Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-03-2017
Ran by [removed] (10-03-2017 14:09:46)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1607 (X64) (2016-10-29 20:23:59)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1846905553-2082907679-4278756267-500 - Administrator - Disabled)
ASPNET (S-1-5-21-1846905553-2082907679-4278756267-1004 - Limited - Enabled)
DefaultAccount (S-1-5-21-1846905553-2082907679-4278756267-503 - Limited - Disabled)
Guest (S-1-5-21-1846905553-2082907679-4278756267-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1846905553-2082907679-4278756267-1002 - Limited - Enabled)
Nancy (S-1-5-21-1846905553-2082907679-4278756267-1001 - Administrator - Enabled) => C:\Users\Nancy
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
AddrBk 473 (HKLM-x32\…\Address Book_is1) (Version: - )
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.023.20070 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe Flash Player 24 PPAPI (HKLM-x32\…\Adobe Flash Player PPAPI) (Version: 24.0.0.221 - Adobe Systems Incorporated)
Adobe Photoshop Elements 8.0 (HKLM-x32\…\Adobe Photoshop Elements 8.0) (Version: 8.0 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.2.2.172 - Adobe Systems, Inc.)
Amazon Music (HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Amazon Amazon Music) (Version: 5.3.2.1634 - Amazon Services LLC)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (32-bit) (HKLM-x32\…\{9BA1A894-B42F-4805-BC8C-349C905A3930}) (Version: 5.3.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{7EAC8A42-9FAC-4F6B-AABF-C08C9F2E0F13}) (Version: 5.3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
BigOven (HKLM-x32\…\{98C4F0D9-3C09-4BD9-B835-29744B94931A}) (Version: 1.9.1 - Lakefront Software)
BigOven (x32 Version: 1.8.999 - Lakefront Software) Hidden
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 5.27 - Piriform)
CleanUp! (HKLM-x32\…\CleanUp!) (Version: - )
Coupon Printer for Windows (HKLM-x32\…\Coupon Printer for Windows5.0.1.7) (Version: 5.0.1.7 - Coupons.com Incorporated)
Digital Coupon Printer (HKLM-x32\…\{2CDD20A5-DFDE-4AC0-97DD-F60B1196BF98}) (Version: 3.50.0.0 - Hopster, Inc. an Inmar company)
ELAN Touchpad 11.15.0.18_X64 (HKLM\…\Elantech) (Version: 11.15.0.18 - ELAN Microelectronic Corp.)
Elevated Installer (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
EPSON WorkForce 545 Series Printer Uninstall (HKLM\…\EPSON WorkForce 545 Series) (Version: - SEIKO EPSON Corporation)
ESET Online Scanner v3 (HKLM-x32\…\ESET Online Scanner) (Version: - )
Evernote v. 6.4.2 (HKLM-x32\…\{E74F0DCA-9FC8-11E6-9D98-005056950253}) (Version: 6.4.2.3788 - Evernote Corp.)
Garmin Express (HKLM-x32\…\{9fbf4745-0038-4ed3-aee1-87af9b9ef8f1}) (Version: 5.1.1.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 5.1.1.0 - Garmin Ltd or its subsidiaries) Hidden
GoodSync (HKLM\…\{B26B00DA-2E5D-4CF2-83C5-911198C0F009}) (Version: 9.9.45.8 - Siber Systems)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
HP ENVY 4500 series Basic Device Software (HKLM\…\{6915424E-704F-4F5D-9057-9C7B406B36DB}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
HP ENVY 4500 series Help (HKLM-x32\…\{95BECC50-22B4-4FCA-8A2E-BF77713E6D3A}) (Version: 30.0.0 - Hewlett Packard)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Support Assistant (HKLM-x32\…\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.3.50.9 - Hewlett-Packard Company)
HP Support Solutions Framework (HKLM-x32\…\{55065080-504F-43BB-BE00-36B80D7D39A5}) (Version: 12.5.32.203 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\…\{302600C1-6BDF-4FD1-1309-148929CC1385}) (Version: 3.1.1309.0390 - Intel Corporation)
iTunes (HKLM\…\{9D0D2A8B-7E7B-4D88-8D50-24286ED6A5EB}) (Version: 12.5.5.5 - Apple Inc.)
LIFX Bulb Update (HKLM-x32\…\{AA0C44A9-01EB-44F7-BE71-72EEC9805D2A}) (Version: 2.0.0 - LIFX)
Living Cookbook 2015 (HKLM-x32\…\Living Cookbook 2015) (Version: 5.0.85 - Radium Technologies, Inc.)
Living Cookbook 2015 (x32 Version: 5.0.85 - Radium Technologies) Hidden
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Money Plus (HKLM-x32\…\Money2008b) (Version: 17 - Microsoft)
Microsoft OneDrive (HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\OneDriveSetup.exe) (Version: 17.3.6743.1212 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Mozilla Firefox 46.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 46.0.1 (x86 en-US)) (Version: 46.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 46.0.1.5966 - Mozilla)
OpenOffice 4.1.3 (HKLM-x32\…\{EEA30AEB-8BA7-465B-85D4-098BB99733E7}) (Version: 4.13.9783 - Apache Software Foundation)
P@H-Protocol (HKLM-x32\…\{14F936AB-5D31-410E-A4E2-70AE504712F2}) (Version: 3.0.8.6 - Valassis)
Product Improvement Study for HP ENVY 4500 series (HKLM\…\{58139103-BACF-4BDC-B71C-955F9164ADA6}) (Version: 32.3.198.49673 - Hewlett-Packard Co.)
QuickTime 7 (HKLM-x32\…\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
RoboForm 7-9-28-8 (All Users) (HKLM-x32\…\AI RoboForm) (Version: 7-9-28-8 - Siber Systems)
SpywareBlaster 5.5 (HKLM-x32\…\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Windows Driver Package - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\…\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows Driver Package - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\…\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001_Classes\CLSID\{004B49B7-11B9-5058-FF22-08DD093ADC4B}\InprocServer32 -> {1F6E2644-9468-D082-12B6-1FEE85889A47} => No File
CustomCLSID: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001_Classes\CLSID\{DD0822FF-3A09-4BDC-B749-4B00B9115850}\InprocServer32 -> {5B37C4F4-9468-D082-A254-46AA85889A47} => No File
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {022C9A37-0F0F-4E20-8450-B83957241C24} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
Task: {0FF0FC1B-B2F7-4411-92B4-FDF864AEF8DB} - System32\Tasks\Updanager_1443125228 => C:\Users\Nancy\AppData\Local\updanager\upd.exe [2015-08-27] ()
Task: {197F1288-EFE1-4B5B-B544-5D06D728AE96} - no filepath
Task: {1FF1059A-15BE-4E17-B2B9-9304236DF372} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {2937C4D3-5CA8-4B9C-8CF8-9572D233E75F} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2017-03-01] (Siber Systems)
Task: {2C332323-1941-421E-B32B-14684BFCCC0E} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {36668100-3F13-4176-8031-6C00D3DCFF27} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-03-02] (HP Inc.)
Task: {37AA8B3D-591B-45A9-8452-BAA457420507} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_CN57A324CZ => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-02-08] (HP Inc.)
Task: {3C746049-BFD0-4E9D-8DBD-ACF5824F10E1} - System32\Tasks\RTKCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [2015-06-24] (Realtek Semiconductor)
Task: {66ABD524-B4FA-4A79-9A45-69501E56E0B3} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe [2017-02-23] (Adobe Systems Incorporated)
Task: {697D14F0-C76B-42AF-B080-77E75E88A63A} - System32\Tasks\HPCeeScheduleForNancy => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {6FDBD80A-D2BA-4CDC-A582-412690BF8389} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-02-07] (Piriform Ltd)
Task: {73AE5C14-FD2D-4D12-8E06-1C4468596143} - System32\Tasks\{B0569A02-899F-4FA8-9C53-EE1C79427AAE} => pcalua.exe -a C:\Users\Nancy\Downloads\3500-4500(1).exe -d C:\Users\Nancy\Downloads
Task: {8891EC3B-83E5-4F0D-89A1-155442F6B9BC} - System32\Tasks\RtHDVBg => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-24] (Realtek Semiconductor)
Task: {8FD0DE1C-2C53-4FE1-ACF6-CF37CCE5A1D0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-12] (Google Inc.)
Task: {91456B91-D4AE-4403-987A-D83F5103B138} - System32\Tasks\RtHDVBg_ListenToDevice => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2015-06-24] (Realtek Semiconductor)
Task: {927DD210-4912-4CC0-85F2-93B160042419} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxamon.exe -unregister
Task: {96B9C065-14B5-4E0E-AF5C-B71FFED45F3C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-11-12] (Google Inc.)
Task: {9C7C4400-BBFA-44FF-90D4-D33DB6EA4A98} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {C1F6AEE8-357A-46B6-B2E7-5E0C341755F2} - System32\Tasks\HPCustParticipation HP ENVY 4500 series => C:\Program Files\HP\HP ENVY 4500 series\Bin\HPCustPartic.exe [2014-07-21] (Hewlett-Packard Development Company, LP)
Task: {CE6F81D4-3DF4-42B6-9347-D2924290D6F3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
Task: {D4A452B0-E8FC-4F18-9067-18248E714286} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-02-24] (Microsoft Corporation)
Task: {D7DB135C-1E06-4413-A4DC-CBB5E80002A8} - System32\Tasks\Open URL by RoboForm => Rundll32.exe url.dll,FileProtocolHandler "hxxps://www.roboform.com/test-pass.html?aaa=KICMKJKMKJMJNMKMGMKMCNNJGMIMLJCNLMKMOMLJCNOJLJKJGMCNJMHMJJMJKJIMOJJJJJOMOMPMJNJICMIMCNGMCNNMHMFMOMOMCNKMIMJMCNOMLMMMGMMMFMPMCNPMCNOMLMMMGMMMCNNMJNPICMOMFMEKMICNJJCKFMOMHMKMHMJNHICMMJBJKJLIMJJNBJCMBLOJBJMJGIJNKJCMJNNICMJNDJCMKJB (the data entry has 58 more characters).
Task: {DAF8A2CE-C90E-487C-AE59-A11BA25700C1} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Nancy\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
Task: {E1A1B839-5141-4517-B4C1-70234BA57E06} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-01-16] ()
Task: {E2799DBD-560C-4669-B12F-01A33873A4B5} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-02-08] (HP Inc.)
