This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

System running very slowly, unresponsive many times [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

For the past 3 days my system has been running very slow, if I leave for even a half hour it takes several minutes to get back to running again. I ran malwarebytes and cleaned the pup files found but still the problem persists.

Hello Bryan A and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please run these in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.


  • run AdwCleaner by clicking on Scan
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Download and run Junkware Removal Tool

Please download Junkware Removal Tool to your desktop.

  • shut down your protection software now to avoid potential conflicts.
  • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
  • the tool will open and start scanning your system
  • please be patient as this can take a while to complete depending on your system's specifications
  • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
  • post the contents of JRT.txt into your next message.

===================================================

Run Farbar Recovery Scan Tool

Please download Farbar Recovery Scan Tool and save it to your Desktop.

Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

  • right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
  • press Scan button
  • it will produce a log called Frst.txt in the same directory the tool is run from
  • please copy and paste log back here.
  • the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.

Logs to include with next post:

AdwCleaner log
JRT.txt
Frst.txt
Addition.txt


Thanks

 

 

BTW, I'm in the UK and might not reply tonight, (10 30pm GMT).

Satchfan

Thank you for your help. Here are the logs you requested.

# AdwCleaner v6.045 - Logfile created 20/04/2017 at 22:06:08
# Updated on 28/03/2017 by Malwarebytes
# Database : 2017-04-21.1 [Local]
# Operating System : Windows 7 Home Premium Service Pack 1 (X64)
# Username : Bryan - ARTADI-PC
# Running from : C:\Users\Bryan\Downloads\adwcleaner_6.045.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support
 
 
 
***** [ Services ] *****
 
 
 
***** [ Folders ] *****
 
[-] Folder deleted: C:\ProgramData\Auslogics
[#] Folder deleted on reboot: C:\ProgramData\Application Data\Auslogics
[-] Folder deleted: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Auslogics
[-] Folder deleted: C:\Program Files (x86)\Auslogics
[-] Folder deleted: C:\Windows\SysWOW64\config\systemprofile\AppData\Local\LavasoftTcpService
 
 
***** [ Files ] *****
 
[-] File deleted: C:\Windows\SysWOW64\drivers\DRVAGENT64.SYS
[-] File deleted: C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default\searchplugins\google-lavasoft.xml
 
 
***** [ DLL ] *****
 
 
 
***** [ WMI ] *****
 
 
 
***** [ Shortcuts ] *****
 
 
 
***** [ Scheduled Tasks ] *****
 
 
 
***** [ Registry ] *****
 
 
 
***** [ Web browsers ] *****
 
[-] [C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: ceopoaldcnmhechacafgagdkklcogkgd
[-] [C:\Users\Zanthia\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: www2.inbox.com
[-] [C:\Users\Zanthia\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
[-] [C:\Users\Zanthia\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
[-] [C:\Users\Guest\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
 
 
*************************
 
:: "Tracing" keys deleted
:: Winsock settings cleared
 
*************************
 
C:\AdwCleaner\AdwCleaner[C0].txt - [2008 Bytes] - [20/04/2017 22:06:08]
C:\AdwCleaner\AdwCleaner[S0].txt - [2221 Bytes] - [20/04/2017 22:04:43]
 
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [2154 Bytes] ##########
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.3 (04.10.2017)
Operating System: Windows 7 Home Premium x64 
Ran by [removed] (Administrator) on Thu 04/20/2017 at 22:15:32.19
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
 
 
 
File System: 10 
 
Successfully deleted: C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ceopoaldcnmhechacafgagdkklcogkgd (Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Roaming\productdata (Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2UHAARRC (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8EDX4OFX (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9TRJS6LJ (Temporary Internet Files Folder) 
Successfully deleted: C:\Users\Bryan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB6WLFD0 (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\2UHAARRC (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8EDX4OFX (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9TRJS6LJ (Temporary Internet Files Folder) 
Successfully deleted: C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CB6WLFD0 (Temporary Internet Files Folder) 
 
 
 
Registry: 0 
 
 
 
 
 
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Thu 04/20/2017 at 22:21:20.24
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20-04-2017
Ran by [removed] (administrator) on ARTADI-PC (20-04-2017 22:24:43)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\wtoolex\wpsupdatesvr.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.3\GoogleCrashHandler64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2015-01-15] (NVIDIA Corporation)
HKLM\…\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-10] (Egis Technology Inc.)
HKLM\…\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [552368 2016-12-15] (Greenshot)
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213824 2017-04-04] (AVAST Software)
HKLM-x32\…\Run: [BackupManagerTray] => C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [261888 2009-08-12] (NewTech Infosystems, Inc.)
HKLM-x32\…\Run: [Acer Assist Launcher] => C:\Program Files (x86)\Acer\Acer Assist\launcher.exe [1261568 2007-11-19] ()
HKLM-x32\…\Run: [Hotkey Utility] => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [629280 2009-08-18] ()
HKLM-x32\…\Run: [EgisTecLiveUpdate] => C:\Program Files (x86)\EgisTec Egis Software Update\EgisUpdate.exe [199464 2009-08-03] (Egis Technology Inc.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [Google Update] => C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.3\GoogleUpdateCore.exe [599632 2017-04-10] (Google Inc.)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8641240 2016-02-12] (Piriform Ltd)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [HP ENVY 4510 series (NET)] => C:\Program Files\HP\HP ENVY 4510 series\Bin\ScanToPCActivationApp.exe [3651080 2015-03-09] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [OpenDNS Updater] => C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe [839680 2010-06-16] ()
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [f.lux] => C:\Users\Bryan\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {14d88b8c-41df-11e5-81d8-00262d289fc4} - G:\LG_PC_Programs.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {2ed78b9e-4ad6-11e4-b18e-00262d289fc4} - G:\LG_PC_Programs.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {a21070b2-0165-11e6-bda4-00262d289fc4} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {bb746c77-426c-11e4-b370-00262d289fc4} - G:\LaunchU3.exe -a
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {ce33646d-05b5-11e6-8974-00262d289fc4} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {eabd1f25-3ae8-11e4-ae5d-806e6f6e6963} - D:\setup\rsrc\Autorun.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-13] (Microsoft Corporation)
HKU\S-1-5-18\…\Run: [AviraSpeedup] => "C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun
ShellIconOverlayIdentifiers: [    BoxSyncFileLocked] -> {2a607da5-abe8-358e-a881-c0f5faf2d3a5} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncFileLockedByOther] -> {f7d2951f-0b6b-346c-99ec-69cffc30a364} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncNotSynced] -> {5ea95e3d-3e46-3812-b03c-49785fa67d41} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncProblem] -> {a88b7184-bfa1-3d14-8efb-2225df9699bc} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [    BoxSyncSynced] -> {c89f9943-8f58-3eca-bd55-a658f53b2f48} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-04-04] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-04-04] (AVAST Software)
ShellIconOverlayIdentifiers: [1MediaFireIconError] -> {5EE8C634-CDC0-453D-9731-DF0B19F4E807} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon3_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconReadOnly] -> {7995D0FC-769B-4197-AEC0-991921CB99E1} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon5_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconSynched] -> {9A3B79CB-D899-40B5-8DBC-20447F1ADC8F} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconSyncing] -> {C4D81971-6B13-4173-AB21-F83AD20CCC04} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon2_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll [2009-09-10] (Egis Technology Inc.)
ShellIconOverlayIdentifiers: [MediaFireIconLock] -> {759F3E92-F4E8-4953-8315-238B8B17E0F3} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon4_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\psdprotect.dll [2009-09-10] (Egis Technology Inc.)
Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-05-06]
ShortcutTarget: Dropbox.lnk -> C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2017-04-17]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Bryan\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook)
BootExecute: autocheck autochk * sdnclean64.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{C9178436-B2FA-4276-BD10-820A7192F6DA}: [DhcpNameServer] 75.75.75.75 75.75.76.76
 
Internet Explorer:
==================
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://duckduckgo.com/
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l;=0409&m;=aspire_x1301&r;=17360914s707p0428v1j5w45j1t539
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKLM -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACAW
SearchScopes: HKLM-x32 -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACAW_enUS605
SearchScopes: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-03-14] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-04-04] (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2017-03-14] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-03-14] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-04-04] (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-28] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2017-03-14] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-28] (Google Inc.)
Toolbar: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-19] (Microsoft Corporation)
 
FireFox:
========
FF ProfilePath: C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default [2016-11-23]
FF Extension: (Avira Browser Safety) - C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default\Extensions\[removed] [2015-09-21] [not signed]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF Extension: (Avast SafePrice) - C:\Program Files\AVAST Software\Avast\SafePrice\FF [2016-10-27]
FF HKLM\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: (Avast Online Security) - C:\Program Files\AVAST Software\Avast\WebRep\FF [2016-10-27]
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\SafePrice\FF
FF HKLM-x32\…\Firefox\Extensions: [[removed]] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_194.dll [2017-01-14] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_194.dll [2017-01-14] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-15] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-03] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-03] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-11] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1069211171-1032678597-3133260682-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-10] (Google Inc.)
FF Plugin HKU\S-1-5-21-1069211171-1032678597-3133260682-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.3\npGoogleUpdate3.dll [2017-04-10] (Google Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com","hxxp://xfinity.comcast.net/?cid=insDate09172012","","file:///usr/share/doc/home.htm"
CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> duckduckgo.com
CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type;=list
CHR Profile: C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default [2017-04-20]
CHR Extension: (Google Slides) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-03]
CHR Extension: (Google Docs) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-03]
CHR Extension: (Google Drive) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2017-03-16]
CHR Extension: (DuckDuckGo Search) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2017-03-22]
CHR Extension: (YouTube) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (uBlock Origin) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-04-20]
CHR Extension: (Google Search) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Dropbox for Gmail) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2017-03-16]
CHR Extension: (Google Sheets) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-03]
CHR Extension: (Avira Browser Safety) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2016-09-22]
CHR Extension: (Google Docs Offline) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-04-15]
CHR Extension: (Privacy Cleaner) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\liiikhhbkpmpomjmdofandjmdgapiahi [2017-03-16]
CHR Extension: (Contest Lobby - DraftKings) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\loelnclfphlfeopbkllhhjjkdnnioacd [2016-11-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-16]
CHR Extension: (Gmail) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-04-12]
CHR HKLM\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7398336 2017-04-04] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [261712 2017-04-04] (AVAST Software)
S3 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [28696 2014-09-24] (Box, Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042544 2017-03-14] (Microsoft Corporation)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [625184 2009-04-19] ()
S3 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2015-01-15] (NVIDIA Corporation)
S3 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [28552 2016-04-26] (Hewlett-Packard Company)
R2 Kingsoft_WPS_UpdateService; C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\wtoolex\wpsupdatesvr.exe [133376 2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [3046688 2016-07-29] (IObit)
S3 MF NTFS Monitor; C:\Users\Bryan\AppData\Local\MediaFire Desktop\MFUsnMonitorService.exe [456504 2015-03-23] ()
S3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-10] (Egis Technology Inc.)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [207904 2009-04-19] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2015-01-15] (NVIDIA Corporation)
S3 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833360 2015-01-15] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-05-24] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S3 wpscloudsvr; C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\wpscloudsvr.exe [162048 2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
S2 NetDrive2_Service_NetDrive2; C:\Program Files\NetDrive2\nd2svc.exe [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 andnetadb; C:\Windows\System32\Drivers\lgandnetadb.sys [31744 2014-05-27] (Google Inc) [File not signed]
S3 AndnetBus; C:\Windows\System32\DRIVERS\lgandnetbus64.sys [20992 2014-05-27] (LG Electronics Inc.) [File not signed]
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [29184 2014-07-07] (LG Electronics Inc.) [File not signed]
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [36352 2014-07-07] (LG Electronics Inc.) [File not signed]
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [307736 2017-04-04] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [189768 2017-04-04] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [334088 2017-04-04] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [48528 2017-04-04] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [38296 2017-04-04] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [32600 2017-04-04] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [127112 2017-04-04] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [101152 2017-04-04] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [75704 2017-04-04] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1005048 2017-04-04] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [556784 2017-04-04] (AVAST Software)
S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [164064 2017-04-04] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [339696 2017-04-04] (AVAST Software)
S3 DigiartyVirtualCDBus; C:\Windows\System32\drivers\DigiartyVirtualCDBus.sys [276256 2015-10-25] (Digiarty Software, Inc.)
S0 eorclc; no ImagePath
U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-04] (Microsoft Corporation)
R3 hsCDFiDrv; C:\Windows\System32\DRIVERS\hsCDFiDrv.sys [7168 2010-07-17] ()
S3 MDA_NTDRV; C:\Windows\system32\MDA_NTDRV.sys [21208 2013-02-25] ()
R2 mfmonitor; C:\Windows\System32\DRIVERS\mfmonitor_x64.sys [20696 2015-03-23] (Windows (R) Win 7 DDK provider)
R2 npf; C:\Windows\System32\drivers\npf.sys [36600 2015-11-15] (Riverbed Technology, Inc.)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-01-15] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2014-11-28] (Secunia)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [92848 2016-08-19] ()
R1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [26800 2016-08-19] ()
R1 Uim_IM; C:\Windows\System32\DRIVERS\uim_im.sys [484528 2016-08-19] ()
S3 uvhid; C:\Windows\System32\DRIVERS\uvhid.sys [25592 2015-07-25] (Windows (R) Win 7 DDK provider)
R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [117768 2015-08-13] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [146072 2015-08-13] (Oracle Corporation)
S3 avchv; system32\DRIVERS\avchv.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-04-20 22:24 - 2017-04-20 22:26 - 00028774 _____ C:\Users\Bryan\Downloads\FRST.txt
2017-04-20 22:24 - 2017-04-20 22:24 - 00000000 ____D C:\FRST
2017-04-20 22:21 - 2017-04-20 22:21 - 00002089 _____ C:\Users\Bryan\Desktop\JRT.txt
2017-04-20 22:15 - 2017-04-20 22:15 - 00000000 ____D C:\ProgramData\SWCUTemp
2017-04-20 22:00 - 2017-04-20 22:06 - 00000000 ____D C:\AdwCleaner
2017-04-20 19:58 - 2017-04-20 22:24 - 00001448 _____ C:\Users\Bryan\Desktop\FRST64.exe - Shortcut.lnk
2017-04-20 19:56 - 2017-04-20 19:57 - 02424832 _____ (Farbar) C:\Users\Bryan\Downloads\FRST64.exe
2017-04-20 19:55 - 2017-04-20 22:15 - 00001417 _____ C:\Users\Bryan\Desktop\JRT.exe - Shortcut.lnk
2017-04-20 19:55 - 2017-04-20 19:55 - 01663672 _____ (Malwarebytes) C:\Users\Bryan\Downloads\JRT.exe
2017-04-20 19:53 - 2017-04-20 19:53 - 00001227 _____ C:\Users\Bryan\Desktop\adwcleaner_6.045.exe - Shortcut.lnk
2017-04-20 19:52 - 2017-04-20 19:52 - 04089296 _____ C:\Users\Bryan\Downloads\adwcleaner_6.045.exe
2017-04-17 10:25 - 2017-04-17 10:25 - 00001171 _____ C:\Users\Bryan\Desktop\Facebook Gameroom.lnk
2017-04-17 10:25 - 2017-04-17 10:25 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook
2017-04-17 10:25 - 2017-04-17 10:25 - 00000000 ____D C:\Users\Bryan\AppData\Local\Facebook
2017-04-17 10:24 - 2017-04-17 10:24 - 00252112 _____ (Facebook) C:\Users\Bryan\Downloads\FacebookGameroom.exe
2017-04-14 21:22 - 2017-04-14 21:22 - 00123446 _____ C:\malware scan 4.txt
2017-04-12 11:42 - 2017-03-27 11:13 - 00394448 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-04-12 11:42 - 2017-03-27 10:28 - 00346320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-04-12 11:42 - 2017-03-25 12:39 - 20284416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-04-12 11:42 - 2017-03-25 12:07 - 04604416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-04-12 11:42 - 2017-03-25 12:06 - 13654016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-04-12 11:42 - 2017-03-25 11:55 - 02767360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-04-12 11:42 - 2017-03-25 11:51 - 01313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-04-12 11:42 - 2017-03-25 11:48 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-04-12 11:42 - 2017-03-25 11:47 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-04-12 11:42 - 2017-03-25 11:46 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-04-12 11:42 - 2017-03-25 11:46 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-04-12 11:42 - 2017-03-25 11:46 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-04-12 11:42 - 2017-03-25 11:14 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-04-12 11:42 - 2017-03-25 11:13 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-04-12 11:42 - 2017-03-25 11:10 - 02898432 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-04-12 11:42 - 2017-03-25 10:56 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-04-12 11:42 - 2017-03-25 10:52 - 25746944 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-04-12 11:42 - 2017-03-25 10:41 - 06045696 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-04-12 11:42 - 2017-03-25 10:04 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-04-12 11:42 - 2017-03-25 10:00 - 00725504 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-04-12 11:42 - 2017-03-25 09:59 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-04-12 11:42 - 2017-03-25 09:57 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-04-12 11:42 - 2017-03-25 09:57 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-04-12 11:42 - 2017-03-25 09:28 - 15259136 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-04-12 11:42 - 2017-03-25 09:27 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-04-12 11:42 - 2017-03-25 09:24 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-04-12 11:42 - 2017-03-25 09:10 - 01546240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-04-12 11:42 - 2017-03-25 09:01 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-04-12 11:42 - 2017-03-24 15:50 - 00405504 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-04-12 11:42 - 2017-03-24 15:42 - 00313344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-04-12 11:42 - 2017-03-22 08:32 - 03165184 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-04-12 11:42 - 2017-03-22 08:32 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-04-12 11:42 - 2017-03-22 08:32 - 00098816 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-04-12 11:42 - 2017-03-22 08:30 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
2017-04-12 11:42 - 2017-03-22 08:24 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-04-12 11:42 - 2017-03-22 08:17 - 02651136 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-04-12 11:42 - 2017-03-22 08:15 - 00709120 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-04-12 11:42 - 2017-03-22 08:15 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-04-12 11:42 - 2017-03-22 08:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2017-04-12 11:42 - 2017-03-22 08:15 - 00037888 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-04-12 11:42 - 2017-03-22 08:15 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
2017-04-12 11:42 - 2017-03-22 08:15 - 00012288 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
2017-04-12 11:42 - 2017-03-22 08:05 - 00573440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-04-12 11:42 - 2017-03-22 08:05 - 00093696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-04-12 11:42 - 2017-03-22 08:05 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-04-12 11:42 - 2017-03-22 08:05 - 00030208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2017-04-12 11:42 - 2017-03-14 08:34 - 00986344 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys
2017-04-12 11:42 - 2017-03-14 08:34 - 00265448 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms1.sys
2017-04-12 11:42 - 2017-03-10 09:35 - 00382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-04-12 11:42 - 2017-03-10 09:27 - 00308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-04-12 11:42 - 2017-03-10 09:00 - 03219968 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-04-12 11:42 - 2017-03-08 13:20 - 01133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2017-04-12 11:42 - 2017-03-08 13:10 - 00805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2017-04-12 11:42 - 2017-03-07 21:37 - 00631176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2017-04-12 11:42 - 2017-03-07 21:36 - 05548264 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-04-12 11:42 - 2017-03-07 21:36 - 00706792 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2017-04-12 11:42 - 2017-03-07 21:36 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2017-04-12 11:42 - 2017-03-07 21:36 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2017-04-12 11:42 - 2017-03-07 21:34 - 01732864 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-04-12 11:42 - 2017-03-07 21:33 - 02064384 _____ (Microsoft Corporation) C:\Windows\system32\ole32.dll
2017-04-12 11:42 - 2017-03-07 21:33 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2017-04-12 11:42 - 2017-03-07 21:33 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2017-04-12 11:42 - 2017-03-07 21:33 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-04-12 11:42 - 2017-03-07 21:26 - 04000488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2017-04-12 11:42 - 2017-03-07 21:26 - 03945192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2017-04-12 11:42 - 2017-03-07 21:24 - 01314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-04-12 11:42 - 2017-03-07 21:22 - 01416192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ole32.dll
2017-04-12 11:42 - 2017-03-07 21:21 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-04-12 11:42 - 2017-03-07 09:30 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\asycfilt.dll
2017-04-12 11:42 - 2017-03-07 09:17 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\asycfilt.dll
2017-04-12 11:42 - 2017-03-07 07:05 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll
2017-04-12 11:42 - 2017-03-03 18:27 - 01574912 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2017-04-12 11:42 - 2017-03-03 18:27 - 00093696 _____ (Microsoft Corporation) C:\Windows\system32\mfmjpegdec.dll
2017-04-12 11:42 - 2017-03-03 18:14 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2017-04-12 11:42 - 2017-03-03 18:14 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmjpegdec.dll
2017-04-12 11:42 - 2017-02-14 09:33 - 00757248 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-04-12 11:42 - 2017-02-14 09:19 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2017-04-12 11:42 - 2017-02-09 09:32 - 00769536 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll
2017-04-12 11:42 - 2017-02-09 09:32 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll
2017-04-12 11:42 - 2017-02-09 09:14 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00994760 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:36 - 00011608 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll
2017-04-12 11:42 - 2017-01-18 08:35 - 00011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll
2017-04-12 11:41 - 2017-03-25 11:52 - 02289152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-04-12 11:41 - 2017-03-25 11:47 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-04-12 11:41 - 2017-03-25 11:47 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-04-12 11:41 - 2017-03-25 11:46 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-04-12 11:41 - 2017-03-25 11:46 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-04-12 11:41 - 2017-03-25 11:46 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-04-12 11:41 - 2017-03-25 11:46 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-04-12 11:41 - 2017-03-25 11:46 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-04-12 11:41 - 2017-03-25 11:45 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-04-12 11:41 - 2017-03-25 11:45 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-04-12 11:41 - 2017-03-25 11:45 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-04-12 11:41 - 2017-03-25 11:45 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-04-12 11:41 - 2017-03-25 11:45 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-04-12 11:41 - 2017-03-25 11:45 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-04-12 11:41 - 2017-03-25 11:45 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-04-12 11:41 - 2017-03-25 11:44 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-04-12 11:41 - 2017-03-25 11:44 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-04-12 11:41 - 2017-03-25 11:35 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-04-12 11:41 - 2017-03-25 11:35 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-04-12 11:41 - 2017-03-25 11:16 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-04-12 11:41 - 2017-03-25 11:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-04-12 11:41 - 2017-03-25 11:13 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-04-12 11:41 - 2017-03-25 11:04 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-04-12 11:41 - 2017-03-25 11:02 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-04-12 11:41 - 2017-03-25 10:57 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-04-12 11:41 - 2017-03-25 10:56 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-04-12 11:41 - 2017-03-25 10:56 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-04-12 11:41 - 2017-03-25 10:56 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-04-12 11:41 - 2017-03-25 10:45 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-04-12 11:41 - 2017-03-25 10:41 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-04-12 11:41 - 2017-03-25 10:30 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-04-12 11:41 - 2017-03-25 10:29 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-04-12 11:41 - 2017-03-25 10:24 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-04-12 11:41 - 2017-03-25 10:23 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-04-12 11:41 - 2017-03-25 10:20 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-04-12 11:41 - 2017-03-25 10:19 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-04-12 11:41 - 2017-03-25 10:17 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-04-12 11:41 - 2017-03-25 10:06 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-04-12 11:41 - 2017-03-14 08:30 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\cdd.dll
2017-04-12 11:41 - 2017-03-10 09:31 - 00100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2017-04-12 11:41 - 2017-03-10 09:31 - 00046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-04-12 11:41 - 2017-03-10 09:31 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2017-04-12 11:41 - 2017-03-10 09:31 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2017-04-12 11:41 - 2017-03-10 09:20 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2017-04-12 11:41 - 2017-03-10 09:19 - 00070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2017-04-12 11:41 - 2017-03-10 09:19 - 00010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2017-04-12 11:41 - 2017-03-10 08:53 - 00034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:33 - 00003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2017-04-12 11:41 - 2017-03-07 21:22 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:21 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 21:03 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2017-04-12 11:41 - 2017-03-07 21:03 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2017-04-12 11:41 - 2017-03-07 21:03 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2017-04-12 11:41 - 2017-03-07 21:03 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2017-04-12 11:41 - 2017-03-07 21:00 - 00338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2017-04-12 11:41 - 2017-03-07 20:59 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2017-04-12 11:41 - 2017-03-07 20:57 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2017-04-12 11:41 - 2017-03-07 20:56 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-04-12 11:41 - 2017-03-07 20:56 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-04-12 11:41 - 2017-03-07 20:56 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-04-12 11:41 - 2017-03-07 20:55 - 00112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2017-04-12 11:41 - 2017-03-07 20:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2017-04-12 11:41 - 2017-03-07 20:54 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2017-04-12 11:41 - 2017-03-07 20:54 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2017-04-12 11:41 - 2017-03-07 20:54 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2017-04-12 11:41 - 2017-03-07 20:54 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2017-04-12 11:41 - 2017-03-07 20:53 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2017-04-12 11:41 - 2017-03-07 20:53 - 00006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 20:53 - 00004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 20:53 - 00003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2017-04-12 11:41 - 2017-03-07 20:53 - 00003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2017-04-12 11:41 - 2017-02-11 09:33 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-04-12 11:41 - 2017-02-11 09:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-04-12 11:41 - 2016-03-23 15:40 - 03181568 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll
2017-04-12 11:41 - 2016-03-23 15:40 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll
2017-04-05 19:46 - 2017-04-05 19:46 - 00000000 ____D C:\Users\Bryan\Downloads\winx-dvd-ripper-pt-offer (1)
2017-04-05 19:45 - 2017-04-05 19:45 - 40125143 _____ C:\Users\Bryan\Downloads\winx-dvd-ripper-pt-offer (1).zip
2017-04-04 20:09 - 2017-04-04 20:09 - 00399944 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-03-27 16:09 - 2017-03-27 16:09 - 00055757 _____ C:\Users\Bryan\Downloads\prize-form (4).pdf
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-04-20 22:23 - 2016-08-04 18:37 - 00000706 _____ C:\Windows\Tasks\WpsKtpcntrQingTask_Bryan.job
2017-04-20 22:21 - 2009-07-13 21:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-04-20 22:21 - 2009-07-13 21:45 - 00018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-04-20 22:14 - 2009-07-13 22:13 - 00781790 _____ C:\Windows\system32\PerfStringBackup.INI
2017-04-20 22:14 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\inf
2017-04-20 22:08 - 2014-09-12 19:01 - 00000000 ____D C:\ProgramData\NVIDIA
2017-04-20 22:08 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-04-20 21:59 - 2016-08-04 18:37 - 00000412 _____ C:\Windows\Tasks\WpsExternal_20160804183703.job
2017-04-18 03:27 - 2015-02-15 02:17 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-04-18 03:25 - 2015-02-15 02:15 - 00000000 ____D C:\Program Files\Microsoft Office 15
2017-04-16 07:48 - 2017-02-21 18:06 - 00004172 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-04-15 12:57 - 2015-12-18 13:57 - 00000000 ____D C:\Program Files\Defraggler
2017-04-14 21:22 - 2016-08-20 11:17 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\IObit
2017-04-14 20:38 - 2014-09-16 22:13 - 00192216 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-04-13 17:18 - 2015-02-18 05:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Picasa 3
2017-04-13 14:01 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\system32\NDF
2017-04-13 10:42 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
2017-04-13 03:24 - 2016-07-31 06:06 - 00374816 _____ C:\Windows\system32\FNTCACHE.DAT
2017-04-12 03:58 - 2016-08-28 12:05 - 00003894 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1472411119
2017-04-12 03:57 - 2014-09-12 21:04 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2017-04-12 03:57 - 2014-09-12 21:04 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2017-04-12 03:36 - 2014-09-12 21:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-04-12 03:31 - 2014-09-12 21:01 - 00000000 ____D C:\Windows\system32\MRT
2017-04-12 03:15 - 2014-09-12 21:01 - 148601744 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-04-12 03:06 - 2014-09-14 00:11 - 00773912 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2017-04-11 20:57 - 2014-09-12 20:37 - 00003330 _____ C:\Windows\System32\Tasks\googleupdatetaskmachineua
2017-04-11 20:57 - 2014-09-12 20:36 - 00003202 _____ C:\Windows\System32\Tasks\googleupdatetaskmachinecore
2017-04-11 18:37 - 2015-07-26 16:33 - 00004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2017-04-11 18:36 - 2016-11-30 15:58 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-04-10 16:08 - 2015-02-18 05:38 - 00003508 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA
2017-04-10 16:08 - 2015-02-18 05:38 - 00003236 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001Core
2017-04-05 19:48 - 2016-11-27 21:07 - 00001338 _____ C:\Users\Public\Desktop\WinX DVD Ripper Platinum.lnk
2017-04-04 20:09 - 2016-08-28 11:51 - 00556784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-04-04 20:09 - 2016-08-28 11:51 - 00339696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-04-04 20:09 - 2016-08-28 11:51 - 00164064 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-04-04 20:09 - 2016-08-28 11:51 - 00127112 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-04-04 20:09 - 2016-08-28 11:51 - 00101152 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-04-04 20:09 - 2016-08-28 11:51 - 00075704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-04-04 20:09 - 2016-08-28 11:51 - 00038296 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-04-04 20:08 - 2017-02-21 18:05 - 00334088 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-04-04 20:08 - 2017-02-21 18:05 - 00307736 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-04-04 20:08 - 2017-02-21 18:05 - 00189768 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-04-04 20:08 - 2017-02-21 18:05 - 00048528 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-04-04 20:08 - 2016-08-28 12:04 - 00032600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-04-04 20:08 - 2016-08-28 11:51 - 01005048 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-04-03 15:59 - 2014-09-12 20:37 - 00002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
 
==================== Files in the root of some directories =======
 
2016-08-28 14:52 - 2016-08-28 15:17 - 0000120 _____ () C:\Users\Bryan\AppData\Roaming\wklnhst.dat
2016-05-24 09:42 - 2016-05-24 09:42 - 0000017 _____ () C:\Users\Bryan\AppData\Local\resmon.resmoncfg
2016-01-11 23:28 - 2016-01-11 23:28 - 0986063 _____ () C:\Users\Bryan\AppData\Local\Zip-File-Opener_1706.rar
2015-01-02 22:38 - 2015-01-02 22:38 - 0000057 _____ () C:\ProgramData\Ament.ini
2015-12-18 13:30 - 2015-12-18 13:38 - 0000193 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
 
Some files in TEMP:
====================
2017-02-26 02:00 - 2017-02-26 02:00 - 0003584 _____ () C:\Users\Bryan\AppData\Local\Temp\ckxj-cvh.dll
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-04-13 01:00
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20-04-2017
Ran by [removed] (20-04-2017 22:26:42)
Running from C:\Users\[removed]\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2014-09-13 02:47:10)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1069211171-1032678597-3133260682-500 - Administrator - Disabled)
Ashanthe (S-1-5-21-1069211171-1032678597-3133260682-1005 - Limited - Enabled) => C:\Users\Ashanthe
Bryan (S-1-5-21-1069211171-1032678597-3133260682-1001 - Administrator - Enabled) => C:\Users\Bryan
danbear11 (S-1-5-21-1069211171-1032678597-3133260682-1004 - Limited - Enabled) => C:\Users\danbear11
Guest (S-1-5-21-1069211171-1032678597-3133260682-501 - Limited - Enabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-1069211171-1032678597-3133260682-1002 - Limited - Enabled)
SophosSAUARTADI-PC0 (S-1-5-21-1069211171-1032678597-3133260682-1006 - Limited - Enabled)
Zanthia (S-1-5-21-1069211171-1032678597-3133260682-1003 - Administrator - Enabled) => C:\Users\Zanthia
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Disabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Disabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 16.01 (HKLM-x32\…\7-Zip) (Version: 16.01 - Igor Pavlov)
7-Zip 16.02 (x64) (HKLM\…\7-Zip) (Version: 16.02 - Igor Pavlov)
7-Zip 16.04 (HKLM-x32\…\{23170F69-40C1-2701-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
7-Zip 16.04 (x64 edition) (HKLM\…\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
Acer Assist (HKLM-x32\…\Acer Assist) (Version:  - Acer Incorporated)
Acer Backup Manager (HKLM-x32\…\InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}) (Version: 2.0.2.19 - NewTech Infosystems)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Acer Incorporated)
Acer Games (HKLM-x32\…\WildTangent acer Master Uninstall) (Version: 1.0.0.71 - WildTangent)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.02.3006 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\…\Acer Screensaver) (Version: 1.2.0812 - Acer Incorporated)
Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 24.0.0.180 - Adobe Systems Incorporated)
Adobe Flash Player 24 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Adobe Flash Player 24 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 24.0.0.194 - Adobe Systems Incorporated)
Advanced IP Scanner 2.4 (HKLM-x32\…\{2E644D2D-993F-43B4-B85A-15363CA777C3}) (Version: 2.4.3021 - Famatech)
Advertising Center (x32 Version: 0.0.0.2 - Nero AG) Hidden
Amazon Music (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Amazon Amazon Music) (Version: 3.8.1.754 - Amazon Services LLC)
Avast Pro Antivirus (HKLM-x32\…\Avast Antivirus) (Version: 17.3.2291 - AVAST Software)
Backup Manager Advance (x32 Version: 2.0.2.19 - NewTech Infosystems) Hidden
Box Sync (HKLM\…\{8706624B-B498-455D-9606-3130782C20B3}) (Version: 4.0.6621.0 - Box, Inc.)
Box Sync (x32 Version: 4.0.5253.0 - Box Inc.) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.15 - Piriform)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Core Temp 1.1 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.1 - Alcpu)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Defraggler (HKLM\…\Defraggler) (Version: 2.21 - Piriform)
Dropbox (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Dropbox) (Version: 3.16.1 - Dropbox, Inc.)
EaseUS Data Recovery Wizard 9.5 (HKLM\…\EaseUS Data Recovery Wizard 9.5_is1) (Version:  - EaseUS)
eSobi v2 (HKLM-x32\…\InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.4.000274 - esobi Inc.)
eSobi v2 (x32 Version: 2.0.4.000274 - esobi Inc.) Hidden
f.lux (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Flux) (Version:  - )
Facebook Gameroom 1.3.1.3 (HKLM-x32\…\{7E155A45-DE1A-46E0-A6B2-10FE1D8501FC}) (Version: 1.3.1.3 - Facebook)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 57.0.2987.133 - Google Inc.)
Google Earth Pro (HKLM-x32\…\{44FC61F0-2F8A-11E3-8CAE-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Photos Backup (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.33.3 - Google Inc.) Hidden
Greenshot 1.2.9.104 (HKLM\…\Greenshot_is1) (Version: 1.2.9.104 - Greenshot)
HostsMan 4.1.96 (HKLM-x32\…\{1A3DD1A9-7B7B-4ECA-AD2F-98466F49F62C}_is1) (Version: 4.1.96.0 - abelhadigital.com)
Hotkey Utility (HKLM-x32\…\Hotkey Utility) (Version: 1.00.3004 - Acer Incorporated)
HP Dropbox Plugin (HKLM-x32\…\{23617173-F935-4C17-A323-EB1207F3ED49}) (Version: 36.0.31.53050 - Hewlett-Packard Co.)
HP ENVY 4510 series Basic Device Software (HKLM\…\{E9FE2E2C-FF62-4C23-B816-62B6EEA1A772}) (Version: 36.0.72.54013 - Hewlett-Packard Co.)
HP ENVY 4510 series Help (HKLM-x32\…\{CB5C9CB2-B471-42CC-93E6-D0E15021D5C2}) (Version: 36.0.0 - Hewlett Packard)
HP FWUpdateEDO2 (HKLM-x32\…\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Google Drive Plugin (HKLM-x32\…\{AFF80405-E56A-48E7-98FC-8E46E261949F}) (Version: 36.0.31.53050 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Support Solutions Framework (HKLM-x32\…\{A772EA32-AE5B-4474-BFC0-4C69C04AFF6A}) (Version: 12.4.18.7 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (x32 Version: 1.00.0001 - Microsoft) Hidden
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3002 - Acer Incorporated)
ImagXpress (x32 Version: 7.0.74.0 - Nero AG) Hidden
Jarte (HKLM-x32\…\Jarte_is1) (Version: 5.4 - Carolina Road Software L.L.C.)
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
LG United Mobile Driver (HKLM-x32\…\{2A3A4BD6-6CE0-4e2a-80D2-1D0FF6ACBFBA}) (Version: 3.12.3.0 - LG Electronics)
LGFlashTool 1.8.1.1023 (HKLM-x32\…\LGFlashTool) (Version: 1.8.1.1023 - LGE)
Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
MediaFire Desktop (HKLM-x32\…\MediaFire Desktop 1.4.25.10813) (Version: 1.4.26.10815 - MediaFire)
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\OneDriveSetup.exe) (Version: 17.3.6390.0509 - Microsoft Corporation)
Microsoft OneNote 2013 - en-us (HKLM\…\OneNoteFreeRetail - en-us) (Version: 15.0.4919.1002 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50906.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB  (HKLM\…\{E4A1FDA3-689D-44DA-9B39-86BD2270F522}) (Version: 11.2.5058.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects  (x64) (HKLM\…\{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\…\{99AC7F47-A4E0-4706-9C65-8948775C2652}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Works (HKLM-x32\…\{67E03279-F703-408F-B4BF-46B5FC8D70CD}) (Version: 9.7.0621 - Microsoft Corporation)
MiniTool Partition Wizard Professional Edition 9.1 (HKLM\…\{69237D97-3063-450F-AE49-2357B191EA5D}_is1) (Version:  - MiniTool Solution Ltd.)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 38.0.5 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 38.0.5 (x86 en-US)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 38.0.5 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyWinLocker (HKLM-x32\…\{68301905-2DEA-41CE-A4D4-E8B443B099BA}) (Version: 3.1.76.0 - Egis Technology Inc.)
Nero 9 Essentials (HKLM-x32\…\{0b739e85-e796-499c-98fe-3be76860dfd0}) (Version:  - Nero AG)
Nmap 7.00 (HKLM-x32\…\Nmap) (Version:  - )
NVIDIA 3D Vision Controller Driver 340.50 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 341.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 341.44 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation)
NVIDIA ForceWare Network Access Manager (HKLM-x32\…\InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}) (Version:  - )
NVIDIA GeForce Experience 2.2.2 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)
NVIDIA Graphics Driver 341.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.44 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\…\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4919.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4919.1002 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4919.1002 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\…\OpenAL) (Version:  - )
OpenDNS Updater 2.2.1 (HKLM-x32\…\OpenDNS Updater) (Version: 2.2.1 - )
Oracle VM VirtualBox 5.0.2 (HKLM\…\{6CB00039-29CC-42A1-8ED2-820821DA2B8A}) (Version: 5.0.2 - Oracle Corporation)
Paragon Backup and Recovery™ 16 (HKLM\…\{DADAA9CF-36B6-11E6-B0B5-005056C00008}) (Version: 10.28.101 - Paragon Software)
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
PokerStars (HKLM-x32\…\PokerStars) (Version:  - PokerStars)
Product Improvement Study for HP ENVY 4510 series (HKLM\…\{CE8D3871-0B4C-45A8-8380-1F1BBD4AD33D}) (Version: 36.0.72.54013 - Hewlett-Packard Co.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5898 - Realtek Semiconductor Corp.)
Recuva (HKLM\…\Recuva) (Version: 1.52 - Piriform)
Revo Uninstaller 2.0.1 (HKLM\…\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.1 - VS Revo Group, Ltd.)
Revo Uninstaller Pro 3.1.7 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.7 - VS Revo Group, Ltd.)
SafeZone Stable 3.55.2393.596 (x32 Version: 3.55.2393.596 - Avast Software) Hidden
Serif PanoramaPlus Starter Edition (HKLM-x32\…\{64AEB598-E518-4AD0-B02B-99F365B8054C}) (Version: 2.0.0.001 - Serif (Europe) Ltd)
SHIELD Streaming (Version: 4.0.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (Version: 17.12.8 - NVIDIA Corporation) Hidden
Stellarium 0.15.0 (HKLM\…\Stellarium_is1) (Version: 0.15.0 - Stellarium team)
System Requirements Lab Detection (HKLM-x32\…\{B9C5A961-B5D5-4F55-9E9E-006FE3A85227}) (Version: 2.2.1.0 - Husdawg, LLC)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Watermark Software 8.1 (HKLM-x32\…\Watermark Software) (Version: 8.1 - watermark-software.com)
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.00.3008 - Acer Incorporated)
Windows Driver Package - Hisense Corporation hsCDFiDrv CDROM  (07/12/2010 1.01.00) (HKLM\…\D6CCB3CCE9E8F1119A58ECAB8CE0B3B24A78942E) (Version: 07/12/2010 1.01.00 - Hisense Corporation)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2980 - CACE Technologies)
WinX DVD Copy Pro 3.6.5 (HKLM\…\WinX DVD Copy Pro_is1) (Version:  - Digiarty Software,Inc.)
WinX DVD Ripper Platinum 8.0.0 (HKLM-x32\…\WinX DVD Ripper Platinum_is1) (Version:  - Digiarty Software, Inc.)
WinX HD Video Converter Deluxe 5.6.2 (HKLM-x32\…\WinX HD Video Converter Deluxe_is1) (Version:  - Digiarty Software, Inc.)
Wireshark 2.0.1 (64-bit) (HKLM-x32\…\Wireshark) (Version: 2.0.1 - The Wireshark developer community, hxxps://www.wireshark.org)
WPS Office (10.1.0.5656) (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Kingsoft Office) (Version: 10.1.0.5656 - Kingsoft Corp.)
Zynewave Podium Free 3.2.1 (x64) (HKLM\…\{EFA46A5D-4ACD-4665-A074-1B7CF713A9BB}) (Version: 3.2.1 - Zynewave)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll ()
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll (Google Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {064EE1AB-DBC2-458B-AB6E-5384536BCF1D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-02-12] (Piriform Ltd)
Task: {0D30B4CF-2B59-4B0E-AFD1-8E7F32225BF5} - System32\Tasks\HPCustParticipation HP ENVY 4510 series => C:\Program Files\HP\HP ENVY 4510 series\Bin\HPCustPartic.exe [2015-03-09] (Hewlett-Packard Development Company, LP)
Task: {17032E99-B369-4201-9703-F2860B7891D3} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-03-14] (Microsoft Corporation)
Task: {2A84CF68-5A68-418E-9C27-DC135EC32E85} - System32\Tasks\googleupdatetaskmachinecore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {2BC2695E-8B0A-4AD2-AB6C-20EC1AD53AB7} - System32\Tasks\WpsKtpcntrQingTask_Bryan => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exe [2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {325D5EEC-A3D8-4FCE-92A8-417092DCF0A5} - System32\Tasks\WpsExternal_20160804183703 => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\ksolaunch.exe [2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {3FE34152-9031-4426-AB0D-73A87CB472E3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-05-09] (Hewlett-Packard)
Task: {5D47D0F6-7E96-47AC-A0D8-4873599B7AD6} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-02-02] (Adobe Systems Incorporated)
Task: {7330AB6F-E50C-47E3-BE07-62C22864CF88} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-04-13] (AVAST Software)
Task: {79C9FB33-975A-4580-9897-6E8615E55720} - System32\Tasks\{486A61CF-7BE3-4D52-81C7-6AE86E41C66E} => Iexplore.exe hxxp://ui.skype.com/ui/0/6.3.73.105.457/en/abandoninstall?page=tsWLM
Task: {79E3E16F-73E3-4D37-B7DA-975698283354} - System32\Tasks\googleupdatetaskmachineua => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {81A4E882-696C-4222-8D9D-71EFE224F729} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-03-14] (Microsoft Corporation)
Task: {89A88E6B-9624-4C8F-9ABB-92125ED0B39A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-01-14] (Adobe Systems Incorporated)
Task: {9E5D32EE-277C-4623-810F-C69B3A0E5978} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {AA6D2334-BA38-4774-91D4-64A432DAE773} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001Core => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {AED7BE87-1F4D-4DB6-A4D5-A50CA89BE6B6} - System32\Tasks\SafeZone scheduled Autoupdate 1472411119 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-03-22] (Avast Software)
Task: {B3CEDE53-F48D-4FF5-A3C0-8E94190DF8DC} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA => C:\Users\Bryan\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-14] (Dropbox, Inc.)
Task: {C6BFBECF-A713-4CBE-9CE3-36C96C805246} - System32\Tasks\Acer Registration Data Sending => C:\Program Files (x86)\Acer\Registration\GREG.exe [2009-08-28] (Acer Incorporated)
Task: {E0B01958-B00F-4779-A383-FDA5C239721E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-05-04] (Hewlett-Packard)
Task: {E48CB9C2-85AE-4F8C-BC2D-8BADD36BBDFE} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-04-04] (AVAST Software)
Task: {FDCCDC42-8A37-4C52-A163-A5AF0DEDCF96} - System32\Tasks\dropboxupdatetaskusers-1-5-21-1069211171-1032678597-3133260682-1001core => C:\Users\Bryan\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-14] (Dropbox, Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\WpsExternal_20160804183703.job => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\ksolaunch.exe
Task: C:\Windows\Tasks\WpsKtpcntrQingTask_Bryan.job => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exe Ãqing 10.1.0.5656 xxx server_url=hxxp:/kdl1.cache.wps.com/ksodl/wpscfg/client/____client____html____service____bubble.html ic_server_url=hxxp:/info.kingsoftstore.com/wpsv6internet/infos.ads
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\Bryan\Desktop\Contest Lobby - DraftKings.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  –profile-directory=Default –app-id=loelnclfphlfeopbkllhhjjkdnnioacd
ShortcutWithArgument: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Contest Lobby - DraftKings.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) ->  –profile-directory=Default –app-id=loelnclfphlfeopbkllhhjjkdnnioacd
ShortcutWithArgument: C:\Users\Public\Desktop\Netflix.lnk -> C:\ProgramData\OEM_E471269A730D\Netflix\StartURL.exe () -> hxxp://homepage.acer.com/redirect.aspx?rid=09000001
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-02-15 02:15 - 2017-01-17 04:25 - 00117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2016-05-24 22:18 - 2016-05-24 22:27 - 00076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2009-04-19 08:34 - 2009-04-19 08:34 - 00625184 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
2009-04-19 08:34 - 2009-04-19 08:34 - 00070176 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll
2009-04-19 08:34 - 2009-04-19 08:34 - 00578080 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll
2009-04-19 08:34 - 2009-04-19 08:34 - 00207904 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
2016-05-21 14:12 - 2016-05-21 14:12 - 00959168 _____ () C:\Users\Bryan\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2017-03-22 08:37 - 2017-01-31 05:34 - 08909512 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2017-04-04 20:09 - 2017-04-04 20:09 - 00170216 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-04-04 20:09 - 2017-04-04 20:09 - 00176480 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-04-20 13:58 - 2017-04-20 13:58 - 05917184 _____ () C:\Program Files\AVAST Software\Avast\defs\17042010\algo.dll
2017-04-04 20:09 - 2017-04-04 20:09 - 00653520 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-04-04 20:09 - 2017-04-04 20:09 - 00230632 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2009-02-02 17:33 - 2009-02-02 17:33 - 00460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2008-09-28 17:55 - 2008-09-28 17:55 - 01076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
2016-08-28 11:50 - 2016-08-28 11:50 - 48936448 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-04-04 20:08 - 2017-04-04 20:08 - 00293936 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-04-03 15:59 - 2017-03-28 19:04 - 02187096 _____ () C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\libglesv2.dll
2017-04-03 15:59 - 2017-03-28 19:04 - 00086360 _____ () C:\Program Files (x86)\Google\Chrome\Application\57.0.2987.133\libegl.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com
 
There are 7865 more sites.
 
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\facebook.com -> hxxps://staticxx.facebook.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\facebook.net -> hxxps://connect.facebook.net
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\fbcdn.net -> hxxps://static.xx.fbcdn.net
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\google-analytics.com -> hxxps://www.google-analytics.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\hosts -> hxxps://hosts
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\paragon-software.com -> hxxps://bo4-fe.paragon-software.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\pch.com -> hxxps://pch.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\pga.com -> hxxps://pga.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123simsen.com -> www.123simsen.com
 
There are 7865 more sites.
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 19:34 - 2016-11-23 14:47 - 00000035 ____A C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: AdobeARMservice => 3
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TCP Query User{8C3230A9-3B37-4AB0-BF07-F92E56E6D000}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [UDP Query User{C5ECB86D-D992-4133-85A8-E2375ADBE977}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [{C1131851-AE0D-47EC-985D-3B54FFB37410}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A2186EEF-31C0-4771-8F5C-20057A62313F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{1F0A2EEF-2338-4C46-B282-735BCF6E757B}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [UDP Query User{EEF57E84-7427-4683-9F0A-911AF23E417E}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [TCP Query User{022FA091-367D-4079-A8A2-ED2592DD7D24}C:\program files (x86)\frostwire\frostwire.exe] => (Block) C:\program files (x86)\frostwire\frostwire.exe
FirewallRules: [UDP Query User{09F60FA5-71A9-473F-8B6A-E4D4253CEA95}C:\program files (x86)\frostwire\frostwire.exe] => (Block) C:\program files (x86)\frostwire\frostwire.exe
FirewallRules: [{B3DA051D-830C-4383-97B3-86C0DDE059B8}] => (Allow) C:\Users\Bryan\Downloads\solutoinstaller.exe
FirewallRules: [{012249DF-E899-4E68-ADA6-4099377F6DD7}] => (Allow) C:\Users\Bryan\Downloads\solutoinstaller.exe
FirewallRules: [{044001A0-E716-4D0D-81B1-70E9FD015F95}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9283772B-511B-4821-B133-BED4BF4AB2AC}] => (Allow) LPort=2869
FirewallRules: [{DCDC16A6-6A0C-4C05-AA19-AFE390FD2405}] => (Allow) LPort=1900
FirewallRules: [{2260B718-D95B-4B4D-95FA-609C9FBB7636}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{695FD75E-C711-464D-BAB3-B87FFB5CB693}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{39F77321-AFFB-49F6-9E20-BB09C6108758}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{5FE532DA-7DCE-4498-B1D7-2EA7839AA5AE}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{8C3A945E-2263-4351-957B-7DB970A38D0C}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{A7F95135-CCD5-473A-839D-E4F426AB21F8}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS09EB\HP.EasyStart.exe
FirewallRules: [{984BB3F6-E964-4B8E-9BA2-E6A1510F0A5E}] => (Allow) C:\Program Files\HP\HP ENVY 4510 series\Bin\DeviceSetup.exe
FirewallRules: [{3BDD8F22-9012-4F6D-9C1A-BED6890F1F1F}] => (Allow) LPort=5357
FirewallRules: [{C7ED9287-EAE5-4029-85CD-CBC94782DC03}] => (Allow) C:\Program Files\HP\HP ENVY 4510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{57ED47F0-4F49-456A-929B-2E775595F985}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2E65\HPDiagnosticCoreUI.exe
FirewallRules: [{539324E4-FE1E-4767-8DC0-C08D87D50E71}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2E65\HPDiagnosticCoreUI.exe
FirewallRules: [{D51CA84B-F225-4D3E-98D5-0E86499BA40A}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2EAD\HPDiagnosticCoreUI.exe
FirewallRules: [{574DA190-38B0-4004-BBAC-4C39E5F47175}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS2EAD\HPDiagnosticCoreUI.exe
FirewallRules: [{A00F1B2E-031B-480F-AE27-B72AF2D5E08A}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
FirewallRules: [{AEF819C4-15BE-4827-A80D-FEFD9DAD7A9A}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
FirewallRules: [{65ABF914-9DF7-4667-940A-D38951B87F6C}] => (Allow) C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{57E388FA-A5E9-44F8-8988-CF70A5ECAF01}] => (Allow) C:\Program Files (x86)\pandasecuritytb\ToolbarCleaner.exe
FirewallRules: [{F2301F04-2268-4612-B640-411F080B6C2A}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS5761\HPDiagnosticCoreUI.exe
FirewallRules: [{BA79D814-7ED2-49B5-ACE1-BF9408D60E3A}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS5761\HPDiagnosticCoreUI.exe
FirewallRules: [{40DE9545-9D62-4219-8336-F7C9D640F5AE}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS6D1A\HPDiagnosticCoreUI.exe
FirewallRules: [{57991DE4-5A64-4175-AB5C-8C993868D41E}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS6D1A\HPDiagnosticCoreUI.exe
FirewallRules: [{610620A6-A213-4C59-AA61-47EDA9D1CC90}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS57A1\HPDiagnosticCoreUI.exe
FirewallRules: [{EBE92228-91A5-4A53-8D86-A7EF6CD77ED4}] => (Allow) C:\Users\Bryan\AppData\Local\Temp\7zS57A1\HPDiagnosticCoreUI.exe
FirewallRules: [{79FF7194-97BF-4CCD-89D2-1497EB37615E}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.590_0\SZBrowser.exe
FirewallRules: [{D6FE2700-2EF8-4F86-ADD4-C4DAD1496CE0}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{1D26E21E-B6B3-4864-83B0-BB8B90B39630}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.596\SZBrowser.exe
 
==================== Restore Points =========================
 
12-04-2017 03:00:47 Windows Update
13-04-2017 03:00:23 Windows Update
20-04-2017 22:15:45 JRT Pre-Junkware Removal
 
==================== Faulty Device Manager Devices =============
 
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (04/13/2017 01:57:06 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/29/2017 05:30:26 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (01/28/2017 04:50:38 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (01/14/2017 08:03:56 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: wmpnetwk.exe, version: 12.0.7601.17514, time stamp: 0x4ce7ae7f
Faulting module name: KERNELBASE.dll, version: 6.1.7601.23572, time stamp: 0x57fd0696
Exception code: 0x0000046b
Fault offset: 0x000000000001a06d
Faulting process id: 0xf8c
Faulting application start time: 0x01d26a9c3c5109c0
Faulting application path: C:\Program Files\Windows Media Player\wmpnetwk.exe
Faulting module path: C:\Windows\system32\KERNELBASE.dll
Report Id: ab6d4380-da6a-11e6-8d9a-00262d289fc4
 
Error: (12/27/2016 12:13:36 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (12/17/2016 09:25:19 AM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: System.Web.Routing, Version=3.5.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35 . Error code = 0x80070020
 
Error: (12/17/2016 09:07:22 AM) (Source: .NET Runtime Optimization Service) (EventID: 1101) (User: )
Description: .NET Runtime Optimization Service (clr_optimization_v4.0.30319_64) - Failed to compile: Microsoft.Office.Tools.Word.v9.0, Version=9.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a . Error code = 0x80070020
 
Error: (12/17/2016 04:42:06 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (12/17/2016 04:42:06 AM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows\Installer\{67E03279-F703-408F-B4BF-46B5FC8D70CD}\WksWP.exe".
Dependent Assembly msadctls,processorArchitecture="x86",type="win32",version="1.0.1801.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
 
Error: (12/17/2016 04:02:18 AM) (Source: Windows Search Service) (EventID: 3007) (User: )
Description: Performance monitoring cannot be initialized for the gatherer object, because the counters are not loaded or the shared memory object cannot be opened. This only affects availability of the perfmon counters. Restart the computer.
 
Context:  Application, SystemIndex Catalog
 
 
System errors:
=============
Error: (04/20/2017 10:17:36 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The NVIDIA Display Driver Service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (04/20/2017 10:08:41 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
eorclc
 
Error: (04/20/2017 10:08:26 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NetDrive2_Service_NetDrive2 service failed to start due to the following error: 
The system cannot find the file specified.
 
Error: (04/20/2017 10:06:21 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
An instance of the service is already running.
 
Error: (04/20/2017 10:05:51 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (04/20/2017 10:05:48 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Microsoft Office ClickToRun Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 0 milliseconds: Restart the service.
 
Error: (04/20/2017 10:05:40 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Media Player Network Sharing Service service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 30000 milliseconds: Restart the service.
 
Error: (04/20/2017 10:05:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The ForceWare IP service service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (04/20/2017 10:05:37 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The ForceWare Intelligent Application Manager (IAM) service terminated unexpectedly.  It has done this 1 time(s).
 
Error: (04/20/2017 10:05:36 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Live ID Sign-in Assistant service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 10000 milliseconds: Restart the service.
 
 
==================== Memory info =========================== 
 
Processor: AMD Athlon™ II X2 215 Processor 
Percentage of memory in use: 50%
Total physical RAM: 3838.55 MB
Available physical RAM: 1905.64 MB
Total Virtual: 7675.29 MB
Available Virtual: 5689.18 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:698.63 GB) (Free:606.6 GB) NTFS ==>[drive with boot components (obtained from BCD)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 698.6 GB) (Disk ID: 6E286E28)
Partition 1: (Active) - (Size=698.6 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

There’s no sign of anything bad on your computer but a few things that need tidying up.

First

You need to move Farbar Recovery Scan Tool to your desktop otherwise fixes will not work.

  • go to your Downloads folder and locate Farbar Recovery Scan Tool
  • right click and select Cut
  • go to an empty spot on your desktop, right click and select Paste

Farbar Recovery Scan Tool should now be on your desktop.

================================================

Run Farbar Recovery Scan Tool

Open notepad. Please copy the contents of the code box below and paste it into Notepad.

CloseProcesses:
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {14d88b8c-41df-11e5-81d8-00262d289fc4} - G:\LG_PC_Programs.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {2ed78b9e-4ad6-11e4-b18e-00262d289fc4} - G:\LG_PC_Programs.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {a21070b2-0165-11e6-bda4-00262d289fc4} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {bb746c77-426c-11e4-b370-00262d289fc4} - G:\LaunchU3.exe -a
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {ce33646d-05b5-11e6-8974-00262d289fc4} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {eabd1f25-3ae8-11e4-ae5d-806e6f6e6963} - D:\setup\rsrc\Autorun.exe
HKU\S-1-5-18\…\Run: [AviraSpeedup] => "C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun
ShellIconOverlayIdentifiers: [    BoxSyncFileLocked] -> {2a607da5-abe8-358e-a881-c0f5faf2d3a5} =>
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShortcutTarget: Dropbox.lnk -> C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
BootExecute: autocheck autochk * sdnclean64.exe
SearchScopes: HKLM -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKLM-x32 -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_enUS605
SearchScopes: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
S2 NetDrive2_Service_NetDrive2; C:\Program Files\NetDrive2\nd2svc.exe [X]
S0 eorclc; no ImagePath
S3 avchv; system32\DRIVERS\avchv.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
2017-04-14 21:22 - 2016-08-20 11:17 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\IObit
C:\Users\Bryan\AppData\Roaming\wklnhst.dat
C:\Users\Bryan\AppData\Local\resmon.resmoncfg
C:\Users\Bryan\AppData\Local\Zip-File-Opener_1706.rar
C:\ProgramData\Ament.ini
C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
C:\Users\Bryan\AppData\Local\Temp\ckxj-cvh.dll
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\facebook.com -> hxxps://staticxx.facebook.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\facebook.net -> hxxps://connect.facebook.net
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\fbcdn.net -> hxxps://static.xx.fbcdn.net
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\google-analytics.com -> hxxps://www.google-analytics.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\hosts -> hxxps://hosts
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\paragon-software.com -> hxxps://bo4-fe.paragon-software.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\pch.com -> hxxps://pch.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\pga.com -> hxxps://pga.com
FirewallRules: [TCP Query User{022FA091-367D-4079-A8A2-ED2592DD7D24}C:\program files (x86)\frostwire\frostwire.exe] => (Block) C:\program files (x86)\frostwire\frostwire.exe
FirewallRules: [UDP Query User{09F60FA5-71A9-473F-8B6A-E4D4253CEA95}C:\program files (x86)\frostwire\frostwire.exe] => (Block) C:\program files (x86)\frostwire\frostwire.exe
C:\Program Files (x86)\Avira
C:\Users\Bryan\AppData\Roaming\IObit
C:\Users\Bryan\AppData\Roaming\wklnhst.dat
C:\Users\Bryan\AppData\Local\resmon.resmoncfg
C:\Users\Bryan\AppData\Local\Zip-File-Opener_1706.rar
C:\ProgramData\Ament.ini
C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
C:\Users\Bryan\AppData\Local\Temp\ckxj-cvh.dll
C:\program files (x86)\frostwire
Hosts:
EmptyTemp:

NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

  • save the files as fixlist.txt in the same folder as FRST – NOTE: It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
  • run FRST64 then click Fix just once and wait
  • it will create a log on your desktop, (Fixlog.txt); please post it to your reply.

================================================

Run Malwarebytes Anti-Malware

Please download and run the installer for Malwarebytes 3.0.

  • follow the prompts to install the program, (Malwarebytes 3.0 will automatically upgrade Malwarebytes Anti-Malware 2.x to Malwarebytes 3.0)
  • at the end, be sure a checkmark is placed next to the following
    • Launch Malwarebytes Anti-Malware
    • a 14 day trial of the Premium features is pre-selected: deselect this if you don’t want it, (it won’t diminish the scanning and removal capabilities of the program).
  • click Finish.
  • on the Dashboard, click Update Now
  • after the update completes, click the Scan Now' button.
  • if an update is available, clicking the Update Now button will update it
  • a Threat Scan will begin.
  • when the scan is complete, if malware has been detected, click Apply Actions to allow MBAM to clean what was found
  • when the prompt to restart the computer appears, click Yes.
  • after the restart once you are back at your desktop, open MBAM once more
  • click on the ‘History’ tab, the ‘Application Logs’
  • double-click on the scan log which shows the date and time of the scan just performed.
  • click Copy to Clipboard
  • please paste the contents of the clipboard into your reply.

================================================

Run Security Check

Download Security Check by screen317 from here.

  • save it to your Desktop.
  • double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • a Notepad document should open automatically called checkup.txt; please post the contents of that document.

NOTE: If you get the following message: UNSUPPORTED OPERATING SYSTEM! ABORTED!, try rebooting the system and then run SecurityCheck again.

Logs to include with the next post:

Fixlog.txt
Mbam.txt
checkup.txt


Satchfan

 

Do you want me to run Farbar tool first then open notepad and paste the script you wrote or do notepad first then run farbar?

Here are the logs.

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 20-04-2017
Ran by [removed] (21-04-2017 09:06:23) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CloseProcesses:
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {14d88b8c-41df-11e5-81d8-00262d289fc4} - G:\LG_PC_Programs.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {2ed78b9e-4ad6-11e4-b18e-00262d289fc4} - G:\LG_PC_Programs.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {a21070b2-0165-11e6-bda4-00262d289fc4} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {bb746c77-426c-11e4-b370-00262d289fc4} - G:\LaunchU3.exe -a
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {ce33646d-05b5-11e6-8974-00262d289fc4} - G:\HTC_Sync_Manager_PC.exe
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\MountPoints2: {eabd1f25-3ae8-11e4-ae5d-806e6f6e6963} - D:\setup\rsrc\Autorun.exe
HKU\S-1-5-18\…\Run: [AviraSpeedup] => "C:\Program Files (x86)\Avira\AviraSpeedup\avira_system_speedup.exe" -autorun
ShellIconOverlayIdentifiers: [    BoxSyncFileLocked] -> {2a607da5-abe8-358e-a881-c0f5faf2d3a5} =>
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} =>  -> No File
ShortcutTarget: Dropbox.lnk -> C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
BootExecute: autocheck autochk * sdnclean64.exe
SearchScopes: HKLM -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACAW
SearchScopes: HKLM-x32 -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7ACAW_enUS605
SearchScopes: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> {FCF54A22-DAC4-463D-B5F0-681321A7F67D} URL = hxxps://www.google.com/search?q={searchTerms}
S2 NetDrive2_Service_NetDrive2; C:\Program Files\NetDrive2\nd2svc.exe [X]
S0 eorclc; no ImagePath
S3 avchv; system32\DRIVERS\avchv.sys [X]
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
S3 cpuz136; \??\C:\Windows\TEMP\cpuz136\cpuz136_x64.sys [X]
2017-04-14 21:22 - 2016-08-20 11:17 - 00000000 ____D C:\Users\Bryan\AppData\Roaming\IObit
C:\Users\Bryan\AppData\Roaming\wklnhst.dat
C:\Users\Bryan\AppData\Local\resmon.resmoncfg
C:\Users\Bryan\AppData\Local\Zip-File-Opener_1706.rar
C:\ProgramData\Ament.ini
C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
C:\Users\Bryan\AppData\Local\Temp\ckxj-cvh.dll
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.30.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.31.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.32.7\psuser_64.dll => No File
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\facebook.com -> hxxps://staticxx.facebook.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\facebook.net -> hxxps://connect.facebook.net
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\fbcdn.net -> hxxps://static.xx.fbcdn.net
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\google-analytics.com -> hxxps://www.google-analytics.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\hosts -> hxxps://hosts
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\paragon-software.com -> hxxps://bo4-fe.paragon-software.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\pch.com -> hxxps://pch.com
IE trusted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\pga.com -> hxxps://pga.com
FirewallRules: [TCP Query User{022FA091-367D-4079-A8A2-ED2592DD7D24}C:\program files (x86)\frostwire\frostwire.exe] => (Block) C:\program files (x86)\frostwire\frostwire.exe
FirewallRules: [UDP Query User{09F60FA5-71A9-473F-8B6A-E4D4253CEA95}C:\program files (x86)\frostwire\frostwire.exe] => (Block) C:\program files (x86)\frostwire\frostwire.exe
C:\Program Files (x86)\Avira
C:\Users\Bryan\AppData\Roaming\IObit
C:\Users\Bryan\AppData\Roaming\wklnhst.dat
C:\Users\Bryan\AppData\Local\resmon.resmoncfg
C:\Users\Bryan\AppData\Local\Zip-File-Opener_1706.rar
C:\ProgramData\Ament.ini
C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
C:\Users\Bryan\AppData\Local\Temp\ckxj-cvh.dll
C:\program files (x86)\frostwire
Hosts:
EmptyTemp:
*****************
 
Processes closed successfully.
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{14d88b8c-41df-11e5-81d8-00262d289fc4} => key removed successfully
HKCR\CLSID\{14d88b8c-41df-11e5-81d8-00262d289fc4} => key not found. 
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2ed78b9e-4ad6-11e4-b18e-00262d289fc4} => key removed successfully
HKCR\CLSID\{2ed78b9e-4ad6-11e4-b18e-00262d289fc4} => key not found. 
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a21070b2-0165-11e6-bda4-00262d289fc4} => key removed successfully
HKCR\CLSID\{a21070b2-0165-11e6-bda4-00262d289fc4} => key not found. 
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{bb746c77-426c-11e4-b370-00262d289fc4} => key removed successfully
HKCR\CLSID\{bb746c77-426c-11e4-b370-00262d289fc4} => key not found. 
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ce33646d-05b5-11e6-8974-00262d289fc4} => key removed successfully
HKCR\CLSID\{ce33646d-05b5-11e6-8974-00262d289fc4} => key not found. 
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{eabd1f25-3ae8-11e4-ae5d-806e6f6e6963} => key removed successfully
HKCR\CLSID\{eabd1f25-3ae8-11e4-ae5d-806e6f6e6963} => key not found. 
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\AviraSpeedup => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\    BoxSyncFileLocked => key removed successfully
HKCR\CLSID\{2a607da5-abe8-358e-a881-c0f5faf2d3a5} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt1" => key removed successfully
HKCR\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt2" => key removed successfully
HKCR\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt3" => key removed successfully
HKCR\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt4" => key removed successfully
HKCR\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt5" => key removed successfully
HKCR\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt6" => key removed successfully
HKCR\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt7" => key removed successfully
HKCR\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers\"DropboxExt8" => key removed successfully
HKCR\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => key not found. 
C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe => not found.
HKLM\System\CurrentControlSet\Control\Session Manager\\BootExecute => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FCF54A22-DAC4-463D-B5F0-681321A7F67D} => key removed successfully
HKCR\CLSID\{FCF54A22-DAC4-463D-B5F0-681321A7F67D} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => key removed successfully
HKCR\Wow6432Node\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => key not found. 
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{FCF54A22-DAC4-463D-B5F0-681321A7F67D} => key removed successfully
HKCR\Wow6432Node\CLSID\{FCF54A22-DAC4-463D-B5F0-681321A7F67D} => key not found. 
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => key removed successfully
HKCR\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64} => key not found. 
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{FCF54A22-DAC4-463D-B5F0-681321A7F67D} => key removed successfully
HKCR\CLSID\{FCF54A22-DAC4-463D-B5F0-681321A7F67D} => key not found. 
HKLM\System\CurrentControlSet\Services\NetDrive2_Service_NetDrive2 => key removed successfully
NetDrive2_Service_NetDrive2 => service removed successfully
HKLM\System\CurrentControlSet\Services\eorclc => key removed successfully
eorclc => service removed successfully
HKLM\System\CurrentControlSet\Services\avchv => key removed successfully
avchv => service removed successfully
HKLM\System\CurrentControlSet\Services\clwvd => key removed successfully
clwvd => service removed successfully
HKLM\System\CurrentControlSet\Services\cpuz136 => key removed successfully
cpuz136 => service removed successfully
C:\Users\Bryan\AppData\Roaming\IObit => moved successfully
C:\Users\Bryan\AppData\Roaming\wklnhst.dat => moved successfully
C:\Users\Bryan\AppData\Local\resmon.resmoncfg => moved successfully
C:\Users\Bryan\AppData\Local\Zip-File-Opener_1706.rar => moved successfully
C:\ProgramData\Ament.ini => moved successfully
C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc => moved successfully
C:\Users\Bryan\AppData\Local\Temp\ckxj-cvh.dll => moved successfully
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{590C4387-5EBD-4D46-8A84-CD0BA2EF2856} => key removed successfully
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{59B55F04-DE14-4BB8-92FF-C4A22EF2E5F4} => key removed successfully
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{CB492AF1-2CEF-4E58-BE47-471C77D0C8BA} => key removed successfully
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\facebook.com => key removed successfully
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\facebook.net => key removed successfully
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\fbcdn.net => key removed successfully
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\google-analytics.com => key removed successfully
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\hosts => key removed successfully
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\paragon-software.com => key removed successfully
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\pch.com => key removed successfully
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\pga.com => key removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\TCP Query User{022FA091-367D-4079-A8A2-ED2592DD7D24}C:\program files (x86)\frostwire\frostwire.exe => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\UDP Query User{09F60FA5-71A9-473F-8B6A-E4D4253CEA95}C:\program files (x86)\frostwire\frostwire.exe => value removed successfully
C:\Program Files (x86)\Avira => moved successfully
"C:\Users\Bryan\AppData\Roaming\IObit" => not found.
"C:\Users\Bryan\AppData\Roaming\wklnhst.dat" => not found.
"C:\Users\Bryan\AppData\Local\resmon.resmoncfg" => not found.
"C:\Users\Bryan\AppData\Local\Zip-File-Opener_1706.rar" => not found.
"C:\ProgramData\Ament.ini" => not found.
"C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc" => not found.
"C:\Users\Bryan\AppData\Local\Temp\ckxj-cvh.dll" => not found.
"C:\program files (x86)\frostwire" => not found.
C:\Windows\System32\Drivers\etc\hosts => moved successfully
Hosts restored successfully.
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 57281600 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 90466668 B
Edge => 0 B
Chrome => 922072907 B
Firefox => 0 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 128 B
systemprofile32 => 0 B
LocalService => 0 B
NetworkService => 0 B
Bryan => 158696997 B
Zanthia => 3141790 B
danbear11 => 0 B
Ashanthe => 0 B
Guest => 1243124 B
 
RecycleBin => 8353 B
EmptyTemp: => 1.2 GB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
==== End of Fixlog 09:06:47 ====
 
Malwarebytes
www.malwarebytes.com
 
-Log Details-
Scan Date: 4/21/17
Scan Time: 9:19 AM
Logfile: malwarebytes log.txt
Administrator: Yes
 
-Software Information-
Version: 3.0.6.1469
Components Version: 1.0.103
Update Package Version: 1.0.1775
License: Free
 
-System Information-
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Artadi-PC\Bryan
 
-Scan Summary-
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 468583
Time Elapsed: 15 min, 25 sec
 
-Scan Options-
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Enabled
PUM: Enabled
 
-Scan Details-
Process: 0
(No malicious items detected)
 
Module: 0
(No malicious items detected)
 
Registry Key: 0
(No malicious items detected)
 
Registry Value: 0
(No malicious items detected)
 
Registry Data: 0
(No malicious items detected)
 
Data Stream: 0
(No malicious items detected)
 
Folder: 0
(No malicious items detected)
 
File: 0
(No malicious items detected)
 
Physical Sector: 0
(No malicious items detected)
 
 
(end)
 Results of screen317's Security Check version 1.014 — 12/23/15  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
 Windows Firewall Enabled!  
Avast Antivirus   
 Antivirus up to date!   
`````````Anti-malware/Other Utilities Check:````````` 
 HostsMan 4.1.96    
 Adobe Flash Player 24.0.0.194  
 Mozilla Firefox 38.0.5 Firefox out of Date!  
 Google Chrome (57.0.2987.133) 
 Google Chrome (plugins…) 
 Google Chrome (SetupMetrics…) 
````````Process Check: objlist.exe by Laurent````````  
 Malwarebytes Anti-Malware mbamservice.exe  
 Malwarebytes Anti-Malware mbam.exe  
 Malwarebytes Anti-Malware mbamtray.exe  
 AVAST Software Avast AvastSvc.exe  
 AVAST Software Avast AvastUI.exe  
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C: 3% 
````````````````````End of Log`````````````````````` 
 
 

Seems to be running smoother. thank you very much for your time and help. When I use CC cleaner what are the best settings to use?

I have never used CCleaner but from information I have it's a good tool to use and would advise you to allow it to do the following:

 

  • Internet Explorer - Deletes Temporary Internet files , history, cookies, autocomplete from history, and index.dat.
  • Firefox - Deletes Temporary files, history, cookies, download history, and form history.
  • Google Chrome - Deletes Temporary files, history, cookies, download history, and form history.
  • Opera - Deletes Temporary files, history, and cookies.
  • Safari - Deletes Temporary files, history, cookies, and form history.
  • Windows - Deletes Recycle Bin, Recent Documents, Temporary files and Log files.

 

However,  I also suggest that you never allow it to 'clean' the registry. ALL registry 'cleaners' can do more harm than good.

 

I'll leave this open for 24 hours in case there are any problems after which I'll close it.

 

Safe computing

 

Satchfan

 

 

I'm sorry but in the last ten minutes things have gotten bad again. The system hangs up for minutes at a time, I got the option to wait or kill the web page and decided to wait, it took about seven minutes for the page to become active again. I wonder if it may be the hard drive is failing, do you know of a program that I can download and run to get a good picture of my drives health without having to burn a disc to do so.

Let’s check your hard drive.

  • go to Start and type in cmd
  • right-click on the cmd icon above, and click Run As Administrator
  • type chkdsk c: /r, (don't forget the spaces: there are two, chkdsk^c/:^/r) and hit Enter
  • type Y to agree to run at restart
  • type Exit and hit enter.

Now reboot your computer and let Chkdsk run.

 

Please go here for how to view the resulting log and let me know how it goes.

 

Nearly midnight here and I'm busy in the morning but will get back as soon as I can

 

Satchfan

Here is the chkdsk log file. 

 

 
 
TimeCreated : 4/21/2017 8:24:53 PM
Message     : 
              
              Checking file system on C:
              The type of the file system is NTFS.
              Volume label is Acer.
              
              A disk check has been scheduled.
              Windows will now check the disk.                         
              
              CHKDSK is verifying files (stage 1 of 5)…
                311296 file records processed.                                 
                      
              File verification completed.
                1889 large file records processed.                             
                    
                0 bad file records processed.                                  
                 
                0 EA records processed.                                        
                 
                9313 reparse records processed.                                
                    
              CHKDSK is verifying indexes (stage 2 of 5)…
                424940 index entries processed.                                
                      
              Index verification completed.
                0 unindexed files scanned.                                     
                 
                0 unindexed files recovered.                                   
                 
              CHKDSK is verifying security descriptors (stage 3 of 5)…
                311296 file SDs/SIDs processed.                                
                      
              Cleaning up 1083 unused index entries from index $SII of file 0x9
              .
              Cleaning up 1083 unused index entries from index $SDH of file 0x9
              .
              Cleaning up 1083 unused security descriptors.
              Security descriptor verification completed.
                56823 data files processed.                                    
                     
              CHKDSK is verifying Usn Journal…
                36540920 USN bytes processed.                                  
                        
              Usn Journal verification completed.
              CHKDSK is verifying file data (stage 4 of 5)…
                311280 files processed.                                        
                      
              File data verification completed.
              CHKDSK is verifying free space (stage 5 of 5)…
                158987836 free clusters processed.                             
                         
              Free space verification is complete.
              Windows has checked the file system and found no problems.
              
               732571647 KB total disk space.
                96029800 KB in 243499 files.
                  151564 KB in 56824 indexes.
                       0 KB in bad sectors.
                  438935 KB in use by the system.
                   65536 KB occupied by the log file.
               635951348 KB available on disk.
              
                    4096 bytes in each allocation unit.
               183142911 total allocation units on disk.
               158987837 allocation units available on disk.
              
              Internal Info:
              00 c0 04 00 23 95 04 00 9a 52 08 00 00 00 00 00  ….#….R……
              20 0e 00 00 61 24 00 00 00 00 00 00 00 00 00 00   …a$……….
              00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  …………….
              
              Windows has finished checking your disk.
              Please wait while your computer restarts.

Sorry for the delay, the scan took several hours to complete. I had to do things early today and just got back home.

Will this scan be able to detect if the drive is failing?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI