My machine has been experiencing some unusual symptoms and erratic behavior. At first i noticed a few times my machine would reboot it self usually on idle or just by running a few system programs. The internet was also not working, i was not able to connect to any domain on any websites. How ever, as the problem persists for a few more days, other symptoms starting appearing such as Disappearing desktop icons flashing off and on rapidly. The start button not functioning, Indexing turned off as well as firewalls turned off. The machine also having very slow boot times and CPU using a constant 90%. I also noticed that my windows login-id and password did not work at all when i tried to run a repair recovery console. I noticed another user established on my network that was never there before titled "person 1". The same user was created for my google chrome account because the proxy settings were not functioning correctly as i said before which i believe led to websites not being able to locate their DNS addresses.
So naturally i decided to isolate this issue to determine if its a hardware or software issue. So i booted the machine into safe mode, let it sit idle for a while. Every symptom that i experience well booted in normal mode was not apparent, in addition the machine stayed on over night and never once rebooted. This is when i came to the conclusion that this must be a software related issue or perhaps even a maleware rogue agent or hyjacker.
So the first step towards resolving this issue was to due a system restore. I successfully completed this and many of the symptoms that i experienced didn't happen any more and i was able to connect to the internet. How ever the "rebooting and restarting" issue still persists.
So with that being said, i'll leave it up to the professionals to figure this one out. In the mean time here is my log.
[removed]
Platform: Windows 10 Pro Version 1703 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(SurfRight B.V.) C:\Program Files\HitmanPro\hmpsched.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Rivet Networks) C:\Program Files\Killer Networking\Network Manager\KillerService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe
() C:\Program Files (x86)\Canon\IJPLM\ijplmsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(AVAST Software s.r.o.) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_11.19.856.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Node.js) C:\Program Files (x86)\NVIDIA Corporation\NvNode\NVIDIA Web Helper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Rivet Networks) C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe
(Creative Technology Ltd) C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8484056 2015-06-12] (Realtek Semiconductor)
HKLM\…\Run: [MBCfg64] => C:\Windows\system32\RunDLL32.exe C:\Windows\system32\MBCfg64.dll,RunDLLEntry MBCfg64
HKLM\…\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\…\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [239856 2017-09-04] (AVAST Software)
HKLM-x32\…\Run: [Sound Blaster Cinema 2] => C:\Program Files (x86)\Creative\Sound Blaster Cinema 2\Sound Blaster Cinema 2\SBCinema2.exe [1442304 2014-05-29] (Creative Technology Ltd)
HKLM-x32\…\Run: [UpdReg] => C:\Windows\UpdReg.EXE [90112 2000-05-11] (Creative Technology Ltd.)
HKLM-x32\…\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [413696 2009-01-05] (Apple Inc.)
HKLM-x32\…\Run: [CanonQuickMenu] => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE [1279120 2012-09-27] (CANON INC.)
HKLM-x32\…\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452272 2012-08-31] (CANON INC.)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
HKU\S-1-5-21-4212484089-3487115953-933115951-1004\…\Run: [Mal Updater 2] => C:\Program Files (x86)\Mal Updater 2\MalUpdater.exe [7100928 2017-06-16] (eden.fm)
HKU\S-1-5-21-4212484089-3487115953-933115951-1004\…\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3071776 2017-09-06] (Valve Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Killer Network Manager.lnk [2016-10-25]
ShortcutTarget: Killer Network Manager.lnk -> C:\Program Files\Killer Networking\Network Manager\NetworkManager.exe (Rivet Networks)
GroupPolicy: Restriction <==== ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{f185da36-ed8e-44d6-a98c-87cebaebd02d}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com
HKU\S-1-5-21-4212484089-3487115953-933115951-1004\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://go.microsoft.com/fwlink/p/?LinkId=619797&pc=UE01&ocid=UE01DHP
SearchScopes: HKU\S-1-5-21-4212484089-3487115953-933115951-1004 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-09-03] (Microsoft Corporation)
BHO: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-09-03] (Microsoft Corporation)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2016-02-23] (CANON INC.)
Toolbar: HKLM - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2016-02-23] (CANON INC.)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-09-03] (Microsoft Corporation)
FireFox:
========
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-09-03] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2017-02-23] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2017-02-23] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-27] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)
Chrome:
=======
CHR DefaultSearchURL: Default -> hxxp://srch.bar/{searchTerms}
CHR DefaultSuggestURL: Default -> hxxp://srch.bar/?s={searchTerms}
CHR Session Restore: Default -> is enabled.
CHR Profile: C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default [2017-09-09]
CHR Extension: (Google Slides) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-09-08]
CHR Extension: (Google Docs) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-09-08]
CHR Extension: (Google Drive) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-10-25]
CHR Extension: (YouTube) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-10-25]
CHR Extension: (uBlock Origin) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-09-08]
CHR Extension: (Adobe Acrobat) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-09-08]
CHR Extension: (Avast SafePrice) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2017-09-08]
CHR Extension: (Google Sheets) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-09-08]
CHR Extension: (Google Docs Offline) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-09-08]
CHR Extension: (Avast Online Security) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-09-08]
CHR Extension: (Search Manager) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\nahhmpbckpgdidfnmfkfgiflpjijilce [2017-09-08]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-08]
CHR Extension: (Gmail) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-10-25]
CHR Extension: (Chrome Media Router) - C:\Users\Jeff M\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-09-08]
CHR HKLM\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-4212484089-3487115953-933115951-1004\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [nahhmpbckpgdidfnmfkfgiflpjijilce] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7452288 2017-09-04] (AVAST Software s.r.o.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [275208 2017-09-04] (AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [322976 2017-09-04] (AVAST Software)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [4424384 2017-08-28] (Microsoft Corporation)
R2 HitmanProScheduler; C:\Program Files\HitmanPro\hmpsched.exe [135488 2017-06-16] (SurfRight B.V.)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
R2 Killer Service V2; C:\Program Files\Killer Networking\Network Manager\KillerService.exe [402432 2015-07-07] (Rivet Networks) [File not signed]
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-11-17] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [462784 2016-11-17] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462968 2017-05-01] (NVIDIA Corporation)
R2 NVIDIA Wireless Controller Service; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\nvwirelesscontroller.exe [1163712 2016-11-17] (NVIDIA Corporation)
S3 Sense; C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe [3913064 2017-03-18] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-07-10] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswbidsdriver; C:\WINDOWS\system32\drivers\aswbidsdrivera.sys [320528 2017-09-04] (AVAST Software s.r.o.)
R0 aswbidsh; C:\WINDOWS\system32\drivers\aswbidsha.sys [198976 2017-09-04] (AVAST Software s.r.o.)
R0 aswblog; C:\WINDOWS\system32\drivers\aswbloga.sys [343296 2017-09-04] (AVAST Software s.r.o.)
R0 aswbuniv; C:\WINDOWS\system32\drivers\aswbuniva.sys [57736 2017-09-04] (AVAST Software s.r.o.)
S3 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [47016 2017-09-04] (AVAST Software)
R1 aswKbd; C:\WINDOWS\system32\drivers\aswKbd.sys [41832 2017-09-04] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [147784 2017-09-04] (AVAST Software)
R1 aswNetSec; C:\WINDOWS\system32\drivers\aswNetSec.sys [555072 2017-09-04] (AVAST Software)
R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr2.sys [110376 2017-09-04] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\system32\drivers\aswRvrt.sys [84416 2017-09-04] (AVAST Software)
R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [1016384 2017-09-04] (AVAST Software)
R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [590880 2017-09-04] (AVAST Software)
R2 aswStm; C:\WINDOWS\system32\drivers\aswStm.sys [199312 2017-09-04] (AVAST Software)
R0 aswVmm; C:\WINDOWS\system32\drivers\aswVmm.sys [361336 2017-09-04] (AVAST Software)
R1 BfLwf; C:\WINDOWS\system32\DRIVERS\bwcW10x64.sys [114736 2015-07-07] (Rivet Networks, LLC.)
R3 KillerEth; C:\WINDOWS\System32\drivers\e2xw10x64.sys [145920 2017-03-18] (Qualcomm Atheros, Inc.)
R3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [253856 2017-09-09] (Malwarebytes)
R3 nvlddmkm; C:\WINDOWS\System32\DriverStore\FileRepository\nv_ref_pubwu.inf_amd64_f9309145156afb40\nvlddmkm.sys [14456912 2017-05-19] (NVIDIA Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [27584 2016-11-17] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\WINDOWS\system32\drivers\nvvad64v.sys [46016 2016-11-17] (NVIDIA Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
R3 XtuAcpiDriver; C:\WINDOWS\System32\drivers\XtuAcpiDriver.sys [63840 2015-06-06] (Intel Corporation)
S3 ALSysIO; \??\C:\Users\JEFFM~1\AppData\Local\Temp\ALSysIO64.sys [X] <==== ATTENTION
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-09-09 20:49 - 2017-09-09 20:49 - 000019588 _____ C:\Users\Jeff M\Desktop\FRST.txt
2017-09-09 20:48 - 2017-09-09 20:49 - 000000000 ____D C:\FRST
2017-09-09 20:48 - 2017-09-09 20:48 - 002396160 _____ (Farbar) C:\Users\Jeff M\Desktop\FRST64.exe
2017-09-09 20:18 - 2017-09-09 20:18 - 000614884 _____ C:\WINDOWS\Minidump\090917-7375-01.dmp
2017-09-09 17:56 - 2017-09-09 17:56 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\4598
2017-09-09 16:20 - 2017-09-09 16:20 - 000646993 _____ C:\Users\Jeff M\Desktop\c1d77b51-2579-4787-b132-2695da92fccb_1.009cbfecfe61be8862a9c75c856c60da (1).jpeg
2017-09-09 16:19 - 2017-09-09 16:19 - 000646993 _____ C:\Users\Jeff M\Desktop\c1d77b51-2579-4787-b132-2695da92fccb_1.009cbfecfe61be8862a9c75c856c60da.jpeg
2017-09-09 16:18 - 2017-09-09 16:18 - 001096086 _____ C:\Users\Jeff M\Desktop\4a60fded-509e-4952-bd92-5b2558b07f15_1.9741e5d681357165c4f5c41b9d9594ce.jpeg
2017-09-09 13:54 - 2017-09-09 13:54 - 000061304 _____ () C:\WINDOWS\system32\Drivers\lpsport.sys
2017-09-09 12:54 - 2017-09-04 13:45 - 000401488 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2017-09-08 21:15 - 2017-09-08 21:15 - 000000989 _____ C:\Users\Jeff M\Desktop\Core Temp.lnk
2017-09-08 21:15 - 2017-09-08 21:15 - 000000165 _____ C:\Users\Jeff M\Desktop\Goodgame Empire.url
2017-09-08 21:15 - 2017-09-08 21:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Core Temp
2017-09-08 21:15 - 2017-09-08 21:15 - 000000000 ____D C:\Program Files\Core Temp
2017-09-08 20:57 - 2017-09-08 22:04 - 000000000 ___HD C:\$SysReset
2017-09-08 19:21 - 2017-09-08 19:21 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Roaming\AVAST Software
2017-09-08 19:21 - 2017-09-08 19:21 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\CEF
2017-09-08 19:20 - 2017-09-08 19:20 - 000000000 ___RD C:\Users\Jeff.DESKTOP-K72D4JE\OneDrive
2017-09-08 19:20 - 2017-09-08 19:20 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\Comms
2017-09-08 19:19 - 2017-09-08 19:19 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Roaming\Canon
2017-09-08 19:04 - 2017-09-08 19:04 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\DBG
2017-09-08 18:59 - 2017-09-08 19:19 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\Packages
2017-09-08 18:59 - 2017-09-08 18:59 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Roaming\Adobe
2017-09-08 18:59 - 2017-09-08 18:59 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\VirtualStore
2017-09-08 18:59 - 2017-09-08 18:59 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\Publishers
2017-09-08 18:59 - 2017-09-08 18:59 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\Google
2017-09-08 18:58 - 2017-09-08 22:04 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE
2017-09-08 18:58 - 2017-09-08 19:00 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\NVIDIA Corporation
2017-09-08 18:58 - 2017-09-08 18:58 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\NVIDIA
2017-09-08 18:58 - 2017-09-08 18:58 - 000000000 ____D C:\Users\Jeff.DESKTOP-K72D4JE\AppData\Local\ConnectedDevicesPlatform
2017-09-04 19:46 - 2017-09-04 19:46 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-09-03 14:42 - 2017-09-03 15:12 - 000012212 _____ C:\Users\Jeff M\Documents\Book1.xlsx
2017-09-03 09:32 - 2017-09-09 20:18 - 4072317727 _____ C:\WINDOWS\MEMORY.DMP
2017-09-03 09:32 - 2017-09-03 09:32 - 000662332 _____ C:\WINDOWS\Minidump\090317-13296-01.dmp
2017-09-03 02:52 - 2017-09-09 20:18 - 000000000 ____D C:\WINDOWS\Minidump
2017-08-28 12:41 - 2017-08-28 12:41 - 000249326 _____ C:\Users\Jeff M\Desktop\key-visual.jpg-723x1024.jpeg
2017-08-21 15:47 - 2017-08-21 15:47 - 000000000 ____D C:\Users\Jeff M\Documents\Proposal and Contract
2017-08-21 15:44 - 2017-08-21 15:45 - 000000000 ___HD C:\ProgramData\CanonIJMIG
2017-08-21 15:43 - 2017-08-21 15:43 - 000000000 ___HD C:\ProgramData\CanonIJScan
2017-08-21 15:28 - 2017-09-04 15:05 - 000000000 ____D C:\ProgramData\CanonIJPLM
2017-08-21 15:28 - 2017-08-28 15:29 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\canon
2017-08-21 15:28 - 2017-08-21 15:28 - 000000000 ___HD C:\ProgramData\CanonIJQuickMenu
2017-08-21 15:28 - 2017-08-21 15:28 - 000000000 ____D C:\ProgramData\Canon IJ Network Tool
2017-08-21 15:27 - 2012-09-21 09:33 - 000321024 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNC_BLL.dll
2017-08-21 15:27 - 2012-05-25 09:21 - 000103936 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNC_BLU.dll
2017-08-21 15:27 - 2012-05-15 15:58 - 000098048 _____ C:\WINDOWS\SysWOW64\CNC176BD.TBL
2017-08-21 15:27 - 2008-08-25 18:02 - 000015872 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNHMCA.dll
2017-08-21 15:25 - 2017-09-08 22:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX920 series User Registration
2017-08-21 15:25 - 2017-08-21 15:25 - 000000000 ____D C:\Users\Jeff M\AppData\LocalLow\Canon Easy-WebPrint EX2
2017-08-21 15:25 - 2017-08-21 15:25 - 000000000 ____D C:\Users\Jeff M\AppData\LocalLow\Canon Easy-WebPrint EX
2017-08-21 15:24 - 2017-08-21 15:24 - 000002094 _____ C:\Users\Public\Desktop\Canon Quick Menu.lnk
2017-08-21 15:24 - 2017-08-21 15:24 - 000000000 ____D C:\ProgramData\CanonIJWSpt
2017-08-21 15:20 - 2017-09-08 22:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
2017-08-21 15:20 - 2017-08-21 15:25 - 000000000 ____D C:\Program Files\Canon
2017-08-21 15:19 - 2017-09-08 22:04 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX920 series Manual
2017-08-21 15:19 - 2017-08-21 15:19 - 000002431 _____ C:\Users\Public\Desktop\Canon MX920 series On-screen Manual.lnk
2017-08-21 15:19 - 2017-08-21 15:19 - 000000000 ___HD C:\Program Files\CanonBJ
2017-08-21 15:19 - 2017-08-21 15:19 - 000000000 ____D C:\WINDOWS\system32\STRING
2017-08-21 15:19 - 2012-07-31 01:48 - 000359936 _____ (CANON INC.) C:\WINDOWS\system32\CNMN6PPM.DLL
2017-08-21 15:19 - 2012-07-31 01:48 - 000039424 _____ (CANON INC.) C:\WINDOWS\system32\CNMN6UI.DLL
2017-08-21 15:19 - 2012-07-31 01:47 - 000366592 _____ (CANON INC.) C:\WINDOWS\SysWOW64\CNMNPPM.DLL
2017-08-21 15:18 - 2017-08-21 15:28 - 000000000 ____D C:\Program Files (x86)\Canon
2017-08-21 09:56 - 2017-08-21 09:56 - 000000000 ____D C:\Users\Jeff M\Desktop\camera pics
2017-08-20 14:39 - 2017-08-20 14:39 - 000000000 ____D C:\Users\Jeff M\Desktop\Walmart pics upload
2017-08-18 00:33 - 2017-08-18 00:33 - 000012872 _____ (SurfRight B.V.) C:\WINDOWS\system32\bootdelete.exe
2017-08-14 13:28 - 2017-08-14 13:28 - 000000000 ____D C:\Users\Jeff M\AppData\Local\DBG
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-09-09 20:24 - 2017-08-09 21:06 - 001130182 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-09-09 20:18 - 2017-08-09 21:01 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-09-09 20:18 - 2017-08-09 20:57 - 000000000 ____D C:\Users\Jeff M
2017-09-09 20:18 - 2017-08-09 20:56 - 000000000 ____D C:\ProgramData\NVIDIA
2017-09-09 20:18 - 2017-06-16 13:18 - 000000000 ____D C:\Program Files (x86)\Steam
2017-09-09 20:18 - 2017-03-24 21:27 - 000253856 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-09-09 20:18 - 2016-12-08 15:46 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Mal Updater
2017-09-09 20:05 - 2017-08-09 20:56 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2017-09-09 19:13 - 2017-08-09 21:01 - 000004168 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{F33DBF81-DB59-40F2-81B3-09A0751603E4}
2017-09-09 12:59 - 2017-03-18 14:03 - 000000000 ___HD C:\Program Files\WindowsApps
2017-09-09 12:59 - 2017-03-18 14:03 - 000000000 ____D C:\WINDOWS\AppReadiness
2017-09-09 12:55 - 2017-03-24 21:56 - 000001979 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Internet Security.lnk
2017-09-09 12:55 - 2017-03-24 21:56 - 000001967 _____ C:\Users\Public\Desktop\Avast Internet Security.lnk
2017-09-09 12:54 - 2017-08-09 21:01 - 000004268 _____ C:\WINDOWS\System32\Tasks\Avast Emergency Update
2017-09-09 12:54 - 2017-08-09 21:01 - 000004022 _____ C:\WINDOWS\System32\Tasks\SafeZone scheduled Autoupdate 1490417705
2017-09-09 12:54 - 2017-03-24 21:55 - 000001088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast SafeZone Browser.lnk
2017-09-09 12:46 - 2017-03-18 04:40 - 001835008 _____ C:\WINDOWS\system32\config\BBI
2017-09-08 22:04 - 2017-08-09 20:57 - 000000000 ____D C:\Users\defaultuser0.DESKTOP-K72D4JE
2017-09-08 22:04 - 2017-06-16 13:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steam
2017-09-08 22:04 - 2017-06-16 11:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
2017-09-08 22:04 - 2017-06-16 03:15 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam
2017-09-08 22:04 - 2017-04-22 00:26 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Shrink
2017-09-08 22:04 - 2017-04-02 19:09 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\FormatFactory
2017-09-08 22:04 - 2017-04-02 19:03 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VSO
2017-09-08 22:04 - 2017-03-24 21:27 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-09-08 22:04 - 2017-03-19 03:11 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sony
2017-09-08 22:04 - 2017-03-19 02:49 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Sony
2017-09-08 22:04 - 2017-03-19 02:28 - 000000000 ____D C:\Users\Jeff M\Documents\Sony Vegas Pro 13.0 Build 453 (x64) + Patch DI
2017-09-08 22:04 - 2017-03-18 14:01 - 000000000 ____D C:\WINDOWS\INF
2017-09-08 22:04 - 2017-01-22 17:07 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2017-09-08 22:04 - 2017-01-22 17:01 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\honestech VHS to DVD 5.0 Deluxe
2017-09-08 22:04 - 2017-01-01 22:22 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDFab 9
2017-09-08 22:04 - 2017-01-01 22:20 - 000000000 ____D C:\Users\Jeff M\Documents\DVDFab Platinum v9.1.2.2 + Crack [ChattChitto RG]
2017-09-08 22:04 - 2016-12-08 15:46 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mal Updater 2
2017-09-08 22:04 - 2016-12-08 15:44 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Taiga
2017-09-08 22:04 - 2016-12-08 15:44 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Taiga
2017-09-08 22:04 - 2016-12-08 15:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KCP
2017-09-08 22:04 - 2016-12-08 15:35 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2017-09-08 22:04 - 2016-12-08 03:44 - 000000000 ____D C:\Users\Jeff M\Desktop\mpv-x86_64-20161120
2017-09-08 22:04 - 2016-12-08 03:44 - 000000000 ____D C:\Users\Jeff M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-09-08 22:04 - 2016-12-08 03:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2017-09-08 22:04 - 2016-11-15 10:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2017-09-08 22:04 - 2016-10-25 23:49 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID
2017-09-08 22:04 - 2016-10-25 23:42 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Creative
2017-09-08 22:04 - 2016-10-25 23:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Killer Networking
2017-09-08 22:04 - 2016-10-25 23:23 - 000000000 __RHD C:\Users\Public\AccountPictures
2017-09-08 22:04 - 2016-10-25 23:23 - 000000000 ____D C:\Users\Jeff M\AppData\Local\VirtualStore
2017-09-08 22:03 - 2017-03-18 14:03 - 000000000 ____D C:\WINDOWS\registration
2017-09-08 22:01 - 2017-06-16 02:38 - 000000000 ____D C:\Users\Jeff M\AppData\Local\Steam
2017-09-08 22:01 - 2017-04-21 01:33 - 000000000 ____D C:\Users\Jeff M\Documents\VSO ConvertXtoDVD v7.0.0.30 Beta + Patch
2017-09-08 22:01 - 2017-04-02 19:10 - 000000000 ____D C:\Users\Jeff M\AppData\Local\chromium
2017-09-08 22:01 - 2017-03-19 03:11 - 000000000 ____D C:\Users\Jeff M\AppData\Local\Sony
2017-09-08 22:01 - 2017-01-01 22:22 - 000000000 ____D C:\Users\Jeff M\Documents\DVDFab9
2017-09-08 22:01 - 2016-12-18 20:25 - 000000000 ____D C:\Users\Jeff M\Desktop\Back-up USB Drive
2017-09-08 22:01 - 2016-12-08 15:36 - 000000000 ____D C:\Users\Jeff M\AppData\Local\NVIDIA Corporation
2017-09-08 22:01 - 2016-10-25 23:46 - 000000000 ____D C:\Users\Jeff M\AppData\Local\Google
2017-09-08 22:01 - 2016-10-25 23:42 - 000000000 ____D C:\Users\Jeff M\AppData\Local\NVIDIA
2017-09-08 22:01 - 2016-10-25 23:23 - 000000000 ____D C:\Users\Jeff M\AppData\Local\TileDataLayer
2017-09-08 21:28 - 2017-06-16 10:53 - 000000000 ____D C:\WINDOWS\pss
2017-09-08 21:20 - 2017-06-16 10:57 - 000000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-09-08 21:14 - 2017-01-01 21:31 - 000000000 ____D C:\Users\Jeff M\AppData\Local\ElevatedDiagnostics
2017-09-08 19:45 - 2017-03-18 14:03 - 000000000 ____D C:\WINDOWS\system32\NDF
2017-09-04 13:45 - 2017-03-24 21:55 - 000555072 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswNetSec.sys
2017-09-04 13:45 - 2017-03-24 21:54 - 000041832 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 001016384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000590880 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000361336 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000343296 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbloga.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000320528 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsdrivera.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000199312 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000198976 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbidsha.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000147784 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000110376 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000084416 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000057736 _____ (AVAST Software s.r.o.) C:\WINDOWS\system32\Drivers\aswbuniva.sys
2017-09-04 13:45 - 2017-03-24 21:53 - 000047016 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2017-09-03 12:42 - 2017-01-22 05:03 - 000017884 ____H C:\Users\Jeff M\Desktop\~WRL2757.tmp
2017-09-03 09:48 - 2016-11-15 10:48 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2017-09-03 09:33 - 2017-03-18 04:40 - 000032768 _____ C:\WINDOWS\system32\config\ELAM
2017-09-03 09:33 - 2016-10-26 02:49 - 000544424 ____N (Microsoft Corporation) C:\WINDOWS\system32\MpSigStub.exe
2017-09-03 05:33 - 2017-03-18 14:03 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-09-03 02:52 - 2016-10-25 23:18 - 000314231 ____N C:\WINDOWS\Minidump\090317-14203-01.dmp
2017-08-31 11:39 - 2017-08-09 21:01 - 000003378 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-4212484089-3487115953-933115951-1004
2017-08-31 11:39 - 2016-10-25 23:24 - 000002366 _____ C:\Users\Jeff M\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-08-31 11:39 - 2016-10-25 23:24 - 000000000 ___RD C:\Users\Jeff M\OneDrive
2017-08-29 13:47 - 2017-01-12 15:15 - 000002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2017-08-28 12:47 - 2016-10-25 23:46 - 000002272 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-08-28 12:47 - 2016-10-25 23:46 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2017-08-21 15:27 - 2017-03-18 14:03 - 000000000 __RSD C:\WINDOWS\Media
2017-08-21 09:55 - 2016-12-30 16:07 - 000000000 ____D C:\Users\Jeff M\Desktop\100PHOTO
2017-08-18 00:33 - 2017-06-16 11:54 - 000000000 ____D C:\ProgramData\HitmanPro
2017-08-17 00:21 - 2017-08-09 20:56 - 000380296 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-08-17 00:21 - 2016-10-25 23:23 - 000000000 ____D C:\Users\Jeff M\AppData\Local\ConnectedDevicesPlatform
2017-08-12 21:09 - 2017-03-18 14:03 - 000000000 ____D C:\WINDOWS\rescache
2017-08-10 20:07 - 2016-10-25 23:23 - 000000000 ____D C:\Users\Jeff M\AppData\Local\Packages
2017-08-10 11:47 - 2017-03-18 13:51 - 000000000 ____D C:\WINDOWS\CbsTemp
2017-08-10 07:47 - 2017-08-09 21:01 - 000004562 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-08-10 03:41 - 2017-03-18 14:03 - 000000000 ____D C:\WINDOWS\appcompat
==================== Files in the root of some directories =======
2017-04-02 19:03 - 2017-04-21 01:35 - 000099384 _____ () C:\Users\Jeff M\AppData\Roaming\inst.exe
2017-04-02 19:03 - 2017-04-21 01:35 - 000007859 _____ () C:\Users\Jeff M\AppData\Roaming\pcouffin.cat
2017-04-02 19:03 - 2017-04-21 01:35 - 000001167 _____ () C:\Users\Jeff M\AppData\Roaming\pcouffin.inf
2017-04-02 19:03 - 2017-04-21 01:35 - 000000055 _____ () C:\Users\Jeff M\AppData\Roaming\pcouffin.log
2017-04-02 19:03 - 2017-04-21 01:35 - 000082816 _____ (VSO Software) C:\Users\Jeff M\AppData\Roaming\pcouffin.sys
Some files in TEMP:
====================
2017-08-21 15:18 - 2012-09-27 03:15 - 000865424 _____ (CANON INC.) C:\Users\Jeff M\AppData\Local\Temp\MSETUP4.EXE
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-08-31 22:59
==================== End of FRST.txt ============================