Task: {E504A4A4-6CEC-4CB8-83D7-7647F30FB278} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {EC1C7EB2-D7A6-446C-BBB6-0B155DA43003} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2016-12-07] (HP Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\WINDOWS\SysWoW64\Macromed\Flash\FlashUtil32_24_0_0_221_pepper.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForNancy.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2016-07-16 06:42 - 2016-07-16 06:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-12-14 07:00 - 2016-12-09 05:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-10-05 17:17 - 2016-10-05 17:17 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2017-01-13 13:56 - 2017-01-13 13:56 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-04-08 19:45 - 2016-04-08 19:45 - 08844000 _____ () C:\Program Files\Siber Systems\GoodSync\gs-server.exe
2016-12-14 07:00 - 2016-12-09 05:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2017-01-11 05:43 - 2016-12-21 01:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-01-11 05:43 - 2016-12-21 01:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-01-11 05:43 - 2016-12-21 01:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-10-29 17:29 - 2016-10-29 17:29 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-01-11 05:43 - 2016-12-21 02:09 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-02-07 05:22 - 2017-02-01 04:47 - 02459992 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libglesv2.dll
2017-02-07 05:22 - 2017-02-01 04:47 - 00099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\56.0.2924.87\libegl.dll
2017-02-22 04:59 - 2017-02-22 04:59 - 00073728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-02-22 04:59 - 2017-02-22 04:59 - 00179712 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-02-22 04:59 - 2017-02-22 04:59 - 42895360 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-02-07 05:24 - 2017-02-07 05:24 - 02215424 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\roottools.dll
2016-12-16 06:31 - 2016-12-16 06:31 - 00017408 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
2016-12-16 06:31 - 2016-12-16 06:31 - 12163072 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Msn.Weather.dll
2016-12-16 06:29 - 2016-12-16 06:29 - 00958464 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\SQLite3Wrapper.dll
2015-09-09 10:27 - 2015-09-09 10:27 - 00645120 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Aria.ClientTelemetry.dll
2016-08-23 04:48 - 2016-08-23 04:48 - 03312024 _____ () C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Advertising.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\localhost -> localhost
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\1001movie.com -> 1001movie.com
There are 6091 more sites.
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2015-07-30 11:06 - 2015-07-30 11:04 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Nancy\Pictures\PC_50th-WIDE.png
DNS Servers: 10.0.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\StartupApproved\StartupFolder: => "EvernoteClipper.lnk"
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\StartupApproved\Run: => "EPLTarget\P0000000000000000"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{5C18B0BF-9961-440E-AE06-C27BF28F6D55}] => (Allow) C:\Program Files\Siber Systems\GoodSync\gs-server.exe
FirewallRules: [UDP Query User{828761B7-1CD5-4627-9C6C-617E3E39B65A}C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe
FirewallRules: [TCP Query User{1D5D90F6-4274-4E08-A226-FB077C472EA7}C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\amcrest surveillance pro\amcrest surveillance pro.exe
FirewallRules: [UDP Query User{F56D4608-DF62-4639-91DD-862B8A646B38}C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe
FirewallRules: [TCP Query User{D0226AF5-22A6-490D-BE19-98E28F54A27E}C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe] => (Allow) C:\program files (x86)\amcrest surveillance pro\pc-nvr\challenge.exe
FirewallRules: [UDP Query User{07BF3F83-DBCA-4A9F-99FA-50644EFF9660}C:\program files (x86)\amcrest ip config\amcrest ip config.exe] => (Allow) C:\program files (x86)\amcrest ip config\amcrest ip config.exe
FirewallRules: [TCP Query User{1C163188-3DC8-4C1B-B9F3-9AA883823D3B}C:\program files (x86)\amcrest ip config\amcrest ip config.exe] => (Allow) C:\program files (x86)\amcrest ip config\amcrest ip config.exe
FirewallRules: [{0593ED53-9B60-4457-A780-46E4F8BEF194}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{656F195E-4A4E-45DC-BB5B-E74FB78DD581}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{FD9D7C6F-62A4-4050-8CE7-732A2C2E3597}] => (Allow) LPort=15600
FirewallRules: [{4F362F99-6171-4C90-8070-508D6DFCF5C2}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS520D\HPDiagnosticCoreUI.exe
FirewallRules: [{C62E4E86-71CA-41EA-A64A-34F164462736}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS520D\HPDiagnosticCoreUI.exe
FirewallRules: [{CB6F60BA-6BE0-4A70-9BCE-1290C1DB1425}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS45FF\HPDiagnosticCoreUI.exe
FirewallRules: [{6AC06B51-5D29-41B0-958B-76B252E54098}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS45FF\HPDiagnosticCoreUI.exe
FirewallRules: [{40D60FED-B41B-4495-AB41-C036DBB14685}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{8BC01190-2CD0-4D0C-BC1B-9F848915393F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{E2C9FE14-33E2-4A6D-9C02-67D3FDA606D9}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxamon.exe
FirewallRules: [{E9D6BCFE-2A3D-4B7A-A1C5-169FF318C8E1}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\lxdxamon.exe
FirewallRules: [{7A83B6B7-EB3B-4C9F-98EA-8F0993B1B2A2}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\frun.exe
FirewallRules: [{2B693B3B-79F3-44CC-AB3E-8BEB028877F7}] => (Allow) C:\Program Files (x86)\Lexmark 3600-4600 Series\frun.exe
FirewallRules: [{1B3BF916-1BC3-41D4-B672-D6697D233420}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{96FDF443-1DBD-42A8-AB95-2741FD888FB6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{88076CD8-92BC-45F2-A35D-026DDECD32EA}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{AB815C1C-F965-4AA7-93A9-298F7B8A2CCB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [TCP Query User{C1E26AEA-A3A3-47B6-9E63-BE5271A60D09}C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe] => (Allow) C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe
FirewallRules: [UDP Query User{317E2EC3-F485-48C7-AA8B-9F46EE5553F2}C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe] => (Allow) C:\program files (x86)\lexmark 3600-4600 series\lxdxmon.exe
FirewallRules: [{C45C1D30-2C02-4D88-AC9C-246B5EC83CC0}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\DeviceSetup.exe
FirewallRules: [{77691047-7821-4B4E-94CE-2A1696654552}] => (Allow) LPort=5357
FirewallRules: [{B6874F85-42BD-4AFA-9464-4B1C6A3A1BAA}] => (Allow) C:\Program Files\HP\HP ENVY 4500 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{48281AEC-C60D-485E-AE0A-8485E35C412D}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS738E\HPDiagnosticCoreUI.exe
FirewallRules: [{A9894A93-F173-406B-83DB-EDAE5F494E1A}] => (Allow) C:\Users\Nancy\AppData\Local\Temp\7zS738E\HPDiagnosticCoreUI.exe
FirewallRules: [TCP Query User{7E2B4FA6-721F-4C85-B776-ADDD5C358A04}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Allow) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [UDP Query User{B59D4F0E-6268-4D6F-9A20-00920349E7A4}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Allow) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [TCP Query User{0FFF73B0-6134-483E-BD24-78C7AE6F4063}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Block) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [UDP Query User{AAA4988D-5713-4CBF-9141-DAF13927348F}C:\users\nancy\appdata\local\amazon music\amazon music helper.exe] => (Block) C:\users\nancy\appdata\local\amazon music\amazon music helper.exe
FirewallRules: [{9A865A28-AA24-4CF7-A160-D6404402FA65}] => (Allow) C:\Program Files (x86)\LIFX Bulb Updater\LIFX Firmware Updater.exe
FirewallRules: [{3E660921-44CD-4EBA-940A-FEACDEF612A2}] => (Allow) C:\Program Files (x86)\LIFX Bulb Updater\LIFX Firmware Updater.exe
FirewallRules: [{8E6D0701-80AC-4869-B427-DF04CB3F246A}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{F9BBC5CE-2617-454E-8B94-563C7823A551}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
22-02-2017 11:39:23 Windows Backup
04-03-2017 09:39:36 Scheduled Checkpoint
09-03-2017 08:40:58 Windows Update
10-03-2017 11:35:44 JRT Pre-Junkware Removal
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (03/10/2017 11:36:11 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (03/10/2017 08:10:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.14393.0, time stamp: 0x57899bb2
Faulting module name: twinapi.appcore.dll, version: 10.0.14393.206, time stamp: 0x57daca78
Exception code: 0xc000027b
Fault offset: 0x000000000006d1c4
Faulting process id: 0x1db8
Faulting application start time: 0x01d2999f902d5e76
Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe
Faulting module path: C:\Windows\System32\twinapi.appcore.dll
Report Id: a3e28789-2217-499b-8737-fba0acc784ef
Faulting package full name: 60986LythixDesigns.BatteryLevel_1.1.42.0_x64__qrx3rfbhcdp2p
Faulting package-relative application ID: App
Error: (03/09/2017 08:41:26 AM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (03/08/2017 06:36:59 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.14393.0, time stamp: 0x57899bb2
Faulting module name: twinapi.appcore.dll, version: 10.0.14393.206, time stamp: 0x57daca78
Exception code: 0xc000027b
Fault offset: 0x000000000006d1c4
Faulting process id: 0x2198
Faulting application start time: 0x01d2980016f4fcae
Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe
Faulting module path: C:\Windows\System32\twinapi.appcore.dll
Report Id: 2b2a007e-e591-47e5-a3ba-d370b8afdd48
Faulting package full name: 60986LythixDesigns.BatteryLevel_1.1.42.0_x64__qrx3rfbhcdp2p
Faulting package-relative application ID: App
Error: (03/06/2017 11:51:29 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2842765
Error: (03/06/2017 11:51:29 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2842765
Error: (03/06/2017 11:51:29 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (03/06/2017 06:19:53 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: backgroundTaskHost.exe, version: 10.0.14393.0, time stamp: 0x57899bb2
Faulting module name: twinapi.appcore.dll, version: 10.0.14393.206, time stamp: 0x57daca78
Exception code: 0xc000027b
Fault offset: 0x000000000006d1c4
Faulting process id: 0x207c
Faulting application start time: 0x01d2966b42778ab7
Faulting application path: C:\WINDOWS\system32\backgroundTaskHost.exe
Faulting module path: C:\Windows\System32\twinapi.appcore.dll
Report Id: 86589b64-5b47-4f0a-9fe1-6e8a53efa233
Faulting package full name: 60986LythixDesigns.BatteryLevel_1.1.42.0_x64__qrx3rfbhcdp2p
Faulting package-relative application ID: App
Error: (03/04/2017 10:34:23 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1203
Error: (03/04/2017 10:34:23 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1203
System errors:
=============
Error: (03/10/2017 11:31:13 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
and APPID
{F72671A9-012C-4725-9D2F-2A4D32D65169}
to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/10/2017 11:30:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Garmin Device Interaction Service service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (03/10/2017 11:30:41 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Garmin Device Interaction Service service to connect.
Error: (03/10/2017 11:30:32 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/10/2017 11:30:32 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
and APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
Error: (03/10/2017 11:28:51 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
An instance of the service is already running.
Error: (03/10/2017 11:28:23 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The HP Support Solutions Framework Service service terminated unexpectedly. It has done this 1 time(s).
Error: (03/10/2017 11:28:22 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Coupon Printer Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
Error: (03/10/2017 11:28:22 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The iPod Service service terminated unexpectedly. It has done this 1 time(s).
Error: (03/10/2017 11:28:22 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Bluetooth OBEX Service service terminated unexpectedly. It has done this 1 time(s).
CodeIntegrity:
===================================
Date: 2017-03-10 09:18:11.301
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-10 09:18:11.296
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-10 09:16:08.269
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-10 09:16:08.264
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-10 09:15:05.005
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-10 09:15:05.002
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-10 09:14:34.858
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-10 09:14:34.853
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-10 09:14:29.747
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
Date: 2017-03-10 09:14:29.738
Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume2\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i7-2640M CPU @ 2.80GHz
Percentage of memory in use: 45%
Total physical RAM: 8102.75 MB
Available physical RAM: 4454.25 MB
Total Virtual: 9382.75 MB
Available Virtual: 5453.46 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:279.01 GB) (Free:46.04 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:394.18 GB) (Free:393.99 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: E3102A4B)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=279 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=451 MB) - (Type=27)
Partition 4: (Not Active) - (Size=394.2 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 08-03-2017
Ran by [removed] (administrator) on NANCY-PC (10-03-2017 14:06:45)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
() C:\Program Files\Siber Systems\GoodSync\Gs-Server.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe2\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersServer.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(Siber Systems Inc.) C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome-nm-host.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.11.110.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe
() C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\Microsoft.Msn.Weather.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Farbar) C:\Users\Nancy\Desktop\FRST64 (2).exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3242696 2015-10-10] (ELAN Microelectronics Corp.)
HKLM\…\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch
HKLM\…\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\…\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\…\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2016-10-29] (Microsoft Corporation)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2017-01-19] (Apple Inc.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-16] (Apple Inc.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [Digital Coupon Print Driver] => "C:\Program Files (x86)\Digital Coupon Printer\DigitalCouponPrinter.exe"
HKLM-x32\…\Run: [PDFVPrinter] => C:\Program Files (x86)\Classic PDF Editor\PDFVPrinter.exe
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [EPLTarget\P0000000000000000] => C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIHWA.EXE [241280 2015-01-06] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [HP ENVY 4500 series (NET)] => C:\Program Files\HP\HP ENVY 4500 series\Bin\ScanToPCActivationApp.exe [3487240 2014-07-21] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9363672 2017-02-07] (Piriform Ltd)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [SpybotPostWindows10UpgradeReInstall] => "C:\Program Files\Common Files\AV\Spybot - Search and Destroy\Test.exe"
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2017-01-16] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [Amazon Music] => C:\Users\Nancy\AppData\Local\Amazon Music\Amazon Music Helper.exe [3494376 2016-12-14] ()
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [RoboForm] => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [110376 2017-03-01] (Siber Systems)
HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Run: [GoogleChromeAutoLaunch_3312EA6C4F41A42564159DA1D2D4BD7F] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1116504 2017-02-01] (Google Inc.)
HKU\S-1-5-18\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1407912 2017-01-16] (Garmin Ltd. or its subsidiaries)
Startup: C:\Users\Nancy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk [2016-05-08]
ShortcutTarget: EvernoteClipper.lnk -> C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
GroupPolicy: Restriction - Chrome <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 10.0.1.1
Tcpip\..\Interfaces\{2b11abdc-a83c-4d6f-b508-6c1b0077fde2}: [DhcpNameServer] 10.0.1.1
Internet Explorer:
==================
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-03-01] (Siber Systems Inc.)
BHO-x32: RoboForm Toolbar Helper -> {724d43a9-0d85-11d4-9908-00400523e39a} -> C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-03-01] (Siber Systems Inc.)
BHO-x32: Evernote extension -> {92EF2EAD-A7CE-4424-B0DB-499CF856608E} -> C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll [2016-10-31] (Evernote Corp., 305 Walnut Street, Redwood City, CA 94063)
Toolbar: HKLM - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll [2017-03-01] (Siber Systems Inc.)
Toolbar: HKLM-x32 - &RoboForm; Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll [2017-03-01] (Siber Systems Inc.)
FireFox:
========
FF ProfilePath: C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605 [2017-03-01]
FF Homepage: Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605 -> hxxps://us-mg6.mail.yahoo.com/neo/launch?.rand=8oagsi4fh2shd
FF Extension: (Firefox Hotfix) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\[removed] [2016-12-26]
FF Extension: (Pin It button) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\[removed] [2015-08-27]
FF Extension: (1-Click YouTube Video Downloader) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\[removed] [2017-01-02]
FF Extension: (All-in-One Sidebar) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\{097d3191-e6fa-4728-9826-b533d755359d}.xpi [2016-05-16]
FF Extension: (web_clipper) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\{E0B8C461-F8FB-49b4-8373-FE32E9252800}.xpi [2016-05-14]
FF Extension: (Greasemonkey) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2017-01-02]
FF Extension: (Youtube Unblocker Remediation) - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\features\{b1de51fa-66e6-45f6-823b-05ba6726d6da}\[removed] [2016-12-26]
FF HKLM-x32\…\Firefox\Extensions: [{jid1-vS7biDmom8YxhA@jetpack}] - C:\Users\Nancy\AppData\Roaming\Mozilla\Firefox\Profiles\u1px9nmx.default-1440687208605\extensions\{jid1-vS7biDmom8YxhA@jetpack} => not found
FF HKLM-x32\…\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Extension: (RoboForm Toolbar) - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi [2017-03-01]
FF HKU\S-1-5-21-1846905553-2082907679-4278756267-1001\…\Firefox\Extensions: [{22119944-ED35-4ab1-910B-E619EA06A115}] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Firefox\roboform.xpi
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_24_0_0_221.dll [2017-02-26] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWoW64\Macromed\Flash\NPSWF32_24_0_0_221.dll [2017-02-26] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1222172.dll [2015-11-19] (Adobe Systems, Inc.)
FF Plugin-x32: @IPC/npmedia3.0.0.3,version=3.0.0.3 -> C:\Program Files\webrec\Torch\3.0.0.3\npmedia3.0.0.3.dll [2015-11-20] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-12-23] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\browser\plugins\npMozCouponPrinter.dll [2015-09-18] (Coupons, Inc.)
Chrome:
=======
CHR DefaultSearchURL: Default -> hxxp://www.swagbucks.com/?f=55&t;=w&p;=1&q;={searchTerms}
CHR DefaultSearchKeyword: Default -> swagbucks.com
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.8.866\_platform_specific\win_x86\widevinecdmadapter.dll => No File
CHR Plugin: (Shockwave Flash) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\PepperFlash\21.0.0.182\pepflashplayer.dll => No File
CHR Profile: C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default [2017-03-10]
CHR Extension: (Perk for Chrome) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\edpaeddemekchnbmjmcjplbbeeheionp [2016-12-31]
CHR Extension: (Pinterest Save Button) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gpdjojdkbbmdfjfahjcgigfpmkopogic [2017-02-28]
CHR Extension: (tampermonkey) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpeahjkbempddijjinnoppjbdegiggba [2016-04-04]
CHR Extension: (Tampermonkey) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\mchbmglgiiijnmpdhcbepaefgljhigdi [2016-01-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-10]
CHR Extension: (Evernote Web Clipper) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc [2017-02-15]
CHR Extension: (Chrome Media Router) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-15]
CHR Extension: (RoboForm Password Manager) - C:\Users\Nancy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnlccmojcmeohlpggmfnbbiapkmbliob [2017-02-15]
CHR HKLM\…\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2015-07-30]
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [pnlccmojcmeohlpggmfnbbiapkmbliob] - C:\Program Files (x86)\Siber Systems\AI RoboForm\Chrome\rf-chrome.crx [2015-07-30]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AdobeActiveFileMonitor8.0; C:\Program Files (x86)\Adobe2\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [169312 2009-09-06] (Adobe Systems Incorporated)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144072 2015-10-10] (ELAN Microelectronics Corp.)
S2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1039376 2017-01-16] (Garmin Ltd. or its subsidiaries)
R2 GsServer; C:\Program Files\Siber Systems\GoodSync\gs-server.exe [8844000 2016-04-08] ()
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [31776 2016-12-07] (HP Inc.)
R2 Intel(R) Wireless Bluetooth(R) 4.0 Radio Management; C:\Program Files (x86)\Intel\Bluetooth\ibtrksrv.exe [157128 2013-09-18] (Intel Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 FLxHCIh; C:\WINDOWS\System32\drivers\FLxHCIh.sys [77040 2015-07-30] (Fresco Logic)
R3 kbfiltr; C:\WINDOWS\System32\drivers\kbfiltr.sys [15416 2009-07-20] ( )
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-10 14:06 - 2017-03-10 14:08 - 00016595 _____ C:\Users\Nancy\Desktop\FRST.txt
2017-03-10 11:41 - 2017-03-10 11:41 - 00001626 _____ C:\Users\Nancy\Desktop\JRT.txt
2017-03-10 11:33 - 2017-03-10 11:35 - 01663736 _____ (Malwarebytes) C:\Users\Nancy\Desktop\JRT (1).exe
2017-03-10 11:21 - 2017-03-10 11:24 - 04031440 _____ C:\Users\Nancy\Desktop\AdwCleaner (1).exe
2017-03-10 08:20 - 2017-03-10 09:43 - 02423808 _____ (Farbar) C:\Users\Nancy\Desktop\FRST64 (2).exe
2017-03-10 08:18 - 2017-03-10 08:18 - 02423808 _____ (Farbar) C:\Users\Nancy\Downloads\FRST64 (1).exe
2017-03-10 08:13 - 2017-03-10 09:42 - 00001481 _____ C:\Users\Nancy\Documents\aswMBR.txt
2017-03-10 08:05 - 2017-03-10 08:06 - 00379220 _____ C:\WINDOWS\Minidump\031017-31156-01.dmp
2017-03-10 08:04 - 2017-03-10 08:04 - 00000000 _____ C:\Users\Nancy\AppData\Local\{8B3C75FB-BFB5-491E-9ECB-DD42A76A979A}
2017-03-10 08:04 - 2017-03-10 08:04 - 00000000 _____ C:\Users\Nancy\AppData\Local\{6702FBBD-5E40-404B-B581-07C5B697FC1E}
2017-03-10 07:59 - 2017-03-10 08:05 - 523190840 _____ C:\WINDOWS\MEMORY.DMP
2017-03-10 07:59 - 2017-03-10 08:00 - 00417412 _____ C:\WINDOWS\Minidump\031017-30140-01.dmp
2017-03-10 07:56 - 2017-03-10 07:57 - 05198336 _____ (AVAST Software) C:\Users\Nancy\Downloads\aswMBR (1).exe
2017-03-09 08:43 - 2017-03-09 08:44 - 00000000 ____D C:\WINDOWS\LastGood.Tmp
2017-03-09 01:17 - 2017-03-09 01:17 - 12935296 _____ (Intel Corporation) C:\WINDOWS\system32\igdumd64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 11460448 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igd10umd32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 11330576 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igdumd32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 01086408 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmrt64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00975184 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmrt32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00558728 _____ (Intel Corporation) C:\WINDOWS\system32\iglhsip64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00553424 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhsip32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00242800 _____ (Intel Corporation) C:\WINDOWS\system32\iglhcp64.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00206000 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\iglhcp32.dll
2017-03-09 01:17 - 2017-03-09 01:17 - 00051184 _____ (Intel Corporation) C:\WINDOWS\system32\igfxexps.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 13046920 _____ (Intel Corporation) C:\WINDOWS\system32\ig4icd64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 10829448 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\ig4icd32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 05925984 _____ (Intel Corporation) C:\WINDOWS\system32\GfxUI.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 03529352 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcmjit64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 03139208 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxcmjit32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00593544 _____ (Intel Corporation) C:\WINDOWS\system32\igfx11cmrt64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00560776 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfx11cmrt32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00536664 _____ (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00460936 _____ (Intel Corporation) C:\WINDOWS\system32\igfxdev.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00458376 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrell.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457864 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrfra.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457864 _____ (Intel Corporation) C:\WINDOWS\system32\igfxresn.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457352 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrrus.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00457344 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrrom.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrsky.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrptg.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrplk.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrnld.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrita.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrhrv.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456840 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrdeu.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456328 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrhun.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456328 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrfin.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00456328 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrcsy.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrtrk.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrsve.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrslv.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrptb.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455816 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrnor.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455304 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrtha.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00455304 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrdan.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00453768 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrheb.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00453768 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrara.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00450184 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrjpn.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00449160 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrkor.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00447112 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrcht.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00446600 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrchs.lrc
2017-03-09 01:16 - 2017-03-09 01:16 - 00428680 _____ (Intel Corporation) C:\WINDOWS\system32\igfxTMM.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00402568 _____ (Intel Corporation) C:\WINDOWS\system32\igfxpph.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00348808 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxdv32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00300128 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\IntelCpHeciSvc.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00276064 _____ (Intel Corporation) C:\WINDOWS\system32\igfxext.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00206944 _____ (Intel Corporation) C:\WINDOWS\system32\difx64.exe
2017-03-09 01:16 - 2017-03-09 01:16 - 00193160 _____ (Intel Corporation) C:\WINDOWS\system32\gfxSrvc.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00160392 _____ (Intel Corporation) C:\WINDOWS\system32\igfxdo.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00145032 _____ (Intel Corporation) C:\WINDOWS\system32\igfxcpl.cpl
2017-03-09 01:16 - 2017-03-09 01:16 - 00134280 _____ (Intel Corporation) C:\WINDOWS\system32\igfxCoIn_v4459.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00119432 _____ C:\WINDOWS\system32\igdde64.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00099464 _____ C:\WINDOWS\SysWOW64\igdde32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00043144 _____ (Intel Corporation) C:\WINDOWS\SysWOW64\igfxexps32.dll
2017-03-09 01:16 - 2017-03-09 01:16 - 00027784 _____ ( ) C:\WINDOWS\system32\IGFXDEVLib.dll
2017-03-05 09:36 - 2017-03-05 09:36 - 02668573 _____ C:\Users\Nancy\Downloads\card.pdf
2017-02-28 07:05 - 2017-02-28 07:05 - 09261616 _____ (Piriform Ltd) C:\Users\Nancy\Downloads\ccsetup527 (1).exe
2017-02-26 08:16 - 2017-02-26 08:16 - 04291320 _____ (BrightFort LLC ) C:\Users\Nancy\Downloads\spywareblastersetup55.exe
2017-02-24 14:08 - 2017-02-24 14:08 - 00105675 _____ C:\Users\Nancy\Documents\declaration.pdf
2017-02-23 09:52 - 2017-02-23 09:52 - 00000000 ____D C:\Program Files\Common Files\Intel
2017-02-23 09:51 - 2017-03-01 06:54 - 00000000 ____D C:\Program Files\Common Files\McAfee
2017-02-23 09:51 - 2017-03-01 06:54 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-02-23 09:43 - 2017-02-23 09:42 - 00000030 _____ C:\AVScanner.ini
2017-02-23 06:07 - 2017-02-23 06:07 - 00758134 _____ C:\Users\Nancy\Downloads\FLW024084_20160729_20160727102658output (1).pdf
2017-02-21 07:04 - 2017-02-21 07:04 - 09261616 _____ (Piriform Ltd) C:\Users\Nancy\Downloads\ccsetup527.exe
2017-02-16 06:48 - 2017-02-16 06:48 - 00076854 _____ C:\Users\Nancy\Downloads\Mary Drake_MedicalClearance.pdf
2017-02-14 16:29 - 2017-02-14 16:29 - 00837472 _____ C:\Users\Nancy\Downloads\doc00510420170214145651.pdf
2017-02-14 16:26 - 2017-02-14 16:26 - 02085345 _____ C:\Users\Nancy\Downloads\doc00510320170214145053.pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-03-10 14:06 - 2015-07-31 05:02 - 00000000 ____D C:\FRST
2017-03-10 13:03 - 2016-10-29 13:37 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-10 11:45 - 2015-07-30 07:51 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-03-10 11:30 - 2016-10-29 15:10 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-10 11:29 - 2016-10-29 13:46 - 00000000 ____D C:\Users\Nancy
2017-03-10 11:29 - 2016-07-16 01:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-03-10 11:29 - 2014-05-29 16:45 - 00000000 ____D C:\AdwCleaner
2017-03-10 09:51 - 2015-07-31 05:07 - 00041152 _____ C:\Users\Nancy\Downloads\Addition.txt
2017-03-10 09:51 - 2015-07-31 05:02 - 00035925 _____ C:\Users\Nancy\Downloads\FRST.txt
2017-03-10 09:18 - 2012-12-31 13:14 - 00000000 ____D C:\Users\Nancy\Downloads\WinAVI_Video_Capture
2017-03-10 08:10 - 2015-07-30 07:45 - 01030638 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-10 08:05 - 2016-10-29 15:59 - 00000000 ____D C:\WINDOWS\Minidump
2017-03-10 08:00 - 2017-01-13 07:06 - 00000892 _____ C:\WINDOWS\Tasks\Adobe Flash Player PPAPI Notifier.job
2017-03-10 08:00 - 2016-11-02 00:56 - 00000350 _____ C:\WINDOWS\Tasks\HPCeeScheduleForNancy.job
2017-03-10 07:59 - 2016-07-02 05:18 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2017-03-10 07:18 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-10 06:20 - 2016-07-16 06:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-10 06:14 - 2015-07-30 07:55 - 00000000 ____D C:\Users\Nancy\Desktop\sweep
2017-03-09 09:44 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-03-09 08:44 - 2015-11-29 08:23 - 00000000 ____D C:\Program Files (x86)\Intel
2017-03-09 08:43 - 2016-07-16 06:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-09 08:33 - 2015-07-30 12:55 - 09211904 _____ C:\Users\Nancy\Documents\My Money.mny
2017-03-09 01:17 - 2015-06-01 20:01 - 13182528 _____ (Intel Corporation) C:\WINDOWS\system32\igd10umd64.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 09025672 _____ (Intel Corporation) C:\WINDOWS\system32\igfxress.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 05382856 _____ (Intel Corporation) C:\WINDOWS\system32\Drivers\igdkmd64.sys
2017-03-09 01:16 - 2015-06-01 20:00 - 00463960 _____ (Intel Corporation) C:\WINDOWS\system32\igfxpers.exe
2017-03-09 01:16 - 2015-06-01 20:00 - 00420960 _____ (Intel Corporation) C:\WINDOWS\system32\hkcmd.exe
2017-03-09 01:16 - 2015-06-01 20:00 - 00304264 _____ (Intel Corporation) C:\WINDOWS\system32\igfxrenu.lrc
2017-03-09 01:16 - 2015-06-01 20:00 - 00193112 _____ (Intel Corporation) C:\WINDOWS\system32\igfxtray.exe
2017-03-09 01:16 - 2015-06-01 20:00 - 00128648 _____ (Intel Corporation) C:\WINDOWS\system32\hccutils.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 00112264 _____ C:\WINDOWS\system32\IccLibDll_x64.dll
2017-03-09 01:16 - 2015-06-01 20:00 - 00082056 _____ (Intel Corporation) C:\WINDOWS\system32\igfxsrvc.dll
2017-03-08 07:54 - 2016-11-02 00:56 - 00003242 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForNancy
2017-03-07 06:26 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\SysWOW64\Macromed
2017-03-07 05:31 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-03-06 06:17 - 2015-07-30 08:30 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2017-03-05 09:47 - 2015-08-24 13:07 - 00000000 ____D C:\Users\Nancy\AppData\Local\ElevatedDiagnostics
2017-03-01 06:50 - 2016-10-29 15:10 - 00004214 _____ C:\WINDOWS\System32\Tasks\Open URL by RoboForm
2017-03-01 06:50 - 2016-10-29 15:10 - 00003578 _____ C:\WINDOWS\System32\Tasks\Run RoboForm TaskBar Icon
2017-03-01 06:48 - 2015-07-30 08:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RoboForm
2017-02-28 07:06 - 2015-12-11 12:11 - 00000865 _____ C:\Users\Public\Desktop\CCleaner.lnk
2017-02-26 19:33 - 2016-07-16 06:47 - 00000000 ____D C:\WINDOWS\system32\Macromed
2017-02-26 08:17 - 2016-02-02 05:59 - 00000000 ____D C:\ProgramData\TEMP
2017-02-26 08:17 - 2015-09-24 06:46 - 00000258 __RSH C:\ProgramData\ntuser.pol
2017-02-26 08:16 - 2016-02-02 06:02 - 00001154 _____ C:\Users\Public\Desktop\SpywareBlaster.lnk
2017-02-26 08:16 - 2016-02-02 06:02 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster
2017-02-26 08:16 - 2016-02-02 06:02 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
2017-02-24 09:22 - 2015-08-18 14:47 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-02-24 09:16 - 2015-08-18 14:47 - 138020592 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-02-23 09:57 - 2015-07-31 06:17 - 00000000 ____D C:\ProgramData\McAfee
2017-02-23 09:51 - 2015-09-03 05:50 - 00000000 ____D C:\ProgramData\Package Cache
2017-02-23 09:42 - 2017-01-13 07:06 - 00004032 _____ C:\WINDOWS\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-02-23 09:42 - 2015-07-31 06:16 - 00000000 ____D C:\Users\Nancy\AppData\Local\Adobe
2017-02-23 08:57 - 2016-07-16 06:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-02-22 11:42 - 2015-11-30 09:29 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-02-22 11:31 - 2012-09-04 06:46 - 00000000 ___RD C:\Users\Nancy\Documents\Scanned Documents
==================== Files in the root of some directories =======
2015-09-01 07:34 - 2007-09-17 08:10 - 0024576 _____ () C:\Program Files (x86)\Lexmark 3500-4500 Series
2017-03-10 08:04 - 2017-03-10 08:04 - 0000000 _____ () C:\Users\Nancy\AppData\Local\{6702FBBD-5E40-404B-B581-07C5B697FC1E}
2017-03-10 08:04 - 2017-03-10 08:04 - 0000000 _____ () C:\Users\Nancy\AppData\Local\{8B3C75FB-BFB5-491E-9ECB-DD42A76A979A}
2015-10-15 06:07 - 2015-10-15 06:07 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-08-02 05:10 - 2015-08-02 05:10 - 0000252 _____ () C:\ProgramData\FastPics.log
2015-08-04 06:54 - 2015-10-15 04:57 - 0000445 _____ () C:\ProgramData\lxdx.log
2015-09-01 06:20 - 2015-09-01 06:28 - 0000248 _____ () C:\ProgramData\lxdxDiagnostics.log
2015-09-01 06:20 - 2015-09-01 06:20 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt
Files to move or delete:
====================
C:\Users\Nancy\CARDFILE.EXE
C:\Users\Nancy\DisneyTime.exe
C:\Users\Nancy\Sweep.dat
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-03-07 09:13
==================== End of FRST.txt ============================