This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Microsoft installer is curropted - deeply infected

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I think this machine is deeply infected, i tried to run some applications and they would not even install. During normal start-up, many website hyperlinks are unclickable, applications have missing graphics when launched, start menu does not work and the machine is very slow in normal mode. It was also stating that there were unknown IP connections connected to the computer and i couldn't even log off or use MSCONFIG to enter safe mode. Cause it would state that there are other users logged onto the machine. I am suspicious of a hyjacker, but i hope that is not the case. I absolutely had to reboot into safe mode in order to achieve any sort of task. Even well in safe mode though, it indicated that the microsoft installer was corrupted so i couldn't remove any applications or run any scanners like Kaskpersky would not run.

 

Also this machine has been infected many times over and i think its because the user uses alot of streaming websites that i believe are the cause. If i could some how pinpoint which links or sites visited that are malicious in any way, i can stop the user from using them or block them. This has been kind of an ongoing issue. The last time i locked the computer down tight with powerful firewall software, ublock origin, script blocker, Crypto prevent and even unchecky, but to no avail does it keep the user from being re-infected. So if you can look into what caused these infections by looking at logs, that would be most helpful in preventing this issue from re-occurring. I did notice some suspicious links in the history of the browser where certain loaded unknown URLS were apparent.

 

Some of the fav sites this user seems to enjoy are:

 

Vidzi.tv

screenertv

tvmuse

allmyvideos

media tumbler

putlocker

Best streams

Novamove

 

 

 

IS there any way to access the history and copy and or download the history. If so we might be able to see clearly where the rerouting of URLS took place and during what site was visited.

 

 

FRST LOG:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-03-2017
Ran by [removed] (administrator) on ASHLEY-PC (23-03-2017 01:36:36)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgent.exe
(Microsoft Corporation) C:\Windows\System32\InstallAgentUserBroker.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-11] (Realtek Semiconductor)
HKLM\…\Run: [ShadowPlay] => "C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\…\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291648 2012-05-20] (Intel Corporation)
HKLM-x32\…\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452272 2012-08-31] (CANON INC.)
HKLM-x32\…\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1085656 2016-06-23] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [PowerDVD16Agent] => C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD16Agent.exe [525352 2016-05-13] (CyberLink Corp.)
HKLM Group Policy restriction on software: *.bmp*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.js <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: cipher.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %programfiles(x86)%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.js <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.com <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.com <====== ATTENTION
HKLM Group Policy restriction on software: syskey.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.pif <====== ATTENTION
HKLM Group Policy restriction on software: vssadmin.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.jse <====== ATTENTION
HKLM Group Policy restriction on software: lsassw86s.exe <====== ATTENTION
HKLM Group Policy restriction on software: lsassvrtdbks.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.js <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.js <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: ** <====== ATTENTION
HKLM Group Policy restriction on software: %programfiles%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *:\$Recycle.Bin <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.com <====== ATTENTION
HKLM Group Policy restriction on software: scsvserv.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.txt*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.rar*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.js <====== ATTENTION
HKLM Group Policy restriction on software: %systemdrive%\*\svchost.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.jpeg*.js <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.gif*.com <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.mp3*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %programdata%\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.bmp*.js <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\LocalLow\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.jpg*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.divx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.wma*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\Appdata\Roaming\Microsoft\Windows\IEUpdate\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.rtf*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.com <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.xlsx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.avi*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.wmv*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.7z*.com <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pptx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.cmd <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.com <====== ATTENTION
HKLM Group Policy restriction on software: *.xls*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: *.pdf*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.wav*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.pub*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: C:\Users\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: *.png*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*.scr <====== ATTENTION
HKLM Group Policy restriction on software: *.doc*.exe <====== ATTENTION
HKLM Group Policy restriction on software: *.zip*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Local\*.jse <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.ppt*.js <====== ATTENTION
HKLM Group Policy restriction on software: *.mp4*.scr <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.pif <====== ATTENTION
HKLM Group Policy restriction on software: *.docx*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %appdata%\*\*.bat <====== ATTENTION
HKLM Group Policy restriction on software: %userprofile%\AppData\Roaming\*\*.exe <====== ATTENTION
HKLM Group Policy restriction on software: %allusersprofile%\*.pif <====== ATTENTION
HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [29502592 2016-07-14] (Skype Technologies S.A.)
HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\RunOnce: [Uninstall 17.3.6743.1212\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Ashley\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64"
HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\RunOnce: [Uninstall 17.3.6743.1212] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Ashley\AppData\Local\Microsoft\OneDrive\17.3.6743.1212"
HKU\S-1-5-21-3018848687-2183701812-1251838533-1003\…\RunOnce: [Uninstall C:\Users\Chuck Matthews\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Chuck Matthews\AppData\Local\Microsoft\OneDrive\17.3.6381.0405\amd64"
HKU\S-1-5-21-3018848687-2183701812-1251838533-1003\…\RunOnce: [Uninstall C:\Users\Chuck Matthews\AppData\Local\Microsoft\OneDrive\17.3.6381.0405] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Chuck Matthews\AppData\Local\Microsoft\OneDrive\17.3.6381.0405"
HKU\S-1-5-21-3018848687-2183701812-1251838533-1003\…\RunOnce: [Uninstall 17.3.6743.1212\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Chuck Matthews\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64"
HKU\S-1-5-21-3018848687-2183701812-1251838533-1003\…\RunOnce: [Uninstall 17.3.6743.1212] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Chuck Matthews\AppData\Local\Microsoft\OneDrive\17.3.6743.1212"
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\…\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2016-07-16] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk [2016-07-30]
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
GroupPolicy: Restriction - Chrome <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{33ce9729-2c43-4527-a503-5541a4195edd}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-3018848687-2183701812-1251838533-1003\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> No File
BHO: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> No File
BHO: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> No File
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO-x32: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> No File
BHO-x32: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> No File
BHO-x32: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> No File
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\TmBpIe64.dll [2016-06-15] (Trend Micro Inc.)
Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\TmBpIe32.dll [2016-06-15] (Trend Micro Inc.)
Handler: tmop - {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg.dll [2015-07-16] (Trend Micro Inc.)
Handler-x32: tmop - {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg32.dll [2015-07-16] (Trend Micro Inc.)
Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
Handler-x32: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ProToolbarIMRatingActiveX.dll [2015-07-16] (Trend Micro Inc.)
Handler-x32: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll [2015-07-16] (Trend Micro Inc.)
 
FireFox:
========
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-16] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2016-06-23] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default [2017-03-23]
CHR Extension: (Google Docs) - C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-10-12]
CHR Extension: (Google Drive) - C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-12]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2017-03-21]
CHR Extension: (YouTube) - C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-30]
CHR Extension: (uBlock Origin) - C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-03-14]
CHR Extension: (Google Docs Offline) - C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-10-12]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-14]
CHR Extension: (Gmail) - C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-30]
CHR Extension: (Chrome Media Router) - C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-02-14]
CHR HKLM-x32\…\Chrome\Extension: [ohhcpmplhhiiaoiddkfboafbhiknefdf] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [9658776 2017-03-16] (Emsisoft Ltd)
S2 asComSvc; C:\Program Files (x86)\ASUS\AXSP\1.00.19\atkexComSvc.exe [920736 2012-06-01] ()
S2 asHmComSvc; C:\Program Files (x86)\ASUS\AAHM\1.00.20\aaHMSvc.exe [951936 2012-06-01] (ASUSTeK Computer Inc.)
S2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [166720 2012-06-25] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes)
S2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-11-17] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-11-17] (NVIDIA Corporation)
S2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [459832 2016-12-01] (NVIDIA Corporation)
S2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-11-17] (NVIDIA Corporation)
S4 Platinum Host Service; C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe [1137664 2015-07-16] (Trend Micro Inc.)
S2 PwmSvc; C:\Program Files\Trend Micro\TMIDS\PwmSvc.exe [2458112 2016-11-30] (Trend Micro Inc.)
S2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1570520 2016-02-02] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [837848 2016-02-02] (Secunia)
S2 TmRhea; C:\ProgramData\Trend Micro Installer\TrendMicro_Download_1489547613\TmRhea.exe [3625216 2016-11-27] (Trend Micro Inc.)
S2 Unchecky; C:\Program Files (x86)\Unchecky\bin\unchecky_svc.exe [304408 2017-01-29] (RaMMicHaeL)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347328 2016-07-16] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103720 2016-07-16] (Microsoft Corporation)
S4 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad -bt=0 [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [15232 2012-08-22] ()
S1 epp; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\epp.sys [124552 2016-11-23] (Emsisoft Ltd)
R3 hitmanpro37; C:\WINDOWS\system32\drivers\hitmanpro37.sys [54736 2017-03-22] ()
R2 MBAMChameleon; C:\WINDOWS\system32\drivers\MBAMChameleon.sys [186304 2017-03-22] (Malwarebytes)
S3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-03-22] (Malwarebytes)
R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [251840 2017-03-22] (Malwarebytes)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
S3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_dispiwu.inf_amd64_b67dc924fff8de6d\nvlddmkm.sys [14199224 2017-01-04] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-11-17] (NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [46016 2016-11-17] (NVIDIA Corporation)
S3 PSI; C:\WINDOWS\System32\DRIVERS\psi_mf_amd64.sys [18456 2016-02-02] (Secunia)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [589824 2016-07-16] (Realtek                                            )
S4 tmactmon; C:\WINDOWS\System32\DRIVERS\tmactmon.sys [140504 2016-08-10] (Trend Micro Inc.)
S4 tmcomm; C:\WINDOWS\System32\DRIVERS\tmcomm.sys [332512 2016-08-10] (Trend Micro Inc.)
S4 TMEBC; C:\WINDOWS\System32\DRIVERS\TMEBC64.sys [72504 2015-11-19] (Trend Micro Inc.)
S4 tmeevw; C:\WINDOWS\System32\DRIVERS\tmeevw.sys [116576 2015-06-07] (Trend Micro Inc.)
S4 tmel; C:\WINDOWS\System32\DRIVERS\tmel.sys [39056 2015-06-22] (Trend Micro Inc.)
S4 tmevtmgr; C:\WINDOWS\System32\DRIVERS\tmevtmgr.sys [106720 2016-08-10] (Trend Micro Inc.)
S4 tmnciesc; C:\WINDOWS\System32\DRIVERS\tmnciesc.sys [561952 2016-06-23] (Trend Micro Inc.)
S4 tmumh; C:\WINDOWS\System32\DRIVERS\TMUMH.sys [101088 2016-08-09] (Trend Micro Inc.)
S4 tmusa; C:\WINDOWS\System32\DRIVERS\tmusa.sys [124752 2015-12-09] (Trend Micro Inc.)
S3 UrsCx01000; C:\WINDOWS\System32\drivers\urscx01000.sys [57696 2016-07-16] () [File not signed]
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
S2 {41E8078B-96D9-42DC-8789-A1CF102CD880}; C:\Program Files (x86)\CyberLink\PowerDVD16\Common\NavFilter\000.fcl [29624 2016-03-27] (CyberLink Corp.)
S3 ALSysIO; \??\C:\Users\Ashley\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S3 cpuz139; \??\C:\Users\Ashley\AppData\Local\Temp\cpuz139\cpuz139_x64.sys [X] <==== ATTENTION
U3 idsvc; no ImagePath
S3 RTVLANPT; \SystemRoot\system32\DRIVERS\RtVlan620.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-03-23 01:35 - 2017-03-23 01:35 - 00032678 _____ C:\Users\Ashley\Desktop\dds.txt
2017-03-23 01:35 - 2017-03-23 01:35 - 00012107 _____ C:\Users\Ashley\Desktop\attach.txt
2017-03-23 01:33 - 2017-03-23 01:33 - 00688992 ____R (Swearware) C:\Users\Ashley\Desktop\dds.com
2017-03-23 01:33 - 2017-03-23 01:33 - 00688992 _____ (Swearware) C:\Users\Ashley\Downloads\dds.com
2017-03-23 01:23 - 2017-03-23 01:23 - 02622304 _____ (Kaspersky Lab) C:\Users\Ashley\Downloads\kss16.0.0.1344en_9702 (2).exe
2017-03-23 00:24 - 2017-03-23 00:44 - 386502656 _____ C:\VAMPIRE_DIARIES_SEASON_7_D2.ISO
2017-03-22 23:27 - 2017-03-22 23:48 - 386555904 _____ C:\OnceUponATime_S5_D2_USA_DES.ISO
2017-03-22 22:36 - 2017-03-22 22:48 - 386463744 _____ C:\SCREAM_S1D3.ISO
2017-03-22 21:33 - 2017-03-22 21:33 - 02622304 _____ (Kaspersky Lab) C:\Users\Ashley\Downloads\kss16.0.0.1344en_9702 (1).exe
2017-03-22 21:32 - 2017-03-22 21:32 - 14504384 _____ (Copyright 2017.) C:\Users\Ashley\Downloads\Zemana.AntiMalware.Portable.exe
2017-03-22 21:32 - 2017-03-22 21:32 - 00000000 ____D C:\Users\Ashley\AppData\Local\Zemana
2017-03-22 21:25 - 2017-03-22 21:32 - 00000000 ____D C:\ProgramData\HitmanPro
2017-03-22 21:25 - 2017-03-22 21:25 - 11581544 _____ (SurfRight B.V.) C:\Users\Ashley\Downloads\hitmanpro_x64.exe
2017-03-22 21:25 - 2017-03-22 21:25 - 00054736 _____ C:\WINDOWS\system32\Drivers\hitmanpro37.sys
2017-03-22 21:23 - 2017-03-22 21:23 - 57131432 _____ (Malwarebytes ) C:\Users\Ashley\Downloads\mb3-setup-consumer-3.0.6.1469-1075 (1).exe
2017-03-22 21:15 - 2017-03-22 21:21 - 00251840 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-03-22 21:15 - 2017-03-22 21:21 - 00186304 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMChameleon.sys
2017-03-22 21:15 - 2017-03-22 21:21 - 00043968 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbam.sys
2017-03-22 21:15 - 2017-03-22 21:15 - 00111544 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\farflt.sys
2017-03-22 21:15 - 2017-03-22 21:15 - 00092088 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mwac.sys
2017-03-22 21:15 - 2017-03-22 21:15 - 00001912 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-03-22 21:15 - 2017-03-22 21:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-03-22 21:15 - 2017-03-22 21:15 - 00000000 ____D C:\Program Files\Malwarebytes
2017-03-22 21:15 - 2017-02-24 06:23 - 00077408 _____ C:\WINDOWS\system32\Drivers\mbae64.sys
2017-03-22 21:14 - 2017-03-22 21:14 - 57131432 _____ (Malwarebytes ) C:\Users\Ashley\Downloads\mb3-setup-consumer-3.0.6.1469-1075.exe
2017-03-22 21:13 - 2017-03-22 21:14 - 00007908 _____ C:\Users\Ashley\Desktop\Rkill.txt
2017-03-22 21:13 - 2017-03-22 21:13 - 02030536 _____ (Bleeping Computer, LLC) C:\Users\Ashley\Downloads\rkill.exe
2017-03-22 21:10 - 2017-03-22 21:11 - 00074504 _____ C:\TDSSKiller.3.1.0.12_22.03.2017_21.10.52_log.txt
2017-03-22 21:10 - 2017-03-22 21:10 - 04747704 _____ (AO Kaspersky Lab) C:\Users\Ashley\Downloads\tdsskiller.exe
2017-03-22 21:07 - 2017-03-22 21:59 - 386689024 _____ C:\OnceUponATime_S4_D5_USA_DES.ISO
2017-03-22 21:03 - 2017-03-22 21:03 - 00000000 ____D C:\Users\Ashley\AppData\Roaming\28718
2017-03-17 22:17 - 2017-03-17 22:21 - 00000000 ____D C:\Users\Ashley\Desktop\The Originals
2017-03-11 01:33 - 2017-03-11 01:33 - 00012567 _____ C:\Users\Ashley\Downloads\Katherine_and_Stefan_go_for_a_Walk_2x01_The_Vampire_Diaries (1)
2017-03-11 01:32 - 2017-03-11 01:32 - 00012567 _____ C:\Users\Ashley\Downloads\Katherine_and_Stefan_go_for_a_Walk_2x01_The_Vampire_Diaries
2017-03-11 01:14 - 2017-03-11 02:42 - 00000000 ____D C:\Users\Ashley\Desktop\The Vampire Diaires Epic Goodbye Pictures
2017-03-01 21:25 - 2017-03-01 21:27 - 00000000 ____D C:\Users\Ashley\Documents\abc family-Freeform Shows
2017-03-01 21:20 - 2017-03-01 21:30 - 00000000 ____D C:\Users\Ashley\Documents\CW Shows
2017-03-01 21:10 - 2017-03-23 01:34 - 00461888 _____ C:\WINDOWS\ntbtlog.txt
2017-03-01 21:10 - 2017-03-01 21:10 - 00000000 ____D C:\WINDOWS\Panther
2017-03-01 20:54 - 2017-03-01 20:56 - 00000000 ____D C:\Users\Ashley\Desktop\[RH] Fate kaleid liner Prisma Illya 2wei! [Dual Audio] [BDRip] [1080p]
2017-03-01 20:52 - 2017-03-01 20:54 - 00000000 ____D C:\Users\Ashley\Desktop\[Tsundere] Fate Kaleid Liner Prisma Illya 2wei Herz [BDRip h264 1920x1080 10bit FLAC]
2017-03-01 20:44 - 2017-03-01 20:44 - 00002332 _____ C:\Users\Ashley\Documents\virus scan log.txt
2017-02-28 22:36 - 2017-02-28 22:37 - 00043484 _____ C:\Users\Ashley\Desktop\Addition.txt
2017-02-28 22:35 - 2017-03-23 01:37 - 00045059 _____ C:\Users\Ashley\Desktop\FRST.txt
2017-02-28 22:35 - 2017-03-23 01:36 - 00000000 ____D C:\FRST
2017-02-28 22:35 - 2017-03-23 01:35 - 02424832 _____ (Farbar) C:\Users\Ashley\Desktop\FRST64.exe
2017-02-28 22:35 - 2017-03-23 01:35 - 00000000 ____D C:\Users\Ashley\Desktop\FRST-OlderVersion
2017-02-28 22:28 - 2017-02-28 22:28 - 00084421 _____ C:\Users\Ashley\Desktop\f33ecbd5c36ede42f02d03db50cb3c0e_computer-tech-size-82-kb-computer-tech-clipart_486-500.jpeg
2017-02-28 22:18 - 2017-03-23 01:24 - 00001179 _____ C:\Users\Ashley\Desktop\Install Kaspersky Security Scan version 16.0.0.1344.lnk
2017-02-28 22:16 - 2017-03-23 01:24 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2017-02-28 22:16 - 2017-02-28 22:16 - 02622304 _____ (Kaspersky Lab) C:\Users\Ashley\Downloads\kss16.0.0.1344en_9702.exe
2017-02-28 22:15 - 2017-02-28 22:15 - 02423296 _____ (Farbar) C:\Users\Ashley\Downloads\FRST64 (2).exe
2017-02-28 22:11 - 2017-03-22 21:21 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-02-28 21:49 - 2017-02-28 21:49 - 00041129 _____ C:\Users\Ashley\Documents\bookmarks_2_28_17.html
2017-02-28 21:49 - 2017-02-28 21:49 - 00000000 ____D C:\WINDOWS\pss
2017-02-23 04:24 - 2017-02-23 04:24 - 00259922 _____ C:\Users\Ashley\Desktop\Shepard_Sara-Lying_Game_The.epub
2017-02-22 22:56 - 2017-02-22 22:56 - 02423296 _____ (Farbar) C:\Users\Ashley\Downloads\FRST64 (1).exe
2017-02-22 22:55 - 2017-02-22 22:55 - 02423296 _____ (Farbar) C:\Users\Ashley\Downloads\FRST64.exe
2017-02-22 22:51 - 2017-02-22 22:51 - 06751360 _____ (ESET spol. s r.o.) C:\Users\Ashley\Downloads\esetonlinescanner_enu.exe
2017-02-22 22:51 - 2017-02-22 22:51 - 00000000 ____D C:\Users\Ashley\AppData\Local\ESET
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-03-23 01:09 - 2016-09-21 18:35 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-03-23 00:21 - 2016-08-04 15:01 - 00000000 ____D C:\ProgramData\DVD Shrink
2017-03-22 21:32 - 2016-07-30 20:47 - 00000000 ____D C:\Users\Ashley\AppData\Local\CrashDumps
2017-03-22 21:27 - 2016-09-21 18:40 - 01445946 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-03-22 21:20 - 2016-07-15 23:04 - 00524288 _____ C:\WINDOWS\system32\config\BBI
2017-03-22 21:15 - 2016-07-30 03:36 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-03-22 20:57 - 2016-09-21 18:51 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-03-22 20:57 - 2016-09-21 18:41 - 00000000 ____D C:\Users\Ashley
2017-03-22 20:57 - 2016-07-30 16:31 - 00000000 ____D C:\Program Files\Emsisoft Anti-Malware
2017-03-22 20:56 - 2016-07-30 18:18 - 00000000 ____D C:\Users\Ashley\AppData\Local\DP_Tower_3.7
2017-03-22 16:36 - 2016-09-22 16:23 - 00000010 _____ C:\Users\Chuck Matthews\AppData\Local\sponge.last.runtime.cache
2017-03-22 15:49 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-03-16 23:31 - 2016-08-13 16:49 - 00000000 ____D C:\Users\Ashley\AppData\Roaming\Skype
2017-03-15 13:05 - 2016-12-16 15:05 - 00003296 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-03-15 13:05 - 2016-09-22 09:17 - 00002433 _____ C:\Users\Chuck Matthews\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-03-15 13:05 - 2016-09-22 09:17 - 00000000 ___RD C:\Users\Chuck Matthews\OneDrive
2017-03-15 13:03 - 2016-09-22 09:13 - 00000000 ____D C:\Users\Chuck Matthews\AppData\Local\Packages
2017-03-15 13:03 - 2016-07-16 04:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-03-15 13:02 - 2016-09-21 18:37 - 00000000 ____D C:\ProgramData\NVIDIA
2017-03-15 09:49 - 2016-08-01 19:10 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-03-15 09:46 - 2016-08-01 19:10 - 138634176 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-03-15 09:46 - 2016-07-16 04:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-03-14 20:14 - 2016-07-30 18:07 - 00000000 ____D C:\ProgramData\Trend Micro
2017-03-14 20:13 - 2016-07-30 17:53 - 00000000 ____D C:\ProgramData\Trend Micro Installer
2017-03-14 20:04 - 2016-07-30 19:58 - 00000010 _____ C:\Users\Ashley\AppData\Local\sponge.last.runtime.cache
2017-03-13 18:27 - 2016-07-16 04:45 - 00000000 ____D C:\WINDOWS\INF
2017-03-12 19:38 - 2016-07-15 23:04 - 00008192 _____ C:\WINDOWS\system32\config\ELAM
2017-03-09 22:17 - 2016-07-16 04:49 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-03-09 22:17 - 2016-07-16 04:49 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-03-05 14:02 - 2016-07-29 19:25 - 00000000 ____D C:\Users\Ashley\AppData\Local\VirtualStore
2017-03-03 15:36 - 2016-08-09 20:02 - 00002409 _____ C:\Users\Ashley\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-03-03 15:36 - 2016-08-09 20:02 - 00000000 ___RD C:\Users\Ashley\OneDrive
2017-03-01 21:28 - 2016-11-25 15:14 - 00000000 ____D C:\Users\Ashley\Documents\Anime
2017-03-01 20:47 - 2016-07-31 13:04 - 00000000 ____D C:\Users\Ashley\Downloads\DVDFab.9.2.2.8 FINAL + Crack [TechTools.NET]
2017-02-25 20:45 - 2016-07-30 20:43 - 00000000 ____D C:\ProgramData\CanonIJPLM
2017-02-22 23:27 - 2016-07-30 19:18 - 00000000 ____D C:\ProgramData\TEMP
2017-02-22 23:24 - 2016-07-30 19:18 - 00000000 ____D C:\Program Files (x86)\SpywareBlaster
 
