd64.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 09025672 _____ (Intel Corporation) C:\WINDOWS\system32\igfxress.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 05382856 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
2017-03-09 01:16 - 2015-06-01 20:00 - 00463960 _____ (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
2017-03-09 01:16 - 2015-06-01 20:00 - 00420960 _____ (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
2017-03-09 01:16 - 2015-06-01 20:00 - 00304264 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrenu.lrc
2017-03-09 01:16 - 2015-06-01 20:00 - 00193112 _____ (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
2017-03-09 01:16 - 2015-06-01 20:00 - 00128648 _____ (Intel Corporation) C:\WINDOWS\system32\hccutils.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 00112264 _____ C:\WINDOWS\system32\IccLibDll_x64.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 00082056 _____ (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.dll
2017-03-08 07:54 - 2016-11-02 00:56 - 00003242 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForNancy
2017-03-07 06:26 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-03-07 05:31 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-03-06 06:17 - 2015-07-30 08:30 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-03-05 09:47 - 2015-08-24 13:07 - 00000000 ____D C:\Users\Nancy\AppData\Local\ElevatedDiagnostics
2017-03-01 06:50 - 2016-10-29 15:10 - 00004214 _____ C:\WINDOWS\System32\Tasks\Open URL by RoboForm
2017-03-01 06:50 - 2016-10-29 15:10 - 00003578 _____ C:\WINDOWS\System32\Tasks\Run RoboForm TaskBar Icon
2017-03-01 06:48 - 2015-07-30 08:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
2017-02-28 07:06 - 2015-12-11 12:11 - 00000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-02-26 19:33 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-26 08:17 - 2016-02-02 05:59 - 00000000 ____D C:\ProgramData\TEMP
2017-02-26 08:17 - 2015-09-24 06:46 - 00000258 __RSH C:\ProgramData\ntuser.pol
2017-02-26 08:16 - 2016-02-02 06:02 - 00001154 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2017-02-26 08:16 - 2016-02-02 06:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2017-02-26 08:16 - 2016-02-02 06:02 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2017-02-24 09:22 - 2015-08-18 14:47 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-24 09:16 - 2015-08-18 14:47 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-23 09:57 - 2015-07-31 06:17 - 00000000 ____D C:\ProgramData\McAfee
2017-02-23 09:51 - 2015-09-03 05:50 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-23 09:42 - 2017-01-13 07:06 - 00004032 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-02-23 09:42 - 2015-07-31 06:16 - 00000000 ____D C:\Users\Nancy\AppData\Local\Adobe
2017-02-23 08:57 - 2016-07-16 06:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-22 11:42 - 2015-11-30 09:29 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-22 11:31 - 2012-09-04 06:46 - 00000000 ___RD C:\Users\Nancy\Documents\Scanned Documents
 
==================== Files in the root of some directories =======
 
2015-09-01 07:34 - 2007-09-17 08:10 - 0024576 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series
2017-03-10 08:04 - 2017-03-10 08:04 - 0000000 _____ () C:\Users\Nancy\AppData\Local\{6702FBBD-5E40-404B-B581-07C5B697FC1E}
2017-03-10 08:04 - 2017-03-10 08:04 - 0000000 _____ () C:\Users\Nancy\AppData\Local\{8B3C75FB-BFB5-491E-9ECB-DD42A76A979A}
2015-10-15 06:07 - 2015-10-15 06:07 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-08-02 05:10 - 2015-08-02 05:10 - 0000252 _____ () C:\ProgramData\FastPics.log
2015-08-04 06:54 - 2015-10-15 04:57 - 0000445 _____ () C:\ProgramData\lxdx.log
2015-09-01 06:20 - 2015-09-01 06:28 - 0000248 _____ () C:\ProgramData\lxdxDiagnostics.log
2015-09-01 06:20 - 2015-09-01 06:20 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt
 
Files to move or delete:
====================
C:\Users\Nancy\CARDFILE.EXE
C:\Users\Nancy\DisneyTime.exe
C:\Users\Nancy\Sweep.dat
 
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-03-07 09:13
 
==================== End of FRST.txt ============================

Thanks for the logs. Let me ask you, do you use this site  swagbucks.com, I am working up a quick fix using FRST64 and I can remove that if you like, let me know please

 
Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.
Please copy the entire contents Inside of the code box below beginning with START and ending with END
(To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
Name the file Fixlist.txt , Save it to your desktop where you have FRST/FRST64 or the fix wont work. Right Click on FRST/FRST64 and select RUN AS ADMINISTRATOR Then click on >FIX< (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
 
Start
CloseProcesses:
CreateRestorePoint:
GroupPolicy: Restriction - Chrome <======= ATTENTION
C:\Users\Nancy\AppData\Local\updanager
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
HKLM-x32\…\Run: [] => [X]
Task: {0FF0FC1B-B2F7-4411-92B4-FDF864AEF8DB} - System32\Tasks\Updanager_1443125228 => C:\Users\Nancy\AppData\Local\updanager\upd.exe [2015-08-27] ()
Task: {197F1288-EFE1-4B5B-B544-5D06D728AE96} - no filepath
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
Fix result of Farbar Recovery Scan Tool (x64) Version: 11-03-2017
Ran by [removed] (11-03-2017 06:36:24) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
Start
CloseProcesses:
CreateRestorePoint:
GroupPolicy: Restriction - Chrome <======= ATTENTION
C:\Users\Nancy\AppData\Local\updanager
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
HKLM-x32\…\Run: [] => [X]
Task: {0FF0FC1B-B2F7-4411-92B4-FDF864AEF8DB} - System32\Tasks\Updanager_1443125228 => C:\Users\Nancy\AppData\Local\updanager\upd.exe [2015-08-27] ()
Task: {197F1288-EFE1-4B5B-B544-5D06D728AE96} - no filepath
Hosts:
CMD: ipconfig /flushdns
EmptyTemp:
End
*****************
 
Processes closed successfully.
Restore point was successfully created.
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
C:\Users\Nancy\AppData\Local\updanager => moved successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0FF0FC1B-B2F7-4411-92B4-FDF864AEF8DB} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0FF0FC1B-B2F7-4411-92B4-FDF864AEF8DB} => key removed successfully
C:\WINDOWS\System32\Tasks\Updanager_1443125228 => moved successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Updanager_1443125228 => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{197F1288-EFE1-4B5B-B544-5D06D728AE96} => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{197F1288-EFE1-4B5B-B544-5D06D728AE96} => key removed successfully
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
========= ipconfig /flushdns =========
 
 
Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 2759668 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 130809287 B
Java, Flash, Steam htmlcache => 588 B
Windows/system/drivers => 119972956 B
Edge => 10286732 B
Chrome => 653007199 B
Firefox => 14659943 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 0 B
NetworkService => 5752 B
Nancy => 3948898 B
 
RecycleBin => 0 B
EmptyTemp: => 892.1 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 06:38:33 ====

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI