This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows 8 browsers freezing. Other devices are OK. [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Both Chrome and Firefox are not functioning. The netsh reset commands don't fix this. 

 

aswMBR Log:

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-04-20 08:35:55
—————————–
08:35:55.255    OS Version: Windows x64 6.2.9200 
08:35:55.255    Number of processors: 8 586 0x3C03
08:35:55.255    ComputerName: LAPTOP-TL-1-8  UserName: 
08:35:56.287    Initialize success
08:35:56.412    AVAST engine defs: 17041902
08:35:58.943    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1
08:35:58.943    Disk 0 Vendor: ST500LM0 DEM9 Size: 476940MB BusType: 8
08:35:58.943    Disk 0 MBR read successfully
08:35:58.943    Disk 0 MBR scan
08:35:58.943    Disk 0 Windows 7 default MBR code
08:35:58.943    Disk 0 Partition 1 80 (A) 07    HPFS/NTFS NTFS          350 MB offset 2048
08:35:58.943    Disk 0 Partition 2 00     07    HPFS/NTFS            476588 MB offset 718848
08:35:58.943    Disk 0 scanning C:\Windows\system32\drivers
08:35:58.943    Service scanning
08:36:07.212    Modules scanning
08:36:07.212    Disk 0 trace - called modules:
08:36:07.212    ntoskrnl.exe CLASSPNP.SYS disk.sys stdcfltn.sys iaStorV.sys hal.dll 
08:36:07.212    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80093d8060]
08:36:07.712    3 CLASSPNP.SYS[fffff88001486e0a] -> nt!IofCallDriver -> [0xfffffa80093d9770]
08:36:07.712    5 stdcfltn.sys[fffff880026c3d12] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa80072a1050]
08:36:08.040    AVAST engine scan C:\Windows
08:36:08.040    AVAST engine scan C:\Windows\system32
08:36:08.056    AVAST engine scan C:\Windows\system32\drivers
08:36:08.056    AVAST engine scan C:\Users\xxxxx
08:36:08.056    AVAST engine scan C:\ProgramData
08:36:08.056    Scan finished successfully
08:36:26.983    Disk 0 MBR has been saved successfully to "C:\Users\xxxxx\Documents\MBR.dat"
08:36:26.998    The log file has been saved successfully to "C:\Users\xxxxx\Documents\aswMBR.txt"
 
Frst64 Log:
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19-04-2017
Ran by [removed] (administrator) on LAPTOP-TL-1-8 (20-04-2017 08:36:52)
Running from C:\Users\[removed]\Documents
[removed]
Platform: Windows 8 Pro (X64) Language: English (United States)
Internet Explorer Version 10 (Default browser: Chrome)
Boot Mode: Safe Mode (with Networking)
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2463552 2014-10-04] (NVIDIA Corporation)
HKLM\…\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\…\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM\…\Run: [EKIJ5000StatusMonitor] => C:\Windows\system32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe [2023936 2009-08-03] (Eastman Kodak Company)
HKLM\…\Run: [CsrHCRPServer] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrHCRPServer.exe [1134288 2012-03-22] (Cambridge Silicon Radio Limited)
HKLM\…\Run: [CsrAudioguiCtrl] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrAudioguiCtrl.exe [511696 2012-03-22] (Cambridge Silicon Radio Limited)
HKLM\…\Run: [CsrSyncMLServer] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrSyncMLServer.exe [244944 2012-03-22] ()
HKLM\…\Run: [vksts] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\vksts.exe [25792 2012-03-22] (Cambridge Silicon Radio Limited)
HKLM\…\Run: [HarmonyUserStartup] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\HarmonyUserStartup.exe [39128 2012-03-22] (Cambridge Silicon Radio Limited)
HKLM\…\Run: [CSRHarmonySkypePlugin] => C:\Program Files (x86)\CSR\CSR Harmony Wireless Software Stack\CSRHarmonySkypePlugin.exe [146656 2012-03-22] (Cambridge Silicon Radio Limited)
HKLM\…\Run: [TrayApplication] => C:\Program Files\CSR\CSR Harmony Wireless Software Stack\TrayApplication.exe [529616 2012-03-22] (Cambridge Silicon Radio Limited)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-11-01] (Apple Inc.)
HKLM\…\Run: [Eraser] => C:\Program Files\Eraser\Eraser.exe [1074088 2015-09-03] (The Eraser Project)
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-04-06] (AVAST Software)
HKLM-x32\…\Run: [AlienwareOn-ScreenDisplay] => C:\Program Files (x86)\Alienware On-Screen Display\AlienwareOn-ScreenDisplay.exe [1636208 2011-12-01] ()
HKLM-x32\…\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\…\Run: [KiesTrayAgent] => C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe [311616 2015-02-24] (Samsung Electronics Co., Ltd.)
HKLM-x32\…\Run: [Conime] => %windir%\system32\conime.exe
HKLM-x32\…\Run: [EKIJ5000StatusMonitor] => C:\Windows\System32\spool\DRIVERS\x64\3\EKIJ5000MUI.exe [2023936 2009-08-03] (Eastman Kodak Company)
HKLM-x32\…\Run: [WD Quick View] => C:\Program Files (x86)\Western Digital\WD Quick View\WDDMStatus.exe [5564784 2015-02-12] (Western Digital Technologies, Inc.)
HKLM-x32\…\Run: [DriveUtilitiesHelper] => C:\Program Files (x86)\Western Digital\WD Utilities\WDDriveUtilitiesHelper.exe [1890664 2015-07-31] (Western Digital Technologies, Inc.)
HKLM-x32\…\Run: [WD Drive Unlocker] => C:\Program Files (x86)\Western Digital\WD Security\WDDriveAutoUnlock.exe [1761120 2015-07-31] (Western Digital Technologies, Inc.)
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [405504 2012-07-26] (Microsoft Corporation)
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Run: [VideoDownloaderUltimate] => C:\ProgramData\VideoDownloaderUltimateWinApp\VideoDownloaderUltimate.exe /repair
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Run: [Amazon Music] => C:\Users\xxxxx\AppData\Local\Amazon Music\Amazon Music Helper.exe [5907944 2016-04-15] ()
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Run: [Spotify Web Helper] => C:\Users\xxxxx\AppData\Roaming\Spotify\SpotifyWebHelper.exe [1444976 2016-12-25] (Spotify Ltd)
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Run: [Spotify] => C:\Users\xxxxx\AppData\Roaming\Spotify\Spotify.exe [7153264 2016-12-25] (Spotify Ltd)
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9292504 2016-12-21] (Piriform Ltd)
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27545048 2017-03-14] (Skype Technologies S.A.)
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Policies\Explorer: [NoLowDiskSpaceChecks] False
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\MountPoints2: {1d134e7b-e9cc-11e5-bed6-801934717d6a} - "G:\WD Drive Unlock.exe" autoplay=true
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\MountPoints2: {50c8a095-6f77-11e4-be77-801934717d6a} - "E:\HTC_Sync_Manager_PC.exe" 
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\MountPoints2: {b5040bcc-519c-11e6-bf01-801934717d6a} - "E:\KODAK_Camera_Setup_App.exe" 
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\MountPoints2: {c9212c8c-ca8b-11e6-bf20-801934717d6a} - "E:\Lenovo_Suite.exe" 
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\MountPoints2: {c9212ced-ca8b-11e6-bf20-801934717d6a} - "E:\Lenovo_Suite.exe" 
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [174856 2014-10-16] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [156840 2014-10-16] (NVIDIA Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-04-06] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-04-06] (AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FAH.lnk [2015-05-21]
ShortcutTarget: FAH.lnk -> C:\Program Files\WinZip\FAH\FAHConsole.exe (Nico Mak Computing)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ImageBrowser EX Agent.lnk [2015-05-20]
ShortcutTarget: ImageBrowser EX Agent.lnk -> C:\Program Files (x86)\Canon\ImageBrowser EX\MFManager.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2014-10-31]
ShortcutTarget: Killer Network Manager.lnk -> C:\Windows\Installer\{987ACE92-A585-45CF-AE43-0B038780B497}\NetworkManager.exe_130C27D738F34C89BDDF21BCFD74B56D.exe (Flexera Software LLC)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\WinZip Preloader.lnk [2015-05-21]
ShortcutTarget: WinZip Preloader.lnk -> C:\Program Files\WinZip\WzPreloader.exe (WinZip Computing, S.L.)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: 91.146.108.71 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{467A6493-1F7C-4D98-8439-7D18A60BC136}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{5CCDE653-E20A-47AF-AFDA-000261DC0389}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{FCADB591-D985-4DF6-BD5A-7F38476CEC4E}: [NameServer] 217.171.135.1
 
Internet Explorer:
==================
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/en-gb/?ocid=iehp
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-06] (AVAST Software)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-06] (AVAST Software)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-01-02] (Skype Technologies)
 
FireFox:
========
FF DefaultProfile: d8v0eyh4.default
FF ProfilePath: C:\Users\xxxxx\AppData\Roaming\ParseHub\parsehub\Profiles\d8v0eyh4.default [2017-02-08]
FF Extension: (Firefox Hotfix) - C:\Users\xxxxx\AppData\Roaming\ParseHub\parsehub\Profiles\d8v0eyh4.default\Extensions\[removed] [2017-01-06]
FF Extension: (ParseHub) - C:\Users\xxxxx\AppData\Roaming\ParseHub\parsehub\Profiles\d8v0eyh4.default\Extensions\[removed] [2017-02-08] [not signed]
FF ProfilePath: C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\wt4gbe3r.default [2017-04-20]
FF Homepage: Mozilla\Firefox\Profiles\wt4gbe3r.default -> hxxp://www.google.co.uk/
FF Extension: (Firebug) - C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\wt4gbe3r.default\Extensions\[removed] [2017-03-01]
FF Extension: (Fire Media Player) - C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\wt4gbe3r.default\Extensions\[removed] [2016-05-01]
FF Extension: (Quick Media Codec) - C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\wt4gbe3r.default\Extensions\[removed] [2016-09-21]
FF Extension: (FlashGot) - C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\wt4gbe3r.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi [2016-12-09]
FF Extension: (Flash and Video Download) - C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\wt4gbe3r.default\Extensions\{bee6eb20-01e0-ebd1-da83-080329fb9a3a} [2017-02-28]
FF Extension: (Greasemonkey) - C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\wt4gbe3r.default\Extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}.xpi [2017-02-28]
FF Extension: (Disable TLS Certificate Transparency) - C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\wt4gbe3r.default\features\{056dbeb7-44e6-4ef8-ad40-4e0f8f755acb}\[removed] [2017-04-18]
FF Extension: (Disable Prefetch) - C:\Users\xxxxx\AppData\Roaming\Mozilla\Firefox\Profiles\wt4gbe3r.default\features\{056dbeb7-44e6-4ef8-ad40-4e0f8f755acb}\[removed] [2017-04-18]
FF Extension: (Site Deployment Checker) - C:\Program Files (x86)\Mozilla Firefox\browser\features\[removed] [2017-03-31] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF48 [2017-04-06]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF48
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_25_0_0_148.dll [2017-04-12] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_25_0_0_148.dll [2017-04-12] ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-03-12] (Intel Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2014-10-16] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2014-10-16] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-19] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-222209725-2823862911-2758884793-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\xxxxx\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2014-12-05] (Unity Technologies ApS)
 
Chrome: 
=======
CHR StartupUrls: Default -> "hxxp://www.google.co.uk/",""
CHR Profile: C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default [2017-04-20]
CHR Extension: (Kindle Cloud Reader) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aicjkkmjijnlncpkailhjcdfkechjbpl [2016-05-13]
CHR Extension: (Google Docs) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-05-13]
CHR Extension: (Google Drive) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-05-13]
CHR Extension: (Rapport) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjllphbppobebmjpjcijfbakobcheof [2016-05-13]
CHR Extension: (YouTube) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-05-13]
CHR Extension: (PDF Editor for Docs:Edit, Fill, Sign, Print) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjboohgkgchdnfnjiaggdbkdmpieoagi [2016-05-16]
CHR Extension: (Google Sheets) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-05-13]
CHR Extension: (Google Docs Offline) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-01-19]
CHR Extension: (Avast Online Security) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-04-12]
CHR Extension: (Child Safe Web Search) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcgcbbnhbaladmnenbijebfdnoaeodld [2016-05-13]
CHR Extension: (Quick Earth) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\khodocggeplgfhppgagfdpbjkniadmdh [2016-05-13]
CHR Extension: (Google Maps) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh [2016-05-13]
CHR Extension: (Video Converter) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcjjnhgakghmggnimjkldjmmpabhnhne [2016-12-23]
CHR Extension: (Google Play Books) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb [2016-05-13]
CHR Extension: (RSS Subscription Extension (by Google)) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nlbjncdgjeocebhnmkbbbdekmmmcbfjd [2016-05-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-11]
CHR Extension: (Docs PDF/PowerPoint Viewer (by Google)) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nnbmlagghjjcbdhgmkedmbmedengocbn [2016-05-13]
CHR Extension: (Gmail) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-05-13]
CHR Extension: (Chrome Media Router) - C:\Users\xxxxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-14]
CHR HKU\S-1-5-21-222209725-2823862911-2758884793-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-09-22] (Apple Inc.)
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7398336 2017-04-06] (AVAST Software s.r.o.)
S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [261712 2017-04-06] (AVAST Software)
S2 BtSwitcherService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\BtSwitcherService.exe [64216 2012-03-22] (Cambridge Silicon Radio Limited)
S2 CSRBtAudioService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtAudioService.exe [465624 2012-03-22] (Cambridge Silicon Radio Limited)
S2 CsrBtOBEXService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtOBEXService.exe [1041616 2012-03-22] (Cambridge Silicon Radio Limited)
S2 CsrBtService; C:\Program Files\CSR\CSR Harmony Wireless Software Stack\CsrBtService.exe [825032 2012-03-22] (Cambridge Silicon Radio Limited)
S2 EaseUS Agent; C:\Program Files (x86)\EaseUS\Todo Backup\bin\Agent.exe [39616 2016-12-06] (CHENGDU YIWO Tech Development Co., Ltd)
S2 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1149760 2014-10-04] (NVIDIA Corporation)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [73728 2004-10-22] (Macrovision Corporation) [File not signed]
S2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [329104 2014-10-03] (Intel Corporation)
S2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed]
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation)
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-03-12] (Intel Corporation)
S2 Motorola Device Manager; C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [137528 2014-04-08] (Motorola Mobility LLC)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [284912 2014-01-08] ()
S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1796928 2014-10-04] (NVIDIA Corporation)
S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [19440960 2014-10-04] (NVIDIA Corporation)
S2 PassThru Service; C:\Program Files (x86)\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2013-10-17] () [File not signed]
S2 PST Service; C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [65657 2011-09-02] (Motorola) [File not signed]
S2 Qualcomm Atheros Killer Service V2; C:\Program Files\Qualcomm Atheros\Network Manager\KillerService.exe [340480 2013-10-08] (Qualcomm Atheros) [File not signed]
S2 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2401264 2017-03-01] (IBM Corp.)
S2 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\25_escape\conn\ss_conn_service.exe [743688 2014-10-13] (DEVGURU Co., LTD.)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
S2 WDDriveService; C:\Program Files (x86)\Western Digital\WD Drive Manager\WDDriveService.exe [307064 2015-07-31] (Western Digital Technologies, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16056 2015-07-06] (Microsoft Corporation)
S2 WsAppService; C:\Program Files (x86)\Wondershare\WAF\2.3.1.1\WsAppService.exe [437392 2016-10-10] (Wondershare)
S2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3674864 2014-01-08] (Intel® Corporation)
S3 WsDrvInst; "C:\Program Files (x86)\Wondershare\MobileGo\DriverInstall.exe" [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [307736 2017-04-06] (AVAST Software s.r.o.)
S0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-04-06] (AVAST Software s.r.o.)
S0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334088 2017-04-06] (AVAST Software s.r.o.)
S0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-04-06] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-04-06] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [127112 2017-04-06] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [101152 2017-04-06] (AVAST Software)
S0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-04-06] (AVAST Software)
S1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1005048 2017-04-06] (AVAST Software)
S1 aswSP; C:\Windows\system32\drivers\aswSP.sys [556784 2017-04-06] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [164064 2017-04-06] (AVAST Software)
R1 BfLwf; C:\Windows\system32\DRIVERS\bwcW8x64.sys [75056 2013-02-13] (Qualcomm Atheros, Inc.)
S3 csravrcp; C:\Windows\System32\drivers\csravrcp.sys [26304 2012-03-22] (Cambridge Silicon Radio Limited)
S3 CsrBthAudioHF; C:\Windows\system32\DRIVERS\CsrBthAudioHF.sys [39120 2012-03-22] (Cambridge Silicon Radio Limited)
S3 CsrBtPort; C:\Windows\system32\DRIVERS\CsrBtPort.sys [2784968 2012-03-22] (Cambridge Silicon Radio Limited)
S3 csrhfgcc; C:\Windows\System32\drivers\csrhfgcc.sys [38080 2012-03-22] (Cambridge Silicon Radio Limited)
S3 csrpan; C:\Windows\system32\DRIVERS\csrpan.sys [39616 2012-03-22] (Cambridge Silicon Radio Limited)
S3 csrserial; C:\Windows\system32\DRIVERS\csrserial.sys [61128 2012-03-22] (Cambridge Silicon Radio Limited)
R3 csrusb; C:\Windows\System32\Drivers\csrusb.sys [47296 2012-03-22] (Cambridge Silicon Radio Limited)
R3 csrusbfilter; C:\Windows\System32\Drivers\csrusbfilter.sys [23752 2012-03-22] (Cambridge Silicon Radio Limited)
S3 csr_bthav; C:\Windows\system32\drivers\csrbthav.sys [99520 2012-03-22] (Cambridge Silicon Radio Limited)
R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-24] (OSR Open Systems Resources, Inc.)
S3 dg_ssudbus; C:\Windows\system32\DRIVERS\ssudbus.sys [131712 2016-09-05] (Samsung Electronics Co., Ltd.)
R0 EUBKMON; C:\Windows\System32\drivers\EUBKMON.sys [53240 2016-12-06] ()
R3 Ke2200; C:\Windows\system32\DRIVERS\e22w8x64.sys [163536 2013-03-20] (Qualcomm Atheros, Inc.)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [192216 2016-07-03] (Malwarebytes)
R3 NETwNe64; C:\Windows\system32\DRIVERS\Netwew02.sys [3670496 2014-01-28] (Intel Corporation)
S1 nvkflt; C:\Windows\system32\DRIVERS\nvkflt.sys [298184 2014-10-16] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20288 2014-10-04] (NVIDIA Corporation)
S3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [38048 2014-09-04] (NVIDIA Corporation)
S1 RapportAegle64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportAegle64.sys [382432 2017-03-01] (IBM Corp.)
S1 RapportCerberus_1804047; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1804047.sys [1264776 2017-02-02] (IBM Corp.)
S1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [582208 2017-03-01] (IBM Corp.)
S3 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [506016 2017-03-01] (IBM Corp.)
S3 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [605024 2017-03-01] (IBM Corp.)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [32496 2013-04-08] (Synaptics Incorporated)
S3 ssudmdm; C:\Windows\system32\DRIVERS\ssudmdm.sys [165504 2016-09-05] (Samsung Electronics Co., Ltd.)
R3 ST_ACCEL; C:\Windows\system32\DRIVERS\ST_Accel.sys [91360 2013-04-11] (STMicroelectronics)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44560 2015-07-06] (Microsoft Corporation)
S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [281944 2015-07-06] (Microsoft Corporation)
S3 wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [150136 2015-08-18] (MBB)
S3 wmbclass; C:\Windows\system32\DRIVERS\wmbclass.sys [230912 2013-04-09] (Microsoft Corporation)
S3 aswVmm; \??\C:\Users\DUNCAN~1\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
S3 MREMP50; \??\C:\PROGRA~2\COMMON~1\Motive\MREMP50.SYS [X]
S3 MREMP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MREMP50a64.SYS [X]
S3 MREMPR5; \??\C:\PROGRA~2\COMMON~1\Motive\MREMPR5.SYS [X]
S3 MRENDIS5; \??\C:\PROGRA~2\COMMON~1\Motive\MRENDIS5.SYS [X]
S3 MRESP50; \??\C:\PROGRA~2\COMMON~1\Motive\MRESP50.SYS [X]
S3 MRESP50a64; \??\C:\PROGRA~1\COMMON~1\Motive\MRESP50a64.SYS [X]
U3 aswMBR; \??\C:\Users\DUNCAN~1\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-04-20 08:36 - 2017-04-20 08:36 - 00029718 _____ C:\Users\xxxxx\Documents\FRST.txt
2017-04-20 08:36 - 2017-04-20 08:36 - 00001934 _____ C:\Users\xxxxx\Documents\aswMBR.txt
2017-04-20 08:22 - 2017-04-20 08:36 - 00000000 ___DC C:\FRST
2017-04-20 08:20 - 2017-04-20 08:21 - 02424832 _____ (Farbar) C:\Users\xxxxx\Documents\FRST64.exe
2017-04-20 08:18 - 2017-04-20 08:36 - 00000512 _____ C:\Users\xxxxx\Documents\MBR.dat
2017-04-20 08:18 - 2017-04-20 08:18 - 05198336 _____ (AVAST Software) C:\Users\xxxxx\Documents\aswMBR.exe
2017-04-20 00:34 - 2017-04-20 00:34 - 00003832 ____N C:\bootsqm.dat
2017-04-17 23:39 - 2017-04-17 23:39 - 00268978 _____ C:\Users\xxxxx\Documents\waste disposal.pdf
2017-04-15 19:41 - 2017-04-15 19:41 - 00000000 ____D C:\Users\xxxxx\Downloads\Blue - Joni Mitchell
2017-04-12 22:38 - 2017-04-12 22:41 - 02525028 _____ C:\Users\xxxxx\Documents\Sinead OConnor - Her Mantle So Green.mp3.crdownload
2017-04-11 14:26 - 2017-04-11 14:26 - 00809472 ____H C:\Users\xxxxx\Documents\~WRL0001.tmp
2017-04-11 12:19 - 2017-04-11 12:19 - 00002483 _____ C:\Users\xxxxx\Documents\tune2211setting155771.mid
2017-04-11 11:54 - 2017-04-11 11:54 - 00000000 ____H C:\Users\xxxxx\Documents\Default.rdp
2017-04-10 15:32 - 2017-04-10 15:32 - 00000000 ____D C:\Users\xxxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MP3Gain
2017-04-10 15:32 - 2017-04-10 15:32 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MP3Gain
2017-04-10 15:32 - 2017-04-10 15:32 - 00000000 ____D C:\Program Files (x86)\MP3Gain
2017-04-10 15:26 - 2017-04-10 15:27 - 00667344 _____ C:\Users\xxxxx\Documents\mp3gain-win-1_2_5.exe
2017-04-09 15:52 - 2017-04-09 15:52 - 00000612 _____ C:\Users\xxxxx\Documents\tune14764setting272571.mid
2017-04-07 18:03 - 2017-04-07 18:03 - 03695377 _____ C:\Users\xxxxx\Documents\NNow33.pdf
2017-04-06 07:41 - 2017-04-06 07:41 - 00399944 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-04-05 17:49 - 2017-04-05 17:49 - 01064615 _____ C:\Users\xxxxx\Documents\170117 Copy of Direction half 8 zzzzz Ard W378402_4-86-42053_Direction-Decrofting_dated-25-03-2014.pdf
2017-04-04 15:45 - 2017-04-04 15:45 - 00805260 _____ C:\Users\xxxxx\Documents\00195932-8D_Upper_Breakage_2500-1C976D4B.zip
2017-04-04 15:40 - 2017-04-04 15:45 - 00000000 ____D C:\Users\xxxxx\Documents\Maps
2017-04-04 15:39 - 2017-04-04 15:39 - 00995083 _____ C:\Users\xxxxx\Documents\00195908-8D_yyyyy_2500-DEA69B1F.zip
2017-04-04 15:39 - 2017-04-04 15:39 - 00354594 _____ C:\Users\xxxxx\Documents\00195909-8D_yyyyy_1000-4BFD933D.zip
2017-04-04 13:58 - 2017-04-04 14:13 - 189106525 _____ C:\Users\xxxxx\Documents\Haydn - The Seasons (Die Jahreszeiten).mp4
2017-03-28 23:29 - 2017-03-29 18:42 - 00008446 _____ C:\Users\xxxxx\Documents\BookingsReport_280317.csv
2017-03-28 20:06 - 2017-03-28 20:06 - 00001348 _____ C:\Users\xxxxx\Documents\tune677setting6771.mid
2017-03-27 17:04 - 2017-03-27 17:04 - 00025693 _____ C:\Users\xxxxx\Desktop\Retro.xspf
2017-03-27 06:25 - 2017-03-27 06:25 - 00304592 _____ C:\Windows\Minidump\032717-30796-01.dmp
2017-03-26 21:22 - 2017-03-26 21:22 - 00000000 ___DC C:\Barbie Hero
2017-03-25 22:35 - 2017-03-25 22:35 - 00549991 _____ C:\Users\xxxxx\Documents\Electromax_user-manual.pdf
2017-03-24 18:49 - 2017-03-24 18:49 - 00497945 _____ C:\Users\xxxxx\Documents\Redring_Installation_Guide.pdf
2017-03-24 12:07 - 2017-03-24 12:08 - 00000000 ____D C:\Windows\LastGood.Tmp
2017-03-23 15:55 - 2017-03-23 15:55 - 01461520 _____ C:\Users\xxxxx\Documents\Beginners Edited.pdf
2017-03-21 18:13 - 2017-03-21 18:13 - 00002692 _____ C:\Users\xxxxx\Documents\tune3154setting162581.mid
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-04-20 08:34 - 2016-03-19 15:52 - 00000000 ____D C:\Temp
2017-04-20 08:08 - 2015-05-21 16:33 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-222209725-2823862911-2758884793-1001
2017-04-20 08:04 - 2015-08-27 17:56 - 00000000 ____D C:\Users\xxxxx\AppData\Roaming\Skype
2017-04-20 08:03 - 2015-05-11 21:01 - 00000443 _____ C:\Windows\system32\Drivers\etc\hosts.ics
2017-04-20 08:02 - 2015-06-24 11:51 - 00000000 ____D C:\ProgramData\Kodak
2017-04-20 08:02 - 2014-10-31 20:51 - 00000000 ____D C:\ProgramData\NVIDIA
2017-04-20 08:02 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-20 07:40 - 2016-11-18 17:24 - 00000000 ____D C:\Users\xxxxx\AppData\LocalLow\Mozilla
2017-04-20 07:34 - 2014-11-02 14:55 - 00000000 ____D C:\Users\xxxxx\AppData\Local\Adobe
2017-04-19 17:11 - 2014-11-02 14:57 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-04-19 16:44 - 2014-11-06 01:06 - 00000000 ____D C:\Users\xxxxx\AppData\Roaming\vlc
2017-04-19 15:39 - 2014-12-29 09:29 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-04-19 15:37 - 2017-01-31 21:28 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2017-04-19 15:37 - 2017-01-31 21:28 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2017-04-19 14:00 - 2012-07-26 06:26 - 00524288 ___SH C:\Windows\system32\config\BBI
2017-04-16 21:56 - 2012-07-26 06:37 - 00000000 ____D C:\Windows\Inf
2017-04-15 20:09 - 2012-07-26 08:28 - 00849706 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-15 14:37 - 2016-04-08 19:59 - 00000680 _____ C:\Users\xxxxx\Desktop\plot.csv
2017-04-13 19:09 - 2015-06-09 18:42 - 00000000 ____D C:\Users\xxxxx\AppData\Local\CrashDumps
2017-04-12 10:39 - 2017-01-25 00:22 - 00004456 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-04-12 10:39 - 2014-11-02 15:15 - 00004288 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2017-04-12 10:39 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-04-12 10:39 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\Macromed
2017-04-12 00:01 - 2014-12-23 01:26 - 00000000 ____D C:\Users\xxxxx\AppData\Roaming\Audacity
2017-04-11 19:41 - 2017-03-12 00:44 - 00004172 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-04-06 07:54 - 2017-01-31 21:32 - 00002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-04-06 07:54 - 2017-01-31 21:32 - 00002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-04-06 07:41 - 2017-03-12 00:44 - 00334088 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-04-06 07:41 - 2017-03-12 00:44 - 00307736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-04-06 07:41 - 2017-03-12 00:44 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-04-06 07:41 - 2017-03-12 00:44 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-04-06 07:41 - 2017-01-24 00:00 - 01005048 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-04-06 07:41 - 2017-01-24 00:00 - 00556784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-04-06 07:41 - 2017-01-24 00:00 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-04-06 07:41 - 2017-01-24 00:00 - 00164064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-04-06 07:41 - 2017-01-24 00:00 - 00127112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-04-06 07:41 - 2017-01-24 00:00 - 00101152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-04-06 07:41 - 2017-01-24 00:00 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-04-06 07:41 - 2017-01-24 00:00 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-04-05 16:58 - 2014-12-06 18:16 - 00001456 _____ C:\Users\xxxxx\AppData\Local\Adobe Save for Web 13.0 Prefs
2017-04-04 15:47 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\FxsTmp
2017-03-31 08:23 - 2016-09-23 19:49 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-03-31 08:23 - 2014-10-31 21:44 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-03-27 06:25 - 2017-02-07 09:03 - 796607120 _____ C:\Windows\MEMORY.DMP
2017-03-27 06:25 - 2014-12-07 19:19 - 00000000 ____D C:\Windows\Minidump
2017-03-26 21:56 - 2015-03-29 22:41 - 00000000 ____D C:\Users\xxxxx\AppData\Roaming\HandBrake
2017-03-26 21:21 - 2015-08-02 18:19 - 00000000 ____D C:\Users\xxxxx\AppData\Roaming\dvdcss
 
==================== Files in the root of some directories =======
 
2015-08-02 20:02 - 2015-08-02 20:02 - 0000132 _____ () C:\Users\xxxxx\AppData\Roaming\Adobe PNG Format CS6 Prefs
2014-12-06 18:16 - 2017-04-05 16:58 - 0001456 _____ () C:\Users\xxxxx\AppData\Local\Adobe Save for Web 13.0 Prefs
2014-10-30 14:41 - 2016-08-27 21:18 - 0000000 _____ () C:\Users\xxxxx\AppData\Local\Driver_LOM_8161Present.flag
2015-06-24 11:50 - 2015-06-24 11:58 - 0082676 _____ () C:\Users\xxxxx\AppData\Local\installer.log
2015-06-24 11:58 - 2015-06-24 11:58 - 0000183 _____ () C:\Users\xxxxx\AppData\Local\LaunchHomeCenter.log
2014-11-06 21:28 - 2015-06-14 17:11 - 0000600 _____ () C:\Users\xxxxx\AppData\Local\PUTTY.RND
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-04-19 11:31
 
==================== End of FRST.txt ============================
 
Addition Log:
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19-04-2017
Ran by [removed] (20-04-2017 08:37:09)
Running from C:\Users\[removed]\Documents
Windows 8 Pro (X64) (2014-10-28 20:18:25)
Boot Mode: Safe Mode (with Networking)
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-222209725-2823862911-2758884793-500 - Administrator - Disabled)
xxxxx (S-1-5-21-222209725-2823862911-2758884793-1001 - Administrator - Enabled) => C:\Users\xxxxx
Guest (S-1-5-21-222209725-2823862911-2758884793-501 - Limited - Disabled)
hssadmin (S-1-5-21-222209725-2823862911-2758884793-1002 - Administrator - Enabled) => C:\Users\hssadmin
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.38 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0938-000001000000}) (Version: 9.38.00.0 - Igor Pavlov)
7-Zip 9.38 beta (HKLM-x32\…\7-Zip) (Version:  - )
AbcNavigator 2.0 (HKLM-x32\…\AbcNavigator 2_is1) (Version:  - Groink, Inc.)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
Adobe Flash Player 25 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated)
Adobe Flash Player 25 PPAPI (HKLM-x32\…\Adobe Flash Player PPAPI) (Version: 25.0.0.148 - Adobe Systems Incorporated)
Adobe Help Manager (HKLM-x32\…\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 4.0.244 - Adobe Systems Incorporated)
Adobe Photoshop CS6 (HKLM-x32\…\{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}) (Version: 13.0 - Adobe Systems Incorporated)
Adobe Premiere Pro CS6 (HKLM-x32\…\{7176B973-6011-43C1-AEBC-2D73FE7C6982}) (Version: 6.0 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.20) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.20 - Adobe Systems Incorporated)
aiofw (x32 Version: 4.2.6.8 - Eastman Kodak Company) Hidden
aioprnt (Version: 4.2.7.4 - Eastman Kodak Company) Hidden
aioscnnr (x32 Version: 4.2.6.0 - Your Company Name) Hidden
Alienware On-Screen Display (HKLM-x32\…\InstallShield_{0D69462F-99CC-4F8D-942E-666E21CE59F8}) (Version: 0.32.0.2C - )
Alienware On-Screen Display (x32 Version: 0.32.0.2C - ) Hidden
Amazon Kindle (HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Amazon Kindle) (Version: 1.15.0.43061 - Amazon)
Amazon Music (HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Amazon Amazon Music) (Version: 4.3.0.1330 - Amazon Services LLC)
Apple Application Support (32-bit) (HKLM-x32\…\{F2871C89-C8A5-42EE-8D45-0F02506385A6}) (Version: 5.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{9BC93467-75D1-4AA4-BD58-D9C51D88DFAB}) (Version: 5.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{55BB2110-FB43-49B3-93F4-945A0CFB0A6C}) (Version: 10.0.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Audacity 2.0.6 (HKLM-x32\…\Audacity_is1) (Version: 2.0.6 - Audacity Team)
AudibleManager (HKLM-x32\…\AudibleManager) (Version: 18414980.4759644.48.2010396024 - Audible, Inc.)
Aura Software Manager 1.0.3 (HKLM-x32\…\Aura Software Manager_is1) (Version:  - aura4you.com)
Aura Video Converter 1.6.2 (HKLM-x32\…\Aura Video Converter_is1) (Version:  - Aura4You.com)
Avast Free Antivirus (HKLM-x32\…\Avast Antivirus) (Version: 17.3.2291 - AVAST Software)
BBC iPlayer Downloads (HKLM-x32\…\{148784F3-3B6E-4DFA-B7A1-3400B277DAF3}) (Version: 1.14.2 - BBC)
bl (x32 Version: 1.0.0 - Your Company Name) Hidden
Blackboard Collaborate Launcher (HKLM-x32\…\{C4F79F84-C509-48B0-81B8-3C2FA2182406}) (Version: 1.6.0.0 - Blackboard)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon Utilities ImageBrowser EX (HKLM-x32\…\ImageBrowser EX) (Version: 1.4.0.5 - Canon Inc.)
CCleaner (HKLM\…\CCleaner) (Version: 5.26 - Piriform)
center (x32 Version: 4.2.6.8 - Eastman Kodak Company) Hidden
CopyTrans Control Center Uninstall Only (HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\CopyTrans Suite) (Version: 4.013 - WindSolutions)
CSR Harmony Wireless Software Stack (HKLM\…\{17DEA095-8EE1-49A2-AC5A-9663DB098FA9}) (Version: 2.1.63.0 - Cambridge Silicon Radio Limited.)
Dell SupportAssist (HKLM\…\PC-Doctor for Windows) (Version: 1.3.6817.133 - Dell)
Dell System Detect (HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\58d94f3ce2c27db0) (Version: 7.6.0.17 - Dell)
DVD Decrypter (Remove Only) (HKLM-x32\…\DVD Decrypter) (Version:  - )
EaseUS Data Recovery Wizard (HKLM\…\EaseUS Data Recovery Wizard_is1) (Version:  - EaseUS)
EaseUS Todo Backup Free 10.0 (HKLM-x32\…\EaseUS Todo Backup_is1) (Version: 10.0 - CHENGDU YIWO Tech Development Co., Ltd)
EMSC (x32 Version: 0.0.0.22C - Compal Electronics, Inc.) Hidden
Eraser 6.2.0.2970 (HKLM\…\{58F37E51-2A83-49F3-9117-6005C63CF399}) (Version: 6.2.2970 - The Eraser Project)
FileZilla Client 3.22.2.2 (HKLM-x32\…\FileZilla Client) (Version: 3.22.2.2 - Tim Kosse)
Flixster Video (HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\5cdf686a56bda3b1) (Version: 2.7.0.602 - Flixster Video)
FreeCommander XE (HKLM-x32\…\FreeCommander XE_is1) (Version:  - Marek Jasinski)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 57.0.2987.133 - Google Inc.)
Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.33.3 - Google Inc.) Hidden
HandBrake 0.10.1 (HKLM-x32\…\HandBrake) (Version: 0.10.1 - )
HTC Driver Installer (HKLM-x32\…\{4CEEE5D0-F905-4688-B9F9-ECC710507796}) (Version: 4.14.0.001 - HTC Corporation)
iExplorer (HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\262f11f6ff148a12) (Version: 4.0.4.0 - Macroplant LLC)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1323 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3960 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{86b86e21-7c9b-4baa-b284-69ce4a918661}) (Version: 16.10.0 - Intel Corporation)
IPTInstaller (HKLM-x32\…\{08208143-777D-4A06-BB54-71BF0AD1BB70}) (Version: 4.0.9 - HTC)
iTunes (HKLM\…\{554C62C7-E6BB-40F1-892B-F0AE02D3C135}) (Version: 12.5.3.17 - Apple Inc.)
Jihosoft Android Phone Recovery version 5.2.0.1 (HKLM-x32\…\{01F86EE4-6518-4BB2-8D11-0039134A6376}_is1) (Version: 5.2.0.1 - HONGKONG JIHO CO., LIMITED)
KODAK AiO Home Centre (HKLM-x32\…\{E0F274B7-592B-4669-8FB8-8D9825A09858}) (Version: 4.2.7.7 - Eastman Kodak Company)
ksDIP (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
LAME v3.99.3 (for Windows) (HKLM-x32\…\LAME_is1) (Version:  - )
LenovoUsbDriver 1.1.9 (HKLM-x32\…\LenovoUsbDriver) (Version: 1.1.9 - Lenovo)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
Microsoft Office Professional Plus 2010 (HKLM-x32\…\Office14.PROPLUS) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 (HKLM\…\{350AA351-21FA-3270-8B7A-835434E766AD}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\…\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Motorola Device Manager (HKLM-x32\…\{28DB8373-C1BB-444F-A427-A55585A12ED7}) (Version: 2.5.4 - Motorola Mobility)
Motorola Device Software Update (x32 Version: 13.09.3001 - Motorola Mobility) Hidden
Motorola Mobile Drivers Installation 6.4.0 (HKLM\…\{27986EDD-C9EC-4B52-B92F-06D073F0AA52}) (Version: 6.4.0 - Motorola Mobility LLC)
Mozilla Firefox 52.0.2 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 52.0.2 (x86 en-US)) (Version: 52.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 52.0.2.6291 - Mozilla)
MSXML 4.0 SP3 Parser (HKLM-x32\…\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyFreeCodec (HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\MyFreeCodec) (Version:  - )
Notepad++ (HKLM-x32\…\Notepad++) (Version: 6.7.8 - Notepad++ Team)
NVIDIA 3D Vision Driver 344.48 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 344.48 - NVIDIA Corporation)
NVIDIA GeForce Experience 2.1.3 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.1.3 - NVIDIA Corporation)
NVIDIA Graphics Driver 344.48 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 344.48 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.32.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.32.1 - NVIDIA Corporation)
NVIDIA PhysX System Software 9.14.0702 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.14.0702 - NVIDIA Corporation)
OEM Application Profile (HKLM-x32\…\{69C424A3-8863-FF59-FCF3-E3D94AB696FA}) (Version: 1.00.0000 - Advanced Micro Devices, Inc.)
Open Broadcaster Software (HKLM-x32\…\Open Broadcaster Software) (Version:  - )
OpenOffice 4.1.3 (HKLM-x32\…\{EEA30AEB-8BA7-465B-85D4-098BB99733E7}) (Version: 4.13.9783 - Apache Software Foundation)
paint.net (HKLM\…\{19BD2C33-16A8-4ED1-B9EA-D9E35B21EC42}) (Version: 4.0.5 - dotPDN LLC)
ParseHub 43.0 (x86 en-US) (HKLM-x32\…\ParseHub 43.0 (x86 en-US)) (Version: 43.0 - Mozilla)
PDF Settings CS6 (x32 Version: 11.0 - Adobe Systems Incorporated) Hidden
ph (x32 Version: 1.0.0 - Your Company Name) Hidden
PreReq (x32 Version: 3.20.0000.0000 - Eastman Kodak Company) Hidden
PrimoPDF – brought to you by Nitro PDF Software (HKLM-x32\…\PrimoPDF) (Version: 5 - Nitro PDF Software)
Qualcomm Atheros Bandwidth Control Filter Driver (Version: 1.0.36.1067 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer E220x Drivers (Version: 1.0.36.1067 - Qualcomm Atheros) Hidden
Qualcomm Atheros Killer Network Manager Suite (HKLM-x32\…\{E70DB50B-10B4-46BC-9DE2-AB8B49E061EE}) (Version: 1.0.36.1067 - Qualcomm Atheros)
Qualcomm Atheros Network Manager (Version: 1.0.36.1067 - Qualcomm Atheros) Hidden
Rapport (x32 Version: 3.5.1804.96 - Trusteer) Hidden
Realtek PCIE Card Reader (HKLM-x32\…\{0D61A55C-3ADC-409F-BF5B-A1766D1F5944}) (Version: 6.2.9200.28134 - Realtek Semiconductor Corp.)
Recuva (HKLM\…\Recuva) (Version: 1.53 - Piriform)
SafeZone Stable 1.51.2220.62 (x32 Version: 1.51.2220.62 - Avast Software) Hidden
Samsung Kies (HKLM-x32\…\InstallShield_{758C8301-2696-4855-AF45-534B1200980A}) (Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.)
Samsung Kies (x32 Version: 2.6.3.15024.5 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (HKLM\…\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.49.0 - SAMSUNG Electronics Co., Ltd.)
Scrivener (HKLM-x32\…\Scrivener 1900) (Version: 1900 - Literature and Latte)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\…\{90140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUS_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
SHIELD Streaming (Version: 3.1.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 16.13.56 - NVIDIA Corporation) Hidden
Skype Click to Call (HKLM-x32\…\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.33 (HKLM-x32\…\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.)
Sophos Virus Removal Tool (HKLM-x32\…\{B829E117-D072-41EA-9606-9826A38D34C1}) (Version: 2.5.6 - Sophos Limited)
Spotify (HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\Spotify) (Version: 1.0.45.186.g3b5036d6 - Spotify AB)
SpywareBlaster 5.5 (HKLM-x32\…\SpywareBlaster_is1) (Version: 5.5.0 - BrightFort LLC)
ST Microelectronics 3 Axis Digital Accelerometer Solution (HKLM-x32\…\{9C24F411-9CA7-4A8A-91F3-F08A4A38EB31}) (Version: 4.12.0040 - ST Microelectronics)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 16.3.8.62 - Synaptics Incorporated)
Synctunes Desktop (HKLM-x32\…\{4503D496-8D6B-4FC2-9A66-1CD6E12CD5DA}) (Version: 1.1.5 - The Bit Studio)
Trusteer Endpoint Protection (HKLM-x32\…\Rapport_msi) (Version: 3.5.1804.96 - Trusteer)
Unity Web Player (HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\UnityWebPlayer) (Version: 4.6.1f1 - Unity Technologies ApS)
VLC media player (HKLM-x32\…\VLC media player) (Version: 2.2.4 - VideoLAN)
WD Drive Utilities (HKLM-x32\…\{22662b08-91e0-4540-bb98-c96f32e09417}) (Version: 1.3.0.18 - Western Digital Technologies, Inc.)
WD Drive Utilities (x32 Version: 1.3.0.18 - Western Digital Technologies, Inc.) Hidden
WD Quick View (HKLM-x32\…\{965D28B5-3C86-41FD-994E-D6376815C9B3}) (Version: 2.4.10.17 - Western Digital Technologies, Inc.)
WD Security (HKLM-x32\…\{429a42d7-4c55-44d4-b38a-5872a0d70495}) (Version: 1.3.0.18 - Western Digital Technologies, Inc.)
WD Security (x32 Version: 1.3.0.18 - Western Digital Technologies, Inc.) Hidden
Windows Driver Package - MediaTek Inc. (wdm_usb) Ports  (01/22/2015 3.0.1504.0) (HKLM\…\BD5E2A628C2263FAEC66A4BFF2E88B897427E4C3) (Version: 01/22/2015 3.0.1504.0 - MediaTek Inc.)
Windows Installer Clean Up (HKLM-x32\…\{121634B0-2F4B-11D3-ADA3-00C04F52DD52}) (Version: 3.00.00.0000 - Microsoft Corporation)
WinHTTrack Website Copier 3.48-21 (x64) (HKLM\…\WinHTTrack Website Copier_is1) (Version: 3.48.21 - HTTrack)
WinMerge 2.14.0 (HKLM-x32\…\WinMerge_is1) (Version: 2.14.0 - Thingamahoochie Software)
WinX DVD Ripper 5.6.1 (HKLM-x32\…\WinX DVD Ripper_is1) (Version:  - Digiarty Software, Inc.)
WinZip 19.5 (HKLM\…\{CD95F661-A5C4-44F5-A6AA-ECDD91C240E9}) (Version: 19.5.11475 - WinZip Computing, S.L. )
XAMPP (HKLM-x32\…\xampp) (Version: 5.5.19-0 - Bitnami)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-222209725-2823862911-2758884793-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\Windows\system32\igfxEM.exe (Intel Corporation)
CustomCLSID: HKU\S-1-5-21-222209725-2823862911-2758884793-1001_Classes\CLSID\{CB2B673F-D441-4CD4-AFBE-DC4037CA4220}\InprocServer32 -> C:\Program Files\WinZip\adxloader64.dll ()
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {003BD9E6-930D-4E1A-B9A3-1DA6D958CEC7} - System32\Tasks\Motorola Device Manager Initial Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2014-10-30] ()
Task: {18F97AD4-4CDD-4282-BE58-9B4E964DA39F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-12-21] (Piriform Ltd)
Task: {21DD8343-42F5-4D19-8DA9-A9A2C67632B2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-31] (Google Inc.)
Task: {21EABD49-2BFE-497B-9B4E-BE28F33FD87B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-02-02] (Adobe Systems Incorporated)
Task: {29E85AC6-7399-4D9F-A8B6-87DA742C6F52} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_25_0_0_148_pepper.exe [2017-04-12] (Adobe Systems Incorporated)
Task: {338248FD-113E-4FA7-804B-1463BB41B267} - System32\Tasks\Microsoft\Windows\Setup\EOSNotify => C:\Windows\system32\EOSNotify.exe [2016-06-25] (Microsoft Corporation)
Task: {55F25501-8A90-4059-9E53-D87D70D0EBB6} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-04-06] (AVAST Software)
Task: {5D227B67-0154-49B9-971A-2EA18D50D556} - System32\Tasks\SafeZone scheduled Autoupdate 1485212786 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe 
Task: {66DEE05E-C389-494B-998B-07B838FF278B} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\Alienware\SupportAssist\sessionchecker.exe [2016-08-02] (PC-Doctor, Inc.)
Task: {769AFFA3-F929-44C4-BF65-51B61B34D805} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-01-31] (Google Inc.)
Task: {90630444-7B7A-4D7D-B13F-BF5BBCF178EC} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {96FF19E9-320A-475D-AB83-DBF77D034698} - System32\Tasks\showdesktop => C:\Users\xxxxx\desktop.scf [2014-11-21] ()
Task: {97CF0B24-773C-487A-AB34-5579DB30A514} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-04-12] (Adobe Systems Incorporated)
Task: {B2CDE911-8130-4812-A9DD-1232C0852ABE} - System32\Tasks\AdobeAAMUpdater-1.0-LAPTOP-TL-1-8-xxxxx => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-04-04] (Adobe Systems Incorporated)
Task: {BB388595-8223-4213-A3C2-AF23C73E7CF7} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-04-13] (AVAST Software)
Task: {D5EA040F-8041-42B7-B58B-08062003CF38} - System32\Tasks\IHSelfDeleteTASK => CMD /C DEL C:\Users\DUNCAN~1\AppData\Local\Temp\IHUA5AC.tmp.exe <==== ATTENTION
Task: {DE4E585E-8AAF-4BAD-9975-793830A574BB} - System32\Tasks\Synaptics TouchPad Enhancements => \Program Files\Synaptics\SynTP\SynTPEnh.exe 
Task: {E84350AC-D570-4C7B-B4CE-3419727F5617} - System32\Tasks\Amazon Music Helper => C:\Users\xxxxx\AppData\Local\Amazon Music\Amazon Music Helper.exe [2016-04-15] ()
Task: {EC8C3F93-DAD2-4ABA-A016-019680C23524} - System32\Tasks\Motorola Device Manager Update => C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotorolaDeviceManagerUpdate.exe [2014-10-30] ()
Task: {F7D24742-F9D5-423B-A3D5-A1B0B2564E4D} - System32\Tasks\IHUninstallTrackingTASK => CMD /C DEL C:\Users\DUNCAN~1\AppData\Local\Temp\IHUA482.tmp.exe <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
==================== Loaded Modules (Whitelisted) ==============
 
2013-09-05 01:17 - 2013-09-05 01:17 - 04300456 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2010-10-20 16:23 - 2010-10-20 16:23 - 08801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2016-11-01 19:10 - 2016-11-01 19:10 - 00052400 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [1034]
AlternateDataStreams: C:\ProgramData\TEMP:F0D7EE30 [138]
AlternateDataStreams: C:\Users\xxxxx\AppData\Local\Temp:120rL6sLi5x65BrffCs9Fcb [2226]
AlternateDataStreams: C:\Users\xxxxx\AppData\Local\Temp:JPn56U8WuanNAxTPyNxsHy52 [2144]
AlternateDataStreams: C:\Users\xxxxx\AppData\Local\Temp:T8yrJM1RPLzjvllV2lt [2376]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="2"
e"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\dell.com -> dell.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\0411dd.com -> 0411dd.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\0511zfhl.com -> 0511zfhl.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\0632qyw.com -> 0632qyw.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\1001movie.com -> 1001movie.com
 
There are 6091 more sites.
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2012-07-26 06:26 - 2016-04-03 16:43 - 00000921 ____A C:\Windows\system32\Drivers\etc\hosts
 
91.146.108.71 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\xxxxx\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
DNS Servers: 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
HKLM\…\StartupApproved\StartupFolder: => "ImageBrowser EX Agent.lnk"
HKLM\…\StartupApproved\StartupFolder: => "WinZip Preloader.lnk"
HKLM\…\StartupApproved\Run: => "iTunesHelper"
HKLM\…\StartupApproved\Run: => "Eraser"
HKLM\…\StartupApproved\Run32: => "SwitchBoard"
HKLM\…\StartupApproved\Run32: => "KiesTrayAgent"
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\StartupApproved\Run: => "VideoDownloaderUltimate"
HKU\S-1-5-21-222209725-2823862911-2758884793-1001\…\StartupApproved\Run: => "Spotify"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{5566A62E-8AB8-4DF3-B751-033822208963}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{268474D7-AB82-450B-AEA3-442D2E10D1F5}] => (Allow) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
FirewallRules: [{375940B1-54F1-4497-A728-79035EE07054}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{0E5EEBD7-BDF6-4B11-A5DE-033AF6026718}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
FirewallRules: [{B56B026D-A806-4384-A801-E35D00C5B99D}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{5EC15602-1BC9-4C5C-A0CC-517AFBA0BC67}] => (Allow) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamer.exe
FirewallRules: [{2984E658-0A96-4F73-AB2B-B0E28D468A74}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{59EE6C7A-BCCE-49BD-9CA4-FDF275604046}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [UDP Query User{1501EBF3-0245-4791-9709-EF69485D583D}C:\xampp\apache\bin\httpd.exe] => (Allow) C:\xampp\apache\bin\httpd.exe
FirewallRules: [{3616BE49-918B-42B3-B0C9-8F2F2BB6DB8E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0671AB01-406D-4B36-B1A2-C24AFEDDA3C8}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{0726A54F-A8A4-4ADA-B153-4A321E76E9EB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{B81A5115-4C10-4C9B-8216-8936EE894D4D}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{FFA3703C-6FD3-4435-AD28-54C3332633B3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{D79D3480-88D3-4DA1-BAA6-B1341E3814FF}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{0F061F83-001B-43C8-95AF-2F1F4D22A277}C:\users\xxxxx\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe] => (Allow) C:\users\xxxxx\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe
FirewallRules: [UDP Query User{B772EA28-F682-4465-B91B-02F8426D0175}C:\users\xxxxx\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe] => (Allow) C:\users\xxxxx\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe
FirewallRules: [TCP Query User{3CA1A338-1C2F-4B71-9E1A-D7AF36A237C2}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{6342AC4C-A3C2-4CB3-9D5E-9C4A286256E6}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{1BFA6C8F-7F3B-43DF-B836-3160106CF28B}] => (Allow) C:\Program Files (x86)\The Bit Studio\Synctunes Desktop\Synctunes.exe
FirewallRules: [{548208E2-6DD0-4D65-A693-FCC65E53FD58}] => (Allow) LPort=9322
FirewallRules: [{BD7F7BBD-3230-47B6-8392-92D8A25A85F5}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe
FirewallRules: [{B03D2127-E0BA-4E60-9E81-FCD60969B434}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\AiOHomeCenter.exe
FirewallRules: [{A61F7E29-3AAD-4050-9687-B384425E3305}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe
FirewallRules: [{8EDFF0A1-86D9-4AE5-9CD2-3D20A1481797}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\Kodak.Statistics.exe
FirewallRules: [{E79AB244-9EE0-4243-A266-32D532918448}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe
FirewallRules: [{5E9CD5D6-5659-43B7-96F4-F3C7438BF311}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Firmware\KodakAiOUpdater.exe
FirewallRules: [{10164327-FF40-4D03-BBC5-FB33D1CCFD55}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe
FirewallRules: [{48FBE4C8-D4CB-403C-8D82-BC8410D82C01}] => (Allow) C:\ProgramData\Kodak\Installer\Setup.exe
FirewallRules: [{F25311C1-74FD-4256-9AC6-F3EB22B32B62}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe
FirewallRules: [{B2A82AC9-9F45-43E1-9202-986C3FE33A28}] => (Allow) C:\Program Files (x86)\Kodak\AiO\Center\NetworkPrinterDiscovery.exe
FirewallRules: [{77F3004E-9D72-4FBA-A3DF-580C5625AC3D}] => (Allow) LPort=9322
FirewallRules: [{EBA61329-7851-4950-B5E2-D186EA02B046}] => (Allow) LPort=9323
FirewallRules: [{D500DC1D-D869-44D4-A408-5E43DDE304CE}] => (Allow) LPort=9324
FirewallRules: [{B18BD260-5A0E-412B-845A-D159A1942E16}] => (Allow) LPort=9324
FirewallRules: [{287F1C45-0F2E-4A7A-BE68-8AC31AF4DCAF}] => (Allow) LPort=9326
FirewallRules: [{BB81AFBE-3227-4C35-B650-9C4AB5437AEA}] => (Allow) LPort=9326
FirewallRules: [{09F5EBE5-4247-46EE-956F-4F61E43C9630}] => (Allow) LPort=9326
FirewallRules: [{663789E1-AE4B-494D-9F04-0C86A4AC0A17}] => (Allow) C:\Program Files (x86)\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe
FirewallRules: [{2F0EE5FD-F86B-41D8-B087-25EB5DD5743B}] => (Allow) C:\Program Files (x86)\BT Broadband Desktop Help\btbb\BTHelpBrowser.exe
FirewallRules: [{8F12D82F-97E6-4D78-A0D4-714C84E281ED}] => (Allow) C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
FirewallRules: [{6982D339-345C-4AA1-857D-5FDFB228B309}] => (Allow) C:\Program Files\BT Broadband Desktop Help\btbb\BTHelpNotifier.exe
FirewallRules: [{1A4F5D7F-0206-4F02-84B0-0A81E794119A}] => (Allow) C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\node.exe
FirewallRules: [{27755286-0054-4B3C-A6D1-13B8E620509B}] => (Allow) C:\Program Files (x86)\BT Broadband Desktop Help\btbb\MA\8.4.0.53.bt.10\ma\bin\node.exe
FirewallRules: [TCP Query User{4DCD59C6-4B63-4078-B8A8-2356F4859EF5}C:\program files\bt broadband desktop help\btbb\bthelpnotifier.exe] => (Block) C:\program files\bt broadband desktop help\btbb\bthelpnotifier.exe
FirewallRules: [UDP Query User{F8B2B1B9-5C58-4A29-BC0F-7FFD916495B8}C:\program files\bt broadband desktop help\btbb\bthelpnotifier.exe] => (Block) C:\program files\bt broadband desktop help\btbb\bthelpnotifier.exe
FirewallRules: [{9FF66763-475F-49CB-89D4-8710AF9A1854}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{39432EB3-5ECC-4AAC-8C03-5040DCD3124D}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{21E578F5-7339-4D6E-A45B-7ACB48A7B4B0}C:\program files (x86)\bt broadband desktop help\btbb\ma\8.4.0.53.bt.10\ma\bin\node.exe] => (Block) C:\program files (x86)\bt broadband desktop help\btbb\ma\8.4.0.53.bt.10\ma\bin\node.exe
FirewallRules: [UDP Query User{D373F87A-E8B0-4F0D-AE62-B2053440188C}C:\program files (x86)\bt broadband desktop help\btbb\ma\8.4.0.53.bt.10\ma\bin\node.exe] => (Block) C:\program files (x86)\bt broadband desktop help\btbb\ma\8.4.0.53.bt.10\ma\bin\node.exe
FirewallRules: [{DD142578-6634-4624-83EB-C441950A72E3}] => (Allow) LPort=9323
FirewallRules: [TCP Query User{7D6C0A24-F537-4961-91FD-995DA7D8799C}C:\users\xxxxx\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_40\bin\javaw.exe] => (Allow) C:\users\xxxxx\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_40\bin\javaw.exe
FirewallRules: [UDP Query User{A86891BB-CABB-4E14-A3CE-47F0928C8252}C:\users\xxxxx\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_40\bin\javaw.exe] => (Allow) C:\users\xxxxx\appdata\local\programs\blackboard\blackboard collaborate launcher\resources\java\jre1.7.0_40\bin\javaw.exe
FirewallRules: [{AB7D2EEC-B193-4AE6-81A0-19FE27D93B77}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{5291D3E6-1449-41C2-ACD9-D8B65E532E6D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{01069304-1143-461F-8534-BEEB03E92CF6}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{A849EC0D-843B-4A8E-917E-A9C68B413A50}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{25538EA3-E380-4556-8DE1-91D0FBB7175B}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [TCP Query User{4D5F6360-3D5C-4862-A44C-E04D2C97E8FB}E:\new folder\powerline utility\powerline scan\powerline scan.exe] => (Allow) E:\new folder\powerline utility\powerline scan\powerline scan.exe
FirewallRules: [UDP Query User{791BCEAF-A6A3-48EA-88BF-DA3B070D63B9}E:\new folder\powerline utility\powerline scan\powerline scan.exe] => (Allow) E:\new folder\powerline utility\powerline scan\powerline scan.exe
FirewallRules: [TCP Query User{DFDFACA6-5088-4B32-A62C-1803D56CB65E}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe
FirewallRules: [UDP Query User{D100C452-9553-4CA6-A767-CC83C74DD448}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe
FirewallRules: [TCP Query User{19CDEC6C-DB2F-49E5-8CCD-7443A27C4188}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe
FirewallRules: [UDP Query User{B5998908-43B8-49F5-9CFD-50D3F42327F8}C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilegoservice.exe
FirewallRules: [{0CDDF40E-253C-464A-A914-62A363B8D069}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [TCP Query User{D4B4536E-463F-4258-880D-FF078D61DDAA}C:\program files (x86)\wondershare\mobilego\mobilego.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilego.exe
FirewallRules: [UDP Query User{72DA06FC-05CD-4BB5-88D2-56B6F96189BA}C:\program files (x86)\wondershare\mobilego\mobilego.exe] => (Allow) C:\program files (x86)\wondershare\mobilego\mobilego.exe
FirewallRules: [TCP Query User{ADDA35B5-6EFB-4B04-A53E-24437C5A6590}C:\users\xxxxx\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\xxxxx\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{C9A8FDAC-2B10-4778-9F6C-41DE8DA0F5CD}C:\users\xxxxx\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\xxxxx\appdata\roaming\spotify\spotify.exe
FirewallRules: [{6466B1E0-5ECE-4972-8B2E-C959D3DE8E0E}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
FirewallRules: [{3F5CFF40-2F67-4E15-8520-71D219DEF3BF}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TbService.exe
FirewallRules: [{5EDE623B-5635-47F0-A66E-EAF0DB2038A9}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
FirewallRules: [{B3ED1A1D-4CCD-439E-B699-47B155818E88}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TBConsoleUI.exe
FirewallRules: [{0F1A960F-DE75-4845-90DF-1749BC5E9677}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{B64A5524-CB35-45AB-99AD-DFA788D452BF}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{4BC2D72B-C334-4ECE-AFCE-7A820E7A4D27}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{D7A1AC39-0F46-480B-8931-03E1E1FD9EAC}] => (Allow) C:\Program Files (x86)\EaseUS\Todo Backup\bin\TodoBackupService.exe
FirewallRules: [{6221CAB2-EECF-4BA0-9F81-A27EF0844508}] => (Allow) C:\Program Files (x86)\ParseHub\parsehub.exe
FirewallRules: [{DCD18460-A92E-46D9-8F63-AC02CDD07EA6}] => (Allow) C:\Program Files (x86)\ParseHub\parsehub.exe
FirewallRules: [TCP Query User{8645B1CD-8EF3-4F49-9E2A-1E1CD9555FA0}C:\users\xxxxx\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\xxxxx\appdata\roaming\spotify\spotify.exe
FirewallRules: [UDP Query User{570A36C2-E45B-48F2-97CB-8D7DB34B6EEE}C:\users\xxxxx\appdata\roaming\spotify\spotify.exe] => (Allow) C:\users\xxxxx\appdata\roaming\spotify\spotify.exe
FirewallRules: [{D1CBFD20-B653-4A0A-A332-1999B353A509}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
27-03-2017 13:29:27 Scheduled Checkpoint
04-04-2017 09:12:24 Scheduled Checkpoint
14-04-2017 16:17:30 Scheduled Checkpoint
19-04-2017 21:45:18 Restore Operation
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/20/2017 08:05:45 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007232B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (04/20/2017 08:05:21 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007232B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
 
Error: (04/20/2017 07:48:10 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007232B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (04/20/2017 07:47:46 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007232B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
 
Error: (04/20/2017 07:46:10 AM) (Source: System Restore) (EventID: 8210) (User: )
Description: An unspecified error occurred during System Restore: (Scheduled Checkpoint). Additional information: 0x81000204.
 
Error: (04/20/2017 07:39:23 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program chrome.exe version 57.0.2987.133 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
 
Process ID: 1600
 
Start Time: 01d2b99f8819f568
 
Termination Time: 4
 
Application Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
Report Id: 104ae1ec-2594-11e7-bf4a-801934717d6a
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (04/20/2017 07:32:40 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007232B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (04/20/2017 07:32:16 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007232B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
 
Error: (04/19/2017 09:55:11 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007232B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=NetworkAvailable
 
Error: (04/19/2017 09:55:03 PM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
Description: License Activation (slui.exe) failed with the following error code:
hr=0x8007232B
Command-line arguments:
RuleId=eeba1977-569e-4571-b639-7623d8bfecc0;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=a98bcd6d-5343-4603-8afe-5908e4611112;NotificationInterval=1440;Trigger=UserLogon;SessionId=1
 
 
System errors:
=============
Error: (04/20/2017 08:36:34 AM) (Source: DCOM) (EventID: 10005) (User: LAPTOP-TL-1-8)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (04/20/2017 08:36:24 AM) (Source: DCOM) (EventID: 10005) (User: LAPTOP-TL-1-8)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (04/20/2017 08:35:41 AM) (Source: DCOM) (EventID: 10005) (User: LAPTOP-TL-1-8)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{9E175B6D-F52A-11D8-B9A5-505054503030}
 
Error: (04/20/2017 08:35:41 AM) (Source: DCOM) (EventID: 10005) (User: LAPTOP-TL-1-8)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (04/20/2017 08:35:37 AM) (Source: DCOM) (EventID: 10005) (User: LAPTOP-TL-1-8)
Description: DCOM got error "1084" attempting to start the service CsrBtService with arguments "Unavailable" in order to run the server:
{BFF6845D-E49A-4A99-9609-418ED36F1C54}
 
Error: (04/20/2017 08:35:37 AM) (Source: DCOM) (EventID: 10005) (User: LAPTOP-TL-1-8)
Description: DCOM got error "1084" attempting to start the service CsrBtOBEXService with arguments "Unavailable" in order to run the server:
{610A06E0-D579-4E30-8AE5-72880327740B}
 
Error: (04/20/2017 08:35:32 AM) (Source: DCOM) (EventID: 10005) (User: LAPTOP-TL-1-8)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{9E175B6D-F52A-11D8-B9A5-505054503030}
 
Error: (04/20/2017 08:35:32 AM) (Source: DCOM) (EventID: 10005) (User: LAPTOP-TL-1-8)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
 
Error: (04/20/2017 08:35:15 AM) (Source: DCOM) (EventID: 10005) (User: LAPTOP-TL-1-8)
Description: DCOM got error "1084" attempting to start the service WSearch with arguments "Unavailable" in order to run the server:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
 
Error: (04/20/2017 08:35:15 AM) (Source: DCOM) (EventID: 10005) (User: LAPTOP-TL-1-8)
Description: DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "Unavailable" in order to run the server:
{DD522ACC-F821-461A-A407-50B198B896DC}
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i7-4710MQ CPU @ 2.50GHz
Percentage of memory in use: 23%
Total physical RAM: 8077.04 MB
Available physical RAM: 6168.44 MB
Total Virtual: 16269.04 MB
Available Virtual: 14382.44 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:465.42 GB) (Free:232.4 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: F729CCB8)
Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=465.4 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

 

Hello elbowpipe and welcome back to the WTT forum.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

This might not be a malware problem but here are a few entries in your logs that need to be dealt with and I’d like another couple of scans before going any further.

Run Zoek

Please temporarily disable your AV program.

Download zoek.exe to your Desktop:

Important: Disable your AntiVirus and AntiSpyware programs, so they do not interfere with the running of Zoek.exe. You can find instructions how to disable your security applications here.
 

  • on Windows Vista, 7, 8 and 10, right-click Zoek.exe and select: Run as Administrator
  • give it a few seconds to appear
  • copy/paste the entire script inside the codebox below into the input field of Zoek:
    autoclean;
    emptyalltemp;
    emptyclsid;
    FFdefaults;
    iedefaults;
    chrdefaults;
    
  • close any open programs.
  • click the Run script button, and wait. It takes a few minutes to run.
  • when the tool finishes, the zoek-results.log is opened in Notepad: the log can also be found on the systemdrive, normally C:\
  • if a reboot is needed, the log will be opened after the reboot.

===================================================

Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download RogueKiller to your desktop

  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

Logs to include with next post:

zoek-results.log
RKreport.txt


Thanks

Satchfan

 

Hi Nina,

 

I know, I only get in touch when I want something! I started running the kit and then I wondered about being in safe mode (it's the only way I can get on the Internet). Should I run the reports in normal mode and then switch to safe to send them?

 

Duncan

Thanks for the logs.

I'm not familiar with OCS software or Blackboard.

Can you tell me if use them and if so, what they are.

Thanks

Nina

OK thanks.

 

Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

  • close all programs
  • double-click RogueKiller.exe - Windows 7/8/10 users right-click the program and select Run as Administrator'
  • after it has completed it's prescan, click on Scan
  • click on the click on the ‘FilesSystem’ tab
  • make sure the following entries there are checked:


    [PUP.Gen1][Folder] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec -> Found
     

  • click on the click on the ‘Registry’ tab
  • make sure the following entries there are checked:


    [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-222209725-2823862911-2758884793-1001\Software\Link64 -> Found
    [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-222209725-2823862911-2758884793-1001\Software\OCS -> Found
    [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-222209725-2823862911-2758884793-1001\Software\Link64 -> Found
    [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-222209725-2823862911-2758884793-1001\Software\OCS -> Found
    [PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-222209725-2823862911-2758884793-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec -> Found
    [PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-222209725-2823862911-2758884793-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall\MyFreeCodec -> Found
    [Suspicious.Path|PUP.Gen0|PUP.Gen1] (X64) HKEY_USERS\S-1-5-21-222209725-2823862911-2758884793-1001\Software\Microsoft\Windows\CurrentVersion\Run | VideoDownloaderUltimate : C:\ProgramData\VideoDownloaderUltimateWinApp\VideoDownloaderUltimate.exe /repair [x] -> Found
    [Suspicious.Path|PUP.Gen0|PUP.Gen1] (X86) HKEY_USERS\S-1-5-21-222209725-2823862911-2758884793-1001\Software\Microsoft\Windows\CurrentVersion\Run | VideoDownloaderUltimate : C:\ProgramData\VideoDownloaderUltimateWinApp\VideoDownloaderUltimate.exe /repair [x] -> Found
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\aswVmm (\??\C:\Users\DUNCAN~1\AppData\Local\Temp\aswVmm.sys) -> Found
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | TCP Query User{0F061F83-001B-43C8-95AF-2F1F4D22A277}C:\users\duncan macinnes\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=6|Profile=Private|Profile=Public|App=C:\users\duncan macinnes\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe|Name=javaw.exe|Desc=javaw.exe|Defer=User| [x] -> Found
    [Suspicious.Path] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules | UDP Query User{B772EA28-F682-4465-B91B-02F8426D0175}C:\users\duncan macinnes\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe : v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Private|Profile=Public|App=C:\users\duncan macinnes\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe|Name=javaw.exe|Desc=javaw.exe|Defer=User| [x] -> Found


     

    NOTE: Do NOT select these:

    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{5CCDE653-E20A-47AF-AFDA-000261DC0389} | DhcpNameServer : 172.20.10.1 ([])  -> Found – Private IP address of router/modem

    [PUM.Dns] (X64) HKEY_LOCAL_MACHINE\System\ControlSet001\Services\Tcpip\Parameters\Interfaces\{FCADB591-D985-4DF6-BD5A-7F38476CEC4E} | NameServer : 217.171.135.1 ([United Kingdom])  -> Found

     
  • then press the Delete button and post the log it produces.

===================================================

Run Farbar Service Scanner

Please download Farbar Service Scanner and run it on the computer with the issue.

Make sure the following options are checked:


Internet Services
Windows Firewallsfc
System Restore
Security Center/Action Center
Windows Update
Windows Defender
Other Services

  • press "Scan".
  • it will create a log (FSS.txt) in the same directory the tool is run.
  • please copy and paste the log to your reply.

Logs to include in the next post:

RogueKiller fix log
FSS.txt


Thanks

I won’t be around for a few hours now but will get back as soon as I can.

Are you still unable to access Firefox & Chrome?

Nina

 

Yeah, I'm back browsing again. Thanks so much. Any advice on protection? I have Avast installed. Should I pay for Malwarebytes?

I have Avast installed

 

My choice is Windows Defender but Avast is fine.

 

Should I pay for Malwarebytes?

 

Your choice again. I personally don't but many of the Malware Team do. I would suggest in your case that it's a small price to pay for the excellent protection it gives these days.

 

I'll leave this open for 24 hours in case there are any remaining problems.

 

Take care Duncan and happy piping.

 

Nina

 

Thanks once again. I'll play 'An Eala Fhiain' (the one you liked) in the pub for you tonight. "This one's for Nina the Tech".  :clap:

I'll play 'An Eala Fhiain' (the one you liked) in the pub for you tonight. "This one's for Nina the Tech".

 

Thank you Duncan, much appreciated.

 

I was just listening to you on Soundcloud playing The Wild Geese and it's so haunting, (reminds me of the Lonesome Boatman).

 

Enjoy tonight.

 

Nina

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI