Hello there.
I have a computer that has been incredibly slow. I am quite sure its not supposed to be this slow because absolutely everything is a chore to do on it. Even you tube videos take forever to load and its so slow the sound gets choppy a lot of the time.
Can someone help me?
ManMan
Hello ManMan and welcome to the WTT forum.
My name is Satchfan and I would be glad to help you with your computer problem.Please read the following guidelines which will help to make cleaning your machine easier:
please follow all instructions in the order posted
please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
all logs/reports, etc. must be posted in Notepad . Please ensure that word wrap is un checked . In Notepad click Format , uncheck Word wrap if it is checked
if you don't understand something, please don't hesitate to ask for clarification before proceeding
the fixes are specific to your problem and should only be used for this issue on this machine.
please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT :
Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested
===================================================Note : Please run these in the order given in the instructions.
===================================================Download and run AdwCleaner
Download AdwCleaner from here and save it to your desktop.
run AdwCleaner by clicking on Scan
when it has finished, leave everything that was found checked, (ticked), then click on Clean
if it asks to reboot, allow the reboot
on reboot a log will be produced; please attach the content of the log to your next reply.
===================================================Download and run Junkware Removal Tool
Please download Junkware Removal Tool to your desktop.
shut down your protection software now to avoid potential conflicts.
run the tool by double-clicking it. If you are using Windows Vista/7/8/10, instead of double-clicking, right-mouse click JRT.exe and select 'Run as Administrator'
the tool will open and start scanning your system
please be patient as this can take a while to complete depending on your system's specifications
on completion, a log (JRT.txt) is saved to your desktop and will automatically open
post the contents of JRT.txt into your next message.
===================================================Run Farbar Recovery Scan Tool
Please download Farbar Recovery Scan Tool and save it to your Desktop.Note : You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
right click to run as administrator (XP users click run after receipt of Windows Security Warning - Open File). When the tool opens click Yes to disclaimer.
press Scan button
it will produce a log called Frst.txt in the same directory the tool is run from
please copy and paste log back here.
the first time the tool is run it generates another log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the Frst.txt into your reply.
Logs to include with next post :AdwCleaner log
JRT.txt
Frst.txt
Addition.txt
Thanks
Satchfan
# AdwCleaner v6.047 - Logfile created 17/07/2017 at 23:02:55
# Updated on 19/05/2017 by Malwarebytes
# Database : 2017-07-13.1 [Server]
# Operating System : Windows 8.1 Connected (X64)
# Username : PComputer - PC
# Running from : C:\Users\PComputer\Downloads\adwcleaner_6.047.exe
# Mode: Clean
# Support : https://www.malwarebytes.com/support
***** [ Services ] *****
***** [ Folders ] *****
***** [ Files ] *****
***** [ DLL ] *****
***** [ WMI ] *****
***** [ Shortcuts ] *****
***** [ Scheduled Tasks ] *****
***** [ Registry ] *****
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\icq.com
[-] Key deleted: HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.icq.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\icq.com
[#] Key deleted on reboot: [x64] HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.icq.com
***** [ Web browsers ] *****
*************************
:: "Tracing" keys deleted
:: Winsock settings cleared
*************************
C:\AdwCleaner\AdwCleaner[C0].txt - [1156 Bytes] - [17/07/2017 23:02:55]
C:\AdwCleaner\AdwCleaner[S0].txt - [1478 Bytes] - [17/07/2017 22:15:20]
########## EOF - C:\AdwCleaner\AdwCleaner[C0].txt - [1302 Bytes] ##########
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.1.4 (07.09.2017)
Operating System: Windows 8.1 Connected x64
Ran by [removed] (Administrator) on Mon 17/07/2017 at 23:09:21.64
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
File System: 0
Registry: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 17/07/2017 at 23:13:33.37
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-07-2017
Ran by [removed] (administrator) on PC (17-07-2017 23:20:50)
Running from C:\Users\[removed]\Downloads
[removed]
Platform: Windows 8.1 Connected (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Dell Inc.) C:\Program Files (x86)\Dell Customer Connect\DCCService.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5776712 2013-11-26] (Dell Inc.)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7506648 2013-12-28] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374424 2014-01-10] (Realtek Semiconductor)
HKLM\…\Run: [WavesSvc] => C:\Program Files\Realtek\Audio\HDA\WavesSvc64.exe [285272 2013-12-31] (Waves Audio Ltd.)
HKLM\…\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374424 2014-01-10] (Realtek Semiconductor)
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213832 2017-07-07] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{0975ED1F-AE1D-413B-817C-45773CEDFBF6}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{BF3E136F-AB8F-4336-BFD0-908EF70224E0}: [DhcpNameServer] 192.168.88.1
Internet Explorer:
==================
HKU\S-1-5-21-157973084-2402647649-1939952699-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://dell13.msn.com/?pc=DCJB
HKU\S-1-5-21-157973084-2402647649-1939952699-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com/?pc=DCJB
SearchScopes: HKU\S-1-5-21-157973084-2402647649-1939952699-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-157973084-2402647649-1939952699-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-04-11] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-03-14] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-20] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\PComputer\AppData\Roaming\Mozilla\Firefox\Profiles\x5n0l7i4.default-1490133011561 [2017-07-17]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-20] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-20] ()
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-157973084-2402647649-1939952699-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\PComputer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-03-27] (Unity Technologies ApS)
Chrome:
=======
CHR DefaultProfile: Default
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default [2017-07-06]
CHR Extension: (Google Slides) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-31]
CHR Extension: (Google Docs) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-04-15]
CHR Extension: (Google Drive) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-15]
CHR Extension: (YouTube) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-15]
CHR Extension: (Google Search) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-31]
CHR Extension: (Google Docs Offline) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-15]
CHR Extension: (Gmail) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-20]
CHR Extension: (Chrome Media Router) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-06]
CHR HKLM-x32\…\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] -
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7430992 2017-07-07] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263312 2017-07-07] (AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042544 2017-03-14] (Microsoft Corporation)
R2 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [130936 2016-12-21] (Dell Inc.)
R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [230248 2017-05-01] (Dell Inc.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [315352 2014-05-22] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [887232 2013-12-25] (Intel(R) Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-09] (Realtek Semiconductor)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-10-13] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-10-13] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [319984 2017-07-07] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [198944 2017-07-07] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [343264 2017-07-07] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [57704 2017-07-07] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [46984 2017-07-07] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41800 2017-07-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [146664 2017-07-07] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [110352 2017-07-07] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [84392 2017-07-07] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1015848 2017-07-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [585608 2017-07-07] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [198768 2017-07-07] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [361336 2017-07-07] (AVAST Software)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3855872 2013-09-12] (Qualcomm Atheros Communications, Inc.)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-19] (ASIX Electronics Corp.)
R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-25] (OSR Open Systems Resources, Inc.)
R3 DUB-13X2; C:\Windows\system32\DRIVERS\DUB-13X2.sys [69592 2013-06-20] (D-Lnk Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-04-04] (Malwarebytes Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2014-02-20] (Synaptics Incorporated)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-16] (Intel Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2014-10-13] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [257880 2014-10-13] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-10-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-17 23:20 - 2017-07-17 23:21 - 00011544 _____ C:\Users\PComputer\Downloads\FRST.txt
2017-07-17 23:20 - 2017-07-17 23:20 - 02435584 _____ (Farbar) C:\Users\PComputer\Downloads\FRST64.exe
2017-07-17 23:20 - 2017-07-17 23:20 - 00000000 ____D C:\FRST
2017-07-17 23:18 - 2017-07-17 23:18 - 01780736 _____ (Farbar) C:\Users\PComputer\Downloads\FRST.exe
2017-07-17 23:13 - 2017-07-17 23:13 - 00000565 _____ C:\Users\PComputer\Desktop\JRT.txt
2017-07-17 23:10 - 2017-07-17 23:10 - 00001389 _____ C:\Users\PComputer\Desktop\AdwCleaner[C0].txt
2017-07-17 23:08 - 2017-07-17 23:08 - 01790024 _____ (Malwarebytes) C:\Users\PComputer\Downloads\JRT(1).exe
2017-07-17 23:07 - 2017-07-17 23:07 - 01790024 _____ (Malwarebytes) C:\Users\PComputer\Downloads\JRT.exe
2017-07-17 22:12 - 2017-07-17 22:12 - 00001529 _____ C:\Users\PComputer\Desktop\adwcleaner_6.047 - Shortcut.lnk
2017-07-17 21:56 - 2017-07-17 23:02 - 00000000 ____D C:\AdwCleaner
2017-07-17 21:55 - 2017-07-17 21:55 - 04110280 _____ C:\Users\PComputer\Downloads\adwcleaner_6.047.exe
2017-07-13 19:06 - 2017-07-13 19:06 - 04113915 _____ C:\Users\PComputer\Downloads\6740584-@Sta20-22.12_Draft+Contract+of+Sale.pdf
2017-07-07 14:19 - 2017-07-07 14:19 - 00400464 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-07-06 20:00 - 2017-07-06 20:00 - 00000000 ____D C:\Program Files (x86)\Dell Update
2017-06-30 09:20 - 2017-07-02 09:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-23 17:56 - 2017-06-23 17:56 - 00924361 _____ C:\Users\PComputer\Downloads\21062017135001-0001.pdf
2017-06-23 14:15 - 2017-06-23 14:15 - 00002923 _____ C:\Users\PComputer\Downloads\6-3_Meadow_Crescent_ofi (3).ics
2017-06-23 14:15 - 2017-06-23 14:15 - 00002923 _____ C:\Users\PComputer\Downloads\6-3_Meadow_Crescent_ofi (2).ics
2017-06-23 13:47 - 2017-06-23 13:47 - 00002923 _____ C:\Users\PComputer\Downloads\6-3_Meadow_Crescent_ofi.ics
2017-06-23 13:47 - 2017-06-23 13:47 - 00002923 _____ C:\Users\PComputer\Downloads\6-3_Meadow_Crescent_ofi (1).ics
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-17 23:17 - 2017-03-25 17:46 - 00000000 ____D C:\Users\PComputer\AppData\LocalLow\Mozilla
2017-07-17 23:04 - 2013-08-23 00:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-07-17 23:03 - 2015-03-31 17:04 - 00000000 ____D C:\Users\PComputer
2017-07-17 17:16 - 2015-03-31 17:10 - 00003918 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C1A6E4AB-D79B-4723-9325-18A958AF24BF}
2017-07-17 10:30 - 2013-08-23 01:36 - 00000000 ____D C:\Windows\AppReadiness
2017-07-15 12:27 - 2013-08-22 23:36 - 00000000 ____D C:\Windows\Inf
2017-07-13 10:38 - 2015-03-31 17:10 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-157973084-2402647649-1939952699-1001
2017-07-10 22:28 - 2014-03-18 19:53 - 00863592 _____ C:\Windows\system32\PerfStringBackup.INI
2017-07-10 22:23 - 2013-08-22 23:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2017-07-07 23:28 - 2016-08-21 22:13 - 00003880 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1471781584
2017-07-07 23:28 - 2016-08-21 22:13 - 00001061 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-07-07 14:20 - 2017-04-06 22:29 - 00003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-07-07 14:20 - 2015-03-31 16:27 - 00361336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2017-07-07 14:19 - 2017-04-06 22:29 - 00343264 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-07-07 14:19 - 2017-04-06 22:29 - 00319984 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-07-07 14:19 - 2017-04-06 22:29 - 00198944 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-07-07 14:19 - 2017-04-06 22:29 - 00057704 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-07-07 14:19 - 2015-10-13 17:24 - 00041800 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 01015848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00585608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00360792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.149940123028106
2017-07-07 14:19 - 2015-03-31 16:27 - 00198768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00146664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00110352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00084392 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00046984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-07-06 20:00 - 2015-06-04 22:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2017-07-02 09:33 - 2015-03-31 16:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-06-27 05:01 - 2017-04-09 20:52 - 00002217 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-27 05:01 - 2017-04-09 20:52 - 00002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-06-21 18:12 - 2013-08-23 01:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-06-21 18:06 - 2015-03-31 16:03 - 00000000 ____D C:\Program Files\Microsoft Office 15
2017-06-20 11:36 - 2017-03-22 07:31 - 00003168 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2
2017-06-20 11:36 - 2016-06-23 02:37 - 00002312 _____ C:\Users\PComputer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2017-06-20 11:36 - 2015-03-31 16:12 - 00003176 _____ C:\Windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-157973084-2402647649-1939952699-1001
2017-06-20 11:25 - 2015-03-31 17:41 - 00000000 ____D C:\Users\PComputer\AppData\Local\Adobe
2017-06-20 11:24 - 2013-08-23 01:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-06-20 11:24 - 2013-08-23 01:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-19 13:16 - 2015-03-31 17:05 - 00000000 ____D C:\Users\PComputer\AppData\Local\Packages
2017-06-17 03:05 - 2013-08-23 01:36 - 00000000 ___HD C:\Program Files\WindowsApps
==================== Files in the root of some directories =======
2014-10-15 11:39 - 2014-10-15 11:39 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
Some files in TEMP:
====================
2015-10-13 17:19 - 2015-10-13 17:19 - 0022770 _____ () C:\Users\PComputer\AppData\Local\Temp\MouseKeyboardCenterx64_1033.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-07-17 10:38
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2017
Ran by [removed] (17-07-2017 23:22:20)
Running from C:\Users\[removed]\Downloads
Windows 8.1 Connected (Update) (X64) (2015-03-31 07:04:46)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-157973084-2402647649-1939952699-500 - Administrator - Disabled)
Guest (S-1-5-21-157973084-2402647649-1939952699-501 - Limited - Disabled)
PComputer (S-1-5-21-157973084-2402647649-1939952699-1001 - Administrator - Enabled) => C:\Users\PComputer
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 26 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated)
Avast Free Antivirus (HKLM-x32\…\Avast Antivirus) (Version: 17.5.2302 - AVAST Software)
Dell Customer Connect (HKLM-x32\…\{4FA72FF9-DD64-43A8-8704-6380A11F11D5}) (Version: 1.4.15.0 - Dell Inc.)
Dell Touchpad (HKLM\…\SynTPDeinstKey) (Version: 18.1.2.1 - Synaptics Incorporated)
Dell Update (HKLM-x32\…\{F91263FA-BE4D-439D-9C0A-2E7204E0E9E3}) (Version: 1.9.20.0 - Dell Inc.)
DUB-13X2 USB3.0 to Gigabit Ethernet Adapter Windows Drivers (HKLM-x32\…\{B5F6C7ED-A669-48A1-B591-E4F853E07AAF}) (Version: 1.0.0.0 - D-Lnk Corporation) Hidden
DUB-13X2 USB3.0 to Gigabit Ethernet Adapter Windows Drivers (HKLM-x32\…\InstallShield_{B5F6C7ED-A669-48A1-B591-E4F853E07AAF}) (Version: 1.0.0.0 - D-Lnk Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3621 - Intel Corporation)
Intel(R) Trusted Execution Engine (HKLM\…\{176E2755-0A17-42C6-88E2-192AB2131278}) (Version: 1.0.0.1064 - Intel Corporation)
League of Legends (HKLM-x32\…\{861927A3-8B12-4BF8-9F2A-7A4ED4C40096}) (Version: 4.1.2 - Riot Games) Hidden
League of Legends (HKLM-x32\…\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Microsoft Office Home and Student 2013 - en-us (HKLM\…\HomeStudentRetail - en-us) (Version: 15.0.4937.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-157973084-2402647649-1939952699-1001\…\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Mozilla Firefox 54.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 54.0.1 (x86 en-US)) (Version: 54.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 54.0.1.6388 - Mozilla)
Office 15 Click-to-Run Extensibility Component (HKLM-x32\…\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.4937.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\…\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.4937.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM-x32\…\{90150000-008C-0409-0000-0000000FF1CE}) (Version: 15.0.4937.1000 - Microsoft Corporation) Hidden
Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.16.005 - Dell Inc.)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39048 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7152 - Realtek Semiconductor Corp.)
SafeZone Stable 3.55.2393.609 (HKLM-x32\…\SafeZone 3.55.2393.609) (Version: 3.55.2393.609 - Avast Software) Hidden
Unity Web Player (HKU\S-1-5-21-157973084-2402647649-1939952699-1001\…\UnityWebPlayer) (Version: 5.0.1f1 - Unity Technologies ApS)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-157973084-2402647649-1939952699-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\PComputer\AppData\Local\Microsoft\OneDrive\17.3.6917.0607\amd64\FileCoAuthLib64.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-07] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-07] (AVAST Software)
ContextMenuHandlers01: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-07] (AVAST Software)
ContextMenuHandlers03: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-07] (AVAST Software)
ContextMenuHandlers05: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers05: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2014-05-22] (Intel Corporation)
ContextMenuHandlers05: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\Windows\system32\igfxOSP.dll [2014-05-22] (Intel Corporation)
ContextMenuHandlers06: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-07] (AVAST Software)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01668538-58DF-46E9-A59F-1176198667D1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-13] (Google Inc.)
Task: {022C1A2F-276D-48E4-80B2-0DA154BA6995} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-07-07] (AVAST Software)
Task: {036F5D1D-9F54-4A11-B74F-544D02D53FFB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-13] (Google Inc.)
Task: {08770B52-5D3A-4A02-845C-61604D961F52} - System32\Tasks\SafeZone scheduled Autoupdate 1471781584 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-06-14] (Avast Software)
Task: {371A8BFE-1671-4EED-AB19-822B04F86C87} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-02-20] (Synaptics Incorporated)
Task: {8887AF32-0DA1-4115-8A22-54B07DD269C1} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-04-11] (Microsoft Corporation)
Task: {90BEDD88-E0C5-47F8-9CD6-BACF615F90B4} - System32\Tasks\Dell\Dell Product Registration Update => C:\Program Files (x86)\Dell Product Registration\prodreg.exe
Task: {DB78B3F2-9952-465D-A682-5FB7AD9021D6} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-07-13] (AVAST Software)
Task: {DBAB435B-8969-4D55-9DBC-B61E38E4DDC8} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-04-11] (Microsoft Corporation)
Task: {DD78B943-69F9-433D-B4E1-5ED6A9832496} - System32\Tasks\Aviata\PowerRegister\Dell Reminder (PComputer) => C:\Program Files (x86)\Dell Product Registration\prodreg.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2017-03-22 07:34 - 2017-01-31 22:34 - 08909512 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-03-31 16:03 - 2017-01-17 04:25 - 00117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2017-07-07 14:19 - 2017-07-07 14:19 - 00170224 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-07-13 10:34 - 2017-07-13 10:34 - 01038952 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll
2017-07-07 14:19 - 2017-07-07 14:19 - 67109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-07-07 14:19 - 2017-07-07 14:19 - 00192664 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-07-07 14:19 - 2017-07-07 14:19 - 00224256 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-07-07 14:19 - 2017-07-07 14:19 - 00292920 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-07-07 14:19 - 2017-07-07 14:20 - 02962096 _____ () C:\Program Files\AVAST Software\Avast\aswDataScan.dll
2017-07-07 14:19 - 2017-07-07 14:19 - 00689272 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2016-12-21 09:24 - 2016-12-21 09:24 - 00134008 _____ () C:\Program Files (x86)\Dell Customer Connect\ServiceTagPlusPlus.dll
2017-05-01 15:27 - 2017-05-01 15:27 - 00133992 _____ () C:\Program Files (x86)\Dell Update\ServiceTagPlusPlus.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 23:25 - 2013-08-22 23:25 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-157973084-2402647649-1939952699-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\dell\BlueLava_1112000xx_inspiron_wallpaper58095_16x9_72dpi_RGB.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{5E5B5368-C83A-403C-87C9-23867E790757}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{DD999330-9EBC-4998-A5DF-96C94AEF8FDC}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{4A0F5173-A8DC-4C45-AAC5-A7C13396AB75}] => (Allow) C:\Users\PComputer\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{F14CF5FF-BA9C-46DE-8370-40267E96137C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{CC2B8C30-A55D-477E-9B6E-3961945C297B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{8D819536-CD9D-437F-BA86-EE8002C545D8}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{CFFD1CFD-2026-421B-B894-F180FFD31F81}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{65BFBB82-B5D2-4C46-B109-903C39DC47DE}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{3B0C5114-432F-4A9F-82E6-3033C21294C9}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{44D1C041-66ED-4644-9C88-B684E495A95D}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.607\SZBrowser.exe
FirewallRules: [{589EFD28-C593-426A-91B9-DFD5290BB476}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{9DCAF409-B3FB-4110-9880-56ED2B02CF8A}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.609\SZBrowser.exe
==================== Restore Points =========================
02-07-2017 10:36:28 Scheduled Checkpoint
11-07-2017 11:23:15 Scheduled Checkpoint
17-07-2017 23:09:27 JRT Pre-Junkware Removal
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/17/2017 11:02:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 54.0.1.6388, time stamp: 0x5953d1f8
Faulting module name: xul.dll, version: 54.0.1.6388, time stamp: 0x5953d62e
Exception code: 0x80000003
Fault offset: 0x008a6bcb
Faulting process id: 0x10b0
Faulting application start time: 0x01d2fed627069968
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\xul.dll
Report Id: 39a02d67-6af0-11e7-82ac-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (07/09/2017 09:38:55 AM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: The Desktop Window Manager has encountered a fatal error (0x8898008d)
Error: (07/06/2017 09:57:37 AM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: The Desktop Window Manager has encountered a fatal error (0x8898008d)
Error: (06/30/2017 09:16:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 54.0.1.6388, time stamp: 0x5953d1f8
Faulting module name: firefox.exe, version: 54.0.1.6388, time stamp: 0x5953d1f8
Exception code: 0xc0000005
Fault offset: 0x000128d8
Faulting process id: 0x1304
Faulting application start time: 0x01d2f19252bcb2df
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Report Id: 91505c9d-5d85-11e7-8299-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (06/25/2017 09:15:48 AM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: The Desktop Window Manager has encountered a fatal error (0x8898008d)
Error: (06/14/2017 10:19:59 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program WINWORD.EXE version 15.0.4927.1000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 14e0
Start Time: 01d2e4a3ca646fc2
Termination Time: 4294967295
Application Path: C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE
Report Id: 2ac6fd79-5097-11e7-828f-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (04/04/2017 11:57:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 52.0.2.6291, time stamp: 0x58d41a2d
Faulting module name: ucrtbase.DLL, version: 10.0.14393.33, time stamp: 0x579994fc
Exception code: 0xc0000409
Fault offset: 0x000891cb
Faulting process id: 0xd7c
Faulting application start time: 0x01d2ad19713fbcf7
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\ucrtbase.DLL
Report Id: 9c2c0a09-193e-11e7-827c-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (04/04/2017 05:59:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 52.0.2.6291, time stamp: 0x58d41a2d
Faulting module name: ucrtbase.DLL, version: 10.0.14393.33, time stamp: 0x579994fc
Exception code: 0xc0000409
Fault offset: 0x000891cb
Faulting process id: 0x11e4
Faulting application start time: 0x01d2ad15eb69c4a5
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\ucrtbase.DLL
Report Id: ab1ec9bd-190c-11e7-827c-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (04/01/2017 10:54:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 52.0.2.6291, time stamp: 0x58d41a2d
Faulting module name: ucrtbase.DLL, version: 10.0.14393.33, time stamp: 0x579994fc
Exception code: 0xc0000409
Fault offset: 0x000891cb
Faulting process id: 0x116c
Faulting application start time: 0x01d2aa76f4f06248
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\ucrtbase.DLL
Report Id: 4f8cece9-16da-11e7-827c-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (03/31/2017 09:43:28 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC)
Description: Activation of app Microsoft.Reader_8wekyb3d8bbwe!Microsoft.Reader failed with error: -2147024809 See the Microsoft-Windows-TWinUI/Operational log for additional information.
System errors:
=============
Error: (07/17/2017 11:02:40 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Dell Update Service service terminated unexpectedly. It has done this 1 time(s).
Error: (07/17/2017 11:02:40 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Dell Customer Connect service terminated unexpectedly. It has done this 1 time(s).
Error: (07/17/2017 11:02:32 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
Error: (07/17/2017 11:02:32 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
Error: (07/17/2017 11:02:28 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Microsoft Office ClickToRun Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
Error: (07/17/2017 11:02:26 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
Error: (07/17/2017 11:02:26 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Andrea RT Filters Service service terminated unexpectedly. It has done this 1 time(s).
Error: (07/17/2017 11:02:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) HD Graphics Control Panel Service service terminated unexpectedly. It has done this 1 time(s).
Error: (07/17/2017 06:23:08 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 5:25:44 PM on 17/07/2017 was unexpected.
Error: (07/17/2017 03:37:50 PM) (Source: DCOM) (EventID: 10010) (User: PC)
Description: The server {1B1F472E-3221-4826-97DB-2C2324D389AE} did not register with DCOM within the required timeout.
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU N2830 @ 2.16GHz
Percentage of memory in use: 43%
Total physical RAM: 3979.2 MB
Available physical RAM: 2259 MB
Total Virtual: 5131.2 MB
Available Virtual: 3449.25 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:457.22 GB) (Free:422.94 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 5FFCAB3E)
Partition: GPT.
==================== End of Addition.txt ============================
There is no sign of malware on your comuter but some tidying up is required.
You need to move Farbar Recovery Scan Tool to your desktop otherwise fixes will not work.
go to your Downloads folder and locate Farbar Recovery Scan Tool
right click and select Cut
go to an empty spot on your desktop, right click and select Paste
Farbar Recovery Scan Tool should now be on your desktop.
================================================Run Farbar Recovery Scan Tool
Open notepad. Please copy the contents of the code box below and paste it into Notepad.
CloseProcesses:
SearchScopes: HKU\S-1-5-21-157973084-2402647649-1939952699-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-157973084-2402647649-1939952699-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
CHR Extension: (Chrome Web Store Payments) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-15]
CHR Extension: (Chrome Media Router) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-06]
CHR HKLM-x32\…\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] -
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [257880 2014-10-13] (Microsoft Corporation)
2014-10-15 11:39 - 2014-10-15 11:39 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-10-13 17:19 - 2015-10-13 17:19 - 0022770 _____ () C:\Users\PComputer\AppData\Local\Temp\MouseKeyboardCenterx64_1033.exe
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
FirewallRules: [{5E5B5368-C83A-403C-87C9-23867E790757}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{DD999330-9EBC-4998-A5DF-96C94AEF8FDC}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
EmptyTemp:
NOTE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
save the files as fixlist.txt in the same folder as FRST – NOTE : It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work
run FRST64 then click Fix just once and wait
it will create a log on your desktop, (Fixlog.txt) ; please post it to your reply.
================================================Run McAfee removal tool
run McAfee Removal Tool
================================================
Please run FRST again and make sure there is a checkmark next to ‘Addition.txt’ before you hit ‘Scan’.Logs to include with next post :Fixlog.txt
New Frst.txt
New Addition.txt
Thanks
Satchfan
Fix result of Farbar Recovery Scan Tool (x64) Version: 15-07-2017
Ran by [removed] (18-07-2017 12:10:03) Run:1
Running from C:\Users\[removed]\Desktop\frst
[removed]
Boot Mode: Normal
==============================================
fixlist content:
*****************
CloseProcesses:
SearchScopes: HKU\S-1-5-21-157973084-2402647649-1939952699-1001 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
SearchScopes: HKU\S-1-5-21-157973084-2402647649-1939952699-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?PC=WCUG&FORM=WCUGDF&q={searchTerms}
CHR Extension: (Chrome Web Store Payments) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-15]
CHR Extension: (Chrome Media Router) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-06]
CHR HKLM-x32\…\Chrome\Extension: [daanglpcpkjjlkhcbladppjphglbigam] -
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [257880 2014-10-13] (Microsoft Corporation)
2014-10-15 11:39 - 2014-10-15 11:39 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
2015-10-13 17:19 - 2015-10-13 17:19 - 0022770 _____ () C:\Users\PComputer\AppData\Local\Temp\MouseKeyboardCenterx64_1033.exe
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
FirewallRules: [{5E5B5368-C83A-403C-87C9-23867E790757}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
FirewallRules: [{DD999330-9EBC-4998-A5DF-96C94AEF8FDC}] => (Allow) C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe
EmptyTemp:
*****************
Processes closed successfully.
HKU\S-1-5-21-157973084-2402647649-1939952699-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value removed successfully
HKU\S-1-5-21-157973084-2402647649-1939952699-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key removed successfully
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => key not found.
CHR Extension: (Chrome Web Store Payments) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-15] => Error: No automatic fix found for this entry.
CHR Extension: (Chrome Media Router) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-06] => Error: No automatic fix found for this entry.
HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\daanglpcpkjjlkhcbladppjphglbigam => key removed successfully
WdFilter => Unable to stop service.
HKLM\System\CurrentControlSet\Services\WdFilter => key could not remove, key could be protected
C:\ProgramData\DP45977C.lfl => moved successfully
C:\Users\PComputer\AppData\Local\Temp\MouseKeyboardCenterx64_1033.exe => moved successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => key removed successfully
HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => key removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{5E5B5368-C83A-403C-87C9-23867E790757} => value removed successfully
HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{DD999330-9EBC-4998-A5DF-96C94AEF8FDC} => value removed successfully
=========== EmptyTemp: ==========
BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12241985 B
Java, Flash, Steam htmlcache => 1046 B
Windows/system/drivers => 28176943 B
Edge => 0 B
Chrome => 22782616 B
Firefox => 389910677 B
Opera => 0 B
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 255106 B
NetworkService => 5190 B
PComputer => 286967776 B
RecycleBin => 17226091 B
EmptyTemp: => 730.5 MB temporary data Removed.
================================
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 18-07-2017 12:12:39)
Result of scheduled keys to remove after reboot:
HKLM\System\CurrentControlSet\Services\WdFilter => key could not remove, key could be protected
==== End of Fixlog 12:12:40 ====
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-07-2017
Ran by [removed] (administrator) on PC (18-07-2017 12:31:35)
Running from C:\Users\[removed]\Desktop\frst
[removed]
Platform: Windows 8.1 Connected (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Waves Audio Ltd.) C:\Program Files\Realtek\Audio\HDA\WavesSvc64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Dell Inc.) C:\Program Files (x86)\Dell Customer Connect\DCCService.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe
(Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [QuickSet] => c:\Program Files\Dell\QuickSet\QuickSet.exe [5776712 2013-11-26] (Dell Inc.)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7506648 2013-12-28] (Realtek Semiconductor)
HKLM\…\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374424 2014-01-10] (Realtek Semiconductor)
HKLM\…\Run: [WavesSvc] => C:\Program Files\Realtek\Audio\HDA\WavesSvc64.exe [285272 2013-12-31] (Waves Audio Ltd.)
HKLM\…\Run: [RtHDVBg_PushButton] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1374424 2014-01-10] (Realtek Semiconductor)
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [213832 2017-07-07] (AVAST Software)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{0975ED1F-AE1D-413B-817C-45773CEDFBF6}: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{BF3E136F-AB8F-4336-BFD0-908EF70224E0}: [DhcpNameServer] 192.168.88.1
Internet Explorer:
==================
HKU\S-1-5-21-157973084-2402647649-1939952699-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://dell13.msn.com/?pc=DCJB
HKU\S-1-5-21-157973084-2402647649-1939952699-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13.msn.com/?pc=DCJB
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-04-11] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-03-14] (Microsoft Corporation)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2016-04-20] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\PComputer\AppData\Roaming\Mozilla\Firefox\Profiles\x5n0l7i4.default-1490133011561 [2017-07-18]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_131.dll [2017-06-20] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_131.dll [2017-06-20] ()
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.)
FF Plugin HKU\S-1-5-21-157973084-2402647649-1939952699-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\PComputer\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-03-27] (Unity Technologies ApS)
Chrome:
=======
CHR DefaultProfile: Default
CHR StartupUrls: Default -> "hxxp://www.google.com/"
CHR Profile: C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default [2017-07-18]
CHR Extension: (Google Slides) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-03-31]
CHR Extension: (Google Docs) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-04-15]
CHR Extension: (Google Drive) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-04-15]
CHR Extension: (YouTube) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-04-15]
CHR Extension: (Google Search) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-03-31]
CHR Extension: (Google Docs Offline) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-04-13]
CHR Extension: (Chrome Web Store Payments) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-04-15]
CHR Extension: (Gmail) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-04-20]
CHR Extension: (Chrome Media Router) - C:\Users\PComputer\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-06]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7430992 2017-07-07] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [263312 2017-07-07] (AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3042544 2017-03-14] (Microsoft Corporation)
R2 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [130936 2016-12-21] (Dell Inc.)
R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [230248 2017-05-01] (Dell Inc.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [315352 2014-05-22] (Intel Corporation)
S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\TXE Components\TCS\SocketHeciServer.exe [887232 2013-12-25] (Intel(R) Corporation)
R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [290520 2014-01-09] (Realtek Semiconductor)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-10-13] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-10-13] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswbidsdriver; C:\Windows\system32\drivers\aswbidsdrivera.sys [319984 2017-07-07] (AVAST Software s.r.o.)
R0 aswbidsh; C:\Windows\system32\drivers\aswbidsha.sys [198944 2017-07-07] (AVAST Software s.r.o.)
R0 aswblog; C:\Windows\system32\drivers\aswbloga.sys [343264 2017-07-07] (AVAST Software s.r.o.)
R0 aswbuniv; C:\Windows\system32\drivers\aswbuniva.sys [57704 2017-07-07] (AVAST Software s.r.o.)
S3 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [46984 2017-07-07] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41800 2017-07-07] (AVAST Software)
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [146664 2017-07-07] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [110352 2017-07-07] (AVAST Software)
R0 aswRvrt; C:\Windows\system32\drivers\aswRvrt.sys [84392 2017-07-07] (AVAST Software)
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1015848 2017-07-07] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [585608 2017-07-07] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [198768 2017-07-07] (AVAST Software)
R0 aswVmm; C:\Windows\system32\drivers\aswVmm.sys [361336 2017-07-07] (AVAST Software)
R3 athr; C:\Windows\system32\DRIVERS\athwbx.sys [3855872 2013-09-12] (Qualcomm Atheros Communications, Inc.)
S3 AX88772; C:\Windows\system32\DRIVERS\ax88772.sys [113864 2013-07-19] (ASIX Electronics Corp.)
R3 DellRbtn; C:\Windows\System32\drivers\DellRbtn.sys [10752 2013-01-25] (OSR Open Systems Resources, Inc.)
R3 DUB-13X2; C:\Windows\system32\DRIVERS\DUB-13X2.sys [69592 2013-06-20] (D-Lnk Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-04-04] (Malwarebytes Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [31472 2014-02-20] (Synaptics Incorporated)
R3 TXEIx64; C:\Windows\System32\drivers\TXEIx64.sys [88592 2014-01-16] (Intel Corporation)
S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2014-10-13] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [257880 2014-10-13] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-10-13] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-18 12:14 - 2017-07-18 12:14 - 03480040 _____ (McAfee, Inc.) C:\Users\PComputer\Downloads\MCPR.exe
2017-07-18 12:08 - 2017-07-18 12:31 - 00000000 ____D C:\Users\PComputer\Desktop\frst
2017-07-17 23:25 - 2017-07-17 23:25 - 00022294 _____ C:\Users\PComputer\Desktop\Addition.txt
2017-07-17 23:25 - 2017-07-17 23:25 - 00019785 _____ C:\Users\PComputer\Desktop\FRST.txt
2017-07-17 23:22 - 2017-07-17 23:23 - 00022291 _____ C:\Users\PComputer\Downloads\Addition.txt
2017-07-17 23:20 - 2017-07-18 12:31 - 00000000 ____D C:\FRST
2017-07-17 23:20 - 2017-07-17 23:23 - 00019785 _____ C:\Users\PComputer\Downloads\FRST.txt
2017-07-17 23:18 - 2017-07-17 23:18 - 01780736 _____ (Farbar) C:\Users\PComputer\Downloads\FRST.exe
2017-07-17 23:13 - 2017-07-17 23:13 - 00000565 _____ C:\Users\PComputer\Desktop\JRT.txt
2017-07-17 23:10 - 2017-07-17 23:10 - 00001389 _____ C:\Users\PComputer\Desktop\AdwCleaner[C0].txt
2017-07-17 23:08 - 2017-07-17 23:08 - 01790024 _____ (Malwarebytes) C:\Users\PComputer\Downloads\JRT(1).exe
2017-07-17 23:07 - 2017-07-17 23:07 - 01790024 _____ (Malwarebytes) C:\Users\PComputer\Downloads\JRT.exe
2017-07-17 22:12 - 2017-07-17 22:12 - 00001529 _____ C:\Users\PComputer\Desktop\adwcleaner_6.047 - Shortcut.lnk
2017-07-17 21:56 - 2017-07-17 23:02 - 00000000 ____D C:\AdwCleaner
2017-07-17 21:55 - 2017-07-17 21:55 - 04110280 _____ C:\Users\PComputer\Downloads\adwcleaner_6.047.exe
2017-07-13 19:06 - 2017-07-13 19:06 - 04113915 _____ C:\Users\PComputer\Downloads\6740584-@Sta20-22.12_Draft+Contract+of+Sale.pdf
2017-07-07 14:19 - 2017-07-07 14:19 - 00400464 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-07-06 20:00 - 2017-07-06 20:00 - 00000000 ____D C:\Program Files (x86)\Dell Update
2017-06-30 09:20 - 2017-07-02 09:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-06-23 17:56 - 2017-06-23 17:56 - 00924361 _____ C:\Users\PComputer\Downloads\21062017135001-0001.pdf
2017-06-23 14:15 - 2017-06-23 14:15 - 00002923 _____ C:\Users\PComputer\Downloads\6-3_Meadow_Crescent_ofi (3).ics
2017-06-23 14:15 - 2017-06-23 14:15 - 00002923 _____ C:\Users\PComputer\Downloads\6-3_Meadow_Crescent_ofi (2).ics
2017-06-23 13:47 - 2017-06-23 13:47 - 00002923 _____ C:\Users\PComputer\Downloads\6-3_Meadow_Crescent_ofi.ics
2017-06-23 13:47 - 2017-06-23 13:47 - 00002923 _____ C:\Users\PComputer\Downloads\6-3_Meadow_Crescent_ofi (1).ics
2017-06-19 13:16 - 2017-06-19 13:16 - 00382201 _____ C:\Users\PComputer\Desktop\Resume (Warren Yi).pdf
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-18 12:29 - 2017-03-25 17:46 - 00000000 ____D C:\Users\PComputer\AppData\LocalLow\Mozilla
2017-07-18 12:28 - 2013-08-23 00:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-07-18 12:20 - 2015-03-31 17:10 - 00003918 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{C1A6E4AB-D79B-4723-9325-18A958AF24BF}
2017-07-17 23:03 - 2015-03-31 17:04 - 00000000 ____D C:\Users\PComputer
2017-07-17 10:30 - 2013-08-23 01:36 - 00000000 ____D C:\Windows\AppReadiness
2017-07-15 12:27 - 2013-08-22 23:36 - 00000000 ____D C:\Windows\Inf
2017-07-13 10:38 - 2015-03-31 17:10 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-157973084-2402647649-1939952699-1001
2017-07-10 22:28 - 2014-03-18 19:53 - 00863592 _____ C:\Windows\system32\PerfStringBackup.INI
2017-07-10 22:23 - 2013-08-22 23:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2017-07-07 23:28 - 2016-08-21 22:13 - 00003880 _____ C:\Windows\System32\Tasks\SafeZone scheduled Autoupdate 1471781584
2017-07-07 23:28 - 2016-08-21 22:13 - 00001061 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-07-07 14:20 - 2017-04-06 22:29 - 00003914 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-07-07 14:20 - 2015-03-31 16:27 - 00361336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys
2017-07-07 14:19 - 2017-04-06 22:29 - 00343264 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbloga.sys
2017-07-07 14:19 - 2017-04-06 22:29 - 00319984 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-07-07 14:19 - 2017-04-06 22:29 - 00198944 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbidsha.sys
2017-07-07 14:19 - 2017-04-06 22:29 - 00057704 _____ (AVAST Software s.r.o.) C:\Windows\system32\Drivers\aswbuniva.sys
2017-07-07 14:19 - 2015-10-13 17:24 - 00041800 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 01015848 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00585608 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00360792 _____ (AVAST Software) C:\Windows\system32\Drivers\aswvmm.sys.149940123028106
2017-07-07 14:19 - 2015-03-31 16:27 - 00198768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00146664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00110352 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00084392 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-07-07 14:19 - 2015-03-31 16:27 - 00046984 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-07-06 20:00 - 2015-06-04 22:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell
2017-07-02 09:33 - 2015-03-31 16:18 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-06-27 05:01 - 2017-04-09 20:52 - 00002217 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-06-27 05:01 - 2017-04-09 20:52 - 00002205 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-06-21 18:12 - 2013-08-23 01:36 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-06-21 18:06 - 2015-03-31 16:03 - 00000000 ____D C:\Program Files\Microsoft Office 15
2017-06-20 11:36 - 2017-03-22 07:31 - 00003168 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2
2017-06-20 11:36 - 2016-06-23 02:37 - 00002312 _____ C:\Users\PComputer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive for Business.lnk
2017-06-20 11:36 - 2015-03-31 16:12 - 00003176 _____ C:\Windows\System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-157973084-2402647649-1939952699-1001
2017-06-20 11:25 - 2015-03-31 17:41 - 00000000 ____D C:\Users\PComputer\AppData\Local\Adobe
2017-06-20 11:24 - 2013-08-23 01:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-06-20 11:24 - 2013-08-23 01:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-19 13:16 - 2015-03-31 17:05 - 00000000 ____D C:\Users\PComputer\AppData\Local\Packages
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-07-17 10:38
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2017
Ran by [removed] (18-07-2017 12:32:58)
Running from C:\Users\[removed]\Desktop\frst
Windows 8.1 Connected (Update) (X64) (2015-03-31 07:04:46)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-157973084-2402647649-1939952699-500 - Administrator - Disabled)
Guest (S-1-5-21-157973084-2402647649-1939952699-501 - Limited - Disabled)
PComputer (S-1-5-21-157973084-2402647649-1939952699-1001 - Administrator - Enabled) => C:\Users\PComputer
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 26 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 26.0.0.131 - Adobe Systems Incorporated)
Avast Free Antivirus (HKLM-x32\…\Avast Antivirus) (Version: 17.5.2302 - AVAST Software)
Dell Customer Connect (HKLM-x32\…\{4FA72FF9-DD64-43A8-8704-6380A11F11D5}) (Version: 1.4.15.0 - Dell Inc.)
Dell Touchpad (HKLM\…\SynTPDeinstKey) (Version: 18.1.2.1 - Synaptics Incorporated)
Dell Update (HKLM-x32\…\{F91263FA-BE4D-439D-9C0A-2E7204E0E9E3}) (Version: 1.9.20.0 - Dell Inc.)
DUB-13X2 USB3.0 to Gigabit Ethernet Adapter Windows Drivers (HKLM-x32\…\{B5F6C7ED-A669-48A1-B591-E4F853E07AAF}) (Version: 1.0.0.0 - D-Lnk Corporation) Hidden
DUB-13X2 USB3.0 to Gigabit Ethernet Adapter Windows Drivers (HKLM-x32\…\InstallShield_{B5F6C7ED-A669-48A1-B591-E4F853E07AAF}) (Version: 1.0.0.0 - D-Lnk Corporation)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3621 - Intel Corporation)
Intel(R) Trusted Execution Engine (HKLM\…\{176E2755-0A17-42C6-88E2-192AB2131278}) (Version: 1.0.0.1064 - Intel Corporation)
League of Legends (HKLM-x32\…\{861927A3-8B12-4BF8-9F2A-7A4ED4C40096}) (Version: 4.1.2 - Riot Games) Hidden
League of Legends (HKLM-x32\…\League of Legends 4.1.2) (Version: 4.1.2 - Riot Games)
Malwarebytes Anti-Malware version 2.1.4.1018 (HKLM-x32\…\Malwarebytes Anti-Malware_is1) (Version: 2.1.4.1018 - Malwarebytes Corporation)
Microsoft Office Home and Student 2013 - en-us (HKLM\…\HomeStudentRetail - en-us) (Version: 15.0.4937.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-157973084-2402647649-1939952699-1001\…\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\…\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Mozilla Firefox 54.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 54.0.1 (x86 en-US)) (Version: 54.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 54.0.1.6388 - Mozilla)
Office 15 Click-to-Run Extensibility Component (HKLM-x32\…\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.4937.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\…\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.4937.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM-x32\…\{90150000-008C-0409-0000-0000000FF1CE}) (Version: 15.0.4937.1000 - Microsoft Corporation) Hidden
Quickset64 (HKLM\…\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.16.005 - Dell Inc.)
Realtek Card Reader (HKLM-x32\…\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 6.2.9200.39048 - Realtek Semiconductor Corp.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7152 - Realtek Semiconductor Corp.)
SafeZone Stable 3.55.2393.609 (HKLM-x32\…\SafeZone 3.55.2393.609) (Version: 3.55.2393.609 - Avast Software) Hidden
Unity Web Player (HKU\S-1-5-21-157973084-2402647649-1939952699-1001\…\UnityWebPlayer) (Version: 5.0.1f1 - Unity Technologies ApS)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-157973084-2402647649-1939952699-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\PComputer\AppData\Local\Microsoft\OneDrive\17.3.6917.0607\amd64\FileCoAuthLib64.dll (Microsoft Corporation)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-07] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-07] (AVAST Software)
ContextMenuHandlers01: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-07] (AVAST Software)
ContextMenuHandlers03: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-07] (AVAST Software)
ContextMenuHandlers05: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => -> No File
ContextMenuHandlers05: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\Windows\system32\igfxDTCM.dll [2014-05-22] (Intel Corporation)
ContextMenuHandlers05: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\Windows\system32\igfxOSP.dll [2014-05-22] (Intel Corporation)
ContextMenuHandlers06: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-07-07] (AVAST Software)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01668538-58DF-46E9-A59F-1176198667D1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-13] (Google Inc.)
Task: {022C1A2F-276D-48E4-80B2-0DA154BA6995} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-07-07] (AVAST Software)
Task: {036F5D1D-9F54-4A11-B74F-544D02D53FFB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-10-13] (Google Inc.)
Task: {08770B52-5D3A-4A02-845C-61604D961F52} - System32\Tasks\SafeZone scheduled Autoupdate 1471781584 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-06-14] (Avast Software)
Task: {371A8BFE-1671-4EED-AB19-822B04F86C87} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2014-02-20] (Synaptics Incorporated)
Task: {8887AF32-0DA1-4115-8A22-54B07DD269C1} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-04-11] (Microsoft Corporation)
Task: {90BEDD88-E0C5-47F8-9CD6-BACF615F90B4} - System32\Tasks\Dell\Dell Product Registration Update => C:\Program Files (x86)\Dell Product Registration\prodreg.exe
Task: {DB78B3F2-9952-465D-A682-5FB7AD9021D6} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2017-07-13] (AVAST Software)
Task: {DBAB435B-8969-4D55-9DBC-B61E38E4DDC8} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-04-11] (Microsoft Corporation)
Task: {DD78B943-69F9-433D-B4E1-5ED6A9832496} - System32\Tasks\Aviata\PowerRegister\Dell Reminder (PComputer) => C:\Program Files (x86)\Dell Product Registration\prodreg.exe
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2017-03-22 07:34 - 2017-01-31 22:34 - 08909512 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2015-03-31 16:03 - 2017-01-17 04:25 - 00117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2017-07-07 14:19 - 2017-07-07 14:19 - 00170224 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-07-13 10:34 - 2017-07-13 10:34 - 01038952 _____ () C:\Program Files\AVAST Software\Avast\AvChrome.dll
2017-07-07 14:19 - 2017-07-07 14:19 - 67109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-07-07 14:19 - 2017-07-07 14:19 - 00192664 _____ () C:\Program Files\AVAST Software\Avast\event_routing_rpc.dll
2017-07-07 14:19 - 2017-07-07 14:19 - 00224256 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-07-07 14:19 - 2017-07-07 14:19 - 00292920 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-07-07 14:19 - 2017-07-07 14:20 - 02962096 _____ () C:\Program Files\AVAST Software\Avast\aswDataScan.dll
2016-12-21 09:24 - 2016-12-21 09:24 - 00134008 _____ () C:\Program Files (x86)\Dell Customer Connect\ServiceTagPlusPlus.dll
2017-05-01 15:27 - 2017-05-01 15:27 - 00133992 _____ () C:\Program Files (x86)\Dell Update\ServiceTagPlusPlus.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 23:25 - 2013-08-22 23:25 - 00000824 _____ C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-157973084-2402647649-1939952699-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\dell\BlueLava_1112000xx_inspiron_wallpaper58095_16x9_72dpi_RGB.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{4A0F5173-A8DC-4C45-AAC5-A7C13396AB75}] => (Allow) C:\Users\PComputer\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{F14CF5FF-BA9C-46DE-8370-40267E96137C}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{CC2B8C30-A55D-477E-9B6E-3961945C297B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{8D819536-CD9D-437F-BA86-EE8002C545D8}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{CFFD1CFD-2026-421B-B894-F180FFD31F81}C:\program files (x86)\mozilla firefox\firefox.exe] => (Allow) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{65BFBB82-B5D2-4C46-B109-903C39DC47DE}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{3B0C5114-432F-4A9F-82E6-3033C21294C9}] => (Allow) C:\Program Files\AVAST Software\Avast\ng\vbox\aswFe.exe
FirewallRules: [{44D1C041-66ED-4644-9C88-B684E495A95D}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.607\SZBrowser.exe
FirewallRules: [{589EFD28-C593-426A-91B9-DFD5290BB476}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{9DCAF409-B3FB-4110-9880-56ED2B02CF8A}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.609\SZBrowser.exe
==================== Restore Points =========================
02-07-2017 10:36:28 Scheduled Checkpoint
11-07-2017 11:23:15 Scheduled Checkpoint
17-07-2017 23:09:27 JRT Pre-Junkware Removal
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (07/17/2017 11:02:45 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 54.0.1.6388, time stamp: 0x5953d1f8
Faulting module name: xul.dll, version: 54.0.1.6388, time stamp: 0x5953d62e
Exception code: 0x80000003
Fault offset: 0x008a6bcb
Faulting process id: 0x10b0
Faulting application start time: 0x01d2fed627069968
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\xul.dll
Report Id: 39a02d67-6af0-11e7-82ac-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (07/09/2017 09:38:55 AM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: The Desktop Window Manager has encountered a fatal error (0x8898008d)
Error: (07/06/2017 09:57:37 AM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: The Desktop Window Manager has encountered a fatal error (0x8898008d)
Error: (06/30/2017 09:16:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 54.0.1.6388, time stamp: 0x5953d1f8
Faulting module name: firefox.exe, version: 54.0.1.6388, time stamp: 0x5953d1f8
Exception code: 0xc0000005
Fault offset: 0x000128d8
Faulting process id: 0x1304
Faulting application start time: 0x01d2f19252bcb2df
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Report Id: 91505c9d-5d85-11e7-8299-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (06/25/2017 09:15:48 AM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
Description: The Desktop Window Manager has encountered a fatal error (0x8898008d)
Error: (06/14/2017 10:19:59 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program WINWORD.EXE version 15.0.4927.1000 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 14e0
Start Time: 01d2e4a3ca646fc2
Termination Time: 4294967295
Application Path: C:\Program Files\Microsoft Office 15\Root\Office15\WINWORD.EXE
Report Id: 2ac6fd79-5097-11e7-828f-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (04/04/2017 11:57:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 52.0.2.6291, time stamp: 0x58d41a2d
Faulting module name: ucrtbase.DLL, version: 10.0.14393.33, time stamp: 0x579994fc
Exception code: 0xc0000409
Fault offset: 0x000891cb
Faulting process id: 0xd7c
Faulting application start time: 0x01d2ad19713fbcf7
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\ucrtbase.DLL
Report Id: 9c2c0a09-193e-11e7-827c-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (04/04/2017 05:59:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 52.0.2.6291, time stamp: 0x58d41a2d
Faulting module name: ucrtbase.DLL, version: 10.0.14393.33, time stamp: 0x579994fc
Exception code: 0xc0000409
Fault offset: 0x000891cb
Faulting process id: 0x11e4
Faulting application start time: 0x01d2ad15eb69c4a5
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\ucrtbase.DLL
Report Id: ab1ec9bd-190c-11e7-827c-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (04/01/2017 10:54:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: firefox.exe, version: 52.0.2.6291, time stamp: 0x58d41a2d
Faulting module name: ucrtbase.DLL, version: 10.0.14393.33, time stamp: 0x579994fc
Exception code: 0xc0000409
Fault offset: 0x000891cb
Faulting process id: 0x116c
Faulting application start time: 0x01d2aa76f4f06248
Faulting application path: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Faulting module path: C:\Program Files (x86)\Mozilla Firefox\ucrtbase.DLL
Report Id: 4f8cece9-16da-11e7-827c-9cd643ae29b8
Faulting package full name:
Faulting package-relative application ID:
Error: (03/31/2017 09:43:28 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 5973) (User: PC)
Description: Activation of app Microsoft.Reader_8wekyb3d8bbwe!Microsoft.Reader failed with error: -2147024809 See the Microsoft-Windows-TWinUI/Operational log for additional information.
System errors:
=============
Error: (07/18/2017 12:10:36 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error:
An instance of the service is already running.
Error: (07/18/2017 12:10:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.
Error: (07/18/2017 12:10:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Microsoft Office ClickToRun Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
Error: (07/18/2017 12:10:06 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Print Spooler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service.
Error: (07/18/2017 12:10:04 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Windows Presentation Foundation Font Cache 3.0.0.0 service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
Error: (07/18/2017 12:10:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Dell Customer Connect service terminated unexpectedly. It has done this 1 time(s).
Error: (07/18/2017 12:10:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Dell Update Service service terminated unexpectedly. It has done this 1 time(s).
Error: (07/18/2017 12:10:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Andrea RT Filters Service service terminated unexpectedly. It has done this 1 time(s).
Error: (07/18/2017 12:10:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Realtek Audio Service service terminated unexpectedly. It has done this 1 time(s).
Error: (07/18/2017 12:10:04 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Intel(R) HD Graphics Control Panel Service service terminated unexpectedly. It has done this 1 time(s).
==================== Memory info ===========================
Processor: Intel(R) Celeron(R) CPU N2830 @ 2.16GHz
Percentage of memory in use: 31%
Total physical RAM: 3979.2 MB
Available physical RAM: 2718.72 MB
Total Virtual: 5131.2 MB
Available Virtual: 3764.51 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:457.22 GB) (Free:423.65 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 465.8 GB) (Disk ID: 5FFCAB3E)
Partition: GPT.
==================== End of Addition.txt ============================
THanks for running me through that but my comp speed doesnt seem to have changed much. For example I am still getting choppy you tube vids.
Did I just buy a really slow comp?
Did I just buy a really slow comp?
I'm not sure.
It might be worth starting a topic in our Windows forum where the experts there may be able to isolate something that's slowing it down as I'm no expert in Windows.
Personally I would uninstall Avast and rely on Windows Defender which uses up fewer resources, (but that's only a personal opinion, not expert advice ).
Also, you need to update Malwarebytes to the latest version but I'll include those instructions when we tidy up.
If you're happy that there is no virus/malware on your computer I'll send those instructions to tidy up and then close this.
Satchfan
Hi ManMan
It has been several days since I replied to you.
Please let me know if you are having problems but if I do not hear from you within 24 hours I'll assume that you no longer need help and close this topic.
Thanks
Satchfan
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please follow the instructions here http://forums.whatthetech.com/you_Infected_t106388.html and start a New Topic.