==================== Files in the root of some directories =======
 
2016-07-30 18:05 - 2016-07-30 18:05 - 0000036 _____ () C:\Users\Ashley\AppData\Local\housecall.guid.cache
2016-09-16 09:20 - 2016-09-16 09:20 - 0000410 _____ () C:\Users\Ashley\AppData\Local\LMIR0001.tmp.bat
2016-07-30 18:47 - 2016-09-16 09:20 - 0000335 _____ () C:\Users\Ashley\AppData\Local\LMIR0001.tmp_r.bat
2017-02-14 18:51 - 2017-02-14 18:51 - 0007625 _____ () C:\Users\Ashley\AppData\Local\Resmon.ResmonCfg
2016-07-30 19:58 - 2017-03-14 20:04 - 0000010 _____ () C:\Users\Ashley\AppData\Local\sponge.last.runtime.cache
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-03-19 19:00
 
==================== End of FRST.txt ============================
Looks like you've run every tool imaginable, I can see so many listed.

Don't know whats on the computer to do all this damage.

See if you can locate C:\Users\Ashley\Desktop\Addition.txt
has a lot of info that needs to be seen.

~~~

[external image: bullseye_zpse9eaf36e.gif]Malwarebytes Anti-Rootkit
  • Download Malwarebytes Anti-Rootkit
  • Once the file has been downloaded, right click on the downloaded file and select the Extract all menu option.
  • Follow the instructions to extract the ZIP file to a folder called mbar-versionnumber on your desktop.
  • Once the ZIP file has been extracted, open the folder and when that folder opens, double-click on the mbar folder.
  • Double-click on the mbar.exe file to launch Malwarebytes Anti-Rootkit.
  • After you double-click on the mbar.exe file, you may receive a User Account Control (UAC) message if you are sure you wish to allow the program to run. Please allow to start Malwarebytes Anti-Rootkit correctly.
  • Malwarebytes Anti-Rootkit will now install necessary drivers that are required for the program to operate correctly.
  • If you receive a DDA driver message like could not load DDA driver, click on the Yes button and Malwarebytes Anti-Rootkit will now restart your computer and will start automatically.
[external image: MBAMAnti-Rootkit1_zps4613be8c.png]
  • Please click by the introduction screen on the Next button to continue.
[external image: MBAMAnti-Rootkit2update_zpsf85fca28.png]
  • Next you will see the Update Database screen.
  • Click on the Update button so Malwarebytes Anti-Rootkit can download the latest definition updates.
[external image: MBAMAnti-Rootkitupdatecomplete_zpscf9f4c]
  • When the update has finished, click on the Next button.
[external image: MBAMAnti-Rootkitscan_zps9b346fe7.png]
  • Next you can select some basic scanning options. Make sure the Drivers, Sectors, and System scan targets are selected before you click on the Scan button.
  • Malwarebytes Anti-Rootkit will now start scanning your computer for rootkits. This scan can take some time, so please be patient.
[external image: MBAMAnti-Rootkitscan-results_zps9f0fdf8e]
  • When the scan with Malwarebytes Anti-Rootkit is finished, the program will display a screen with the results from the scan.
  • Make sure everything is selected and that the option to create a restore point is checked.
  • Next click on the Cleanup button. Malwarebytes Anti-Rootkit will then prompt you to reboot your computer.
  • Click on Yes button to restart your computer.
  • There will now be two log files created in the mbar folder called system-log.txt and one that starts with mbar-log.
  • The mbar-log file will always start with mbar-log, but the rest will be named using a timestamp indicating the time it was run.
    • For example, mbar-log-2012-11-12 (19-13-32).txt corresponds to mbar-log-year-month-day (hour-minute-second).txt.
  • The system-log.txt contains information about each time you have run MBAR and contains diagnostic information from the program.

There was no maleware found but the software indicated there was a missing DLL file when i tried to run it. Clearly there is an issue with this computer because its strange that so many malware software is not detecting anything. Maybe its a windows Corruption?

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by [removed] (23-03-2017 01:37:26)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1607 (X64) (2016-09-22 01:58:43)
Boot Mode: Safe Mode (with Networking)
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-3018848687-2183701812-1251838533-500 - Administrator - Disabled)
Ashley (S-1-5-21-3018848687-2183701812-1251838533-1000 - Administrator - Enabled) => C:\Users\Ashley
Chuck Matthews (S-1-5-21-3018848687-2183701812-1251838533-1003 - Administrator - Enabled) => C:\Users\Chuck Matthews
DefaultAccount (S-1-5-21-3018848687-2183701812-1251838533-503 - Limited - Disabled)
Guest (S-1-5-21-3018848687-2183701812-1251838533-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3018848687-2183701812-1251838533-1002 - Limited - Enabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Trend Micro Internet Security (Enabled - Up to date) {8242D66F-41BD-4049-C2E6-E578E73B62A0}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Emsisoft Anti-Malware (Disabled - Up to date) {701CB209-EBBC-AADC-11E6-DE73E7AF4C9D}
AS: Emsisoft Anti-Malware (Disabled - Up to date) {CB7D53ED-CD86-A552-2B56-E5019C280620}
AS: Trend Micro Internet Security (Enabled - Up to date) {3923378B-6787-4FC7-F856-DE0A9CBC281D}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
µTorrent (HKLM-x32\…\uTorrent) (Version: 3.0.0 - )
7-Zip 16.00 (HKLM-x32\…\7-Zip) (Version: 16.00 - Igor Pavlov)
Active@ File Recovery 15 (HKLM\…\{177608F6-F029-4301-B176-15BA7C605B73}_is1) (Version: 15 - LSoft Technologies Inc)
Adobe Reader XI (11.0.17) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.17 - Adobe Systems Incorporated)
Ansel (Version: 376.19 - NVIDIA Corporation) Hidden
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.16.2.0 - Asmedia Technology)
Canon Easy-WebPrint EX (HKLM-x32\…\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM-x32\…\Canon_IJ_Network_Scanner_Selector_EX) (Version:  - Canon Inc.)
Canon IJ Network Tool (HKLM-x32\…\Canon_IJ_Network_UTILITY) (Version: 3.2.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\…\Canon_IJ_Scan_Utility) (Version:  - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\…\CANONIJPLM100) (Version: 4.0.0 - Canon Inc.)
Canon MX920 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX920_series) (Version: 1.00 - Canon Inc.)
Canon MX920 series On-screen Manual (HKLM-x32\…\Canon MX920 series On-screen Manual) (Version: 7.6.0 - Canon Inc.)
Canon MX920 series User Registration (HKLM-x32\…\Canon MX920 series User Registration) (Version:  - ‭Canon Inc.)
Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
CBR Reader (HKLM-x32\…\{EDAAC216-AC73-4152-9654-E12FE5A69F5D}_is1) (Version:  - cbrreader.com)
Core Temp 1.5.1 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.5.1 - ALCPU)
CPUID CPU-Z 1.77 (HKLM\…\CPUID CPU-Z_is1) (Version:  - )
CryptoPrevent (HKLM-x32\…\{5C5B24E7-4694-4049-A222-CCE7D3FAC63F}_is1) (Version:  - Foolish IT LLC)
CyberLink PowerDVD 16 (HKLM-x32\…\{7CD1ACC0-3DD0-4894-90C7-BF2A136C074D}) (Version: 16.0.1713.60 - CyberLink Corp.)
DVD Decrypter (Remove Only) (HKLM-x32\…\DVD Decrypter) (Version:  - )
DVD Shrink 3.2 (HKLM-x32\…\DVD Shrink_is1) (Version:  - DVD Shrink)
DVDFab 9.1.2.2 (08/01/2014) (HKLM-x32\…\DVDFab 9_is1) (Version:  - Fengtao Software Inc.)
Emsisoft Anti-Malware (HKLM\…\{5502032C-88C1-4303-99FE-B5CBD7684CEA}_is1) (Version: 11.0 - Emsisoft Ltd.)
FINAL FANTASY XIV - A Realm Reborn (HKLM-x32\…\{2B41E132-07DF-4925-A3D3-F2D1765CCDFE}) (Version: 1.0.0000 - SQUARE ENIX CO., LTD.)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 56.0.2924.87 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.99 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.5.235 - Intel Corporation)
Malwarebytes version 3.0.6.1469 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes)
Microsoft OneDrive (HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\OneDriveSetup.exe) (Version: 17.3.6798.0207 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3018848687-2183701812-1251838533-1003\…\OneDriveSetup.exe) (Version: 17.3.6798.0207 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft WSE 3.0 Runtime (HKLM-x32\…\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.)
MPC-HC 1.7.10 (64-bit) (HKLM\…\{2ACBF1FA-F5C3-4B19-A774-B22A31F231B9}_is1) (Version: 1.7.10 - MPC-HC Team)
NVIDIA 3D Vision Controller Driver 369.04 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 369.04 - NVIDIA Corporation)
NVIDIA GeForce Experience 3.1.2.31 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 3.1.2.31 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.16.0318 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.16.0318 - NVIDIA Corporation)
NvNodejs (Version: 3.1.2.31 - NVIDIA Corporation) Hidden
NvTelemetry (Version: 1.2.0.0 - NVIDIA Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.61.612.2012 - Realtek)
Realtek Ethernet Diagnostic Utility (HKLM-x32\…\{DADC7AB0-E554-4705-9F6A-83EA82ED708E}) (Version: 1.00.0000 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6657 - Realtek Semiconductor Corp.)
Secunia PSI (3.0.0.11005) (HKLM-x32\…\Secunia PSI) (Version: 3.0.0.11005 - Secunia)
SHIELD Streaming (Version: 7.1.0340 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 3.1.2.31 - NVIDIA Corporation) Hidden
Skype™ 7.26 (HKLM-x32\…\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.26.101 - Skype Technologies S.A.)
SpywareBlaster 5.5 (HKLM-x32\…\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
The Sims Medieval (HKLM-x32\…\{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}) (Version: 1.0.0 - Electronic Arts)
Trend Micro Internet Security (HKLM\…\{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}) (Version: 10.0 - Trend Micro Inc.)
Trend Micro Password Manager (HKLM\…\3A0FB4E3-2C0D-4572-A24D-67F1CAABDDP35_is1) (Version: 3.7.0.1125 - Trend Micro Inc.)
Trend Micro Titanium (Version: 10.0 - Trend Micro Inc.) Hidden
Unchecky v1.0.2 (HKLM-x32\…\Unchecky) (Version: 1.0.2 - RaMMicHaeL)
Windows 10 Upgrade Assistant (HKLM-x32\…\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17343 - Microsoft Corporation)
WinRAR 5.31 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.31.0 - win.rar GmbH)
Wizard101 (HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}) (Version: 1.0.0 - KingsIsle Entertainment, Inc.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0C570DB7-E13D-4533-A66A-248E9D34A0B0} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {19BAAE6D-D476-403A-AFB5-C4DBADE5D905} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {293D4D77-593C-488C-A0E7-80554E26F3FA} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {2A860624-0E69-439A-9075-9C1AFA167C04} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => %SystemRoot%\ehome\mcupdate.exe 
Task: {331D7B46-2019-4D1B-A0E5-CBC51B7F932A} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => %SystemRoot%\ehome\mcupdate.exe 
Task: {3480A523-911D-44D5-9DCE-CC2258BE0EE4} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {41161D9D-2FDD-4D4B-80E1-62A5097AE537} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {425229AA-F49D-47BD-98F3-8EA99A3F6699} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => %windir%\ehome\MCUpdate.exe 
Task: {475E6128-18AC-4253-ABDC-713B72455F1D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-29] (Google Inc.)
Task: {4F19967A-6A01-4002-AA1D-6712C7A17646} - System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-11-17] (NVIDIA Corporation)
Task: {532B7CC3-A881-4728-9DDF-130168EF8152} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => %SystemRoot%\ehome\mcupdate.exe 
Task: {570A2B41-B597-4E22-AA63-44D6088AFC7C} - System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-11-17] (NVIDIA Corporation)
Task: {58C652E1-92D0-4EBD-8539-18477B5E28F3} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {629ADCC5-1437-4AB2-9A58-1D7D3A1982E6} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => %SystemRoot%\ehome\mcupdate.exe 
Task: {6B36304C-AC99-4E61-BAD5-AC5C276CCD25} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => %SystemRoot%\ehome\mcupdate.exe 
Task: {6BB85D39-FB7D-4406-8EE0-34ACD6B71939} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {6C22DA3C-69A8-4C4C-ABFA-42D596AD5E2D} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {7207B1F7-B68E-4252-A8E2-00A9AC785968} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {7B90D6F0-2596-4D97-A614-F2893574629A} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => %SystemRoot%\ehome\ehrec.exe 
Task: {9028B4D3-70F1-4F91-9536-D8F29C86FA3A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {96D1C7DC-C7D3-458B-ADB3-2351D365A8BE} - System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe [2016-11-17] (NVIDIA Corporation)
Task: {ADBD6711-3BB9-4B1F-92CA-82C843729D0A} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {AE2CC30B-AF40-4318-8B7E-07EBD5457A0F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => %SystemRoot%\ehome\mcupdate.exe 
Task: {AF30A72A-514B-4E0F-8598-1D2FAE10A72B} - System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe [2016-11-17] (NVIDIA Corporation)
Task: {B367B1C0-E48E-4AA7-871E-F50F7A690422} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {B7762BC9-6F59-434B-B928-30566FE30F72} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => %SystemRoot%\ehome\ehPrivJob.exe 
Task: {BBC263E9-8A07-4C3E-9303-A72C43C0E4AC} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => %SystemRoot%\ehome\mcupdate.exe 
Task: {DA30424A-17D4-40A6-8B4B-6D5EA4ECC6B0} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\Ashley\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe 
Task: {DA70FABD-61E8-40A5-8A32-FBBF602D4863} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-29] (Google Inc.)
Task: {ED186A83-676A-4526-B06B-C2114C0E2B3C} - System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe [2016-11-17] (NVIDIA Corporation)
Task: {EEAFE8B7-F42F-4CA0-A485-0E6C957CD852} - System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} => C:\Program Files (x86)\NVIDIA Corporation\NvNode\nvnodejslauncher.exe [2016-11-17] (NVIDIA Corporation)
Task: {FB6E31CC-5824-4607-91C1-31C401ADE46A} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => %SystemRoot%\ehome\ehrec.exe 
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-07-16 04:42 - 2016-07-16 04:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2016-12-13 20:02 - 2016-12-09 03:29 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2017-03-22 21:15 - 2017-02-24 06:23 - 02264352 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll
2016-12-13 20:02 - 2016-12-09 03:29 - 02681200 _____ () C:\WINDOWS\SYSTEM32\CoreUIComponents.dll
2017-01-11 15:59 - 2016-12-20 23:54 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-01-11 15:59 - 2016-12-20 23:48 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-01-11 15:59 - 2016-12-20 23:48 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-01-11 15:59 - 2016-12-20 23:48 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-01-11 15:59 - 2016-12-20 23:48 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-01-11 15:59 - 2016-12-20 23:53 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2017-02-28 22:21 - 2016-09-06 12:00 - 05197312 _____ () C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libglesv2.dll
2017-02-28 22:21 - 2016-09-06 12:00 - 00147456 _____ () C:\Users\Ashley\AppData\Local\Google\Chrome\User Data\SwiftShader\3.3.0.1\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
iver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMChameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMSwissArmy => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMChameleon => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMSwissArmy => ""="Driver"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKLM\…\.scr: CryptoPreventSCR => "C:\Program Files (x86)\Foolish IT\CryptoPrevent\CryptoPreventFilterMod.CryptoPreventEXEC" "%1" /S %*
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\trendmicro.com -> hxxps://pwm.trendmicro.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\…\1001movie.com -> 1001movie.com
 
There are 6091 more sites.
 
 
==================== Hosts content: ==========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 19:34 - 2017-03-01 21:10 - 00003226 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
0.0.0.0 cdn.appround.biz
0.0.0.0 cdn.bigspeedpro.com
0.0.0.0 cdn.bispd.com
0.0.0.0 cdn.bisrv.com
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-3018848687-2183701812-1251838533-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Ashley\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\LocalState\PhotosAppBackground\{b044935f-8b8c-4fe1-adb1-11a8f6f1559f}.jpg
HKU\S-1-5-21-3018848687-2183701812-1251838533-1003\Control Panel\Desktop\\Wallpaper -> C:\WINDOWS\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-82-3006700770-424185619-1745488364-794895919-4004696415\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 1) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{A6F997B3-F28E-4F88-9A89-BAF8D090A77C}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{914878B7-7B84-4207-B146-0733248B5844}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{02DD40C5-D414-4EE9-BC7F-3E1D716588E0}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamUserAgent.exe
FirewallRules: [{DAE8EA85-C1BB-416D-98EB-3D4265365CFA}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{302BF223-C5B1-4A6A-9327-E0980114ADA9}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5E84D1DE-DE3B-4C17-A01B-4FA4FD02DA96}] => (Allow) C:\Program Files (x86)\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe
FirewallRules: [{529F02E2-23F6-4B07-9F27-86BAA996E6D8}] => (Allow) C:\Program Files (x86)\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivboot.exe
FirewallRules: [{4EE8F4E2-3253-487C-8A89-283A6C171AA1}] => (Allow) C:\Program Files (x86)\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivlauncher.exe
FirewallRules: [{3E779C58-47AB-43CC-AE4F-D71A5029710F}] => (Allow) C:\Program Files (x86)\SquareEnix\FINAL FANTASY XIV - A Realm Reborn\boot\ffxivlauncher.exe
FirewallRules: [{687C02BF-17C5-4C16-95A3-118C7A2F0080}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD.exe
FirewallRules: [{FBA77102-B7AE-402A-935B-D61ECCCB8308}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD16\Kernel\DMS\CLMSServerPDVD16.exe
FirewallRules: [{A72C0FCA-0A04-4206-95E7-A99CD507E2BF}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD16\PowerDVD16Agent.exe
FirewallRules: [{A9398298-C41B-437A-8A48-D5C67297C1DD}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD16\Movie\PowerDVDMovie.exe
FirewallRules: [{4F4418D4-1B74-4455-94AB-CA8C03625981}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD16\CastingStation.exe
FirewallRules: [{38BC8513-7071-44FE-B1A5-4F41FF1BACE2}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{988A41FA-4044-45BA-8D12-159A8EC42F2D}] => (Allow) C:\Program Files (x86)\uTorrent\uTorrent.exe
FirewallRules: [{CF2799F3-A130-45AF-8F82-C757D8DF230D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvContainer\NvContainer.exe
FirewallRules: [{37ED78BE-23DC-4917-A1A7-CCA69A7B7CE7}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
01-03-2017 21:45:04 Scheduled Checkpoint
10-03-2017 00:50:43 Scheduled Checkpoint
19-03-2017 13:31:55 Scheduled Checkpoint
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/22/2017 09:45:15 PM) (Source: Application Error) (EventID: 1005) (User: )
Description: Windows cannot access the file C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\resources.pri for one of the following reasons:
there is a problem with the network connection, the disk that the file is stored on, or the storage
drivers installed on this computer; or the disk is missing.
Windows closed the program Host Process for Windows Services because of this error.
 
Program: Host Process for Windows Services
File: C:\Program Files\WindowsApps\Microsoft.BingWeather_4.18.37.0_x86__8wekyb3d8bbwe\resources.pri
 
The error value is listed in the Additional Data section.
User Action
1. Open the file again.
This situation might be a temporary problem that corrects itself when the program runs again.
2.
If the file still cannot be accessed and
- It is on the network,
your network administrator should verify that there is not a problem with the network and that the server can be contacted.
- It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the disk is fully inserted into the computer.
3. Check and repair the file system by running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click OK. At the command prompt, type CHKDSK /F, and then press ENTER.
4. If the problem persists, restore the file from a backup copy.
5. Determine whether other files on the same disk can be opened. If not, the disk might be damaged. If it is a hard disk, contact your administrator or computer hardware vendor for
further assistance.
 
Additional Data
Error value: C0000242
Disk type: 3
 
Error: (03/22/2017 09:45:15 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: svchost.exe_StateRepository, version: 10.0.14393.0, time stamp: 0x57899b1c
Faulting module name: MrmCoreR.dll, version: 10.0.14393.479, time stamp: 0x582589a4
Exception code: 0xc0000006
Fault offset: 0x0000000000042193
Faulting process id: 0x5dc
Faulting application start time: 0x01d2a38ce9dd8d45
Faulting application path: C:\WINDOWS\system32\svchost.exe
Faulting module path: C:\Windows\System32\MrmCoreR.dll
Report Id: e76c1287-0162-497e-891a-034e9d962967
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (03/22/2017 09:32:13 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: hitmanpro_x64.exe, version: 3.7.15.281, time stamp: 0x57fb56a4
Faulting module name: hitmanpro_x64.exe, version: 3.7.15.281, time stamp: 0x57fb56a4
Exception code: 0xc0000005
Fault offset: 0x00000000002bf385
Faulting process id: 0xf40
Faulting application start time: 0x01d2a38d84b5ce48
Faulting application path: C:\Users\Ashley\Downloads\hitmanpro_x64.exe
Faulting module path: C:\Users\Ashley\Downloads\hitmanpro_x64.exe
Report Id: 5bad0f93-3c76-44be-b587-5f35cb74c3a0
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (03/22/2017 09:32:08 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Ashley-PC)
Description: Activation of app Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe:MicrosoftEdge.AppX9zvsr9qeth9e9a03yr0g7rpdrcrwgn5r.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (03/22/2017 09:31:58 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Users\Ashley\Downloads\hitmanpro_x64.exe ; Description = Checkpoint by HitmanPro; Error = 0x8007043c).
 
Error: (03/22/2017 09:31:37 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Failed to create restore point (Process = C:\Users\Ashley\Downloads\hitmanpro_x64.exe ; Description = Checkpoint by HitmanPro; Error = 0x8007043c).
 
Error: (03/22/2017 09:22:04 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Ashley-PC)
Description: Activation of app Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe:MicrosoftEdge.AppX9zvsr9qeth9e9a03yr0g7rpdrcrwgn5r.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (03/22/2017 09:20:28 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 512) (User: )
Description: The Cryptographic Services service failed to initialize the VSS backup "System Writer" object.
 
Details:
Could not query the status of the EventSystem service.
 
System Error:
A system shutdown is in progress.
.
 
Error: (03/22/2017 09:00:41 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: Ashley-PC)
Description: Activation of app Microsoft.MicrosoftEdge_38.14393.0.0_neutral__8wekyb3d8bbwe:MicrosoftEdge.AppX9zvsr9qeth9e9a03yr0g7rpdrcrwgn5r.mca failed with error: -2144927149 See the Microsoft-Windows-TWinUI/Operational log for additional information.
 
Error: (03/22/2017 08:53:58 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program SearchUI.exe version 10.0.14393.693 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: cf4
 
Start Time: 01d2930b02b939f2
 
Termination Time: 4294967295
 
Application Path: C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe
 
Report Id: 56a2a374-0f7c-11e7-9be9-10bf4884cce8
 
Faulting package full name: Microsoft.Windows.Cortana_1.7.0.14393_neutral_neutral_cw5n1h2txyewy
 
Faulting package-relative application ID: CortanaUI
 
 
System errors:
=============
Error: (03/23/2017 01:37:40 AM) (Source: DCOM) (EventID: 10005) (User: Ashley-PC)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (03/23/2017 01:37:27 AM) (Source: DCOM) (EventID: 10005) (User: Ashley-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (03/23/2017 01:37:27 AM) (Source: DCOM) (EventID: 10005) (User: Ashley-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (03/23/2017 01:37:23 AM) (Source: DCOM) (EventID: 10005) (User: Ashley-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (03/23/2017 01:37:23 AM) (Source: DCOM) (EventID: 10005) (User: Ashley-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (03/23/2017 01:37:23 AM) (Source: DCOM) (EventID: 10005) (User: Ashley-PC)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (03/23/2017 01:36:37 AM) (Source: DCOM) (EventID: 10005) (User: Ashley-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (03/23/2017 01:36:37 AM) (Source: DCOM) (EventID: 10005) (User: Ashley-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (03/23/2017 01:36:37 AM) (Source: DCOM) (EventID: 10005) (User: Ashley-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
Error: (03/23/2017 01:36:37 AM) (Source: DCOM) (EventID: 10005) (User: Ashley-PC)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{B52D54BB-4818-4EB9-AA80-F9EACD371DF8}
 
 
CodeIntegrity:
===================================
  Date: 2017-03-22 19:04:32.337
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2017-03-22 19:04:30.842
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks32.dll that did not meet the Microsoft signing level requirements.
 
  Date: 2017-03-22 19:04:20.409
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.
 
  Date: 2017-03-22 18:20:29.380
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.
 
  Date: 2017-03-22 18:05:13.827
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.
 
  Date: 2017-03-22 15:48:54.325
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.
 
  Date: 2017-03-22 14:48:02.841
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll because the set of per-page image hashes could not be found on the system.
 
  Date: 2017-03-22 14:05:13.699
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.
 
  Date: 2017-03-22 10:05:13.586
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.
 
  Date: 2017-03-22 06:05:13.487
  Description: Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume2\Program Files\Emsisoft Anti-Malware\a2hooks64.dll that did not meet the Windows signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i3-3220 CPU @ 3.30GHz
Percentage of memory in use: 39%
Total physical RAM: 8133.12 MB
Available physical RAM: 4940.04 MB
Total Virtual: 16325.12 MB
Available Virtual: 12778.15 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:930.53 GB) (Free:148.56 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 8B964B56)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=930.5 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450 MB) - (Type=27)
Partition 4: (Not Active) - (Size=450 MB) - (Type=27)
 
==================== End of Addition.txt ============================

There was no maleware found but the software indicated there was a missing DLL file when i tried to run it. Clearly there is an issue with this computer because its strange that so many malware software is not detecting anything. Maybe its a windows Corruption?

Let's try to temporarily disable TrendMicro to run a few tools,  it might be interfering.
http://esupport.trendmicro.com/en-us/home/pages/technical-support/1058376.aspx
 
Emisoft Antimalware follow the below.  When we're finished we can just simply reverse this.
You can disable the File Guard temporarily or permanently in Emsisoft Anti-Malware as well. Simply right click the tray icon and select "Disable File Guard" under guard state. This will disable all real time scans until you enable them again through the very same menu, but choosing "Enable File Guard" instead now. You can proceed the same with all other real time protection modules as well.
 
~~~~~~
Please open Notepad *Do Not Use Wordpad!* or use any other text editor than Notepad or the script will fail. (Start -> Run -> type notepad in the Open field -> OK) and copy and paste  the text present inside the quote box below:
Or use this method Press the windows key [external image: Windows_Logo_key.gif]+ r on your keyboard at the same time. This will open the RUN BOX.
Type Notepad and and click the OK key.

 To do this highlight the contents of the box and right click on it and select copy.
Paste this into the open notepad. save it to the Desktop as fixlist.txt
NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)
[external image: Fixlist_zpsdjgcelfa.jpg]

start
CreateRestorePoint:
CloseProcesses:
GroupPolicy: Restriction - Chrome <======= ATTENTION
BHO: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> No File
BHO: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> No File
BHO: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> No File
BHO-x32: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> No File
BHO-x32: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> No File
BHO-x32: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> No File
S3 ALSysIO; \??\C:\Users\Ashley\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S3 cpuz139; \??\C:\Users\Ashley\AppData\Local\Temp\cpuz139\cpuz139_x64.sys [X] <==== ATTENTION
U3 idsvc; no ImagePath
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]
EmptyTemp:
End


Open  FRST/FRST64 and press the > Fix < button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.

~~~~~~~~~~~~~~~~~~
 
[external image: BY4dvz9.png]AdwCleaner
  • Please download AdwCleaner and save the file to your Desktop.
    In order to use AdwCleaner, you have to agree the Eula:
  • Right-click AdwCleaner.exe and select [external image: AVOiBNU.jpg] Run as administrator to run the programme.
  • Follow the prompts.
  • Click [external image: A49sxPr.png]Scan.
  • Upon completion, click [external image: 6cyn5v5.png]Logfile. A log (AdwCleaner[S1].txt) will open. Briefly check the log for anything you know to be legitimate.
  • Return to AdwCleaner. Ensure anything you know to be legitimate does not have a checkmark under the corresponding tab.
  • Click [external image: MqHawIb.png]Clean.
  • Follow the prompts and allow your computer to reboot.
  • After the reboot, a log (AdwCleaner[C1].txt) will open. Copy the contents of the log and paste in your next reply.
– File and folder backups are made for items removed using this programme. Should a legitimate file or folder be removed (otherwise known as a 'false-positive'), simple steps can be taken to restore the item. Please do not overly concern yourself with the contents of AdwCleaner[C1].txt.
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Please download Junkware Removal Tool
or from here http://downloads.malwarebytes.org/file/jrt
to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
~~
please post
Fixlog.txt
AdwCleaner[C1].txt  
JRT.txt

There were quite a few errors running these applications. Do you think this might have anything to do with the fact that i am in safe mode? In any case i was able to successfully get the FRST log. The ADW cleaner log how ever did not open. It shown 4 results infected and i removed them, they were only ask tool bar items though. The third scan with the JRT produced an error related to a missing DLL.

 

Also the start menu no longer works in safe mode.

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 15-03-2017
Ran by [removed] (25-03-2017 19:37:18) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Safe Mode (with Networking)
==============================================
 
fixlist content:
*****************
start
CreateRestorePoint:
CloseProcesses:
GroupPolicy: Restriction - Chrome <======= ATTENTION
BHO: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> No File
BHO: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> No File
BHO: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> No File
BHO-x32: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> No File
BHO-x32: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> No File
BHO-x32: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> No File
S3 ALSysIO; \??\C:\Users\Ashley\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
S3 cpuz139; \??\C:\Users\Ashley\AppData\Local\Temp\cpuz139\cpuz139_x64.sys [X] <==== ATTENTION
U3 idsvc; no ImagePath
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [125]
EmptyTemp:
End
*****************
 
Error: Restore point can only be created in normal mode.
Processes closed successfully.
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{43C6D902-A1C5-45c9-91F6-FD9E90337E18} => key removed successfully
HKCR\CLSID\{43C6D902-A1C5-45c9-91F6-FD9E90337E18} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{959A5673-7971-48e6-AF54-58F745AC4ABC} => key removed successfully
HKCR\CLSID\{959A5673-7971-48e6-AF54-58F745AC4ABC} => key not found. 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} => key removed successfully
HKCR\CLSID\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{43C6D902-A1C5-45c9-91F6-FD9E90337E18} => key removed successfully
HKCR\Wow6432Node\CLSID\{43C6D902-A1C5-45c9-91F6-FD9E90337E18} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{959A5673-7971-48e6-AF54-58F745AC4ABC} => key removed successfully
HKCR\Wow6432Node\CLSID\{959A5673-7971-48e6-AF54-58F745AC4ABC} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} => key removed successfully
HKCR\Wow6432Node\CLSID\{BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} => key not found. 
HKLM\System\CurrentControlSet\Services\ALSysIO => key removed successfully
ALSysIO => service removed successfully
HKLM\System\CurrentControlSet\Services\cpuz139 => key removed successfully
cpuz139 => service removed successfully
HKLM\System\CurrentControlSet\Services\idsvc => key removed successfully
idsvc => service removed successfully
C:\ProgramData\TEMP => ":5C321E34" ADS removed successfully.
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 0 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 99726169 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 246346014 B
Edge => 2684176 B
Chrome => 811669509 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Default => 38178 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 128 B
systemprofile32 => 128 B
LocalService => 6354296 B
NetworkService => 10766 B
Ashley => 71890172 B
Chuck Matthews => 20802860 B
DefaultAppPool => 33058 B
 
RecycleBin => 2424938 B
EmptyTemp: => 1.2 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 

 

==== End of Fixlog 19:37:57 ====
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.2 (03.10.2017)
Operating System: Windows 10 Home x64 
Ran by [removed] (Limited) on Sat 03/25/2017 at 19:53:49.11
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 1 
 
Successfully deleted: C:\Users\Ashley\AppData\Roaming\4450 (Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Sat 03/25/2017 at 19:54:58.72
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 

There were quite a few errors running these applications. Do you think this might have anything to do with the fact that i am in safe mode? In any case i was able to successfully get the FRST log. The ADW cleaner log how ever did not open. It shown 4 results infected and i removed them, they were only ask tool bar items though. The third scan with the JRT produced an error related to a missing DLL.

Did you disable security apps?

Wonder if these items would had downloaded in safe mode with networking better then in normal mode. To be honest, sounds like a corrupt Microsoft windows installer.
Why….no idea really other then maybe Crypto prevent or TrendMicro security suite possibly. And then if thats the problem.

read over this link
Microsoft installer cleanup utility
https://support.microsoft.com/en-us/help/907749/basic-troubleshooting-steps-for-windows-installer

I worry what we attempt to do is going to return with a dll error.

~~~~~~~~~~~~~~~~~~~~~`
This repair may take a bit of time to start and complete.

Tweaking.com - Windows Repair All-In-One (Portable)

- Download Windows Repair All-In-One (Portable Version) from here.

- Extract tweaking.com_windows_repair_aio.zip to your Desktop.

- Disable all your antivirus and antimalware software - see how to do that here.
- Right click on 🖼Click to load external image (QfBzvq1.png) and select Run as Administrator (XP users just double click) to start Windows Repair All-In-One.
(Windows Vista/7/8 users: Accept UAC warning if it is enabled.)

- A window will appear. Click Step 2.
[external image: 2f8o60N.png]

- Click the Open Pre-Scan button, then click Start Scan. Wait for Windows Repair to finish scanning.

- Depending on which error Windows Repair found, click Repair Reparse Point or Repair Environment Variable accordingly. When the button changes to "Done!", click the close button to return to Windows Repair.

- Go to Step 3, then click Check in the See If Check Disk Is Needed.

- If Windows Repair stated that errors are found, click Open Check Disk At Next Boot. Choose (/R) Fixes errors on the disk also locate bad sectors and recovers readable information, then click Add To Next Boot. Reboot the computer to let Windows check the disk.
[external image: Ymy7crZ.png]

- Go to Step 4, then click Do It.
[external image: zDtdN75.png]

- Go to Step 5. Under System Restore click Create.
[external image: f7lEe1N.png]

- Go to Repairs and click Open Repairs. Leave all checkmarks as they are, then click Start Repairs.
[external image: PGv2vtD.png]

- By default Windows Repair All-In-One will create a "Logs" folder in its folder on the Desktop. Please post the contents of the log in your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~`

See is these scanners will run.
  • Enable detection of potentially unsafe applications
  • Enable detection of suspicious applications
  • Scan archives
  • Enable Anti-Stealth Technology
  • Click on the Change button and select only Operating memory, Autostart locations and drive C:\ to be scanned.
🖼Click to load external image (yKulboi.jpg)
  • Push the Scan button.
  • ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  • When the scan completes a list of found threats will open automatically (if any malicious files are found).
  • Push save to text file and save the file to your desktop using a unique name, such as ESETScan.txt. Include the contents of this report in your next reply.
  • Push the do not clean button.
  • Push 🖼Click to load external image (a3dBJq5.jpg) and the close the application.
~~~~~~~~~~~~~~~~~~~~~~~`
  • Download Emsisoft Emergency Kit and save it to your desktop.
  • Double-click icon then click Install
  • A Window should open highlighting Start Emergency Kit Scanner
  • Right click on the icon and select Run as administrator
  • Click 1. Update now!
  • Once the update is completed select Settings under Scan
  • Uncheck Join the Emsisoft Anti-Malware Network
  • Click Scan at the top
  • Click On scan completion
  • Click Quarantine detected objects, then click OK
  • Click Malware Scan
  • Once completed click View Report
  • Save the file to your Desktop using the default file name
  • Copy and paste the report in your reply
  • ===============

Thanks. I will get right on this. I just wanted to notify you at the fact that i attempted my self to try and isolate and fix the issue with viruses and infections. I found quite a few in previous scans, unfortunately i didn't save the logs but most were found with malewarebytes and hitman Pro as well as antispyware. It is possible that the numerous infections and maleware from past scans on this machine may of caused some instability and corruption. Though i am wondering why the scans we ran, specifically FRST did not pick up any traces of anything previously. I think you have the right idea though with using the "repair All in one" to fix any permanent damage to drivers or system files and then proceed to scan with some online scanners. 

 

I think what i may do though is to try and operate these scanners well in Normal startup Mode. I know safe mode often limits usability of some tools so it could also be the reason why so many error were apparent when trying to run the scans. Let me know if this is advisable?

 

Also to answer the question bout firewalls, arnt' most firewalls already disabled in safe mode? I didn't see anything running in the tool bar. Anyways, ill be working on these next steps and report back to you soon.

 

I found quite a few in previous scans, unfortunately i didn't save the logs but most were found with malewarebytes and hitman Pro as well as antispyware. It is possible that the numerous infections and maleware from past scans on this machine may of caused some instability and corruption. Though i am wondering why the scans we ran, specifically FRST did not pick up any traces of anything previously.
 

My first comment was

 

Looks like you've run every tool imaginable, I can see so many listed.

FRST shows me

Malwarebytes
EMSISOFT ANTI-MALWARE
dds.txt
kss16.0.0.1344en_9702 (1).exe
Zemana.AntiMalware.Portable.exe
HitmanPro
rkill.exe
tdsskiller.exe
ESET

 

 

The Tweaking.com certainly found a whole alot of errors with system files and the like. But i am not sure i did this correctly, the instructions you gave me were a little bit different. 

 

 

STEP 2

 

I basically did a pre scan, then proceeded to do a full scan. After the scan was finished it shown the results of the files that are corrupted. I then selected "repair reparse points" but it opened up a different window with nothing selected. So i clicked on "scan for parse points" so then i had to scan for reparse points, after that was finished scanning. I clicked on "Select all" and then it proceeded to supposedly repair those files i think.

 

There was no "Done" though indicating that the process completed successfully. I had to close out of this window and return to the previous scan window.

 

The next step i did a pre scan and full scan again. I opened up the next tab "repair environment Variables" on the bottom of the screen which opened up a screen with different windows pertaining to different information.

 

#1. Environmental Variable Path

#2. Apply New paths

#3. Environmental PS module Path

#4. Environmental PS module Path: Apply new paths

#5. Environmental Variable: Pathext

#7 Environmental Variables: OS, Comspec, Windir and username

 

So which of these buttons do i have to use. I didn't notice any scan on this window at all.

 

 

I do have a log though that i saved, after running these scans, can you confirm rather or not i completed all the necessary tasks from Steps #2. I think i repair the reparse points but i don't think anything was fixed with the "repair Environment Variables"

 

 

 

┌────────────────────────────────────────────────────────────────────────────────┐
│ Tweaking.com - Windows Repair v3.9.27 - Pre-Scan
│ Computer: ASHLEY-PC (Windows 10 Home 10.0.14393.693 ) (64-bit)
│ [Started Scan - 3/26/2017 3:35:06 PM]
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ Scanning Windows Packages Files.
│ Started at (3/26/2017 3:35:06 PM)
│ 
│ These Files Are Possibly Corrupt (Bad Digital Signature): (Total: 31)
C:\WINDOWS\servicing\Packages\Microsoft-OneCore-TroubleShooting-Package~31bf3856ad364e35~amd64~~10.0.14393.0.cat
C:\WINDOWS\servicing\Packages\Microsoft-Windows-Branding-Education-Package~31bf3856ad364e35~amd64~~10.0.14393.0.cat
C:\WINDOWS\servicing\Packages\Package_759_for_KB3213986~31bf3856ad364e35~amd64~~10.0.1.1.cat
C:\WINDOWS\servicing\Packages\Microsoft-OneCore-Gaming-Preview-GamesEnumeration-Package~31bf3856ad364e35~amd64~en-US~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-OneCore-Gaming-Preview-GamesEnumeration-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-OneCore-Gaming-Preview-GamesEnumeration-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-OneCore-Graphics-DirectX-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-OneCore-Graphics-Required-windows-Package~31bf3856ad364e35~amd64~en-US~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-OneCore-Graphics-Required-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-OneCore-InputService-WOW64-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-OneCore-StorageManagement-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-OneCore-TroubleShooting-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-Branding-Education-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-Client-Features-Package-AutoMerged-admin~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-Client-Features-WOW64-Package-AutoMerged-sdktools~31bf3856ad364e35~amd64~en-US~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-Client-Features-WOW64-Package-AutoMerged-sdktools~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-Desktop-Shared-Dual-Drivers-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-LanguageFeatures-Speech-en-us-enduser-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-OneCoreUAP-WLAN-WOW64-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-OneDrive-Setup-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-Provisioning-Platform-Package~31bf3856ad364e35~amd64~en-US~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-RAS-Package~31bf3856ad364e35~amd64~en-US~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-RAS-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-SecureStartup-Subsystem-base-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-SecureStartup-Subsystem-onecore-Package~31bf3856ad364e35~amd64~en-US~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-Security-AADBrokerPlugin-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Microsoft-Windows-SenseClient-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Multimedia-MMECoreWdmAudio-WOW64-Package~31bf3856ad364e35~amd64~en-US~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Multimedia-MMECoreWdmAudio-WOW64-Package~31bf3856ad364e35~amd64~~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Multimedia-RestrictedCodecsCore-avcore-Package~31bf3856ad364e35~amd64~en-US~10.0.14393.0.mum
C:\WINDOWS\servicing\Packages\Package_759_for_KB3213986~31bf3856ad364e35~amd64~~10.0.1.1.mum
│ 
31 Combined Problems were found with the packages files, these files need to be replaced (These mainly only effect installing Windows Updates.)
│ The SFC (System File Checker) doesn't scan and replace some of these files, so you may need to replace them manually.
│ 
│ THESE FILES DO NOT KEEP THE REPAIRS FROM WORKING; YOU MAY STILL RUN THE REPAIRS IN THE PROGRAM.
│ 
│ Files Checked & Verified: 8,436
│ 
│ Done Scanning Windows Packages Files.(3/26/2017 3:38:31 PM)
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ Scanning Reparse Points.
│ Started at (3/26/2017 3:38:31 PM)
│ 
│ Reparse Points are OK!.
│ 
│ Files & Folders Searched: 301,725
│ Reparse Points Found: 91
│ 
│ Done Scanning Reparse Points.(3/26/2017 3:38:49 PM)
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ Checking Environment Variables.
│ Started at (3/26/2017 3:38:49 PM)
│ 
│ No problems were found with the Environment Variables.
│ 
│ Done Checking Environment Variables. (3/26/2017 3:38:49 PM)
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ [Finished Scan - 3/26/2017 3:38:49 PM]
│ 
│ [x] Scan Complete - Problems Found!
│ [x] 
│ [x] You can use the Repair Reparse Points or Repair Environment Variables tools at the bottom of this Window if needed.
│ [x] 
│ [x] While problems have been found, you can still run the repairs in the program.
│ [x] But for the best results it is recommended to fix the problems reported in this scan if possible.
└────────────────────────────────────────────────────────────────────────────────┘
 
 
STEP 3
 
I followed the steps exactly and performed a CHK disk check at first it indicated that the disk needed to be checked. So i rebooted the machine, but it loaded right back into the windows desktop again. The 2nd time i tried, it finally performed the actual CHECK but its been at 13% for the past hr and has not changed at all. This is currently whats happening right now.
 
UPDATE: So the CHK Disk scan actually finished. I am not sure if it finished sucesfully or not but when i came back into the room, the Computer was on the Desktop screen. 
 
In addition it looks upon loading the Desktop Screen, Trend Micro also found a malicious file and removed it. I will post the log here:
 
Date/Time,Threat,Source,Affected Files,Response,Detected By,From,To,Subject,Protocol
3/24/2017 3:37 PM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp000012aa\tmp00000001,Removed,Real Time Scan,,,,
3/24/2017 4:26 PM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp000038b1\tmp00000001,Access Denied,Real Time Scan,,,,
3/24/2017 6:27 PM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp000014ff\tmp00000001,Access Denied,Real Time Scan,,,,
3/24/2017 8:27 PM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp000070b6\tmp00000001,Access Denied,Real Time Scan,,,,
3/24/2017 9:27 PM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00001ea6\tmp00000001,Access Denied,Real Time Scan,,,,
3/24/2017 10:27 PM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00004c95\tmp00000001,Access Denied,Real Time Scan,,,,
3/24/2017 11:27 PM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00007a77\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 12:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00002863\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 1:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00005650\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 1:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00005650\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 2:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00000442\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 2:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00000442\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 3:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00003228\tmp00000001,Removed,Real Time Scan,,,,
3/25/2017 4:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00006017\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 5:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00000dfd\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 6:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00003bec\tmp00000001,Removed,Real Time Scan,,,,
3/25/2017 7:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp000069d8\tmp00000001,Removed,Real Time Scan,,,,
3/25/2017 8:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp000017c4\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 9:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp000045b3\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 9:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp000045b3\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 10:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00007399\tmp00000001,Access Denied,Real Time Scan,,,,
3/25/2017 10:27 AM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00007399\tmp00000001,Access Denied,Real Time Scan,,,,
3/26/2017 6:44 PM,TROJ_GEN.R01BC0EAK17,Virus,C:\WINDOWS\TEMP\tmp00003e60\tmp00000001,Removed,Real Time Scan,,,,
 
 
Moving onto to STEP 4
 
It indicates that "there is another servicing or repair function still running" so the File system checker utility did not successfully scan the system. It then prompts me to press any key and wait for a reboot in order for the scan to finish. So i did this but nothing happened.
 
 
 
STEP 5
 
I successfully created a restore point.
I opened the repair menu and clicked on OPEN repairs and then i selected start repairs. This process took a while. But it was at around 40/42 operations completed before it prompted me to restart my machine. Upon rebooting my computer. I noticed the network and internet has a yellow exclamation mark next to the icon in the tool bar indicating that the internet is not connected, but yet it is. So thats strange.
 
Windows Repair All in one, did not create a Logs folder either that i could see on the Desktop. How ever i did manually save a few logs and posted them.
 
I won't move onto any further steps until i know all of this has been resolved successfully.
Sorry, I did not receive a notice to your reply…

Trend micro went after temp files, C:\WINDOWS\TEMP\

AllInOne is pretty much the last tool we can use other then trying to do a last known good configuration

And even then, I'm afraid it's corrupt some way.

Since the last steps, have you rebooted and tried using the computer?

Can you be a little bit more specific. What do you mean by 

 

"Trend micro went after temp files, C:\WINDOWS\TEMP\"

 

Also can you confirm rather or not the required steps were successful and how do you know to what extent is the OS corrupted? I need a little more info so i can understand precisely whats going on here.

 

Based on the logs was there any files or any sort of procedures not executed efficiently with ALL in one?

 

To answer the question related to usage of the machine. Yes i have, the start menu is still having a few issues opening though but other then that i do for sure notice a quicker boot-up time. But in regards to rather or not its fully repaired? I have no idea. Some of the software used during this diagnoses had some issues as well so that may or may not be related to the corruption of the file system. Certain tools were not able to run efficiently either like SFC.

 

 

EDIT: I just ran another prescan with Tweeker and it picked up some 4000+ corrupted files I have not executed any other commands beyond the initial prescan.

 

EDIT2: The computer is running extremely slow. I am in normal start up mode and my keyboard can barely manage to keep up with my key strokes. I am running the ESET scanner currently but its chugging along at a slow rate.

post #10

In addition it looks upon loading the Desktop Screen, Trend Micro also found a malicious file and removed it. I will post the log here:

I read over the Trend Micro log, Trend micro went after temp files, C:\WINDOWS\TEMP\
it evidently is coded to remove temp files, that is what the statement was in response to.
 

Also can you confirm rather or not the required steps were successful and how do you know to what extent is the OS corrupted? I need a little more info so i can understand precisely whats going on here.

From what I can see the tool did what it could, very possible onboard security apps stops like CryptoPrevent, from completing everything it could had done.
Possible user profile is corrupt and by creating a new user profile you could experiment to see if all works better, but my thoughts are it wont make a difference.

 

But in regards to rather or not its fully repaired? I have no idea. Some of the software used during this diagnoses had some issues as well so that may or may not be related to the corruption of the file system. Certain tools were not able to run efficiently either like SFC.

This is up in the air as to why, thoughts are installer corruption.which we were not able to fix.

 

EDIT: I just ran another prescan with Tweeker and it picked up some 4000+ corrupted files I have not executed any other commands beyond the initial prescan.

we can try to do a manually
CHKDSK
https://www.tenforums.com/tutorials/40734-drive-error-checking-windows-10-a.html

Emisoft found no infected files, ESET is still running but this is a pretty deep rooted scanner. If ESET finds nothing, then the likehood of infections is highly unlikely.

we can try to do a manually
CHKDSK
https://www.tenforums.com/tutorials/40734-drive-error-checking-windows-10-a.html

 

 

 

Yeah i can try this. Won't this just fix internal HD errors though and not the actual operating system files? What bout what you also said before bout a repair recovery console. I am not to familiar with how this works on a windows 10 based platform. But i have used something similar on windows 7 where windows would repair all files and re-install them, keeping all your data files in tact. Would you recommend something like this.

 

 

Also if we have exhausted all possible options at this point, maybe there is another user on here that can provide some input and look into an alternative method that they might know, in regards to another way, with out having to re partition the drive. That would be my absolute last resort if i had to do that. This seems more likely that its starting to fall under the category of the "windows Team".

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI