This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Internet surfing slow, 64 bit Windows 10 intel core i5 [Closed]

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Thanks for your help, here are the logs

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2017-06-09 20:38:49
—————————–
20:38:49.125    OS Version: Windows x64 6.2.9200 
20:38:49.125    Number of processors: 4 586 0x4E03
20:38:49.126    ComputerName: DESKTOP-D22I8SO  UserName: ihave3gals
20:38:51.936    Initialize success
20:38:52.040    VM: initialized successfully
20:38:52.041    VM: Intel CPU BiosDisabled 
20:40:38.873    AVAST engine defs: 17030301
20:40:56.883    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000038
20:40:56.883    Disk 0 Vendor: HGST_HTS721010A9E630 JB0OA3T0 Size: 953869MB BusType: 11
20:40:57.002    Disk 0 MBR read successfully
20:40:57.006    Disk 0 MBR scan
20:40:57.015    Disk 0 unknown MBR code
20:40:57.018    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
20:40:57.103    Disk 0 scanning C:\WINDOWS\system32\drivers
20:41:10.902    Service scanning
20:41:25.740    Service MpKsl5cb4887e C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{07BF9455-A276-446A-B1C5-679EFC6D6869}\MpKsl5cb4887e.sys **LOCKED** 32
20:41:36.732    Modules scanning
20:41:36.737    Disk 0 trace - called modules:
20:41:36.762    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ACPI.sys storport.sys hal.dll iaStorA.sys 
20:41:36.767    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffdb0881224060]
20:41:36.767    3 CLASSPNP.SYS[fffff80d51165efb] -> nt!IofCallDriver -> [0xffffdb087ef81b10]
20:41:36.767    5 hpdskflt.sys[fffff80d5101242b] -> nt!IofCallDriver -> [0xffffdb087e862040]
20:41:36.767    7 ACPI.sys[fffff80d4f854571] -> nt!IofCallDriver -> \Device\00000038[0xffffdb087ce5f400]
20:41:38.321    AVAST engine scan C:\WINDOWS
20:41:41.452    AVAST engine scan C:\WINDOWS\system32
20:44:25.421    AVAST engine scan C:\WINDOWS\system32\drivers
20:44:44.299    AVAST engine scan C:\Users\ihave3gals
20:47:20.658    Disk 0 statistics 824934/0/0 @ 2.02 MB/s
20:47:20.662    Scan stopped
20:47:24.809    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000038
20:47:24.814    Disk 0 Vendor: HGST_HTS721010A9E630 JB0OA3T0 Size: 953869MB BusType: 11
20:47:24.919    Disk 0 MBR read successfully
20:47:24.922    Disk 0 MBR scan
20:47:24.945    Disk 0 unknown MBR code
20:47:24.949    Disk 0 Partition 1 00     EE          GPT           2097151 MB offset 1
20:47:25.008    Disk 0 scanning C:\WINDOWS\system32\drivers
20:47:35.552    Service scanning
20:47:50.045    Service MpKsl5cb4887e C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{07BF9455-A276-446A-B1C5-679EFC6D6869}\MpKsl5cb4887e.sys **LOCKED** 32
20:48:01.243    Modules scanning
20:48:01.254    Disk 0 trace - called modules:
20:48:01.269    ntoskrnl.exe CLASSPNP.SYS disk.sys hpdskflt.sys ACPI.sys storport.sys hal.dll iaStorA.sys 
20:48:01.272    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffdb0881224060]
20:48:01.277    3 CLASSPNP.SYS[fffff80d51165efb] -> nt!IofCallDriver -> [0xffffdb087ef81b10]
20:48:01.280    5 hpdskflt.sys[fffff80d5101242b] -> nt!IofCallDriver -> [0xffffdb087e862040]
20:48:01.286    7 ACPI.sys[fffff80d4f854571] -> nt!IofCallDriver -> \Device\00000038[0xffffdb087ce5f400]
20:48:02.603    AVAST engine scan C:\WINDOWS
20:48:05.753    AVAST engine scan C:\WINDOWS\system32
20:51:02.822    AVAST engine scan C:\WINDOWS\system32\drivers
20:51:22.223    AVAST engine scan C:\Users\ihave3gals
21:32:28.355    AVAST engine scan C:\ProgramData
21:34:47.558    Disk 0 statistics 5659143/0/0 @ 1.54 MB/s
21:34:47.566    Scan finished successfully
21:54:23.305    Disk 0 MBR has been saved successfully to "C:\Users\ihave3gals\Desktop\MBR.dat"
21:54:23.337    The log file has been saved successfully to "C:\Users\ihave3gals\Desktop\aswMBR.txt"
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 07-06-2017 01
Ran by [removed] (administrator) on DESKTOP-D22I8SO (09-06-2017 21:59:12)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igfxCUIService.exe
(Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Windows\System32\ibtsiva.exe
(Conexant Systems, Inc) C:\Windows\CxSvc\CxMonSvc.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
(Conexant Systems, Inc.) C:\Windows\CxSvc\CxUtilSvc.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\CyberLink\Shared files\RichVideo64.exe
() C:\Program Files\AVAST Software\SecureLine\vpnsvc.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
(Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Conexant) C:\Windows\System32\MicTray64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(McAfee, Inc.) C:\Program Files\mcafee\MSC\McAPExe.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igfxEM.exe
(HP Development Company, L.P.) C:\Program Files (x86)\HP\HP CoolSense\CoolSense.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerSt.exe
(HP) C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Conexant Systems, Inc) C:\Program Files\CONEXANT\Flow\Flow.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\HP-NB-AIO\SmartAudio3.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(AVAST Software) C:\Program Files\AVAST Software\SecureLine\secureline.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(McAfee, Inc.) C:\Program Files\mcafee\MAT\McPvTray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\Video.UI.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\cmd.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe
(Microsoft Corporation) C:\Windows\System32\WWAHost.exe
(Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\IntelCpHeciSvc.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(McAfee, Inc.) C:\Program Files\mcafee\vul\McVulCtr.exe
(McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)
HKLM\…\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-27] (Microsoft Corporation)
HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [657424 2016-01-11] (HP Inc.)
HKLM-x32\…\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [127528 2015-07-08] (Hewlett-Packard Company)
HKLM-x32\…\Run: [PowerDVD14Agent] => C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe [795336 2016-01-29] (CyberLink Corp.)
HKLM-x32\…\Run: [HPRadioMgr] => C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe [268896 2016-04-14] (HP)
HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-09-01] (Apple Inc.)
HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1314432 2016-03-11] (CANON INC.)
HKLM-x32\…\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [438888 2014-01-15] (CANON INC.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{7b6b2825-dccd-4690-a787-5c75c18cef19}: [DhcpNameServer] [removed]
Tcpip\..\Interfaces\{cd5d1a67-fdc9-478d-9498-ae65a1dbb601}: [DhcpNameServer] 192.168.1.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp15-comm.msn.com/?pc=HRTE
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\S-1-5-21-121274051-3287072310-3552221101-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp15-comm.msn.com/?pc=HRTE
HKU\S-1-5-21-121274051-3287072310-3552221101-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
SearchScopes: HKLM -> {9FB80709-BE3D-4A96-B000-9C61345C9E56} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKLM-x32 -> {9FB80709-BE3D-4A96-B000-9C61345C9E56} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
SearchScopes: HKU\S-1-5-21-121274051-3287072310-3552221101-1001 -> {9FB80709-BE3D-4A96-B000-9C61345C9E56} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag=hp-us2-vsb-20&link%5Fcode=qs&index=aps&field-keywords={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\MSC\McSnIePl64.dll [2016-07-07] (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2016-07-07] (McAfee, Inc.)
 
FireFox:
========
FF DefaultProfile: ad2f9vxu.default
FF ProfilePath: C:\Users\ihave3gals\AppData\Roaming\Mozilla\Firefox\Profiles\ad2f9vxu.default [2017-05-30]
FF HKLM\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2017-04-18]
FF HKLM-x32\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK
FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2016-08-02] [not signed]
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2016-07-07] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1219159.dll [2015-06-26] (Adobe Systems, Inc.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-08-24] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-08-24] (Intel Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2016-07-07] ()
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-05-26] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-26] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR NewTab: Default ->  Not-active:"chrome-extension://hcfalfpgiocaoobnlaeljmljhcnbnfjk/newtab/newtab.html", Not-active:"chrome-extension://eoilkaejhmjjbdongpiccbjcmgdepiem/newtab/newtab.html", Not-active:"chrome-extension://mallpejgeafdahhflmliiahjdpgbegpk/stubby.html", Not-active:"chrome-extension://kpocjpoifmommoiiiamepombpeoaehfh/stubby.html"
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US0D20160802&p={searchTerms}
CHR DefaultSearchKeyword: Default -> mcafee
CHR Profile: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default [2017-06-09]
CHR Extension: (Google Slides) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-07-27]
CHR Extension: (Google Docs) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-27]
CHR Extension: (Google Drive) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-27]
CHR Extension: (Ask Web Search) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkbpfdkbpbckgkcelkfjjhepmdcdmahi [2017-04-18]
CHR Extension: (YouTube) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-27]
CHR Extension: (Honey) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2017-06-02]
CHR Extension: (Adobe Acrobat) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-04-18]
CHR Extension: (Renew It Now V2.0) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem [2017-05-10]
CHR Extension: (Google Sheets) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-07-27]
CHR Extension: (McAfee® WebAdvisor) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2017-06-06]
CHR Extension: (Google Docs Offline) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-27]
CHR Extension: (Renew It Now V2.1) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk [2017-05-10]
CHR Extension: (EasyPDFCombine) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpocjpoifmommoiiiamepombpeoaehfh [2017-05-18]
CHR Extension: (FromDocToPDF) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk [2017-05-18]
CHR Extension: (Chrome Web Store Payments) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-17]
CHR Extension: (Search Encrypt) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\oafomabmeffnelgdleajddppakeakfna [2017-05-10]
CHR Extension: (Gmail) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-27]
CHR Extension: (Chrome Media Router) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-18]
CHR HKLM\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [jkfpchpiljkaemlpmpebnglgkomamfeo] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3971264 2017-05-14] (Microsoft Corporation)
R3 cphs; C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\IntelCpHeciSvc.exe [310240 2017-02-22] (Intel Corporation)
S3 cplspcon; C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\IntelCpHDCPSvc.exe [488928 2017-02-22] (Intel Corporation)
R2 CxMonSvc; C:\WINDOWS\CxSvc\CxMonSvc.exe [22648 2016-06-07] (Conexant Systems, Inc)
R2 CxUtilSvc; C:\WINDOWS\CxSvc\CxUtilSvc.exe [141432 2016-07-30] (Conexant Systems, Inc.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
R2 esifsvc; C:\WINDOWS\SysWoW64\esif_uf.exe [1392792 2015-12-02] (Intel Corporation)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [33640 2017-04-07] (HP Inc.)
R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [606224 2016-01-11] (HP Inc.)
R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation)
R2 igfxCUIService2.0.0.0; C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igfxCUIService.exe [350688 2017-02-22] (Intel Corporation)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
S3 Intel(R) WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-09-17] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [207648 2016-01-07] (Intel Corporation)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [188256 2017-05-16] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [993824 2016-07-07] (McAfee, Inc.)
R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [816128 2016-06-21] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232688 2016-04-26] (McAfee, Inc.)
R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [382456 2016-06-23] (McAfee, Inc.)
R3 mfevtp; C:\windows\system32\mfevtps.exe [277744 2016-04-26] (McAfee, Inc.)
S3 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2016-02-08] ()
R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] ()
R2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [592392 2016-07-25] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [266872 2016-08-19] (Synaptics Incorporated)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-27] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-27] (Microsoft Corporation)
R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3833248 2016-02-08] (Intel® Corporation)
R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [78632 2016-04-27] (McAfee, Inc.)
R3 dptf_acpi; C:\WINDOWS\System32\drivers\dptf_acpi.sys [55784 2015-12-02] (Intel Corporation)
R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [52200 2015-12-02] (Intel Corporation)
R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [260072 2015-12-02] (Intel Corporation)
R3 HID_PCI; C:\WINDOWS\System32\drivers\HID_PCI.sys [47928 2015-11-26] (Intel)
S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [207968 2016-02-24] (McAfee, Inc.)
R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [244744 2017-04-13] (Intel Corporation)
R3 igfx; C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igdkmd64.sys [11036640 2017-02-22] (Intel Corporation)
R3 ISH; C:\WINDOWS\System32\drivers\ISH.sys [139064 2015-11-26] (Intel)
R3 ISH_BusDriver; C:\WINDOWS\System32\drivers\ISH_BusDriver.sys [75576 2015-11-26] (Intel)
R2 McPvDrv; C:\WINDOWS\system32\drivers\McPvDrv.sys [79192 2016-04-20] (McAfee, Inc.)
R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [419616 2016-04-27] (McAfee, Inc.)
R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [349480 2016-04-27] (McAfee, Inc.)
S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [83608 2016-04-27] (McAfee, Inc.)
R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [493352 2016-04-27] (McAfee, Inc.)
R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [843048 2016-04-27] (McAfee, Inc.)
R3 mfencbdc; C:\WINDOWS\system32\DRIVERS\mfencbdc.sys [519976 2016-04-27] (McAfee, Inc.)
S3 mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [100136 2016-04-27] (McAfee, Inc.)
R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [46240 2016-06-06] (McAfee, Inc.)
R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [243488 2016-04-27] (McAfee, Inc.)
R1 MpKsl5cb4887e; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{07BF9455-A276-446A-B1C5-679EFC6D6869}\MpKsl5cb4887e.sys [44928 2017-06-08] (Microsoft Corporation)
S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
U5 Netwtw02; C:\Windows\System32\Drivers\Netwtw02.sys [6722824 2016-01-01] (Intel Corporation)
R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [7116288 2016-07-16] (Intel Corporation)
R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [758488 2016-02-02] (Realsil Semiconductor Corporation)
S3 rtux64w10; C:\WINDOWS\System32\drivers\rtux64w10.sys [323072 2015-10-30] (Realtek                                                                ) [File not signed]
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [58984 2015-12-21] (Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [72824 2016-08-19] (Synaptics Incorporated)
R3 VirtualButtons; C:\WINDOWS\System32\drivers\VirtualButtons.sys [31280 2016-01-18] (Intel Corporation)
S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\system32\DRIVERS\WirelessButtonDriver64.sys [31656 2016-04-14] (HP)
U3 aswMBR; C:\Users\ihave3gals\AppData\Local\Temp\aswMBR.sys [62728 2017-06-09] () [File not signed] <==== ATTENTION
U3 aswVmm; C:\Users\ihave3gals\AppData\Local\Temp\aswVmm.sys [224896 2017-06-09] () <==== ATTENTION
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-06-09 21:59 - 2017-06-09 22:00 - 00028144 _____ C:\Users\ihave3gals\Downloads\FRST.txt
2017-06-09 21:58 - 2017-06-09 21:59 - 00000000 ____D C:\FRST
2017-06-09 21:57 - 2017-06-09 21:58 - 02435072 _____ (Farbar) C:\Users\ihave3gals\Downloads\FRST64.exe
2017-06-09 21:54 - 2017-06-09 21:54 - 00003751 _____ C:\Users\ihave3gals\Desktop\aswMBR.txt
2017-06-09 21:54 - 2017-06-09 21:54 - 00000512 _____ C:\Users\ihave3gals\Desktop\MBR.dat
2017-06-09 20:38 - 2017-06-09 20:38 - 05198336 _____ (AVAST Software) C:\Users\ihave3gals\Downloads\aswMBR.exe
2017-06-09 12:19 - 2017-06-09 12:19 - 00074260 _____ C:\Users\ihave3gals\Downloads\posh_label_593a15f020b687373007837d.pdf
2017-06-07 23:07 - 2017-06-07 23:07 - 00072260 _____ C:\Users\ihave3gals\Downloads\posh_label_5938ae6154b35ecb8108f9cb.pdf
2017-06-07 10:53 - 2017-06-07 10:53 - 00074239 _____ C:\Users\ihave3gals\Downloads\posh_label_5937ee18d8ff09340e331304.pdf
2017-06-07 10:52 - 2017-06-07 10:52 - 00074031 _____ C:\Users\ihave3gals\Downloads\posh_label_5936a189426737f143161cca.pdf
2017-06-07 10:52 - 2017-06-07 10:52 - 00072212 _____ C:\Users\ihave3gals\Downloads\posh_label_5937d51cd8ff09089731be73.pdf
2017-06-05 22:34 - 2017-06-05 22:34 - 00072793 _____ C:\Users\ihave3gals\Downloads\posh_label_59358e4b4267378d9354e044.pdf
2017-06-04 20:10 - 2017-06-04 20:10 - 00073724 _____ C:\Users\ihave3gals\Downloads\posh_label_5932b52aadce924eba134f10.pdf
2017-06-04 20:09 - 2017-06-04 20:09 - 00073519 _____ C:\Users\ihave3gals\Downloads\posh_label_593301e6426737005a1b5f03.pdf
2017-06-04 20:07 - 2017-06-04 20:07 - 00074065 _____ C:\Users\ihave3gals\Downloads\posh_label_593376028031c8c17c26f4b7.pdf
2017-06-03 22:18 - 2017-06-03 22:18 - 00073727 _____ C:\Users\ihave3gals\Downloads\posh_label_59334b7c09e95303ef22b068 (1).pdf
2017-06-03 22:17 - 2017-06-03 22:17 - 00073727 _____ C:\Users\ihave3gals\Downloads\posh_label_59334b7c09e95303ef22b068.pdf
2017-06-02 23:11 - 2017-06-02 23:11 - 00073676 _____ C:\Users\ihave3gals\Downloads\posh_label_5931a43709e95368f70dee85.pdf
2017-06-02 23:10 - 2017-06-02 23:10 - 00073215 _____ C:\Users\ihave3gals\Downloads\posh_label_59319115d31164fadb0c09f2.pdf
2017-06-02 08:10 - 2017-06-02 08:10 - 00073684 _____ C:\Users\ihave3gals\Downloads\posh_label_592f948ba457c8ca27d5afe4.pdf
2017-06-02 08:09 - 2017-06-02 08:09 - 00073377 _____ C:\Users\ihave3gals\Downloads\posh_label_5930a55247b2f32dd801f5ab.pdf
2017-06-02 08:09 - 2017-06-02 08:09 - 00073377 _____ C:\Users\ihave3gals\Downloads\posh_label_5930a55247b2f32dd801f5ab (1).pdf
2017-06-02 08:08 - 2017-06-02 08:08 - 00072953 _____ C:\Users\ihave3gals\Downloads\posh_label_59306f7dca5c4d19fc0161ef.pdf
2017-06-02 08:05 - 2017-06-02 08:05 - 00072453 _____ C:\Users\ihave3gals\Downloads\posh_label_59306732adce925ca7007d1d.pdf
2017-05-31 10:49 - 2017-05-31 10:49 - 01388432 _____ C:\Users\Public\VOIP.dat
2017-05-30 19:19 - 2017-05-30 19:19 - 00119639 _____ C:\Users\ihave3gals\Downloads\CignaMobileIDCard (1).pdf
2017-05-30 19:18 - 2017-05-30 19:18 - 00119639 _____ C:\Users\ihave3gals\Downloads\CignaMobileIDCard.pdf
2017-05-29 21:16 - 2017-05-29 21:16 - 00075473 _____ C:\Users\ihave3gals\Downloads\posh_label_592acd0bb73984ae3263fec0.pdf
2017-05-29 21:15 - 2017-05-29 21:15 - 00073306 _____ C:\Users\ihave3gals\Downloads\posh_label_592a3578d8ff09b72d5b5403.pdf
2017-05-29 21:15 - 2017-05-29 21:15 - 00073306 _____ C:\Users\ihave3gals\Downloads\posh_label_592a3578d8ff09b72d5b5403 (1).pdf
2017-05-26 19:36 - 2017-05-26 19:36 - 00031109 _____ C:\Users\ihave3gals\Downloads\INV-001116.pdf
2017-05-26 19:16 - 2017-05-26 19:16 - 00355892 _____ C:\Users\ihave3gals\Downloads\Inv_06011700_from_Simply_Serving_LLC_1260.pdf
2017-05-24 22:28 - 2017-05-24 22:28 - 00073948 _____ C:\Users\ihave3gals\Downloads\posh_label_592625b273e444a76b0827f1.pdf
2017-05-22 21:25 - 2017-05-22 21:25 - 00073892 _____ C:\Users\ihave3gals\Downloads\posh_label_592358d2b7398410eb7162aa.pdf
2017-05-19 20:43 - 2017-05-19 20:43 - 00074500 _____ C:\Users\ihave3gals\Downloads\posh_label_591f855c93039450f31fda1a.pdf
2017-05-19 20:43 - 2017-05-19 20:43 - 00073395 _____ C:\Users\ihave3gals\Downloads\posh_label_591f3c97b88c5634441956a5 (1).pdf
2017-05-19 20:42 - 2017-05-19 20:42 - 00073395 _____ C:\Users\ihave3gals\Downloads\posh_label_591f3c97b88c5634441956a5.pdf
2017-05-19 08:01 - 2017-05-19 08:01 - 00073336 _____ C:\Users\ihave3gals\Downloads\posh_label_591ec17ad31164af610e80d1.pdf
2017-05-19 08:01 - 2017-05-19 08:01 - 00073336 _____ C:\Users\ihave3gals\Downloads\posh_label_591ec17ad31164af610e80d1 (1).pdf
2017-05-19 08:00 - 2017-05-19 08:00 - 00073372 _____ C:\Users\ihave3gals\Downloads\posh_label_591da22854b35e1ea7180aa5 (1).pdf
2017-05-19 07:59 - 2017-05-19 07:59 - 00073372 _____ C:\Users\ihave3gals\Downloads\posh_label_591da22854b35e1ea7180aa5.pdf
2017-05-17 22:49 - 2017-05-17 22:49 - 00073996 _____ C:\Users\ihave3gals\Downloads\posh_label_591cb5a9d142c30f89ff2098.pdf
2017-05-16 16:09 - 2017-05-16 16:09 - 00074585 _____ C:\Users\ihave3gals\Downloads\posh_label_5919d45842a322396a19025e (1).pdf
2017-05-16 16:08 - 2017-05-16 16:08 - 00074585 _____ C:\Users\ihave3gals\Downloads\posh_label_5919d45842a322396a19025e.pdf
2017-05-15 11:12 - 2016-06-29 13:11 - 00007068 _____ C:\WINDOWS\system32\cxapo2.prop
2017-05-15 11:12 - 2016-06-29 13:11 - 00007068 _____ C:\WINDOWS\system32\cxapo.prop
2017-05-15 11:12 - 2016-04-19 13:46 - 00004664 _____ C:\WINDOWS\system32\Drivers\SSPTunePt.DAT
2017-05-15 11:11 - 2017-05-15 11:11 - 00002192 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bang & Olufsen Audio Control.lnk
2017-05-15 11:11 - 2017-05-15 11:11 - 00000000 ____D C:\ProgramData\SRS Labs
2017-05-15 11:11 - 2017-05-14 10:09 - 02758232 _____ (Conexant) C:\WINDOWS\system32\MicTray64.exe
2017-05-15 11:11 - 2016-02-17 18:02 - 00002988 _____ C:\WINDOWS\system32\MicTray64.xml
2017-05-14 21:55 - 2017-05-14 21:55 - 00074451 _____ C:\Users\ihave3gals\Downloads\posh_label_5917ebc2a44b4aea6acedfa6.pdf
2017-05-14 12:37 - 2017-05-14 12:37 - 00000000 ____D C:\WINDOWS\UCI
2017-05-14 12:36 - 2017-05-15 11:12 - 00000000 ____D C:\WINDOWS\CxSvc
2017-05-14 12:35 - 2017-05-14 12:35 - 00000000 ____D C:\ProgramData\UIU
2017-05-14 12:35 - 2016-01-14 15:09 - 00004664 _____ C:\WINDOWS\system32\Drivers\CxSfPt.dat
2017-05-14 05:22 - 2017-05-14 05:22 - 01608120 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64APO.dll
2017-05-14 05:22 - 2017-05-14 05:22 - 01529136 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64Proxy.dll
2017-05-14 05:22 - 2017-05-14 05:22 - 01046712 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CX64BP24.dll
2017-05-14 05:22 - 2017-05-14 05:22 - 00550240 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\CX64APO2.dll
2017-05-14 05:22 - 2017-05-14 05:22 - 00060192 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\CxPageMaster64.dll
2017-05-14 05:21 - 2017-05-14 05:21 - 02362904 _____ (Conexant Systems Inc.) C:\WINDOWS\system32\Drivers\CHDRT64.sys
2017-05-14 05:21 - 2017-05-14 05:21 - 00410752 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\CSpkExt64.dll
2017-05-12 10:41 - 2017-05-12 10:42 - 01196884 _____ C:\WINDOWS\Minidump\051217-40531-01.dmp
2017-05-12 10:41 - 2017-05-12 10:41 - 00000000 ____D C:\WINDOWS\Minidump
2017-05-11 00:19 - 2017-05-14 05:22 - 04812160 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\UCI64A138.dll
2017-05-11 00:19 - 2017-05-11 00:19 - 04812128 _____ (Conexant Systems, Inc.) C:\WINDOWS\system32\SETF546.tmp
2017-05-10 21:08 - 2017-05-10 21:08 - 00095159 _____ C:\WINDOWS\system32\Drivers\HWPID.ini
2017-05-10 21:08 - 2017-05-10 21:08 - 00064142 _____ C:\WINDOWS\system32\Drivers\Mixer.ini
2017-05-10 21:08 - 2017-05-10 21:08 - 00010122 _____ C:\WINDOWS\system32\Drivers\EPKeys.ini
2017-05-10 21:08 - 2017-05-10 21:08 - 00007083 _____ C:\WINDOWS\system32\Drivers\PASettings.ini
2017-05-10 21:08 - 2017-05-10 21:08 - 00004105 _____ C:\WINDOWS\system32\Drivers\ForceDetectionTip.ini
2017-05-10 21:08 - 2017-05-10 21:08 - 00002623 _____ C:\WINDOWS\system32\Drivers\SPKID.ini
2017-05-10 14:49 - 2017-05-10 15:49 - 00003446 _____ C:\WINDOWS\System32\Tasks\McAfee Remediation (Prepare)
2017-05-10 12:27 - 2017-05-10 12:27 - 00951558 _____ C:\Users\ihave3gals\Downloads\Seeds Worksheet Packet.pdf
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-06-09 21:53 - 2016-10-02 17:13 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-06-09 21:30 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-06-09 20:02 - 2016-08-02 23:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
2017-06-08 22:52 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-06-08 22:52 - 2016-07-16 07:36 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-06-08 15:09 - 2016-07-16 07:47 - 00000000 ___HD C:\Program Files\WindowsApps
2017-06-07 22:17 - 2016-10-10 22:15 - 00000000 ____D C:\ProgramData\CanonIJPLM
2017-06-06 18:37 - 2016-10-02 17:36 - 00003296 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForihave3gals
2017-06-06 18:37 - 2016-09-13 15:19 - 00000384 _____ C:\WINDOWS\Tasks\HPCeeScheduleForihave3gals.job
2017-05-31 19:46 - 2016-08-02 23:13 - 00565416 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-05-30 17:54 - 2016-08-02 23:23 - 00000000 __RSD C:\Users\ihave3gals\Documents\McAfee Vaults
2017-05-30 17:51 - 2016-07-24 23:53 - 00000000 __SHD C:\Users\ihave3gals\IntelGraphicsProfiles
2017-05-30 17:50 - 2016-10-02 17:36 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-05-30 17:50 - 2016-07-16 02:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-05-26 23:57 - 2016-07-16 02:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
2017-05-26 08:29 - 2016-07-16 07:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-05-26 08:28 - 2016-04-22 18:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2017-05-22 17:51 - 2016-07-26 09:37 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-05-22 17:48 - 2016-07-26 09:37 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-05-21 13:29 - 2016-10-02 17:20 - 00000000 ____D C:\Users\ihave3gals
2017-05-21 13:11 - 2016-07-27 22:13 - 00000000 ____D C:\Users\ihave3gals\AppData\Roaming\Mozilla
2017-05-18 19:23 - 2016-10-02 17:20 - 01473004 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-05-18 19:17 - 2016-08-02 23:18 - 00000000 ____D C:\Program Files (x86)\McAfee
2017-05-15 11:13 - 2016-07-24 23:56 - 00000000 ____D C:\Users\ihave3gals\AppData\Local\Conexant
2017-05-15 11:10 - 2016-10-02 17:15 - 01701376 _____ (TODO: ) C:\WINDOWS\SysWOW64\RebootPrompt.exe
2017-05-15 11:10 - 2016-10-02 17:15 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
2017-05-15 11:08 - 2016-07-16 07:45 - 00000000 ____D C:\WINDOWS\INF
2017-05-14 12:38 - 2016-10-02 17:15 - 00000000 ____D C:\ProgramData\Conexant
2017-05-14 12:36 - 2016-10-02 17:15 - 00000000 ____D C:\Program Files\CONEXANT
2017-05-12 11:51 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\rescache
2017-05-12 10:48 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-05-12 10:41 - 2016-08-02 22:24 - 914082889 _____ C:\WINDOWS\MEMORY.DMP
2017-05-11 23:31 - 2016-06-26 08:13 - 00000000 ____D C:\ProgramData\McAfee
2017-05-11 23:22 - 2016-07-27 22:22 - 00002279 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-05-11 23:22 - 2016-07-27 22:22 - 00002267 _____ C:\Users\Public\Desktop\Google Chrome.lnk
 
Files to move or delete:
====================
C:\Users\Public\VOIP.dat
 
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-05-30 18:46
 
==================== End of FRST.txt ============================
 
 

Thanks Ken.  Here's the log

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 07-06-2017 01
Ran by [removed] (09-06-2017 22:00:33)
Running from C:\Users\[removed]\Downloads
Windows 10 Home Version 1607 (X64) (2016-10-02 21:39:32)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-121274051-3287072310-3552221101-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-121274051-3287072310-3552221101-503 - Limited - Disabled)
Guest (S-1-5-21-121274051-3287072310-3552221101-501 - Limited - Disabled)
ihave3gals (S-1-5-21-121274051-3287072310-3552221101-1001 - Administrator - Enabled) => C:\Users\ihave3gals
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
FW: McAfee Firewall (Disabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.9.159 - Adobe Systems, Inc.)
Apple Application Support (32-bit) (HKLM-x32\…\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Avast SecureLine (HKLM\…\{2CD3C92F-EDC5-4B02-9B0A-9C1D37C58EF5}_is1) (Version: 1.0.275.2 - AVAST Software)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon Easy-WebPrint EX (HKLM-x32\…\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
Canon IJ Network Scanner Selector EX (HKLM-x32\…\Canon_IJ_Network_Scanner_Selector_EX) (Version: 1.5.2.3 - Canon Inc.)
Canon IJ Network Tool (HKLM-x32\…\Canon_IJ_Network_UTILITY) (Version: 3.5.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\…\Canon_IJ_Scan_Utility) (Version: 1.1.10.15 - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\…\CANONIJPLM100) (Version: 4.2.0 - Canon Inc.)
Canon MG6600 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6600_series) (Version: 1.01 - Canon Inc.)
Canon MG6600 series On-screen Manual (HKLM-x32\…\Canon MG6600 series On-screen Manual) (Version: 7.7.0 - Canon Inc.)
Canon MG6600 series User Registration (HKLM-x32\…\Canon MG6600 series User Registration) (Version:  - ‭Canon Inc.)
Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\…\CanonQuickMenu) (Version: 2.7.0 - Canon Inc.)
Conexant HD Audio (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.65.165.11 - Conexant Systems)
CyberLink Power Media Player 14 (HKLM-x32\…\{32C8E300-BDB4-4398-92C2-E9B7D8A233DB}) (Version: 14.0.3.6129 - CyberLink Corp.)
CyberLink PowerDirector 12 (HKLM-x32\…\InstallShield_{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.6.4925 - CyberLink Corp.)
CyberLink PowerDirector 12 (Version: 12.0.6.4925 - CyberLink Corp.) Hidden
DisableMSDefender (Version: 1.0.0 - Hewlett-Packard Company) Hidden
Dropbox 25 GB (HKLM-x32\…\{0867A88D-764F-366E-9E21-130DA8B472C3}) (Version: 3.1.18.0 - Dropbox, Inc.)
Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden
Energy Star (HKLM\…\{5CB22648-35F8-41BC-9C35-1E41FE6E12A5}) (Version: 1.1.1 - HP Inc.)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 58.0.3029.110 - Google Inc.)
Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
HP 3D DriveGuard (HKLM-x32\…\{E8D0E2B8-B64B-44BC-8E01-00DDACBDF78A}) (Version: 6.0.28.1 - Hewlett-Packard Company)
HP CoolSense (HKLM-x32\…\{0C723C74-62DF-4B35-9490-A207546D866D}) (Version: 2.21.4 - HP Inc.)
HP Documentation (HKLM\…\HP_Documentation) (Version: 1.0.0.1 - HP)
HP ePrint SW (HKLM-x32\…\{88970959-baf7-4864-a39a-69a58e8ae5cf}) (Version: 5.0.18701 - HP)
HP Registration Service (HKLM\…\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.8318.5320 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\…\{E959FD01-BD01-4CC4-9BB8-4EBE8309BF37}) (Version: 8.4.14.41 - HP)
HP Support Solutions Framework (HKLM-x32\…\{E2CB09C1-3C76-4395-BB47-50C066535CF8}) (Version: 12.6.14.19 - HP)
HP System Event Utility (HKLM-x32\…\{09D0DB68-90EA-4015-983E-A0BD777D5A02}) (Version: 1.4.9 - HP Inc.)
HP Welcome (HKLM\…\HPWelcome) (Version: 1.0 - HP Inc.)
HP Wireless Button Driver (HKLM-x32\…\{AF4C5F64-4E6A-438B-9832-8BDEE0E7B43D}) (Version: 1.1.17.1 - HP)
Intel(R) Chipset Device Software (x32 Version: 10.1.1.13 - Intel(R) Corporation) Hidden
Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\…\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.1.10605.221 - Intel Corporation)
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1177 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4377 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.0.1042 - Intel Corporation)
Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.63.1519.7 - Intel Corporation)
Intel(R) Virtual Buttons (HKLM-x32\…\1992736F-C90A-481C-B21B-EE34CAD07387) (Version: 1.1.0.21 - Intel Corporation)
Intel(R) WiDi (HKLM\…\{6B15F1EF-F3A8-4C29-BF9E-18EB3683A83D}) (Version: 6.0.60.0 - Intel Corporation)
Intel(R) WiDi Software Asset Manager (x32 Version: 3.2.1184 - Intel Corporation) Hidden
Intel(R) Wireless Bluetooth(R) (HKLM-x32\…\{5068B0F8-CE24-4B61-9C2F-301B411FFB9C}) (Version: 18.1.1611.3223 - Intel Corporation)
Intel® Integrated Sensor Solution (HKLM-x32\…\{33418794-f1ee-42cb-a2a6-472126fe03c9}) (Version: 3.0.0.1008 - Intel Corporation)
Intel® PROSet/Wireless Software (HKLM-x32\…\{d5572863-793c-4ec8-872a-43cccc68b948}) (Version: 18.40.0 - Intel Corporation)
ISS_Drivers_x64 (Version: 3.0.0.1008 - Intel Corporation) Hidden
iTunes (HKLM\…\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.)
McAfee Total Protection (HKLM-x32\…\MSC) (Version: 15.0.166 - McAfee, Inc.)
McAfee WebAdvisor (HKLM-x32\…\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.139 - McAfee, Inc.)
Microsoft Office Professional Plus 2016 - en-us (HKLM\…\ProPlusRetail - en-us) (Version: 16.0.8067.2115 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-121274051-3287072310-3552221101-1001\…\OneDriveSetup.exe) (Version: 17.3.6799.0327 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50906.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.8067.2115 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.8067.2115 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (Version: 16.0.8067.2115 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7967.2073 - Microsoft Corporation) Hidden
Optimum (HKU\S-1-5-21-121274051-3287072310-3552221101-1001\…\3146597695.optimumapp.iptv.optimum.net) (Version:  - optimumapp.iptv.optimum.net)
Optimum App for Laptop 4.12 (HKLM\…\{6082AB31-92B1-4832-AC89-3B2E6D8C14FE}) (Version: 4.12 - Cablevision)
QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics ClickPad Driver (HKLM\…\SynTPDeinstKey) (Version: 19.3.11.37 - Synaptics Incorporated)
Windows 10 Update and Privacy Settings (HKLM\…\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {11A11EC2-D611-429F-BB78-0DF1B4A65888} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\ihave3gals\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
Task: {2FC9C5F5-7F6F-4896-8B36-352652FD8193} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {326E184D-CDA0-41E6-8EB8-F76FACACE53C} - System32\Tasks\HPDAS => C:\Program [Argument = Files\HP\HP ePrint\HP.DeliveryAndStatus.Desktop.App.exe /CheckJobs]
Task: {402CFF77-B3B8-4FD9-93A7-67678EE6CF84} - System32\Tasks\HPCeeScheduleForihave3gals => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {40589131-B03A-456D-941F-5BF379AB3F06} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
Task: {442AD0D9-DE70-43CA-9AB3-C22BBD7D0F2E} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
Task: {452A1636-E974-4A70-AB0F-11AB936B5E36} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-05-14] (Microsoft Corporation)
Task: {51EE0877-371B-422B-8298-7E3DB6E21B55} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {5213AD96-6046-4DA2-8919-7BDCC6DB553C} - System32\Tasks\Microsoft\Windows\Conexant\MicTray => C:\Windows\System32\MicTray64.exe [2017-05-14] (Conexant)
Task: {54724C21-FB4D-4246-B8F1-5DF4E1A71933} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-05-14] (Microsoft Corporation)
Task: {555CFAC0-2CE7-46A3-B548-D08FE97B092F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {5AA361F1-D205-48E5-8B5A-848B66ED087D} - System32\Tasks\avast! SL Update => C:\Program Files\AVAST Software\SecureLine\SLUpdate.exe [2016-07-25] (AVAST Software)
Task: {5FBC6735-CB1D-49B8-885F-4C14777E1B25} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2015-09-17] (Intel Corporation)
Task: {61EE3755-027D-4876-8AE5-0190A1284681} - System32\Tasks\HP\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\HP\HP CoolSense\CoolSense.exe [2016-01-21] (HP Development Company, L.P.)
Task: {64514458-B2FD-4370-90F1-ECF2D0943AA0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-04-01] (HP Inc.)
Task: {6941EA39-88D1-4F55-9B34-2F39C83DA74F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-04-06] (HP Inc.)
Task: {6B6C4F8F-E9AE-4F6D-B4C5-C841E2E811C5} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-05-26] ()
Task: {90B21D84-5041-4BBA-9EE9-EF511711A609} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-27] (Google Inc.)
Task: {9174AC26-76F4-4C4D-88C5-A8107A3953DC} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [2015-06-05] (Intel Corporation)
Task: {920F3DF3-7CE5-40EF-8ABB-E77DA70BA47C} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2016-07-07] (McAfee, Inc.)
Task: {ABA80ACA-7D63-4C50-AC30-BD8946D64692} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent
Task: {B11FB292-E332-4371-BAE8-B53C743D736A} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
Task: {B2A39930-A216-4A33-8FEB-3375A1D9781C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
Task: {B63478DF-B3FD-4C42-B03A-2240A859B88B} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2015-09-17] (Intel Corporation)
Task: {B80EEE79-4591-492D-A124-59EF0BEA408D} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
Task: {BD4BEB68-4F1D-46BE-9020-FD8517B41066} - System32\Tasks\DropboxOEM => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2016-09-21] ()
Task: {BF9B0E83-E834-4703-BCBC-CD146D14985D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {C2358725-0298-4A48-98A4-6495804C7B35} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
Task: {C53A5D3F-66A1-4BF4-80A5-C6BB0427A126} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {C542A672-CDDB-4CB5-800C-21F8B22BA647} - System32\Tasks\Avast SecureLine => C:\Program Files\AVAST Software\SecureLine\SecureLine.exe [2016-07-25] (AVAST Software)
Task: {C7629495-3A00-4A2D-A761-3941F20419A2} - System32\Tasks\Microsoft\Windows\Conexant\FLOW => C:\Program Files\CONEXANT\FLOW\SACpl.exe [2016-06-23] (Conexant Systems, Inc.)
Task: {CCFB69ED-BD28-482B-AF77-13B555C12BE9} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [2017-04-12] (McAfee, Inc.)
Task: {D57FCA82-BA50-44F8-9A30-0E86C76D9A30} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-05-26] ()
Task: {E63D6726-0930-4032-AB37-41D6C130E995} - System32\Tasks\McAfee\McAfee Idle Detection Task
Task: {E84EFDA9-66A3-4F8E-9D5A-C8A419E1EDCA} - System32\Tasks\Microsoft\Windows\Conexant\SA3 => C:\Program Files\CONEXANT\SA3\HP-NB-AIO\SACpl.exe [2016-01-08] (Conexant Systems, Inc.)
Task: {EC474F25-86B3-46E6-A945-39010F7D7971} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-27] (Google Inc.)
Task: {EDE4DA7A-2C2F-4B0F-BAE9-24D2D7F0F7C8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-05-26] (Microsoft Corporation)
Task: {F2117ECE-3739-4300-820E-46C450374DDE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-05-26] (Microsoft Corporation)
Task: {FF5B04DF-D99D-48BA-A808-EDEAD832121F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-04-06] (HP Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForihave3gals.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
 
==================== Shortcuts =============================
 
(The entries could be listed to be restored or removed.)
 
ShortcutWithArgument: C:\Users\ihave3gals\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\AmazonShopping.lnk -> C:\Program Files (x86)\HP\Shared\WizLink.exe () -> hxxp://www.amazon.com/gp/bit/amazonbookmark.html?tag=hp2-desktop-us-20&partner;=HP
ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Priceline.com.lnk -> C:\Program Files (x86)\HP\Shared\WizLink.exe () -> hxxp://www.priceline.com/?refid=PLHBC6240OPQ&refclickid;=square
 
==================== Loaded Modules (Whitelisted) ==============
 
2016-07-16 07:42 - 2016-07-16 07:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
2017-05-09 16:14 - 2017-04-27 20:49 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2016-09-01 18:12 - 2016-09-01 18:12 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2016-09-01 18:12 - 2016-09-01 18:12 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2016-10-10 22:15 - 2013-06-28 15:28 - 00084616 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2016-06-26 08:05 - 2014-04-14 21:59 - 00389896 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
2016-07-25 20:03 - 2016-07-25 20:03 - 00592392 _____ () C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
2017-04-17 21:33 - 2017-05-26 08:27 - 08931008 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2016-10-02 21:07 - 2016-10-02 21:07 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
2017-03-17 12:18 - 2017-03-04 02:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
2017-03-17 12:18 - 2017-03-04 02:30 - 00693248 _____ () C:\Windows\ShellExperiences\MtcUvc.dll
2017-05-11 23:22 - 2017-05-09 05:13 - 03767640 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libglesv2.dll
2017-05-11 23:22 - 2017-05-09 05:13 - 00100696 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libegl.dll
2017-06-02 08:01 - 2017-06-02 08:01 - 23661056 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\Video.UI.exe
2017-06-02 08:01 - 2017-06-02 08:01 - 09016320 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\EntCommon.dll
2017-05-26 08:18 - 2017-05-26 08:19 - 03140520 _____ () C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.17042.14211.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2017-06-07 18:55 - 2017-06-07 18:55 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2017-06-07 18:55 - 2017-06-07 18:55 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2017-06-07 18:55 - 2017-06-07 18:55 - 43318784 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2017-06-07 18:55 - 2017-06-07 18:55 - 02427904 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\skypert.dll
2017-03-17 12:18 - 2017-03-04 02:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-03-17 12:18 - 2017-03-04 02:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2017-03-17 12:18 - 2017-03-04 02:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
2017-05-09 16:14 - 2017-04-27 19:36 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
2017-05-09 16:14 - 2017-04-27 19:36 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2017-05-09 16:14 - 2017-04-27 19:37 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2016-07-25 20:03 - 2016-07-25 20:03 - 38907672 _____ () C:\Program Files\AVAST Software\SecureLine\libcef.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="Service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-10-30 03:24 - 2015-10-30 03:21 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-121274051-3287072310-3552221101-1001\Control Panel\Desktop\\Wallpaper -> C:\windows\web\wallpaper\Hewlett-Packard Backgrounds\backgroundDefault.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
HKLM\…\StartupApproved\Run: => "iTunesHelper"
HKLM\…\StartupApproved\Run32: => "HPMessageService"
HKLM\…\StartupApproved\Run32: => "AccelerometerSysTrayApplet"
HKLM\…\StartupApproved\Run32: => "HPRadioMgr"
HKLM\…\StartupApproved\Run32: => "PowerDVD14Agent"
HKLM\…\StartupApproved\Run32: => "APSDaemon"
HKU\S-1-5-21-121274051-3287072310-3552221101-1001\…\StartupApproved\Run: => "OneDrive"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{12E9A58A-C981-4B8A-8A3D-CE98E4D451D8}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{3ACED9FF-FB69-4058-AD8D-CA17361631AB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{799A0EF9-E789-4E29-AD1D-9F8BE2CA8E23}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{CB5F51AA-D236-4FE4-B131-973FEDB0ADC4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{7EAAB1F1-22A8-4619-B56F-273595838D26}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{F2EF520F-089C-4C3E-87BB-6097F567C28B}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
FirewallRules: [{2384820D-9B87-4E7E-9CC3-839C5653F4B4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{9318496D-F8DE-4C2A-B0B2-F395EDABF03C}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
FirewallRules: [{11095877-0F24-475B-9E88-052E3CC61288}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\SmartAgentTest.exe
FirewallRules: [{1DC094FF-631A-4379-864A-2769CF5C07AC}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\Next\WirelessDisplay.exe
FirewallRules: [{BCBF97CA-4539-41A4-85B1-AF4BA3546027}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiAppOld.exe
FirewallRules: [{F6FB54B3-CE74-4165-94B8-0B3AA8480A28}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
FirewallRules: [{80A9326C-3228-4190-A3F5-9F99F9005B8F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Movie\PowerDVD Cinema\PowerDVDCinema.exe
FirewallRules: [{97814783-041D-41E7-A83D-92DF98D3543C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Movie\PowerDVDMovie.exe
FirewallRules: [{D6EA5020-E1A6-437B-B1A7-D79BC62020E3}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe
FirewallRules: [{65F947B9-D7BF-49AC-9C91-295F0EF15DA7}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Kernel\DMS\CLMSServerPDVD14.exe
FirewallRules: [{594B753F-EC89-4B3C-8FC8-9D914EF19B39}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD.exe
FirewallRules: [{997B2FA0-FCB2-4153-A5BA-218B6CDC747A}] => (Allow) c:\Program Files\CyberLink\PowerDirector12\PDR10.EXE
FirewallRules: [TCP Query User{4CE5A3A4-D330-4753-8E78-54034948B5F7}C:\users\ihave3gals\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe] => (Allow) C:\users\ihave3gals\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe
FirewallRules: [UDP Query User{7F9E8A05-5368-4970-BE2C-4F9408CA9745}C:\users\ihave3gals\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe] => (Allow) C:\users\ihave3gals\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe
FirewallRules: [{ED4E3304-ABC9-4C18-A623-B1CA4903B61F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{C3035295-C0FB-44AF-90F6-CFC56A11757B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{3079220E-11CC-49B8-9DBD-58C9ED45CC5F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{C72DB456-6A84-41C4-A748-3460596EC6DA}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{96A20136-C54E-4D63-ADB2-3AAB62C55B41}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{88AE5486-5D16-43FF-A883-DECAE005C0AC}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
 
==================== Restore Points =========================
 
14-05-2017 12:33:02 Windows Update
22-05-2017 17:47:47 Windows Update
30-05-2017 20:58:37 Scheduled Checkpoint
08-06-2017 22:51:43 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/09/2017 09:53:43 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "WmiApRpl" in DLL "C:\WINDOWS\system32\wbem\wmiaprpl.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (06/09/2017 09:53:42 PM) (Source: PerfNet) (EventID: 2004) (User: )
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
 
Error: (06/09/2017 09:53:42 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "MSDTC" in DLL "C:\WINDOWS\system32\msdtcuiu.DLL" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (06/09/2017 09:53:42 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "Lsa" in DLL "C:\Windows\System32\Secur32.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (06/09/2017 09:53:42 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "ESENT" in DLL "C:\WINDOWS\system32\esentprf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (06/09/2017 09:53:42 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (06/09/2017 09:53:27 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10605.221) TYPE: ERROR
 
DPTF Build Version:  8.1.10605.221
DPTF Build Date:  Oct 23 2015 12:24:15
Source File:  ..\..\..\Sources\Manager\WIDomainPowerControlCapabilityChanged.cpp @ line 63
Executing Function:  WIDomainPowerControlCapabilityChanged::execute
Message:  Unhandled exception caught during execution of work item
Framework Event:  DomainPowerControlCapabilityChanged [19]
Participant:  TCPU [1]
Policy:  Passive Policy 2 [2]
Exception Function:  Policy::executeDomainPowerControlCapabilityChanged
Exception Text:  
Could not find client in directory.
 
Error: (06/09/2017 09:53:27 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10605.221) TYPE: ERROR
 
DPTF Build Version:  8.1.10605.221
DPTF Build Date:  Oct 23 2015 12:24:15
Source File:  ..\..\..\Sources\Manager\WIDomainPerformanceControlCapabilityChanged.cpp @ line 63
Executing Function:  WIDomainPerformanceControlCapabilityChanged::execute
Message:  Unhandled exception caught during execution of work item
Framework Event:  DomainPerformanceControlCapabilityChanged [17]
Participant:  TCPU [1]
Policy:  Passive Policy 2 [2]
Exception Function:  Policy::executeDomainPerformanceControlCapabilityChanged
Exception Text:  
Could not find client in directory.
 
Error: (06/09/2017 09:53:27 PM) (Source: DPTF) (EventID: 256) (User: )
Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10605.221) TYPE: ERROR
 
DPTF Build Version:  8.1.10605.221
DPTF Build Date:  Oct 23 2015 12:24:15
Source File:  ..\..\..\Sources\Manager\WIDomainPerformanceControlCapabilityChanged.cpp @ line 63
Executing Function:  WIDomainPerformanceControlCapabilityChanged::execute
Message:  Unhandled exception caught during execution of work item
Framework Event:  DomainPerformanceControlCapabilityChanged [17]
Participant:  TCPU [1]
Policy:  Passive Policy 2 [2]
Exception Function:  Policy::executeDomainPerformanceControlCapabilityChanged
Exception Text:  
Could not find client in directory.
 
Error: (06/09/2017 09:48:55 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1063
 
 
System errors:
=============
Error: (06/09/2017 08:29:23 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{D63B10C5-BB46-4990-A94F-E40B9D520160}
 and APPID 
{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
 to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
 
Error: (06/08/2017 10:52:18 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Interactive Services Detection service terminated with the following error: 
Incorrect function.
 
Error: (06/07/2017 10:21:21 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Interactive Services Detection service terminated with the following error: 
Incorrect function.
 
Error: (06/07/2017 09:49:10 PM) (Source: Tcpip) (EventID: 4199) (User: )
Description: The system detected an address conflict for IP address 0.0.0.0 with the system
having network hardware address C2-56-27-9A-D0-46. Network operations on this system may
be disrupted as a result.
 
Error: (06/06/2017 10:21:22 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Interactive Services Detection service terminated with the following error: 
Incorrect function.
 
Error: (06/05/2017 10:21:21 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Interactive Services Detection service terminated with the following error: 
Incorrect function.
 
Error: (06/04/2017 10:21:20 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Interactive Services Detection service terminated with the following error: 
Incorrect function.
 
Error: (06/03/2017 10:21:21 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Interactive Services Detection service terminated with the following error: 
Incorrect function.
 
Error: (06/02/2017 12:44:14 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Interactive Services Detection service terminated with the following error: 
Incorrect function.
 
Error: (06/01/2017 12:10:05 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Interactive Services Detection service terminated with the following error: 
Incorrect function.
 
 
CodeIntegrity:
===================================
  Date: 2017-06-09 21:57:47.357
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-06-09 21:57:47.355
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: Intel(R) Core(TM) i5-6200U CPU @ 2.30GHz
Percentage of memory in use: 41%
Total physical RAM: 12176.41 MB
Available physical RAM: 7122.11 MB
Total Virtual: 14864.41 MB
Available Virtual: 8951.8 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:918.85 GB) (Free:868.21 GB) NTFS
Drive d: (RECOVERY) (Fixed) (Total:11.43 GB) (Free:1.4 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive z: () (Fixed) (Total:0.25 GB) (Free:0.17 GB) FAT32
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: A50E1C7D)
 
Partition: GPT.
 
==================== End of Addition.txt ============================

Good Morning

 

Not looking at anything earth shattering on your logs, lets do some general clean up

 

All our tools and scanners work more efficiently when run from the DESKTOP in lieu of being buried in some folder, so download and run these tools right from the DESKTOP
 
 
-AdwCleaner-by Xplode
 
Click on this link to download : ADWCleaner TO YOUR DESKTOP
 
Use my link only, do not do a search for AdwCleaner as there is a bogus copy going around by scammers
 
[external image: AdwCleaner4.201_zpsxrbk2llq.jpg]
 
 
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next reply.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.
  •  
     
    ===============================================================================
     
     
     
     
    [external image: Capture_zpsge1t2tk9.jpg] Please download Junkware Removal Tool TO YOUR DESKTOP
    • Download the one from Bleeping Computer
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.
    •  
       
       
      ===============================================================================
       
       
       
      Download Malwarebytes' Anti-Malware  TO YOUR DESKTOP
       
      • Windows XP : Double click on the icon to run it.
      • Windows Vista, Windows 7 , 8, 8.1 and 10 : Right click and select "Run as Administrator"
      •  
        [external image: 3.0.6_zps4qucu0yg.jpg]
         
         
        • After the installation IS complete let it update if it asks.
        • Under SETTINGS…..APPLICATIONS leave everything at default
        • Under SETTINGS…..PROTECTION make sure AUTOMATIC QUARANTINE is on. 
        • Then go to the Dashboard and click on SCAN NOW
        • When the scan is finished click on EXPORT SUMMARY……COPY TO CLIPBOARD
        • Then come back to this thread and and under REPLY TO THIS TOPIC, right click in the reply and select Paste
        • Then click on POST
        • Exit Malwarebytes
        • Ken, thanks for all your help

          Here are the 3 logs.

           

          # AdwCleaner v6.047 - Logfile created 13/06/2017 at 08:20:16
          # Updated on 19/05/2017 by Malwarebytes
          # Database : 2017-06-13.2 [Server]
          # Operating System : Windows 10 Home  (X64)
          # Username : ihave3gals - DESKTOP-D22I8SO
          # Running from : C:\Users\ihave3gals\Desktop\AdwCleaner.exe
          # Mode: Clean
          # Support : https://www.malwarebytes.com/support
           
           
           
          ***** [ Services ] *****
           
           
           
          ***** [ Folders ] *****
           
          [-] Folder deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\kpocjpoifmommoiiiamepombpeoaehfh
          [-] Folder deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\kpocjpoifmommoiiiamepombpeoaehfh
          [-] Folder deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\mallpejgeafdahhflmliiahjdpgbegpk
          [-] Folder deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\mallpejgeafdahhflmliiahjdpgbegpk
          [-] Folder deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkbpfdkbpbckgkcelkfjjhepmdcdmahi
           
           
          ***** [ Files ] *****
           
          [-] File deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kpocjpoifmommoiiiamepombpeoaehfh_0.localstorage
          [-] File deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_kpocjpoifmommoiiiamepombpeoaehfh_0.localstorage-journal
          [-] File deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mallpejgeafdahhflmliiahjdpgbegpk_0.localstorage
          [-] File deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_mallpejgeafdahhflmliiahjdpgbegpk_0.localstorage-journal
          [-] File deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bkbpfdkbpbckgkcelkfjjhepmdcdmahi_0.localstorage
          [-] File deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Local Storage\chrome-extension_bkbpfdkbpbckgkcelkfjjhepmdcdmahi_0.localstorage-journal
           
           
          ***** [ DLL ] *****
           
           
           
          ***** [ WMI ] *****
           
           
           
          ***** [ Shortcuts ] *****
           
           
           
          ***** [ Scheduled Tasks ] *****
           
           
           
          ***** [ Registry ] *****
           
           
           
          ***** [ Web browsers ] *****
           
          [-] [C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: aol.com
          [-] [C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Web data] [Search Provider] Deleted: ask.com
          [-] [C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: bkbpfdkbpbckgkcelkfjjhepmdcdmahi
          [-] [C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: kpocjpoifmommoiiiamepombpeoaehfh
          [-] [C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default] [extension] Deleted: mallpejgeafdahhflmliiahjdpgbegpk
           
           
          *************************
           
          :: "Tracing" keys deleted
          :: Winsock settings cleared
           
          *************************
           
          C:\AdwCleaner\AdwCleaner[C0].txt - [3067 Bytes] - [13/06/2017 08:20:16]
          C:\AdwCleaner\AdwCleaner[S0].txt - [3560 Bytes] - [13/06/2017 08:19:24]
           
          ########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [3213 Bytes] ##########
           
           
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Junkware Removal Tool (JRT) by Malwarebytes
          Version: 8.1.3 (04.10.2017)
          Operating System: Windows 10 Home x64 
          Ran by [removed] (Administrator) on Tue 06/13/2017 at  8:24:09.25
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           
           
           
           
          File System: 2 
           
          Successfully deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj (Folder) 
          Successfully deleted: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Local Extension Settings\bmnlcjabgnpnenekpadlanbbkooimhnj (Folder) 
           
           
           
          Registry: 2 
           
          Successfully deleted: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9FB80709-BE3D-4A96-B000-9C61345C9E56} (Registry Key)
          Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\SearchScopes\{9FB80709-BE3D-4A96-B000-9C61345C9E56} (Registry Key)
           
           
           
           
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
          Scan was completed on Tue 06/13/2017 at  8:27:16.78
          End of JRT log
          ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
           
           
          Malwarebytes
          www.malwarebytes.com
           
          -Log Details-
          Scan Date: 6/13/17
          Scan Time: 8:30 AM
          Log File: MB.txt
          Administrator: Yes
           
          -Software Information-
          Version: 3.1.2.1733
          Components Version: 1.0.141
          Update Package Version: 1.0.2143
          License: Trial
           
          -System Information-
          OS: Windows 10
          CPU: x64
          File System: NTFS
          User: DESKTOP-D22I8SO\ihave3gals
           
          -Scan Summary-
          Scan Type: Threat Scan
          Result: Completed
          Objects Scanned: 397943
          Threats Detected: 64
          Threats Quarantined: 64
          Time Elapsed: 8 min, 46 sec
           
          -Scan Options-
          Memory: Enabled
          Startup: Enabled
          Filesystem: Enabled
          Archives: Enabled
          Rootkits: Disabled
          Heuristics: Enabled
          PUP: Enabled
          PUM: Enabled
           
          -Scan Details-
          Process: 0
          (No malicious items detected)
           
          Module: 0
          (No malicious items detected)
           
          Registry Key: 0
          (No malicious items detected)
           
          Registry Value: 0
          (No malicious items detected)
           
          Registry Data: 0
          (No malicious items detected)
           
          Data Stream: 0
          (No malicious items detected)
           
          Folder: 22
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\_locales\en, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\html\popup, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\_metadata, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\js\popup, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\_locales, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\newtab, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\html, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\css, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\js, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\HCFALFPGIOCAOOBNLAELJMLJHCNBNFJK, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\_locales\en, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\html\popup, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\_metadata, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\js\popup, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\_locales, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\newtab, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\html, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\css, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\js, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\EOILKAEJHMJJBDONGPICCBJCMGDEPIEM, Delete-on-Reboot, [2048], [362981],1.0.2143
           
          File: 42
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_easypdfcombine.dl.myway.com_0.localstorage, Delete-on-Reboot, [276], [240305],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_easypdfcombine.dl.myway.com_0.localstorage-journal, Delete-on-Reboot, [276], [240305],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_fromdoctopdf.dl.myway.com_0.localstorage, Delete-on-Reboot, [276], [240305],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_fromdoctopdf.dl.myway.com_0.localstorage-journal, Delete-on-Reboot, [276], [240305],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_yourtemplatefinder.dl.myway.com_0.localstorage, Delete-on-Reboot, [276], [240305],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_yourtemplatefinder.dl.myway.com_0.localstorage-journal, Delete-on-Reboot, [276], [240305],1.0.2143
          PUP.Optional.Spigot.Generic, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\HCFALFPGIOCAOOBNLAELJMLJHCNBNFJK\2.1_0\BACKGROUND.JS, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\css\description.css, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\css\popup.css, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\html\popup\description.html, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\html\popup\popup.html, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\js\popup\popup.js, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\js\userNewTab.js, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\newtab\newtab.html, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\_locales\en\messages.json, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\_metadata\computed_hashes.json, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\_metadata\verified_contents.json, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\contentscript.js, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\icon.png, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\hcfalfpgiocaoobnlaeljmljhcnbnfjk\2.1_0\manifest.json, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_easypdfcombine.dl.tb.ask.com_0.localstorage, Delete-on-Reboot, [276], [240306],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_easypdfcombine.dl.tb.ask.com_0.localstorage-journal, Delete-on-Reboot, [276], [240306],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_ext.dl.tb.ask.com_0.localstorage, Delete-on-Reboot, [276], [240306],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_ext.dl.tb.ask.com_0.localstorage-journal, Delete-on-Reboot, [276], [240306],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_fromdoctopdf.dl.tb.ask.com_0.localstorage, Delete-on-Reboot, [276], [240306],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_fromdoctopdf.dl.tb.ask.com_0.localstorage-journal, Delete-on-Reboot, [276], [240306],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_yourtemplatefinder.dl.tb.ask.com_0.localstorage, Delete-on-Reboot, [276], [240306],1.0.2143
          PUP.Optional.MindSpark, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\LOCAL STORAGE\http_yourtemplatefinder.dl.tb.ask.com_0.localstorage-journal, Delete-on-Reboot, [276], [240306],1.0.2143
          PUP.Optional.Spigot.Generic, C:\USERS\IHAVE3GALS\APPDATA\LOCAL\GOOGLE\CHROME\USER DATA\DEFAULT\EXTENSIONS\EOILKAEJHMJJBDONGPICCBJCMGDEPIEM\2.0_0\BACKGROUND.JS, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\css\description.css, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\css\popup.css, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\html\popup\description.html, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\html\popup\popup.html, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\js\popup\popup.js, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\js\userNewTab.js, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\newtab\newtab.html, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\_locales\en\messages.json, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\_metadata\computed_hashes.json, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\_metadata\verified_contents.json, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\contentscript.js, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\icon.png, Delete-on-Reboot, [2048], [362981],1.0.2143
          PUP.Optional.Spigot.Generic, C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\eoilkaejhmjjbdongpiccbjcmgdepiem\2.0_0\manifest.json, Delete-on-Reboot, [2048], [362981],1.0.2143
           
          Physical Sector: 0
          (No malicious items detected)
           
           
          (end)

          Hi,

           

          You had a bit going on, make sure to reboot your computer so that Malwarebytes will remove all that junk.

           

          Go to your downloads folder and look for FRST64, right click on it and select CUT, come back to your desktop and right click on a blank space and select PASTE, then we will have FRST64 right where it needs to be.

           

          Then right click on FRST64 and when it opens checkmark Additons, leave everything else as is, click on SCAN and post both new FRST64 and Additions logs and let me take another peek.

           

          Are things any better now ??

          Dear Ken:

           

          Thanks for your help.  The report from my wife is things are working better.

          Here are the logs.

           

          Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 12-06-2017
          Ran by [removed] (administrator) on DESKTOP-D22I8SO (14-06-2017 00:39:14)
          Running from C:\Users\[removed]\Desktop
          [removed]
          Platform: Windows 10 Home Version 1607 (X64) Language: English (United States)
          Internet Explorer Version 11 (Default browser: Edge)
          Boot Mode: Normal
          Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
           
          ==================== Processes (Whitelisted) =================
           
          (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
           
          (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igfxCUIService.exe
          (Hewlett-Packard Company) C:\Windows\System32\hpservice.exe
          (Microsoft Corporation) C:\Windows\System32\wlanext.exe
          (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
          (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
          (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
          (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
          (Conexant Systems, Inc) C:\Windows\CxSvc\CxMonSvc.exe
          (Conexant Systems, Inc.) C:\Windows\CxSvc\CxUtilSvc.exe
          (Intel Corporation) C:\Windows\SysWOW64\esif_uf.exe
          (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
          (HP Inc.) C:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe
          (Intel Corporation) C:\Windows\System32\ibtsiva.exe
          () C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
          (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
          (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe
          (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
          () C:\Program Files\AVAST Software\SecureLine\vpnsvc.exe
          (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
          () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
          (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
          (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe
          (Intel Corporation) C:\Windows\Temp\DPTF\esif_assist_64.exe
          (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
          (Intel Corporation) C:\Windows\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igfxEM.exe
          (McAfee, Inc.) C:\Windows\System32\mfevtps.exe
          (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
          (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
          (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
          (Conexant) C:\Windows\System32\MicTray64.exe
          (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
          () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe
          (Microsoft Corporation) C:\Windows\System32\smartscreen.exe
          (Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
          (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
          (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
          (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
          (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
          (HP Development Company, L.P.) C:\Program Files (x86)\HP\HP CoolSense\CoolSense.exe
          (McAfee, Inc.) C:\Program Files\mcafee\MSC\McAPExe.exe
          (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe
          (Microsoft Corporation) C:\Windows\System32\cmd.exe
          (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\McChHost.exe
          (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          (Microsoft Corporation) C:\Windows\splwow64.exe
          (CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
          (Conexant Systems, Inc) C:\Program Files\CONEXANT\Flow\Flow.exe
          (Conexant Systems, Inc.) C:\Program Files\CONEXANT\SA3\HP-NB-AIO\SmartAudio3.exe
          (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
          (AVAST Software) C:\Program Files\AVAST Software\SecureLine\secureline.exe
          (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
          (HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
          (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
          (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
          (McAfee, Inc.) C:\Program Files\mcafee\MAT\McPvTray.exe
          (Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.14393.1051_none_7f2bf7ea21d201b2\TiWorker.exe
          (Microsoft Corporation) C:\Windows\System32\dllhost.exe
           
          ==================== Registry (Whitelisted) ====================
           
          (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
           
          HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)
          HKLM\…\Run: [WindowsDefender] => C:\Program Files\Windows Defender\MSASCuiL.exe [631808 2017-04-27] (Microsoft Corporation)
          HKLM-x32\…\Run: [HPMessageService] => C:\Program Files (x86)\HP\HP System Event\HPMSGSVC.exe [657424 2016-01-11] (HP Inc.)
          HKLM-x32\…\Run: [AccelerometerSysTrayApplet] => C:\Program Files (x86)\Hewlett-Packard\HP 3D DriveGuard\AccelerometerST.exe [127528 2015-07-08] (Hewlett-Packard Company)
          HKLM-x32\…\Run: [PowerDVD14Agent] => C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe [795336 2016-01-29] (CyberLink Corp.)
          HKLM-x32\…\Run: [HPRadioMgr] => C:\Program Files (x86)\HP\HP Wireless Button Driver\HPRadioMgr64.exe [268896 2016-04-14] (HP)
          HKLM-x32\…\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-09-01] (Apple Inc.)
          HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1314432 2016-03-11] (CANON INC.)
          HKLM-x32\…\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [438888 2014-01-15] (CANON INC.)
           
          ==================== Internet (Whitelisted) ====================
           
          (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
           
          Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
          Tcpip\..\Interfaces\{7b6b2825-dccd-4690-a787-5c75c18cef19}: [DhcpNameServer] [removed]
          Tcpip\..\Interfaces\{cd5d1a67-fdc9-478d-9498-ae65a1dbb601}: [DhcpNameServer] 192.168.1.1
           
          Internet Explorer:
          ==================
          HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp15-comm.msn.com/?pc=HRTE
          HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
          HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp15-comm.msn.com/?pc=HRTE
          HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
          HKU\S-1-5-21-121274051-3287072310-3552221101-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://hp15-comm.msn.com/?pc=HRTE
          HKU\S-1-5-21-121274051-3287072310-3552221101-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://hp15-comm.msn.com/?pc=HRTE
          SearchScopes: HKLM -> {9FB80709-BE3D-4A96-B000-9C61345C9E56} URL = hxxp://www.amazon.com/s/ref=azs_osd_iea?ie=UTF-8&tag;=hp-us2-vsb-20&link;%5Fcode=qs&index;=aps&field-keywords;={searchTerms}
          BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
          BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
          BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
          BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
          BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-07-21] (HP Inc.)
          BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-05-26] (Microsoft Corporation)
          BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
          BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
          BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-05-26] (Microsoft Corporation)
          BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-07-21] (HP Inc.)
          Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
          Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
          Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
          Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
          Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
          Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
          Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
          Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-05-26] (Microsoft Corporation)
          Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
          Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-05-16] (McAfee, Inc.)
          Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\MSC\McSnIePl64.dll [2016-07-07] (McAfee, Inc.)
          Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2016-07-07] (McAfee, Inc.)
           
          FireFox:
          ========
          FF DefaultProfile: ad2f9vxu.default
          FF ProfilePath: C:\Users\ihave3gals\AppData\Roaming\Mozilla\Firefox\Profiles\ad2f9vxu.default [2017-05-30]
          FF HKLM\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
          FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2017-04-18]
          FF HKLM-x32\…\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi
          FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK
          FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2016-08-02] [not signed]
          FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2016-07-07] ()
          FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
          FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\windows\SysWOW64\Adobe\Director\np32dsw_1219159.dll [2015-06-26] (Adobe Systems, Inc.)
          FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-08-24] (Intel Corporation)
          FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-08-24] (Intel Corporation)
          FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2016-07-07] ()
          FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-05-26] (Microsoft Corporation)
          FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50906.0\npctrl.dll [2017-03-09] ( Microsoft Corporation)
          FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-05-26] (Microsoft Corporation)
          FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
          FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
          FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.)
           
          Chrome: 
          =======
          CHR NewTab: Default ->  Not-active:"chrome-extension://hcfalfpgiocaoobnlaeljmljhcnbnfjk/newtab/newtab.html", Not-active:"chrome-extension://eoilkaejhmjjbdongpiccbjcmgdepiem/newtab/newtab.html"
          CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type;=C211US0D20160802&p;={searchTerms}
          CHR DefaultSearchKeyword: Default -> mcafee
          CHR Profile: C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default [2017-06-14]
          CHR Extension: (Google Slides) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2016-07-27]
          CHR Extension: (Google Docs) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2016-07-27]
          CHR Extension: (Google Drive) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-07-27]
          CHR Extension: (YouTube) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-07-27]
          CHR Extension: (Honey) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2017-06-13]
          CHR Extension: (Adobe Acrobat) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-04-18]
          CHR Extension: (Google Sheets) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2016-07-27]
          CHR Extension: (McAfee® WebAdvisor) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2017-06-09]
          CHR Extension: (Google Docs Offline) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-07-27]
          CHR Extension: (Chrome Web Store Payments) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-03-17]
          CHR Extension: (Search Encrypt) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\oafomabmeffnelgdleajddppakeakfna [2017-05-10]
          CHR Extension: (Gmail) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-07-27]
          CHR Extension: (Chrome Media Router) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-05-18]
          CHR HKLM\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
          CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
          CHR HKLM-x32\…\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx
          CHR HKLM-x32\…\Chrome\Extension: [jkfpchpiljkaemlpmpebnglgkomamfeo] - hxxps://clients2.google.com/service/update2/crx
           
          ==================== Services (Whitelisted) ====================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)
          R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3971264 2017-05-14] (Microsoft Corporation)
          S3 cphs; C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\IntelCpHeciSvc.exe [310240 2017-02-22] (Intel Corporation)
          S3 cplspcon; C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\IntelCpHDCPSvc.exe [488928 2017-02-22] (Intel Corporation)
          R2 CxMonSvc; C:\WINDOWS\CxSvc\CxMonSvc.exe [22648 2016-06-07] (Conexant Systems, Inc)
          R2 CxUtilSvc; C:\WINDOWS\CxSvc\CxUtilSvc.exe [141432 2016-07-30] (Conexant Systems, Inc.)
          S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
          S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
          R2 esifsvc; C:\WINDOWS\SysWoW64\esif_uf.exe [1392792 2015-12-02] (Intel Corporation)
          R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
          R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [321056 2017-06-01] (HP Inc.)
          R2 HPWMISVC; c:\Program Files (x86)\HP\HP System Event\HPWMISVC.exe [606224 2016-01-11] (HP Inc.)
          R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [19440 2015-11-04] (Intel Corporation)
          R2 igfxCUIService2.0.0.0; C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igfxCUIService.exe [350688 2017-02-22] (Intel Corporation)
          R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [84616 2013-06-28] ()
          S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation)
          S3 Intel(R) WiDi SAM; C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [19088 2015-09-17] (Intel Corporation)
          R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [207648 2016-01-07] (Intel Corporation)
          R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [188256 2017-05-16] (McAfee, Inc.)
          R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [993824 2016-07-07] (McAfee, Inc.)
          R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
          R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
          R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
          S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [816128 2016-06-21] (McAfee, Inc.)
          R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
          R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
          R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [232688 2016-04-26] (McAfee, Inc.)
          R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [382456 2016-06-23] (McAfee, Inc.)
          R3 mfevtp; C:\windows\system32\mfevtps.exe [277744 2016-04-26] (McAfee, Inc.)
          S3 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [596768 2016-07-07] (McAfee, Inc.)
          S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2016-02-08] ()
          R2 RichVideo64; C:\Program Files\CyberLink\Shared files\RichVideo64.exe [389896 2014-04-14] ()
          R2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [592392 2016-07-25] ()
          R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [266872 2016-08-19] (Synaptics Incorporated)
          R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347320 2017-04-27] (Microsoft Corporation)
          R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [103712 2017-04-27] (Microsoft Corporation)
          R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3833248 2016-02-08] (Intel® Corporation)
          R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X]
           
          ===================== Drivers (Whitelisted) ======================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          R3 cfwids; C:\WINDOWS\System32\drivers\cfwids.sys [78632 2016-04-27] (McAfee, Inc.)
          R3 dptf_acpi; C:\WINDOWS\System32\drivers\dptf_acpi.sys [55784 2015-12-02] (Intel Corporation)
          R3 dptf_cpu; C:\WINDOWS\System32\drivers\dptf_cpu.sys [52200 2015-12-02] (Intel Corporation)
          R3 esif_lf; C:\WINDOWS\system32\DRIVERS\esif_lf.sys [260072 2015-12-02] (Intel Corporation)
          R3 HID_PCI; C:\WINDOWS\System32\drivers\HID_PCI.sys [47928 2015-11-26] (Intel)
          S3 HipShieldK; C:\WINDOWS\System32\drivers\HipShieldK.sys [207968 2016-02-24] (McAfee, Inc.)
          R3 ibtusb; C:\WINDOWS\system32\DRIVERS\ibtusb.sys [244744 2017-04-13] (Intel Corporation)
          R3 igfx; C:\WINDOWS\System32\DriverStore\FileRepository\120322.inf_amd64_496b556827a662cb\igdkmd64.sys [11036640 2017-02-22] (Intel Corporation)
          R3 ISH; C:\WINDOWS\System32\drivers\ISH.sys [139064 2015-11-26] (Intel)
          R3 ISH_BusDriver; C:\WINDOWS\System32\drivers\ISH_BusDriver.sys [75576 2015-11-26] (Intel)
          R0 MBAMSwissArmy; C:\WINDOWS\System32\drivers\MBAMSwissArmy.sys [252832 2017-06-13] (Malwarebytes)
          R2 McPvDrv; C:\WINDOWS\system32\drivers\McPvDrv.sys [79192 2016-04-20] (McAfee, Inc.)
          R3 mfeaack; C:\WINDOWS\System32\drivers\mfeaack.sys [419616 2016-04-27] (McAfee, Inc.)
          R3 mfeavfk; C:\WINDOWS\System32\drivers\mfeavfk.sys [349480 2016-04-27] (McAfee, Inc.)
          S0 mfeelamk; C:\WINDOWS\System32\drivers\mfeelamk.sys [83608 2016-04-27] (McAfee, Inc.)
          R3 mfefirek; C:\WINDOWS\System32\drivers\mfefirek.sys [493352 2016-04-27] (McAfee, Inc.)
          R0 mfehidk; C:\WINDOWS\System32\drivers\mfehidk.sys [843048 2016-04-27] (McAfee, Inc.)
          R3 mfencbdc; C:\WINDOWS\system32\DRIVERS\mfencbdc.sys [519976 2016-04-27] (McAfee, Inc.)
          S3 mfencrk; C:\WINDOWS\system32\DRIVERS\mfencrk.sys [100136 2016-04-27] (McAfee, Inc.)
          R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [46240 2016-06-06] (McAfee, Inc.)
          R0 mfewfpk; C:\WINDOWS\System32\drivers\mfewfpk.sys [243488 2016-04-27] (McAfee, Inc.)
          S3 NetAdapterCx; C:\WINDOWS\System32\drivers\NetAdapterCx.sys [90624 2016-07-16] ()
          U5 Netwtw02; C:\Windows\System32\Drivers\Netwtw02.sys [6722824 2016-01-01] (Intel Corporation)
          R3 Netwtw04; C:\WINDOWS\System32\drivers\Netwtw04.sys [7116288 2016-07-16] (Intel Corporation)
          R3 RTSPER; C:\WINDOWS\system32\DRIVERS\RtsPer.sys [758488 2016-02-02] (Realsil Semiconductor Corporation)
          S3 rtux64w10; C:\WINDOWS\System32\drivers\rtux64w10.sys [323072 2015-10-30] (Realtek                                                                ) [File not signed]
          S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [58984 2015-12-21] (Synaptics Incorporated)
          R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [72824 2016-08-19] (Synaptics Incorporated)
          R3 VirtualButtons; C:\WINDOWS\System32\drivers\VirtualButtons.sys [31280 2016-01-18] (Intel Corporation)
          S0 WdBoot; C:\WINDOWS\System32\drivers\WdBoot.sys [44056 2016-07-16] (Microsoft Corporation)
          R0 WdFilter; C:\WINDOWS\System32\drivers\WdFilter.sys [290144 2016-07-16] (Microsoft Corporation)
          R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [123232 2016-07-16] (Microsoft Corporation)
          R3 WirelessButtonDriver64; C:\WINDOWS\system32\DRIVERS\WirelessButtonDriver64.sys [31656 2016-04-14] (HP)
           
          ==================== NetSvcs (Whitelisted) ===================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
           
          ==================== One Month Created files and folders ========
           
          (If an entry is included in the fixlist, the file/folder will be moved.)
           
          2017-06-14 00:38 - 2017-06-14 00:38 - 00000000 ____D C:\Users\ihave3gals\Desktop\FRST-OlderVersion
          2017-06-13 15:32 - 2017-06-13 15:32 - 00072809 _____ C:\Users\ihave3gals\Downloads\posh_label_58dc3b58ca5c4d733600fea9.pdf
          2017-06-13 15:31 - 2017-06-13 15:31 - 00073296 _____ C:\Users\ihave3gals\Downloads\posh_label_593f4ac822172d0dfb0d470c.pdf
          2017-06-13 15:30 - 2017-06-13 15:30 - 00072415 _____ C:\Users\ihave3gals\Downloads\posh_label_593d7f189d78f809821be7ec.pdf
          2017-06-13 08:50 - 2017-06-13 08:50 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\104B0A2E.sys
          2017-06-13 08:42 - 2017-06-13 08:42 - 00014129 _____ C:\Users\ihave3gals\Desktop\MB.txt
          2017-06-13 08:29 - 2017-06-13 08:29 - 00252832 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
          2017-06-13 08:27 - 2017-06-13 08:27 - 00001124 _____ C:\Users\ihave3gals\Desktop\JRT.txt
          2017-06-13 08:22 - 2017-06-13 08:22 - 00003292 _____ C:\Users\ihave3gals\Desktop\AdwCleaner[C0].txt
          2017-06-13 08:17 - 2017-06-13 08:20 - 00000000 ____D C:\AdwCleaner
          2017-06-13 08:11 - 2017-06-13 08:28 - 64232976 _____ (Malwarebytes ) C:\Users\ihave3gals\Desktop\mb3-setup-consumer-3.1.2.1733-1.0.141-1.0.2092.exe
          2017-06-13 08:10 - 2017-06-13 08:23 - 01663672 _____ (Malwarebytes) C:\Users\ihave3gals\Desktop\JRT.exe
          2017-06-13 08:09 - 2017-06-13 08:17 - 04110280 _____ C:\Users\ihave3gals\Desktop\AdwCleaner.exe
          2017-06-11 23:32 - 2017-06-11 23:32 - 00000000 ____D C:\Users\ihave3gals\Downloads\FRST-OlderVersion
          2017-06-09 22:00 - 2017-06-09 22:01 - 00037696 _____ C:\Users\ihave3gals\Downloads\Addition.txt
          2017-06-09 21:59 - 2017-06-14 00:40 - 00025958 _____ C:\Users\ihave3gals\Desktop\FRST.txt
          2017-06-09 21:58 - 2017-06-14 00:39 - 00000000 ____D C:\FRST
          2017-06-09 21:57 - 2017-06-14 00:38 - 02438656 _____ (Farbar) C:\Users\ihave3gals\Desktop\FRST64.exe
          2017-06-09 21:54 - 2017-06-09 21:54 - 00003751 _____ C:\Users\ihave3gals\Desktop\aswMBR.txt
          2017-06-09 21:54 - 2017-06-09 21:54 - 00000512 _____ C:\Users\ihave3gals\Desktop\MBR.dat
          2017-06-09 20:38 - 2017-06-09 20:38 - 05198336 _____ (AVAST Software) C:\Users\ihave3gals\Downloads\aswMBR.exe
          2017-06-09 12:19 - 2017-06-09 12:19 - 00074260 _____ C:\Users\ihave3gals\Downloads\posh_label_593a15f020b687373007837d.pdf
          2017-06-07 23:07 - 2017-06-07 23:07 - 00072260 _____ C:\Users\ihave3gals\Downloads\posh_label_5938ae6154b35ecb8108f9cb.pdf
          2017-06-07 10:53 - 2017-06-07 10:53 - 00074239 _____ C:\Users\ihave3gals\Downloads\posh_label_5937ee18d8ff09340e331304.pdf
          2017-06-07 10:52 - 2017-06-07 10:52 - 00074031 _____ C:\Users\ihave3gals\Downloads\posh_label_5936a189426737f143161cca.pdf
          2017-06-07 10:52 - 2017-06-07 10:52 - 00072212 _____ C:\Users\ihave3gals\Downloads\posh_label_5937d51cd8ff09089731be73.pdf
          2017-06-05 22:34 - 2017-06-05 22:34 - 00072793 _____ C:\Users\ihave3gals\Downloads\posh_label_59358e4b4267378d9354e044.pdf
          2017-06-04 20:10 - 2017-06-04 20:10 - 00073724 _____ C:\Users\ihave3gals\Downloads\posh_label_5932b52aadce924eba134f10.pdf
          2017-06-04 20:09 - 2017-06-04 20:09 - 00073519 _____ C:\Users\ihave3gals\Downloads\posh_label_593301e6426737005a1b5f03.pdf
          2017-06-04 20:07 - 2017-06-04 20:07 - 00074065 _____ C:\Users\ihave3gals\Downloads\posh_label_593376028031c8c17c26f4b7.pdf
          2017-06-03 22:18 - 2017-06-03 22:18 - 00073727 _____ C:\Users\ihave3gals\Downloads\posh_label_59334b7c09e95303ef22b068 (1).pdf
          2017-06-03 22:17 - 2017-06-03 22:17 - 00073727 _____ C:\Users\ihave3gals\Downloads\posh_label_59334b7c09e95303ef22b068.pdf
          2017-06-02 23:11 - 2017-06-02 23:11 - 00073676 _____ C:\Users\ihave3gals\Downloads\posh_label_5931a43709e95368f70dee85.pdf
          2017-06-02 23:10 - 2017-06-02 23:10 - 00073215 _____ C:\Users\ihave3gals\Downloads\posh_label_59319115d31164fadb0c09f2.pdf
          2017-06-02 08:10 - 2017-06-02 08:10 - 00073684 _____ C:\Users\ihave3gals\Downloads\posh_label_592f948ba457c8ca27d5afe4.pdf
          2017-06-02 08:09 - 2017-06-02 08:09 - 00073377 _____ C:\Users\ihave3gals\Downloads\posh_label_5930a55247b2f32dd801f5ab.pdf
          2017-06-02 08:09 - 2017-06-02 08:09 - 00073377 _____ C:\Users\ihave3gals\Downloads\posh_label_5930a55247b2f32dd801f5ab (1).pdf
          2017-06-02 08:08 - 2017-06-02 08:08 - 00072953 _____ C:\Users\ihave3gals\Downloads\posh_label_59306f7dca5c4d19fc0161ef.pdf
          2017-06-02 08:05 - 2017-06-02 08:05 - 00072453 _____ C:\Users\ihave3gals\Downloads\posh_label_59306732adce925ca7007d1d.pdf
          2017-05-30 19:19 - 2017-05-30 19:19 - 00119639 _____ C:\Users\ihave3gals\Downloads\CignaMobileIDCard (1).pdf
          2017-05-30 19:18 - 2017-05-30 19:18 - 00119639 _____ C:\Users\ihave3gals\Downloads\CignaMobileIDCard.pdf
          2017-05-29 21:16 - 2017-05-29 21:16 - 00075473 _____ C:\Users\ihave3gals\Downloads\posh_label_592acd0bb73984ae3263fec0.pdf
          2017-05-29 21:15 - 2017-05-29 21:15 - 00073306 _____ C:\Users\ihave3gals\Downloads\posh_label_592a3578d8ff09b72d5b5403.pdf
          2017-05-29 21:15 - 2017-05-29 21:15 - 00073306 _____ C:\Users\ihave3gals\Downloads\posh_label_592a3578d8ff09b72d5b5403 (1).pdf
          2017-05-26 19:36 - 2017-05-26 19:36 - 00031109 _____ C:\Users\ihave3gals\Downloads\INV-001116.pdf
          2017-05-26 19:16 - 2017-05-26 19:16 - 00355892 _____ C:\Users\ihave3gals\Downloads\Inv_06011700_from_Simply_Serving_LLC_1260.pdf
          2017-05-24 22:28 - 2017-05-24 22:28 - 00073948 _____ C:\Users\ihave3gals\Downloads\posh_label_592625b273e444a76b0827f1.pdf
          2017-05-22 21:25 - 2017-05-22 21:25 - 00073892 _____ C:\Users\ihave3gals\Downloads\posh_label_592358d2b7398410eb7162aa.pdf
          2017-05-19 20:43 - 2017-05-19 20:43 - 00074500 _____ C:\Users\ihave3gals\Downloads\posh_label_591f855c93039450f31fda1a.pdf
          2017-05-19 20:43 - 2017-05-19 20:43 - 00073395 _____ C:\Users\ihave3gals\Downloads\posh_label_591f3c97b88c5634441956a5 (1).pdf
          2017-05-19 20:42 - 2017-05-19 20:42 - 00073395 _____ C:\Users\ihave3gals\Downloads\posh_label_591f3c97b88c5634441956a5.pdf
          2017-05-19 08:01 - 2017-05-19 08:01 - 00073336 _____ C:\Users\ihave3gals\Downloads\posh_label_591ec17ad31164af610e80d1.pdf
          2017-05-19 08:01 - 2017-05-19 08:01 - 00073336 _____ C:\Users\ihave3gals\Downloads\posh_label_591ec17ad31164af610e80d1 (1).pdf
          2017-05-19 08:00 - 2017-05-19 08:00 - 00073372 _____ C:\Users\ihave3gals\Downloads\posh_label_591da22854b35e1ea7180aa5 (1).pdf
          2017-05-19 07:59 - 2017-05-19 07:59 - 00073372 _____ C:\Users\ihave3gals\Downloads\posh_label_591da22854b35e1ea7180aa5.pdf
          2017-05-17 22:49 - 2017-05-17 22:49 - 00073996 _____ C:\Users\ihave3gals\Downloads\posh_label_591cb5a9d142c30f89ff2098.pdf
          2017-05-16 16:09 - 2017-05-16 16:09 - 00074585 _____ C:\Users\ihave3gals\Downloads\posh_label_5919d45842a322396a19025e (1).pdf
          2017-05-16 16:08 - 2017-05-16 16:08 - 00074585 _____ C:\Users\ihave3gals\Downloads\posh_label_5919d45842a322396a19025e.pdf
          2017-05-15 11:12 - 2016-06-29 13:11 - 00007068 _____ C:\WINDOWS\system32\cxapo2.prop
          2017-05-15 11:12 - 2016-06-29 13:11 - 00007068 _____ C:\WINDOWS\system32\cxapo.prop
          2017-05-15 11:12 - 2016-04-19 13:46 - 00004664 _____ C:\WINDOWS\system32\Drivers\SSPTunePt.DAT
          2017-05-15 11:11 - 2017-05-15 11:11 - 00002192 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bang & Olufsen Audio Control.lnk
          2017-05-15 11:11 - 2017-05-15 11:11 - 00000000 ____D C:\ProgramData\SRS Labs
          2017-05-15 11:11 - 2017-05-14 10:09 - 02758232 _____ (Conexant) C:\WINDOWS\system32\MicTray64.exe
          2017-05-15 11:11 - 2016-02-17 18:02 - 00002988 _____ C:\WINDOWS\system32\MicTray64.xml
           
          ==================== One Month Modified files and folders ========
           
          (If an entry is included in the fixlist, the file/folder will be moved.)
           
          2017-06-14 00:38 - 2016-08-02 23:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
          2017-06-14 00:38 - 2016-07-16 07:36 - 00000000 ____D C:\WINDOWS\CbsTemp
          2017-06-14 00:36 - 2016-08-02 23:23 - 00000000 __RSD C:\Users\ihave3gals\Documents\McAfee Vaults
          2017-06-14 00:35 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\AppReadiness
          2017-06-14 00:33 - 2016-10-02 17:36 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
          2017-06-14 00:33 - 2016-07-24 23:53 - 00000000 __SHD C:\Users\ihave3gals\IntelGraphicsProfiles
          2017-06-14 00:32 - 2016-07-16 02:04 - 00786432 _____ C:\WINDOWS\system32\config\BBI
          2017-06-13 21:11 - 2016-10-02 17:13 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
          2017-06-13 08:21 - 2016-09-13 15:19 - 00000384 _____ C:\WINDOWS\Tasks\HPCeeScheduleForihave3gals.job
          2017-06-12 21:55 - 2016-07-16 07:47 - 00000000 ___HD C:\Program Files\WindowsApps
          2017-06-12 12:37 - 2016-10-02 17:36 - 00003296 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForihave3gals
          2017-06-09 23:02 - 2016-07-16 02:04 - 00032768 _____ C:\WINDOWS\system32\config\ELAM
          2017-06-08 22:52 - 2016-07-16 07:47 - 00000000 ____D C:\WINDOWS\system32\appraiser
          2017-06-07 22:17 - 2016-10-10 22:15 - 00000000 ____D C:\ProgramData\CanonIJPLM
          2017-05-31 19:46 - 2016-08-02 23:13 - 00565416 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
          2017-05-26 08:29 - 2016-07-16 07:47 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
          2017-05-26 08:28 - 2016-04-22 18:16 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
          2017-05-22 17:51 - 2016-07-26 09:37 - 00000000 ____D C:\WINDOWS\system32\MRT
          2017-05-22 17:48 - 2016-07-26 09:37 - 132223576 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
          2017-05-21 13:29 - 2016-10-02 17:20 - 00000000 ____D C:\Users\ihave3gals
          2017-05-21 13:11 - 2016-07-27 22:13 - 00000000 ____D C:\Users\ihave3gals\AppData\Roaming\Mozilla
          2017-05-18 19:23 - 2016-10-02 17:20 - 01473004 _____ C:\WINDOWS\system32\PerfStringBackup.INI
          2017-05-18 19:17 - 2016-08-02 23:18 - 00000000 ____D C:\Program Files (x86)\McAfee
          2017-05-15 11:13 - 2016-07-24 23:56 - 00000000 ____D C:\Users\ihave3gals\AppData\Local\Conexant
          2017-05-15 11:12 - 2017-05-14 12:36 - 00000000 ____D C:\WINDOWS\CxSvc
          2017-05-15 11:10 - 2016-10-02 17:15 - 01701376 _____ (TODO: ) C:\WINDOWS\SysWOW64\RebootPrompt.exe
          2017-05-15 11:10 - 2016-10-02 17:15 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
          2017-05-15 11:08 - 2016-07-16 07:45 - 00000000 ____D C:\WINDOWS\INF
           
          ==================== Bamital & volsnap ======================
           
          (There is no automatic fix for files that do not pass verification.)
           
          C:\WINDOWS\system32\winlogon.exe => File is digitally signed
          C:\WINDOWS\system32\wininit.exe => File is digitally signed
          C:\WINDOWS\explorer.exe => File is digitally signed
          C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
          C:\WINDOWS\system32\svchost.exe => File is digitally signed
          C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
          C:\WINDOWS\system32\services.exe => File is digitally signed
          C:\WINDOWS\system32\User32.dll => File is digitally signed
          C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
          C:\WINDOWS\system32\userinit.exe => File is digitally signed
          C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
          C:\WINDOWS\system32\rpcss.dll => File is digitally signed
          C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
          C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
          C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
           
          LastRegBack: 2017-06-10 08:01
           
          ==================== End of FRST.txt ============================
           
           
          Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-06-2017
          Ran by [removed] (14-06-2017 00:40:35)
          Running from C:\Users\[removed]\Desktop
          Windows 10 Home Version 1607 (X64) (2016-10-02 21:39:32)
          Boot Mode: Normal
          ==========================================================
           
           
          ==================== Accounts: =============================
           
          Administrator (S-1-5-21-121274051-3287072310-3552221101-500 - Administrator - Disabled)
          DefaultAccount (S-1-5-21-121274051-3287072310-3552221101-503 - Limited - Disabled)
          Guest (S-1-5-21-121274051-3287072310-3552221101-501 - Limited - Disabled)
          ihave3gals (S-1-5-21-121274051-3287072310-3552221101-1001 - Administrator - Enabled) => C:\Users\ihave3gals
           
          ==================== Security Center ========================
           
          (If an entry is included in the fixlist, it will be removed.)
           
          AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          AV: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {DA9F8ED0-D0DE-39CC-F55A-51AB4CC1B556}
          AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
          AS: McAfee Anti-Virus and Anti-Spyware (Disabled - Up to date) {61FE6F34-F6E4-3642-CFEA-6AD93746FFEB}
          FW: McAfee Firewall (Disabled) {E2A40FF5-9AB1-3894-DE05-F89EB212F22D}
           
          ==================== Installed Programs ======================
           
          (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
           
          Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated)
          Adobe Shockwave Player 12.1 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.1.9.159 - Adobe Systems, Inc.)
          Apple Application Support (32-bit) (HKLM-x32\…\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.)
          Apple Application Support (64-bit) (HKLM\…\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.)
          Apple Mobile Device Support (HKLM\…\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.)
          Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
          Avast SecureLine (HKLM\…\{2CD3C92F-EDC5-4B02-9B0A-9C1D37C58EF5}_is1) (Version: 1.0.275.2 - AVAST Software)
          Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
          Canon Easy-WebPrint EX (HKLM-x32\…\Easy-WebPrint EX) (Version: 1.7.0.0 - Canon Inc.)
          Canon IJ Network Scanner Selector EX (HKLM-x32\…\Canon_IJ_Network_Scanner_Selector_EX) (Version: 1.5.2.3 - Canon Inc.)
          Canon IJ Network Tool (HKLM-x32\…\Canon_IJ_Network_UTILITY) (Version: 3.5.0 - Canon Inc.)
          Canon IJ Scan Utility (HKLM-x32\…\Canon_IJ_Scan_Utility) (Version: 1.1.10.15 - Canon Inc.)
          Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\…\CANONIJPLM100) (Version: 4.2.0 - Canon Inc.)
          Canon MG6600 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6600_series) (Version: 1.01 - Canon Inc.)
          Canon MG6600 series On-screen Manual (HKLM-x32\…\Canon MG6600 series On-screen Manual) (Version: 7.7.0 - Canon Inc.)
          Canon MG6600 series User Registration (HKLM-x32\…\Canon MG6600 series User Registration) (Version:  - ‭Canon Inc.)
          Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: 3.3.0 - Canon Inc.)
          Canon Quick Menu (HKLM-x32\…\CanonQuickMenu) (Version: 2.7.0 - Canon Inc.)
          Conexant HD Audio (HKLM\…\CNXT_AUDIO_HDA) (Version: 8.65.165.11 - Conexant Systems)
          CyberLink Power Media Player 14 (HKLM-x32\…\{32C8E300-BDB4-4398-92C2-E9B7D8A233DB}) (Version: 14.0.3.6129 - CyberLink Corp.)
          CyberLink PowerDirector 12 (HKLM-x32\…\InstallShield_{E1646825-D391-42A0-93AA-27FA810DA093}) (Version: 12.0.6.4925 - CyberLink Corp.)
          CyberLink PowerDirector 12 (Version: 12.0.6.4925 - CyberLink Corp.) Hidden
          DisableMSDefender (Version: 1.0.0 - Hewlett-Packard Company) Hidden
          Dropbox 25 GB (HKLM-x32\…\{0867A88D-764F-366E-9E21-130DA8B472C3}) (Version: 3.1.18.0 - Dropbox, Inc.)
          Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden
          Energy Star (HKLM\…\{5CB22648-35F8-41BC-9C35-1E41FE6E12A5}) (Version: 1.1.1 - HP Inc.)
          Google Chrome (HKLM-x32\…\Google Chrome) (Version: 58.0.3029.110 - Google Inc.)
          Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden
          HP 3D DriveGuard (HKLM-x32\…\{E8D0E2B8-B64B-44BC-8E01-00DDACBDF78A}) (Version: 6.0.28.1 - Hewlett-Packard Company)
          HP CoolSense (HKLM-x32\…\{0C723C74-62DF-4B35-9490-A207546D866D}) (Version: 2.21.4 - HP Inc.)
          HP Documentation (HKLM\…\HP_Documentation) (Version: 1.0.0.1 - HP)
          HP ePrint SW (HKLM-x32\…\{88970959-baf7-4864-a39a-69a58e8ae5cf}) (Version: 5.0.18701 - HP)
          HP Registration Service (HKLM\…\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.8318.5320 - Hewlett-Packard)
          HP Support Assistant (HKLM-x32\…\{E959FD01-BD01-4CC4-9BB8-4EBE8309BF37}) (Version: 8.4.14.41 - HP)
          HP Support Solutions Framework (HKLM-x32\…\{E2CB09C1-3C76-4395-BB47-50C066535CF8}) (Version: 12.7.22.13 - HP)
          HP System Event Utility (HKLM-x32\…\{09D0DB68-90EA-4015-983E-A0BD777D5A02}) (Version: 1.4.9 - HP Inc.)
          HP Welcome (HKLM\…\HPWelcome) (Version: 1.0 - HP Inc.)
          HP Wireless Button Driver (HKLM-x32\…\{AF4C5F64-4E6A-438B-9832-8BDEE0E7B43D}) (Version: 1.1.17.1 - HP)
          Intel(R) Chipset Device Software (x32 Version: 10.1.1.13 - Intel(R) Corporation) Hidden
          Intel(R) Dynamic Platform and Thermal Framework (HKLM-x32\…\{654EE65D-FAA4-4EA6-8C07-DC94E6A304D4}) (Version: 8.1.10605.221 - Intel Corporation)
          Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1177 - Intel Corporation)
          Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 20.19.15.4377 - Intel Corporation)
          Intel(R) Rapid Storage Technology (HKLM\…\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.8.0.1042 - Intel Corporation)
          Intel(R) Serial IO (HKLM\…\{9FD91C5C-44AE-4D9D-85BE-AE52816B0294}) (Version: 30.63.1519.7 - Intel Corporation)
          Intel(R) Virtual Buttons (HKLM-x32\…\1992736F-C90A-481C-B21B-EE34CAD07387) (Version: 1.1.0.21 - Intel Corporation)
          Intel(R) WiDi (HKLM\…\{6B15F1EF-F3A8-4C29-BF9E-18EB3683A83D}) (Version: 6.0.60.0 - Intel Corporation)
          Intel(R) WiDi Software Asset Manager (x32 Version: 3.2.1184 - Intel Corporation) Hidden
          Intel(R) Wireless Bluetooth(R) (HKLM-x32\…\{5068B0F8-CE24-4B61-9C2F-301B411FFB9C}) (Version: 18.1.1611.3223 - Intel Corporation)
          Intel® Integrated Sensor Solution (HKLM-x32\…\{33418794-f1ee-42cb-a2a6-472126fe03c9}) (Version: 3.0.0.1008 - Intel Corporation)
          Intel® PROSet/Wireless Software (HKLM-x32\…\{d5572863-793c-4ec8-872a-43cccc68b948}) (Version: 18.40.0 - Intel Corporation)
          ISS_Drivers_x64 (Version: 3.0.0.1008 - Intel Corporation) Hidden
          iTunes (HKLM\…\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.)
          McAfee Total Protection (HKLM-x32\…\MSC) (Version: 15.0.166 - McAfee, Inc.)
          McAfee WebAdvisor (HKLM-x32\…\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.139 - McAfee, Inc.)
          Microsoft Office Professional Plus 2016 - en-us (HKLM\…\ProPlusRetail - en-us) (Version: 16.0.8067.2115 - Microsoft Corporation)
          Microsoft OneDrive (HKU\S-1-5-21-121274051-3287072310-3552221101-1001\…\OneDriveSetup.exe) (Version: 17.3.6799.0327 - Microsoft Corporation)
          Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50906.0 - Microsoft Corporation)
          Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\…\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
          Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
          Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\…\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
          Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
          Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.21005 (HKLM-x32\…\{7f51bdb9-ee21-49ee-94d6-90afc321780e}) (Version: 12.0.21005.1 - Microsoft Corporation)
          Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
          Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.8067.2115 - Microsoft Corporation) Hidden
          Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.8067.2115 - Microsoft Corporation) Hidden
          Office 16 Click-to-Run Licensing Component (Version: 16.0.8067.2115 - Microsoft Corporation) Hidden
          Office 16 Click-to-Run Localization Component (x32 Version: 16.0.7967.2073 - Microsoft Corporation) Hidden
          Optimum (HKU\S-1-5-21-121274051-3287072310-3552221101-1001\…\3146597695.optimumapp.iptv.optimum.net) (Version:  - optimumapp.iptv.optimum.net)
          Optimum App for Laptop 4.12 (HKLM\…\{6082AB31-92B1-4832-AC89-3B2E6D8C14FE}) (Version: 4.12 - Cablevision)
          QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
          swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
          Synaptics ClickPad Driver (HKLM\…\SynTPDeinstKey) (Version: 19.3.11.37 - Synaptics Incorporated)
          Windows 10 Update and Privacy Settings (HKLM\…\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation)
           
          ==================== Custom CLSID (Whitelisted): ==========================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
           
          ==================== Scheduled Tasks (Whitelisted) =============
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          Task: {11A11EC2-D611-429F-BB78-0DF1B4A65888} - System32\Tasks\OneDrive Standalone Update Task => C:\Users\ihave3gals\AppData\Local\Microsoft\OneDrive\17.3.6517.0809\OneDriveStandaloneUpdater.exe
          Task: {2C2F396E-9C5B-4D84-8953-B950E6E6F046} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
          Task: {2FC9C5F5-7F6F-4896-8B36-352652FD8193} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
          Task: {326E184D-CDA0-41E6-8EB8-F76FACACE53C} - System32\Tasks\HPDAS => C:\Program [Argument = Files\HP\HP ePrint\HP.DeliveryAndStatus.Desktop.App.exe /CheckJobs]
          Task: {402CFF77-B3B8-4FD9-93A7-67678EE6CF84} - System32\Tasks\HPCeeScheduleForihave3gals => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
          Task: {40589131-B03A-456D-941F-5BF379AB3F06} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated)
          Task: {452A1636-E974-4A70-AB0F-11AB936B5E36} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-05-14] (Microsoft Corporation)
          Task: {51EE0877-371B-422B-8298-7E3DB6E21B55} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
          Task: {5213AD96-6046-4DA2-8919-7BDCC6DB553C} - System32\Tasks\Microsoft\Windows\Conexant\MicTray => C:\Windows\System32\MicTray64.exe [2017-05-14] (Conexant)
          Task: {54724C21-FB4D-4246-B8F1-5DF4E1A71933} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-05-14] (Microsoft Corporation)
          Task: {555CFAC0-2CE7-46A3-B548-D08FE97B092F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
          Task: {5AA361F1-D205-48E5-8B5A-848B66ED087D} - System32\Tasks\avast! SL Update => C:\Program Files\AVAST Software\SecureLine\SLUpdate.exe [2016-07-25] (AVAST Software)
          Task: {5FBC6735-CB1D-49B8-885F-4C14777E1B25} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2015-09-17] (Intel Corporation)
          Task: {61EE3755-027D-4876-8AE5-0190A1284681} - System32\Tasks\HP\HP CoolSense\HP CoolSense Start at Logon => C:\Program Files (x86)\HP\HP CoolSense\CoolSense.exe [2016-01-21] (HP Development Company, L.P.)
          Task: {64514458-B2FD-4370-90F1-ECF2D0943AA0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-05-25] (HP Inc.)
          Task: {6941EA39-88D1-4F55-9B34-2F39C83DA74F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-04-06] (HP Inc.)
          Task: {6B6C4F8F-E9AE-4F6D-B4C5-C841E2E811C5} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-05-26] ()
          Task: {90B21D84-5041-4BBA-9EE9-EF511711A609} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-27] (Google Inc.)
          Task: {9174AC26-76F4-4C4D-88C5-A8107A3953DC} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [2015-06-05] (Intel Corporation)
          Task: {920F3DF3-7CE5-40EF-8ABB-E77DA70BA47C} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2016-07-07] (McAfee, Inc.)
          Task: {ABA80ACA-7D63-4C50-AC30-BD8946D64692} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent
          Task: {B11FB292-E332-4371-BAE8-B53C743D736A} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
          Task: {B2A39930-A216-4A33-8FEB-3375A1D9781C} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-12-21] (HP Inc.)
          Task: {B63478DF-B3FD-4C42-B03A-2240A859B88B} - System32\Tasks\IntelWiDi-Upgrade-91ba0caa-28a7-4f47-8d08-f71b4b10fbec-Logon => C:\Program Files (x86)\Intel Corporation\Intel WiDi\Intel(R) Software Asset Manager\bin\IntelSoftwareAssetManagerService.exe [2015-09-17] (Intel Corporation)
          Task: {B80EEE79-4591-492D-A124-59EF0BEA408D} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
          Task: {BD4BEB68-4F1D-46BE-9020-FD8517B41066} - System32\Tasks\DropboxOEM => C:\Program Files (x86)\Dropbox\DropboxOEM\DropboxOEM.exe [2016-09-21] ()
          Task: {BF9B0E83-E834-4703-BCBC-CD146D14985D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
          Task: {C2358725-0298-4A48-98A4-6495804C7B35} - System32\Tasks\IUM-F1E24CA0-B63E-4F13-A9E3-4ADE3BFF3473 => C:\Program Files (x86)\Intel\Intel(R) Update Manager\bin\iumsvc.exe
          Task: {C53A5D3F-66A1-4BF4-80A5-C6BB0427A126} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
          Task: {C542A672-CDDB-4CB5-800C-21F8B22BA647} - System32\Tasks\Avast SecureLine => C:\Program Files\AVAST Software\SecureLine\SecureLine.exe [2016-07-25] (AVAST Software)
          Task: {C7629495-3A00-4A2D-A761-3941F20419A2} - System32\Tasks\Microsoft\Windows\Conexant\FLOW => C:\Program Files\CONEXANT\FLOW\SACpl.exe [2016-06-23] (Conexant Systems, Inc.)
          Task: {CCFB69ED-BD28-482B-AF77-13B555C12BE9} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [2017-04-12] (McAfee, Inc.)
          Task: {D57FCA82-BA50-44F8-9A30-0E86C76D9A30} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-05-26] ()
          Task: {E63D6726-0930-4032-AB37-41D6C130E995} - System32\Tasks\McAfee\McAfee Idle Detection Task
          Task: {E84EFDA9-66A3-4F8E-9D5A-C8A419E1EDCA} - System32\Tasks\Microsoft\Windows\Conexant\SA3 => C:\Program Files\CONEXANT\SA3\HP-NB-AIO\SACpl.exe [2016-01-08] (Conexant Systems, Inc.)
          Task: {EC474F25-86B3-46E6-A945-39010F7D7971} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-07-27] (Google Inc.)
          Task: {EDE4DA7A-2C2F-4B0F-BAE9-24D2D7F0F7C8} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-05-26] (Microsoft Corporation)
          Task: {F2117ECE-3739-4300-820E-46C450374DDE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-05-26] (Microsoft Corporation)
          Task: {FF5B04DF-D99D-48BA-A808-EDEAD832121F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-04-06] (HP Inc.)
           
          (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
           
          Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
          Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
          Task: C:\WINDOWS\Tasks\HPCeeScheduleForihave3gals.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
           
          ==================== Shortcuts =============================
           
          (The entries could be listed to be restored or removed.)
           
          ShortcutWithArgument: C:\Users\ihave3gals\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\AmazonShopping.lnk -> C:\Program Files (x86)\HP\Shared\WizLink.exe () -> hxxp://www.amazon.com/gp/bit/amazonbookmark.html?tag=hp2-desktop-us-20&partner;=HP
          ShortcutWithArgument: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Priceline.com.lnk -> C:\Program Files (x86)\HP\Shared\WizLink.exe () -> hxxp://www.priceline.com/?refid=PLHBC6240OPQ&refclickid;=square
           
          ==================== Loaded Modules (Whitelisted) ==============
           
          2016-07-16 07:42 - 2016-07-16 07:42 - 00231424 _____ () C:\WINDOWS\SYSTEM32\ism32k.dll
          2017-05-09 16:14 - 2017-04-27 20:49 - 02681200 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
          2016-09-01 18:12 - 2016-09-01 18:12 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
          2016-09-01 18:12 - 2016-09-01 18:12 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
          2016-10-10 22:15 - 2013-06-28 15:28 - 00084616 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
          2016-07-25 20:03 - 2016-07-25 20:03 - 00592392 _____ () C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
          2016-06-26 08:05 - 2014-04-14 21:59 - 00389896 _____ () C:\Program Files\CyberLink\Shared files\RichVideo64.exe
          2017-04-17 21:33 - 2017-05-26 08:27 - 08931008 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
          2016-10-02 21:07 - 2016-10-02 21:07 - 00134656 _____ () C:\Windows\ShellExperiences\Windows.UI.Shell.SharedUtilities.dll
          2017-03-17 12:18 - 2017-03-04 02:31 - 00474112 _____ () C:\Windows\ShellExperiences\QuickActions.dll
          2017-03-17 12:18 - 2017-03-04 02:12 - 09760768 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
          2017-03-17 12:18 - 2017-03-04 02:05 - 01401856 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
          2017-03-17 12:18 - 2017-03-04 02:05 - 00757248 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CSGSuggestLib.dll
          2017-05-09 16:14 - 2017-04-27 19:36 - 01033216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Actions.dll
          2017-05-09 16:14 - 2017-04-27 19:36 - 02424320 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
          2017-05-09 16:14 - 2017-04-27 19:37 - 04853760 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
          2017-06-07 18:55 - 2017-06-07 18:55 - 00074752 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeHost.exe
          2017-06-07 18:55 - 2017-06-07 18:55 - 00201728 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
          2017-06-07 18:55 - 2017-06-07 18:55 - 43318784 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\SkyWrap.dll
          2017-06-07 18:55 - 2017-06-07 18:55 - 02427904 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.17.420.0_x64__kzf8qxf38zg5c\skypert.dll
          2017-05-11 23:22 - 2017-05-09 05:13 - 03767640 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libglesv2.dll
          2017-05-11 23:22 - 2017-05-09 05:13 - 00100696 _____ () C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\libegl.dll
          2016-07-25 20:03 - 2016-07-25 20:03 - 38907672 _____ () C:\Program Files\AVAST Software\SecureLine\libcef.dll
           
          ==================== Alternate Data Streams (Whitelisted) =========
           
          (If an entry is included in the fixlist, only the ADS will be removed.)
           
           
          ==================== Safe Mode (Whitelisted) ===================
           
          (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
           
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="Service"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
          HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="Service"
           
          ==================== Association (Whitelisted) ===============
           
          (If an entry is included in the fixlist, the registry item will be restored to default or removed.)
           
           
          ==================== Internet Explorer trusted/restricted ===============
           
          (If an entry is included in the fixlist, it will be removed from the registry.)
           
           
          ==================== Hosts content: ===============================
           
          (If needed Hosts: directive could be included in the fixlist to reset Hosts.)
           
          2015-10-30 03:24 - 2015-10-30 03:21 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts
           
           
          ==================== Other Areas ============================
           
          (Currently there is no automatic fix for this section.)
           
          HKU\S-1-5-21-121274051-3287072310-3552221101-1001\Control Panel\Desktop\\Wallpaper -> C:\windows\web\wallpaper\Hewlett-Packard Backgrounds\backgroundDefault.jpg
          DNS Servers: 192.168.1.1
          HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
          Windows Firewall is enabled.
           
          ==================== MSCONFIG/TASK MANAGER disabled items ==
           
          HKLM\…\StartupApproved\Run: => "iTunesHelper"
          HKLM\…\StartupApproved\Run32: => "HPMessageService"
          HKLM\…\StartupApproved\Run32: => "AccelerometerSysTrayApplet"
          HKLM\…\StartupApproved\Run32: => "HPRadioMgr"
          HKLM\…\StartupApproved\Run32: => "PowerDVD14Agent"
          HKLM\…\StartupApproved\Run32: => "APSDaemon"
          HKU\S-1-5-21-121274051-3287072310-3552221101-1001\…\StartupApproved\Run: => "OneDrive"
           
          ==================== FirewallRules (Whitelisted) ===============
           
          (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
           
          FirewallRules: [{12E9A58A-C981-4B8A-8A3D-CE98E4D451D8}] => (Allow) C:\Program Files\iTunes\iTunes.exe
          FirewallRules: [{3ACED9FF-FB69-4058-AD8D-CA17361631AB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
          FirewallRules: [{799A0EF9-E789-4E29-AD1D-9F8BE2CA8E23}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
          FirewallRules: [{CB5F51AA-D236-4FE4-B131-973FEDB0ADC4}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{7EAAB1F1-22A8-4619-B56F-273595838D26}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
          FirewallRules: [{F2EF520F-089C-4C3E-87BB-6097F567C28B}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe
          FirewallRules: [{2384820D-9B87-4E7E-9CC3-839C5653F4B4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
          FirewallRules: [{9318496D-F8DE-4C2A-B0B2-F395EDABF03C}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
          FirewallRules: [{11095877-0F24-475B-9E88-052E3CC61288}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\SmartAgentTest.exe
          FirewallRules: [{1DC094FF-631A-4379-864A-2769CF5C07AC}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\Next\WirelessDisplay.exe
          FirewallRules: [{BCBF97CA-4539-41A4-85B1-AF4BA3546027}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiAppOld.exe
          FirewallRules: [{F6FB54B3-CE74-4165-94B8-0B3AA8480A28}] => (Allow) C:\Program Files\Intel Corporation\Intel WiDi\WiDiApp.exe
          FirewallRules: [{80A9326C-3228-4190-A3F5-9F99F9005B8F}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Movie\PowerDVD Cinema\PowerDVDCinema.exe
          FirewallRules: [{97814783-041D-41E7-A83D-92DF98D3543C}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Movie\PowerDVDMovie.exe
          FirewallRules: [{D6EA5020-E1A6-437B-B1A7-D79BC62020E3}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD14Agent.exe
          FirewallRules: [{65F947B9-D7BF-49AC-9C91-295F0EF15DA7}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\Kernel\DMS\CLMSServerPDVD14.exe
          FirewallRules: [{594B753F-EC89-4B3C-8FC8-9D914EF19B39}] => (Allow) C:\Program Files (x86)\CyberLink\PowerDVD14\PowerDVD.exe
          FirewallRules: [{997B2FA0-FCB2-4153-A5BA-218B6CDC747A}] => (Allow) c:\Program Files\CyberLink\PowerDirector12\PDR10.EXE
          FirewallRules: [TCP Query User{4CE5A3A4-D330-4753-8E78-54034948B5F7}C:\users\ihave3gals\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe] => (Allow) C:\users\ihave3gals\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe
          FirewallRules: [UDP Query User{7F9E8A05-5368-4970-BE2C-4F9408CA9745}C:\users\ihave3gals\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe] => (Allow) C:\users\ihave3gals\appdata\local\microsoft\lwaplugin\x86\15.8\lwaplugin.exe
          FirewallRules: [{ED4E3304-ABC9-4C18-A623-B1CA4903B61F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
          FirewallRules: [{C3035295-C0FB-44AF-90F6-CFC56A11757B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
          FirewallRules: [{3079220E-11CC-49B8-9DBD-58C9ED45CC5F}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
          FirewallRules: [{C72DB456-6A84-41C4-A748-3460596EC6DA}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
          FirewallRules: [{96A20136-C54E-4D63-ADB2-3AAB62C55B41}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
          FirewallRules: [{88AE5486-5D16-43FF-A883-DECAE005C0AC}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
           
          ==================== Restore Points =========================
           
          22-05-2017 17:47:47 Windows Update
          30-05-2017 20:58:37 Scheduled Checkpoint
          08-06-2017 22:51:43 Windows Update
          13-06-2017 08:24:12 JRT Pre-Junkware Removal
           
          ==================== Faulty Device Manager Devices =============
           
           
          ==================== Event log errors: =========================
           
          Application errors:
          ==================
          Error: (06/14/2017 12:40:55 AM) (Source: Application Error) (EventID: 1000) (User: )
          Description: Faulting application name: McSync.exe, version: 15.0.166.0, time stamp: 0x577e3dec
          Faulting module name: McSync.exe, version: 15.0.166.0, time stamp: 0x577e3dec
          Exception code: 0xc0000005
          Fault offset: 0x0000000000086788
          Faulting process id: 0x27e0
          Faulting application start time: 0x01d2e4c8684c1b83
          Faulting application path: C:\PROGRA~1\McAfee\MSC\McSync.exe
          Faulting module path: C:\PROGRA~1\McAfee\MSC\McSync.exe
          Report Id: d66fdbe3-4bfd-4c49-97c6-80109ddd61bc
          Faulting package full name: 
          Faulting package-relative application ID:
           
          Error: (06/14/2017 12:33:36 AM) (Source: COM) (EventID: 10031) (User: )
          Description: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class {2CD39202-3A2F-4935-9A86-65B919919A7F} was rejected
           
          Error: (06/14/2017 12:33:11 AM) (Source: DPTF) (EventID: 256) (User: )
          Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10605.221) TYPE: ERROR
           
          DPTF Build Version:  8.1.10605.221
          DPTF Build Date:  Oct 23 2015 12:24:15
          Source File:  ..\..\..\Sources\Manager\WIDomainPowerControlCapabilityChanged.cpp @ line 63
          Executing Function:  WIDomainPowerControlCapabilityChanged::execute
          Message:  Unhandled exception caught during execution of work item
          Framework Event:  DomainPowerControlCapabilityChanged [19]
          Participant:  TCPU [1]
          Policy:  Passive Policy 2 [2]
          Exception Function:  Policy::executeDomainPowerControlCapabilityChanged
          Exception Text:  
          Could not find client in directory.
           
          Error: (06/14/2017 12:33:11 AM) (Source: DPTF) (EventID: 256) (User: )
          Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10605.221) TYPE: ERROR
           
          DPTF Build Version:  8.1.10605.221
          DPTF Build Date:  Oct 23 2015 12:24:15
          Source File:  ..\..\..\Sources\Manager\WIDomainPerformanceControlCapabilityChanged.cpp @ line 63
          Executing Function:  WIDomainPerformanceControlCapabilityChanged::execute
          Message:  Unhandled exception caught during execution of work item
          Framework Event:  DomainPerformanceControlCapabilityChanged [17]
          Participant:  TCPU [1]
          Policy:  Passive Policy 2 [2]
          Exception Function:  Policy::executeDomainPerformanceControlCapabilityChanged
          Exception Text:  
          Could not find client in directory.
           
          Error: (06/14/2017 12:33:11 AM) (Source: DPTF) (EventID: 256) (User: )
          Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10605.221) TYPE: ERROR
           
          DPTF Build Version:  8.1.10605.221
          DPTF Build Date:  Oct 23 2015 12:24:15
          Source File:  ..\..\..\Sources\Manager\WIDomainPerformanceControlCapabilityChanged.cpp @ line 63
          Executing Function:  WIDomainPerformanceControlCapabilityChanged::execute
          Message:  Unhandled exception caught during execution of work item
          Framework Event:  DomainPerformanceControlCapabilityChanged [17]
          Participant:  TCPU [1]
          Policy:  Passive Policy 2 [2]
          Exception Function:  Policy::executeDomainPerformanceControlCapabilityChanged
          Exception Text:  
          Could not find client in directory.
           
          Error: (06/14/2017 12:33:11 AM) (Source: DPTF) (EventID: 256) (User: )
          Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10605.221) TYPE: ERROR
           
          DPTF Build Version:  8.1.10605.221
          DPTF Build Date:  Oct 23 2015 12:24:15
          Source File:  ..\..\..\..\Sources\Policies\PolicyLib\PolicyBase.cpp @ line 673
          Executing Function:  PolicyBase::takeControlOfOsc
          Message:  Failed to acquire OSC: Failure during execution of _OSC: 
          DPTF Build Version:  8.1.10605.221
          DPTF Build Date:  Oct 23 2015 12:24:15
          Source File:  ..\..\..\Sources\Manager\EsifServices.cpp @ line 473
          Executing Function:  EsifServices::primitiveExecuteSet
          Message:  Error returned from ESIF services interface function call
          Participant:  NoParticipant
          Domain:  NoDomain
          ESIF Primitive:  SET_OPERATING_SYSTEM_CAPABILITIES [93]
          ESIF Instance:  255
          ESIF Return Code:  ESIF_E_UNSUPPORTED_ACTION_TYPE [1202]
           
           
          Policy:  Passive Policy 2 [2]
           
          Error: (06/14/2017 12:33:11 AM) (Source: DPTF) (EventID: 256) (User: )
          Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10605.221) TYPE: ERROR
           
          DPTF Build Version:  8.1.10605.221
          DPTF Build Date:  Oct 23 2015 12:24:15
          Source File:  ..\..\..\..\Sources\Policies\PolicyLib\PolicyBase.cpp @ line 673
          Executing Function:  PolicyBase::takeControlOfOsc
          Message:  Failed to acquire OSC: Failure during execution of _OSC: 
          DPTF Build Version:  8.1.10605.221
          DPTF Build Date:  Oct 23 2015 12:24:15
          Source File:  ..\..\..\Sources\Manager\EsifServices.cpp @ line 473
          Executing Function:  EsifServices::primitiveExecuteSet
          Message:  Error returned from ESIF services interface function call
          Participant:  NoParticipant
          Domain:  NoDomain
          ESIF Primitive:  SET_OPERATING_SYSTEM_CAPABILITIES [93]
          ESIF Instance:  255
          ESIF Return Code:  ESIF_E_UNSUPPORTED_ACTION_TYPE [1202]
           
           
          Policy:  Critical Policy [1]
           
          Error: (06/14/2017 12:28:23 AM) (Source: COM) (EventID: 10031) (User: )
          Description: An unmarshaling policy check was performed when unmarshaling a custom marshaled object and the class {2CD39202-3A2F-4935-9A86-65B919919A7F} was rejected
           
          Error: (06/14/2017 12:28:15 AM) (Source: DPTF) (EventID: 256) (User: )
          Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10605.221) TYPE: ERROR
           
          DPTF Build Version:  8.1.10605.221
          DPTF Build Date:  Oct 23 2015 12:24:15
          Source File:  ..\..\..\Sources\Manager\WIDomainPowerControlCapabilityChanged.cpp @ line 63
          Executing Function:  WIDomainPowerControlCapabilityChanged::execute
          Message:  Unhandled exception caught during execution of work item
          Framework Event:  DomainPowerControlCapabilityChanged [19]
          Participant:  TCPU [1]
          Policy:  Passive Policy 2 [2]
          Exception Function:  Policy::executeDomainPowerControlCapabilityChanged
          Exception Text:  
          Could not find client in directory.
           
          Error: (06/14/2017 12:28:15 AM) (Source: DPTF) (EventID: 256) (User: )
          Description: Intel(R) Dynamic Platform and Thermal Framework : ESIF(8.1.10605.221) TYPE: ERROR
           
          DPTF Build Version:  8.1.10605.221
          DPTF Build Date:  Oct 23 2015 12:24:15
          Source File:  ..\..\..\Sources\Manager\WIDomainPerformanceControlCapabilityChanged.cpp @ line 63
          Executing Function:  WIDomainPerformanceControlCapabilityChanged::execute
          Message:  Unhandled exception caught during execution of work item
          Framework Event:  DomainPerformanceControlCapabilityChanged [17]
          Participant:  TCPU [1]
          Policy:  Passive Policy 2 [2]
          Exception Function:  Policy::executeDomainPerformanceControlCapabilityChanged
          Exception Text:  
          Could not find client in directory.
           
           
          System errors:
          =============
          Error: (06/14/2017 12:40:46 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
          Description: The Interactive Services Detection service terminated with the following error: 
          Incorrect function.
           
          Error: (06/14/2017 12:33:17 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
          Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
          {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
           and APPID 
          {F72671A9-012C-4725-9D2F-2A4D32D65169}
           to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
           
          Error: (06/14/2017 12:32:29 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
          Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
          {D63B10C5-BB46-4990-A94F-E40B9D520160}
           and APPID 
          {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
           to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
           
          Error: (06/13/2017 08:51:12 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
          Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
          {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
           and APPID 
          {F72671A9-012C-4725-9D2F-2A4D32D65169}
           to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
           
          Error: (06/13/2017 08:50:17 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
          Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
          {D63B10C5-BB46-4990-A94F-E40B9D520160}
           and APPID 
          {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}
           to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
           
          Error: (06/13/2017 08:21:57 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
          Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
          {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}
           and APPID 
          {F72671A9-012C-4725-9D2F-2A4D32D65169}
           to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
           
          Error: (06/13/2017 08:21:34 AM) (Source: BTHUSB) (EventID: 17) (User: )
          Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.
           
          Error: (06/13/2017 08:21:00 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
          Description: WLAN Extensibility Module has stopped unexpectedly.
           
          Module Path: C:\WINDOWS\System32\IWMSSvc.dll
           
          Error: (06/13/2017 08:21:00 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
          Description: WLAN Extensibility Module has stopped unexpectedly.
           
          Module Path: C:\WINDOWS\System32\IWMSSvc.dll
           
          Error: (06/13/2017 08:20:58 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY)
          Description: WLAN Extensibility Module has stopped unexpectedly.
           
          Module Path: C:\WINDOWS\System32\IWMSSvc.dll
           
           
          CodeIntegrity:
          ===================================
            Date: 2017-06-14 00:38:21.264
            Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
           
            Date: 2017-06-14 00:38:21.261
            Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
           
            Date: 2017-06-09 21:57:47.357
            Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
           
            Date: 2017-06-09 21:57:47.355
            Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
           
           
          ==================== Memory info =========================== 
           
          Processor: Intel(R) Core(TM) i5-6200U CPU @ 2.30GHz
          Percentage of memory in use: 24%
          Total physical RAM: 12176.41 MB
          Available physical RAM: 9244.11 MB
          Total Virtual: 14032.41 MB
          Available Virtual: 11094.78 MB
           
          ==================== Drives ================================
           
          Drive c: (Windows) (Fixed) (Total:918.85 GB) (Free:870.26 GB) NTFS
          Drive d: (RECOVERY) (Fixed) (Total:11.43 GB) (Free:1.4 GB) NTFS ==>[system with boot components (obtained from drive)]
           
          ==================== MBR & Partition Table ==================
           
          ========================================================
          Disk: 0 (Size: 931.5 GB) (Disk ID: A50E1C7D)
           
          Partition: GPT.
           
          ==================== End of Addition.txt ============================

          Good Morning

           

          Looks like your main Anti Virus program is  McAfee  but I also see Avast SecureLine running in the background as a task , the genaral rule of thumb from Microsoft is to just have one AV program , keep it updated and run regular scans. Let me know what you want to do about Avast SecureLine, you can uninstall it via Programs and Features in the Control Panel, if you do uninstall it let me know so we can remove leftover enrties with a FRST fix

          Hi,

           

          Logs lookiing very good,  First go into Programs and Features in the Control Panel and uninstall Avast SecureLine

           

          Then run this quick fix

           

          Open notepad , Go to Start –> All Programs –> Accessories –> Notepad.

          Please copy the entire contents Inside of the code box below beginning with START and ending with END
          (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
          Name the file Fixlist, Save it to your desktop where you have FRST/FRST64 or the fix wont work, . Then open up FRST/FRST64 and click on FIX (Not Scan) It won't take long, after your computer reboots you will find a FIXLOG.TXT on your desktop, post it please
           
          Start
          CloseProcesses:
          CreateRestorePoint: 
          CHR NewTab: Default ->  Not-active:"chrome-extension://hcfalfpgiocaoobnlaeljmljhcnbnfjk/newtab/newtab.html", Not-active:"chrome-extension://eoilkaejhmjjbdongpiccbjcmgdepiem/newtab/newtab.html"
          CHR Extension: (Search Encrypt) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\oafomabmeffnelgdleajddppakeakfna [2017-05-10]
          R2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [592392 2016-07-25] ()
          Task: {5AA361F1-D205-48E5-8B5A-848B66ED087D} - System32\Tasks\avast! SL Update => C:\Program Files\AVAST Software\SecureLine\SLUpdate.exe [2016-07-25] (AVAST Software)
          Task: {C542A672-CDDB-4CB5-800C-21F8B22BA647} - System32\Tasks\Avast SecureLine => C:\Program Files\AVAST Software\SecureLine\SecureLine.exe [2016-07-25] (AVAST Software)
          2016-07-25 20:03 - 2016-07-25 20:03 - 00592392 _____ () C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
          2016-07-25 20:03 - 2016-07-25 20:03 - 38907672 _____ () C:\Program Files\AVAST Software\SecureLine\libcef.dll
          EmptyTemp:
          CMD: ipconfig /flushdns
          Hosts:
          End
          
           
          NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

          Thanks Ken, here's the post.

           

          Fix result of Farbar Recovery Scan Tool (x64) Version: 15-06-2017 01
          Ran by [removed] (16-06-2017 07:08:23) Run:1
          Running from C:\Users\[removed]\Desktop
          [removed]
          Boot Mode: Normal
          ==============================================
           
          fixlist content:
          *****************
          Start
          CloseProcesses:
          CreateRestorePoint: 
          CHR NewTab: Default ->  Not-active:"chrome-extension://hcfalfpgiocaoobnlaeljmljhcnbnfjk/newtab/newtab.html", Not-active:"chrome-extension://eoilkaejhmjjbdongpiccbjcmgdepiem/newtab/newtab.html"
          CHR Extension: (Search Encrypt) - C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\oafomabmeffnelgdleajddppakeakfna [2017-05-10]
          R2 SecureLine; C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe [592392 2016-07-25] ()
          Task: {5AA361F1-D205-48E5-8B5A-848B66ED087D} - System32\Tasks\avast! SL Update => C:\Program Files\AVAST Software\SecureLine\SLUpdate.exe [2016-07-25] (AVAST Software)
          Task: {C542A672-CDDB-4CB5-800C-21F8B22BA647} - System32\Tasks\Avast SecureLine => C:\Program Files\AVAST Software\SecureLine\SecureLine.exe [2016-07-25] (AVAST Software)
          2016-07-25 20:03 - 2016-07-25 20:03 - 00592392 _____ () C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe
          2016-07-25 20:03 - 2016-07-25 20:03 - 38907672 _____ () C:\Program Files\AVAST Software\SecureLine\libcef.dll
          EmptyTemp:
          CMD: ipconfig /flushdns
          Hosts:
          End
          *****************
           
          Processes closed successfully.
          Restore point was successfully created.
          Chrome NewTab => removed successfully
          C:\Users\ihave3gals\AppData\Local\Google\Chrome\User Data\Default\Extensions\oafomabmeffnelgdleajddppakeakfna => moved successfully
          SecureLine => service not found.
          HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5AA361F1-D205-48E5-8B5A-848B66ED087D} => key not found. 
          C:\WINDOWS\System32\Tasks\avast! SL Update => not found.
          HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\avast! SL Update => key not found. 
          HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C542A672-CDDB-4CB5-800C-21F8B22BA647} => key not found. 
          C:\WINDOWS\System32\Tasks\Avast SecureLine => not found.
          HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast SecureLine => key not found. 
          "C:\Program Files\AVAST Software\SecureLine\VpnSvc.exe" => not found.
          "C:\Program Files\AVAST Software\SecureLine\libcef.dll" => not found.
           
          ========= ipconfig /flushdns =========
           
           
          Windows IP Configuration
           
          Successfully flushed the DNS Resolver Cache.
           
          ========= End of CMD: =========
           
          C:\Windows\System32\Drivers\etc\hosts => moved successfully
          Hosts restored successfully.
           
          =========== EmptyTemp: ==========
           
          BITS transfer queue => 1122870 B
          DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 121347626 B
          Java, Flash, Steam htmlcache => 2060 B
          Windows/system/drivers => 214831168 B
          Edge => 2664410 B
          Chrome => 896506446 B
          Firefox => 24289399 B
          Opera => 0 B
           
          Temp, IE cache, history, cookies, recent:
          Default => 6656 B
          Users => 0 B
          ProgramData => 0 B
          Public => 0 B
          systemprofile => 153758 B
          systemprofile32 => 128 B
          LocalService => 78302 B
          NetworkService => 144272628 B
          ihave3gals => 2804764776 B
           
          RecycleBin => 26633200 B
          EmptyTemp: => 3.9 GB temporary data Removed.
           
          ================================
           
           
          The system needed a reboot.
           
          ==== End of Fixlog 07:12:56 ====
          Thanks Ken, things are running well.
          My wife complains that some sites load slower than when the computer was new.
          Is there a way to verify that?

          JB

          Hey

           

          What browser are we talking about or is it all of them. ?  Sometimes you may just have added to many add ons and or plugins. Also its good idea maybe once a month or so to unplug your router and cable modem for about 5 minutes, with all the surfing sometimes they get a bit clogged up.

           

          Try this if no help then we can set each brower back to defaults

           

           
          1. Turn off your computer
          2. Turn off your  router by unplugging the power cord on the back of the unit
          3. Turn off your Cable / DSL modem by unplugging the power cord on the back of the unit
           
                  Leave everything off for about 5 minutes, this lets it all reset 
           
          Then
           
          1. Plug in your Cable / DSL modem and wait until all the lights come back on
          2. Now do the same thing with your router
          3. Turn your computer back on and see if it made a difference

          Ask AI

          AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

          Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI