Happy New year Juliet, here are the results of the FarbaR SCAN.
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02.01.2018
Ran by [removed] (03-01-2018 10:16:46)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2014-09-13 02:47:10)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1069211171-1032678597-3133260682-500 - Administrator - Disabled)
Ashanthe (S-1-5-21-1069211171-1032678597-3133260682-1005 - Limited - Enabled) => C:\Users\Ashanthe
Bryan (S-1-5-21-1069211171-1032678597-3133260682-1001 - Administrator - Enabled) => C:\Users\Bryan
danbear11 (S-1-5-21-1069211171-1032678597-3133260682-1004 - Limited - Enabled) => C:\Users\danbear11
Guest (S-1-5-21-1069211171-1032678597-3133260682-501 - Limited - Enabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-1069211171-1032678597-3133260682-1002 - Limited - Enabled)
SophosSAUARTADI-PC0 (S-1-5-21-1069211171-1032678597-3133260682-1006 - Limited - Enabled)
Zanthia (S-1-5-21-1069211171-1032678597-3133260682-1003 - Administrator - Enabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 16.01 (HKLM-x32\…\7-Zip) (Version: 16.01 - Igor Pavlov)
7-Zip 16.02 (x64) (HKLM\…\7-Zip) (Version: 16.02 - Igor Pavlov)
7-Zip 16.04 (HKLM-x32\…\{23170F69-40C1-2701-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
7-Zip 16.04 (x64 edition) (HKLM\…\{23170F69-40C1-2702-1604-000001000000}) (Version: 16.04.00.0 - Igor Pavlov)
Acer Assist (HKLM-x32\…\Acer Assist) (Version: - Acer Incorporated)
Acer Backup Manager (HKLM-x32\…\InstallShield_{30075A70-B5D2-440B-AFA3-FB2021740121}) (Version: 2.0.2.19 - NewTech Infosystems)
Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.05.3005 - Acer Incorporated)
Acer Games (HKLM-x32\…\WildTangent acer Master Uninstall) (Version: 1.0.0.71 - WildTangent)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.02.3006 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\…\Acer Screensaver) (Version: 1.2.0812 - Acer Incorporated)
Acrobat.com (HKLM-x32\…\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 26.0.0.127 - Adobe Systems Incorporated)
Adobe Flash Player 26 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 26.0.0.151 - Adobe Systems Incorporated)
Adobe Flash Player 26 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 26.0.0.151 - Adobe Systems Incorporated)
Advanced IP Scanner 2.4 (HKLM-x32\…\{2E644D2D-993F-43B4-B85A-15363CA777C3}) (Version: 2.4.3021 - Famatech)
Advertising Center (HKLM-x32\…\{b2ec4a38-b545-4a00-8214-13fe0e915e6d}) (Version: 0.0.0.2 - Nero AG) Hidden
Amazon Music (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Amazon Amazon Music) (Version: 3.8.1.754 - Amazon Services LLC)
Avast Free Antivirus (HKLM-x32\…\Avast Antivirus) (Version: 17.9.2322 - AVAST Software)
Backup and Sync from Google (HKLM-x32\…\{908DB568-E5FA-40C7-A2AA-AB340190858B}) (Version: 3.38.7642.3857 - Google, Inc.)
Backup Manager Advance (HKLM-x32\…\{30075A70-B5D2-440B-AFA3-FB2021740121}) (Version: 2.0.2.19 - NewTech Infosystems) Hidden
Box Sync (HKLM\…\{0653E263-C86D-44AB-AE83-25407370FCE1}) (Version: 4.0.7848.0 - Box, Inc.)
Box Sync (HKLM-x32\…\{4bee5a36-c035-4e40-954e-788728d74093}) (Version: 4.0.5253.0 - Box Inc.) Hidden
CCleaner (HKLM\…\CCleaner) (Version: 5.29 - Piriform)
Compatibility Pack for the 2007 Office system (HKLM-x32\…\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Core Temp 1.1 (HKLM\…\{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1) (Version: 1.1 - Alcpu)
D3DX10 (HKLM-x32\…\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Defraggler (HKLM\…\Defraggler) (Version: 2.21 - Piriform)
Dropbox (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Dropbox) (Version: 3.16.1 - Dropbox, Inc.)
EaseUS Data Recovery Wizard 9.5 (HKLM\…\EaseUS Data Recovery Wizard 9.5_is1) (Version: - EaseUS)
eSobi v2 (HKLM-x32\…\{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.4.000274 - esobi Inc.) Hidden
eSobi v2 (HKLM-x32\…\InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}) (Version: 2.0.4.000274 - esobi Inc.)
f.lux (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Flux) (Version: - )
Facebook Gameroom 1.3.1.3 (HKLM-x32\…\{7E155A45-DE1A-46E0-A6B2-10FE1D8501FC}) (Version: 1.3.1.3 - Facebook)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 63.0.3239.84 - Google Inc.)
Google Earth Pro (HKLM-x32\…\{44FC61F0-2F8A-11E3-8CAE-B8AC6F97B88E}) (Version: 7.1.2.2041 - Google)
Google Photos Backup (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Google Photos Backup) (Version: 1.1.2.13 - Google, Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\…\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Greenshot 1.2.9.104 (HKLM\…\Greenshot_is1) (Version: 1.2.9.104 - Greenshot)
HostsMan 4.1.96 (HKLM-x32\…\{1A3DD1A9-7B7B-4ECA-AD2F-98466F49F62C}_is1) (Version: 4.1.96.0 - abelhadigital.com)
Hotkey Utility (HKLM-x32\…\Hotkey Utility) (Version: 1.00.3004 - Acer Incorporated)
HP Dropbox Plugin (HKLM-x32\…\{23617173-F935-4C17-A323-EB1207F3ED49}) (Version: 36.0.31.53050 - Hewlett-Packard Co.)
HP ENVY 4510 series Basic Device Software (HKLM\…\{E9FE2E2C-FF62-4C23-B816-62B6EEA1A772}) (Version: 36.0.72.54013 - Hewlett-Packard Co.)
HP ENVY 4510 series Help (HKLM-x32\…\{CB5C9CB2-B471-42CC-93E6-D0E15021D5C2}) (Version: 36.0.0 - Hewlett Packard)
HP FWUpdateEDO2 (HKLM-x32\…\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Google Drive Plugin (HKLM-x32\…\{AFF80405-E56A-48E7-98FC-8E46E261949F}) (Version: 36.0.31.53050 - Hewlett-Packard Co.)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Support Solutions Framework (HKLM-x32\…\{A772EA32-AE5B-4474-BFC0-4C69C04AFF6A}) (Version: 12.4.18.7 - Hewlett-Packard Company)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (HKLM-x32\…\{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}) (Version: 1.00.0001 - Microsoft) Hidden
Identity Card (HKLM-x32\…\Identity Card) (Version: 1.00.3002 - Acer Incorporated)
ImagXpress (HKLM-x32\…\{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}) (Version: 7.0.74.0 - Nero AG) Hidden
Jarte (HKLM-x32\…\Jarte_is1) (Version: 5.4 - Carolina Road Software L.L.C.)
Junk Mail filter update (HKLM-x32\…\{0BE9E708-5DC0-4963-9CFD-0AA519090E79}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Kiwi for Gmail (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\KiwiForGmail) (Version: 2.0.119 - Zive, Inc.)
LG AirDrive (HKLM-x32\…\{101E5DB3-07FA-4E52-8923-05068C94CF43}) (Version: 1.2.60617.11 - LG Electronics)
LG Bridge (HKLM-x32\…\LG Bridge) (Version: 1.2.36 - LG Electronics)
LG Mobile Drivers (HKLM-x32\…\{C3C008A7-D4A5-4E19-B0D6-72043D6EFE34}) (Version: 4.2.0 - LG Electronics)
LGFlashTool 1.8.1.1023 (HKLM-x32\…\LGFlashTool) (Version: 1.8.1.1023 - LGE)
MediaFire Desktop (HKLM-x32\…\MediaFire Desktop 1.4.25.10813) (Version: 1.4.26.10815 - MediaFire)
Microsoft .NET Framework 4.6.1 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
Microsoft ASP.NET MVC 4 Runtime (HKLM-x32\…\{3FE312D5-B862-40CE-8E4E-A6D8ABF62736}) (Version: 4.0.40804.0 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Suite Activation Assistant (HKLM-x32\…\{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}) (Version: 2.9 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\OneDriveSetup.exe) (Version: 17.3.6390.0509 - Microsoft Corporation)
Microsoft OneNote 2013 - en-us (HKLM\…\OneNoteFreeRetail - en-us) (Version: 15.0.4981.1001 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2012 Express LocalDB (HKLM\…\{E4A1FDA3-689D-44DA-9B39-86BD2270F522}) (Version: 11.2.5058.0 - Microsoft Corporation)
Microsoft SQL Server 2012 Management Objects (x64) (HKLM\…\{43A5C316-9521-49C3-B9B6-FCE5E1005DF0}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft System CLR Types for SQL Server 2012 (x64) (HKLM\…\{99AC7F47-A4E0-4706-9C65-8948775C2652}) (Version: 11.1.3000.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Works (HKLM-x32\…\{67E03279-F703-408F-B4BF-46B5FC8D70CD}) (Version: 9.7.0621 - Microsoft Corporation)
Minimal ADB and Fastboot version 1.4 (HKLM-x32\…\{C5564379-582D-457A-9E68-A9E7C1F1C4EC}_is1) (Version: 1.4 - Sam Rodberg)
MiniTool Partition Wizard Professional Edition 9.1 (HKLM\…\{69237D97-3063-450F-AE49-2357B191EA5D}_is1) (Version: - MiniTool Solution Ltd.)
Movie Maker (HKLM-x32\…\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\…\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 38.0.5 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 38.0.5 (x86 en-US)) (Version: 38.0.5 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 38.0.5 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\…\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)
MyWinLocker (HKLM-x32\…\{68301905-2DEA-41CE-A4D4-E8B443B099BA}) (Version: 3.1.76.0 - Egis Technology Inc.)
Nero 9 Essentials (HKLM-x32\…\{0b739e85-e796-499c-98fe-3be76860dfd0}) (Version: - Nero AG)
Nmap 7.00 (HKLM-x32\…\Nmap) (Version: - )
NVIDIA 3D Vision Controller Driver 340.50 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 340.50 - NVIDIA Corporation)
NVIDIA 3D Vision Driver 341.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 341.44 - NVIDIA Corporation)
NVIDIA Drivers (HKLM\…\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation)
NVIDIA ForceWare Network Access Manager (HKLM-x32\…\InstallShield_{7CFA46E3-CC2F-4355-82AE-6012DC3633FD}) (Version: - )
NVIDIA GeForce Experience 2.2.2 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.2.2 - NVIDIA Corporation)
NVIDIA Graphics Driver 341.44 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 341.44 - NVIDIA Corporation)
NVIDIA HD Audio Driver 1.3.30.1 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver) (Version: 1.3.30.1 - NVIDIA Corporation)
NVIDIA PhysX (HKLM-x32\…\{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}) (Version: 9.12.1031 - NVIDIA Corporation)
Office 15 Click-to-Run Extensibility Component (HKLM-x32\…\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.4981.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\…\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.4981.1001 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM-x32\…\{90150000-008C-0409-0000-0000000FF1CE}) (Version: 15.0.4981.1001 - Microsoft Corporation) Hidden
OpenAL (HKLM-x32\…\OpenAL) (Version: - )
OpenDNS Updater 2.2.1 (HKLM-x32\…\OpenDNS Updater) (Version: 2.2.1 - )
Oracle VM VirtualBox 5.0.2 (HKLM\…\{6CB00039-29CC-42A1-8ED2-820821DA2B8A}) (Version: 5.0.2 - Oracle Corporation)
Paragon Backup and Recovery™ 16 (HKLM\…\{DADAA9CF-36B6-11E6-B0B5-005056C00008}) (Version: 10.28.101 - Paragon Software)
Picasa 3 (HKLM-x32\…\Picasa 3) (Version: 3.9.141.259 - Google, Inc.)
PokerStars (HKLM-x32\…\PokerStars) (Version: - PokerStars)
Product Improvement Study for HP ENVY 4510 series (HKLM\…\{CE8D3871-0B4C-45A8-8380-1F1BBD4AD33D}) (Version: 36.0.72.54013 - Hewlett-Packard Co.)
RAR File Open Knife - Free Opener (HKLM-x32\…\RAR File Open Knife - Free Opener) (Version: 7 - Philipp Winterberg)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5898 - Realtek Semiconductor Corp.)
Recuva (HKLM\…\Recuva) (Version: 1.52 - Piriform)
Revo Uninstaller 2.0.1 (HKLM\…\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.1 - VS Revo Group, Ltd.)
Revo Uninstaller Pro 3.1.7 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.1.7 - VS Revo Group, Ltd.)
RogueKiller version 12.10.5.0 (HKLM\…\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.10.5.0 - Adlice Software)
SafeZone Stable 4.58.2552.909 (HKLM-x32\…\SafeZone 4.58.2552.909) (Version: 4.58.2552.909 - Avast Software) Hidden
Serif PanoramaPlus Starter Edition (HKLM-x32\…\{64AEB598-E518-4AD0-B02B-99F365B8054C}) (Version: 2.0.0.001 - Serif (Europe) Ltd)
SHIELD Streaming (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_GFExperience.NvStreamSrv) (Version: 4.0.1000 - NVIDIA Corporation) Hidden
SHIELD Wireless Controller Driver (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_ShieldWirelessController) (Version: 17.12.8 - NVIDIA Corporation) Hidden
Stellarium 0.15.0 (HKLM\…\Stellarium_is1) (Version: 0.15.0 - Stellarium team)
System Requirements Lab Detection (HKLM-x32\…\{B9C5A961-B5D5-4F55-9E9E-006FE3A85227}) (Version: 2.2.1.0 - Husdawg, LLC)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Watermark Software 8.1 (HKLM-x32\…\Watermark Software) (Version: 8.1 - watermark-software.com)
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.00.3008 - Acer Incorporated)
Windows Driver Package - Google, Inc. (WinUSB) AndroidUsbDeviceClass (08/28/2014 11.0.0000.00000) (HKLM\…\092555911492C6959D2596D612F52DCA71881CA2) (Version: 08/28/2014 11.0.0000.00000 - Google, Inc.)
Windows Driver Package - Hisense Corporation hsCDFiDrv CDROM (07/12/2010 1.01.00) (HKLM\…\D6CCB3CCE9E8F1119A58ECAB8CE0B3B24A78942E) (Version: 07/12/2010 1.01.00 - Hisense Corporation)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
Windows Live Sync (HKLM-x32\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
WinPcap 4.1.3 (HKLM-x32\…\WinPcapInst) (Version: 4.1.0.2980 - CACE Technologies)
WinX DVD Copy Pro 3.7.2 (HKLM\…\WinX DVD Copy Pro_is1) (Version: - Digiarty Software,Inc.)
WinX DVD Ripper Platinum 8.0.0 (HKLM-x32\…\WinX DVD Ripper Platinum_is1) (Version: - Digiarty Software, Inc.)
WinX HD Video Converter Deluxe 5.6.2 (HKLM-x32\…\WinX HD Video Converter Deluxe_is1) (Version: - Digiarty Software, Inc.)
Wireshark 2.0.1 (64-bit) (HKLM-x32\…\Wireshark) (Version: 2.0.1 - The Wireshark developer community, hxxps://www.wireshark.org)
WPS Office (10.1.0.5656) (HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Kingsoft Office) (Version: 10.1.0.5656 - Kingsoft Corp.)
Zynewave Podium Free 3.2.1 (x64) (HKLM\…\{EFA46A5D-4ACD-4665-A074-1B7CF713A9BB}) (Version: 3.2.1 - Zynewave)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{144DF3B2-2402-47AE-9583-5A045929A8D4}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.5\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll ()
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{8C46158B-D978-483C-A312-16EE5013BE04}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.3\psuser_64.dll => No File
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{91A41FCC-BC02-42D8-A36E-0D27FF9BFFC8}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll (Google Inc.)
CustomCLSID: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001_Classes\CLSID\{E8CF3E55-F919-49D9-ABC0-948E6CB34B9F}\InprocServer32 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.7\psuser_64.dll (Google Inc.)
ShellIconOverlayIdentifiers: [ BoxSyncFileLockedByOther] -> {f7d2951f-0b6b-346c-99ec-69cffc30a364} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncNotSynced] -> {5ea95e3d-3e46-3812-b03c-49785fa67d41} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncProblem] -> {a88b7184-bfa1-3d14-8efb-2225df9699bc} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ BoxSyncSynced] -> {c89f9943-8f58-3eca-bd55-a658f53b2f48} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ShellIconOverlayIdentifiers: [ GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-11-20] (Google)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-12-31] (AVAST Software)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-12-31] (AVAST Software)
ShellIconOverlayIdentifiers: [1MediaFireIconError] -> {5EE8C634-CDC0-453D-9731-DF0B19F4E807} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon3_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconReadOnly] -> {7995D0FC-769B-4197-AEC0-991921CB99E1} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon5_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconSynched] -> {9A3B79CB-D899-40B5-8DBC-20447F1ADC8F} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [1MediaFireIconSyncing] -> {C4D81971-6B13-4173-AB21-F83AD20CCC04} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon2_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll [2009-09-10] (Egis Technology Inc.)
ShellIconOverlayIdentifiers: [MediaFireIconLock] -> {759F3E92-F4E8-4953-8315-238B8B17E0F3} => C:\Program Files (x86)\MediaFire Desktop\MediaFireIcon4_1686d.dll [2015-03-17] (TODO: )
ShellIconOverlayIdentifiers-x32: [egisPSDP] -> {30A0A3F6-38AC-4C53-BB8B-0D95238E25BA} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\psdprotect.dll [2009-09-10] (Egis Technology Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-12-31] (AVAST Software)
ContextMenuHandlers1: [BoxContextMenuClient] -> {87768833-3c5c-30fb-af03-ba34bc95d084} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ContextMenuHandlers1: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers1: [EDSshellExt] -> {29FF7AB0-BE34-4992-A30B-53A9D86EE239} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\mwlshellext.dll [2009-09-10] (Egis Technology Inc.)
ContextMenuHandlers1: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-20] (Google)
ContextMenuHandlers1: [ISOWINDOWMENU] -> {3A05F453-60CA-4311-9DA3-FE348CB76056} => C:\Program Files\Digiarty\WinX_DVD_Copy_Pro\IsoWindowMenu64.dll [2013-11-19] (TODO: )
ContextMenuHandlers1: [MFShellStatic] -> {007D3D20-762B-40FF-BE6A-15E479A9DBFA} => C:\Program Files (x86)\MediaFire Desktop\MFDesktopShellStatic_1686d.dll [2015-03-17] (TODO: )
ContextMenuHandlers1: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-12-31] (AVAST Software)
ContextMenuHandlers3: [SendAnywhere] -> {BFD98515-CD74-48A4-98E2-13D209E3EE4F} => -> No File
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers4: [BoxContextMenuClient] -> {87768833-3c5c-30fb-af03-ba34bc95d084} => C:\Windows\system32\mscoree.dll [2010-11-04] (Microsoft Corporation)
ContextMenuHandlers4: [EDSshellExt] -> {29FF7AB0-BE34-4992-A30B-53A9D86EE239} => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x64\mwlshellext.dll [2009-09-10] (Egis Technology Inc.)
ContextMenuHandlers4: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-11-20] (Google)
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2015-04-08] (Piriform Ltd)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2015-02-03] (NVIDIA Corporation)
ContextMenuHandlers5: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers6: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2016-10-04] (Igor Pavlov)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2017-12-31] (AVAST Software)
ContextMenuHandlers6: [DefragglerShellExtension] -> {4380C993-0C43-4E02-9A7A-0D40B6EA7590} => C:\Program Files\Defraggler\DefragglerShell64.dll [2016-03-08] (Piriform Ltd)
ContextMenuHandlers6: [MFShellStatic] -> {007D3D20-762B-40FF-BE6A-15E479A9DBFA} => C:\Program Files (x86)\MediaFire Desktop\MFDesktopShellStatic_1686d.dll [2015-03-17] (TODO: )
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2015-04-08] (Piriform Ltd)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2012-12-29] (VS Revo Group)
ContextMenuHandlers6: [UAContextMenu] -> {A9B8E64D-3F7E-4D32-8FC9-E391DEE67D75} => C:\Program Files (x86)\Panda Security\Panda Security Protection\PSUAShell.dll -> No File
ContextMenuHandlers1_S-1-5-21-1069211171-1032678597-3133260682-1001: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => -> No File
ContextMenuHandlers4_S-1-5-21-1069211171-1032678597-3133260682-1001: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => -> No File
ContextMenuHandlers5_S-1-5-21-1069211171-1032678597-3133260682-1001: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => -> No File
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {064EE1AB-DBC2-458B-AB6E-5384536BCF1D} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2017-04-10] (Piriform Ltd)
Task: {0D30B4CF-2B59-4B0E-AFD1-8E7F32225BF5} - System32\Tasks\HPCustParticipation HP ENVY 4510 series => C:\Program Files\HP\HP ENVY 4510 series\Bin\HPCustPartic.exe [2015-03-09] (Hewlett-Packard Development Company, LP)
Task: {108611F4-BCA4-4BDC-A791-CFF137B955AE} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {17D47879-4848-4ADC-A9AA-CEA009CA2C0C} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2017-12-06] (AVAST Software)
Task: {1F34B24B-4D87-433C-8CA6-122EDD3DE79F} - System32\Tasks\SafeZone scheduled Autoupdate 1493245990 => C:\Program Files\AVAST Software\SZBrowser\launcher.exe [2017-08-04] (Avast Software)
Task: {2A84CF68-5A68-418E-9C27-DC135EC32E85} - System32\Tasks\googleupdatetaskmachinecore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {2BC2695E-8B0A-4AD2-AB6C-20EC1AD53AB7} - System32\Tasks\WpsKtpcntrQingTask_Bryan => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exe [2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {2BDE355D-7F79-4375-AEA9-21F5F6832290} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-09-05] (Microsoft Corporation)
Task: {325D5EEC-A3D8-4FCE-92A8-417092DCF0A5} - System32\Tasks\WpsExternal_20160804183703 => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\ksolaunch.exe [2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
Task: {3FE34152-9031-4426-AB0D-73A87CB472E3} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2016-05-09] (Hewlett-Packard)
Task: {79C9FB33-975A-4580-9897-6E8615E55720} - System32\Tasks\{486A61CF-7BE3-4D52-81C7-6AE86E41C66E} => "c:\program files (x86)\internet explorer\iexplore.exe" hxxp://ui.skype.com/ui/0/6.3.73.105.457/en/abandoninstall?page=tsWLM
Task: {79E3E16F-73E3-4D37-B7DA-975698283354} - System32\Tasks\googleupdatetaskmachineua => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {89A88E6B-9624-4C8F-9ABB-92125ED0B39A} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-08-30] (Adobe Systems Incorporated)
Task: {9E5D32EE-277C-4623-810F-C69B3A0E5978} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {AA6D2334-BA38-4774-91D4-64A432DAE773} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001Core => C:\Users\Bryan\AppData\Local\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {AAA03986-28F5-4497-A762-9DF0D1B50922} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-09-05] (Microsoft Corporation)
Task: {B3CEDE53-F48D-4FF5-A3C0-8E94190DF8DC} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-1069211171-1032678597-3133260682-1001UA => C:\Users\Bryan\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-14] (Dropbox, Inc.)
Task: {C6BFBECF-A713-4CBE-9CE3-36C96C805246} - System32\Tasks\Acer Registration Data Sending => C:\Program Files (x86)\Acer\Registration\GREG.exe [2009-08-28] (Acer Incorporated)
Task: {D40F653A-9AEC-4789-BF48-A093C01DC359} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2017-12-31] (AVAST Software)
Task: {E0B01958-B00F-4779-A383-FDA5C239721E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-05-04] (Hewlett-Packard)
Task: {EDB97BA8-9F97-4702-AA42-FF254502EAD2} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe
Task: {FDCCDC42-8A37-4C52-A163-A5AF0DEDCF96} - System32\Tasks\dropboxupdatetaskusers-1-5-21-1069211171-1032678597-3133260682-1001core => C:\Users\Bryan\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2015-06-14] (Dropbox, Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\WpsExternal_20160804183703.job => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\ksolaunch.exe
Task: C:\Windows\Tasks\WpsKtpcntrQingTask_Bryan.job => C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exeÃqing 10.1.0.5656 xxx server_url=hxxp:/kdl1.cache.wps.com/ksodl/wpscfg/client/____client____html____service____bubble.html ic_server_url=hxxp:/info.kingsoftstore.com/wpsv6internet/infos.ads
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2014-09-13 16:32 - 2015-02-03 18:21 - 000115400 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2015-02-15 01:15 - 2017-01-17 04:25 - 000117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2016-05-24 21:18 - 2016-05-24 21:27 - 000076152 _____ () C:\Windows\SysWOW64\PnkBstrA.exe
2009-04-19 07:34 - 2009-04-19 07:34 - 000625184 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
2009-04-19 07:34 - 2009-04-19 07:34 - 000070176 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nv_common.dll
2009-04-19 07:34 - 2009-04-19 07:34 - 000578080 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\SpecialCase.dll
2009-04-19 07:34 - 2009-04-19 07:34 - 000207904 _____ () C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
2016-05-21 13:12 - 2016-05-21 13:12 - 000959168 _____ () C:\Users\Bryan\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\ClientTelemetry.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000067920 _____ () c:\Program Files\AVAST Software\Avast\x64\module_lifetime.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000067984 _____ () C:\Program Files\AVAST Software\Avast\x64\dll_loader.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000236840 _____ () c:\Program Files\AVAST Software\Avast\x64\vaarclient.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000902824 _____ () C:\Program Files\AVAST Software\Avast\x64\ffl2.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000349568 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000337096 _____ () C:\Program Files\AVAST Software\Avast\x64\tasks_core.dll
2010-06-16 13:42 - 2010-06-16 13:42 - 000839680 _____ () C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe
2017-11-20 15:27 - 2017-11-20 15:27 - 041061856 _____ () C:\Program Files (x86)\Google\Drive\googledrivesync.exe
2009-08-17 23:27 - 2009-08-17 23:27 - 000629280 _____ () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
2017-12-11 23:51 - 2017-12-05 20:24 - 004063064 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.84\libglesv2.dll
2017-12-11 23:51 - 2017-12-05 20:24 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\63.0.3239.84\libegl.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000058016 _____ () C:\Program Files\AVAST Software\Avast\module_lifetime.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000057504 _____ () C:\Program Files\AVAST Software\Avast\dll_loader.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000206152 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000289272 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000196248 _____ () C:\Program Files\AVAST Software\Avast\network_notifications.dll
2017-12-31 08:50 - 2017-12-31 08:50 - 005767312 _____ () C:\Program Files\AVAST Software\Avast\defs\17123100\algo.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000745408 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000148936 _____ () C:\Program Files\AVAST Software\Avast\hns_tools.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000293944 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2018-01-03 10:02 - 2018-01-03 10:02 - 005767312 _____ () C:\Program Files\AVAST Software\Avast\defs\18010304\algo.dll
2009-02-02 16:33 - 2009-02-02 16:33 - 000460199 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll
2008-09-28 16:55 - 2008-09-28 16:55 - 001076224 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll
2017-06-26 08:22 - 2017-06-26 08:22 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2017-12-31 14:47 - 2017-12-31 14:47 - 000282560 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2017-02-15 16:58 - 2017-02-15 16:58 - 001162752 _____ () C:\Users\Bryan\AppData\Local\Facebook\Games\CefSharp.Core.dll
2017-02-15 16:58 - 2017-02-15 16:58 - 067197440 _____ () C:\Users\Bryan\AppData\Local\Facebook\Games\libcef.dll
2009-08-17 23:31 - 2009-08-17 23:31 - 000163840 _____ () C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyHook.dll
2017-12-31 14:55 - 2017-12-31 14:55 - 000088064 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\_ctypes.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000919552 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\_hashlib.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000098816 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32api.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000110080 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\pywintypes27.dll
2017-12-31 14:55 - 2017-12-31 14:55 - 000364544 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\pythoncom27.dll
2017-12-31 14:55 - 2017-12-31 14:55 - 000686080 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\unicodedata.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000320512 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32com.shell.shell.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 001177088 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\wx._core_.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000806912 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\wx._gdi_.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000816640 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\wx._windows_.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 001067520 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\wx._controls_.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000733696 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\wx._misc_.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000736256 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\pysqlite2._sqlite.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000119808 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32file.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000108544 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32security.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000007168 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\hashobjs_ext.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000017920 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\thumbnails_ext.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000082432 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\usb_ext.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000013824 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\common.time34.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000018432 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32event.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000027648 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\windows.conditional.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000017408 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\windows.winwrap.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000089088 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\windows.volumes.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000167936 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32gui.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000046080 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\_socket.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 001311744 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\_ssl.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000129536 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\_elementtree.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000127488 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\pyexpat.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000038912 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32inet.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000077824 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\wx._html2.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000036864 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\_psutil_windows.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000524248 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\windows._lib_cacheinvalidation.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000011264 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32crypt.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000218624 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\PIL._imaging.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000027648 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\_multiprocessing.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000020480 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\_yappi.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000035840 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32process.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000024064 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32pipe.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000010240 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\select.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000025600 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32pdh.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000059392 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\windows.device_monitor.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000017408 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32profile.pyd
2017-12-31 14:55 - 2017-12-31 14:55 - 000022528 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI23922\win32ts.pyd
2017-02-15 16:58 - 2017-02-15 16:58 - 000752640 _____ () C:\Users\Bryan\AppData\Local\Facebook\Games\CefSharp.BrowserSubprocess.Core.dll
2017-02-15 16:58 - 2017-02-15 16:58 - 001886208 _____ () C:\Users\Bryan\AppData\Local\Facebook\Games\libglesv2.dll
2017-02-15 16:58 - 2017-02-15 16:58 - 000078848 _____ () C:\Users\Bryan\AppData\Local\Facebook\Games\libegl.dll
2017-12-31 15:00 - 2017-12-31 15:00 - 000088064 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\_ctypes.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000919552 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\_hashlib.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000098816 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32api.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000110080 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\pywintypes27.dll
2017-12-31 15:00 - 2017-12-31 15:00 - 000364544 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\pythoncom27.dll
2017-12-31 15:00 - 2017-12-31 15:00 - 000686080 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\unicodedata.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000320512 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32com.shell.shell.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 001177088 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\wx._core_.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000806912 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\wx._gdi_.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000816640 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\wx._windows_.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 001067520 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\wx._controls_.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000733696 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\wx._misc_.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000736256 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\pysqlite2._sqlite.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000119808 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32file.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000108544 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32security.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000007168 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\hashobjs_ext.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000017920 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\thumbnails_ext.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000082432 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\usb_ext.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000013824 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\common.time34.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000018432 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32event.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000027648 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\windows.conditional.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000017408 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\windows.winwrap.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000089088 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\windows.volumes.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000167936 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32gui.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000046080 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\_socket.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 001311744 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\_ssl.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000129536 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\_elementtree.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000127488 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\pyexpat.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000038912 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32inet.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000077824 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\wx._html2.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000036864 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\_psutil_windows.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000524248 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\windows._lib_cacheinvalidation.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000011264 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32crypt.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000218624 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\PIL._imaging.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000027648 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\_multiprocessing.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000020480 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\_yappi.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000035840 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32process.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000024064 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32pipe.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000010240 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\select.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000025600 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32pdh.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000059392 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\windows.device_monitor.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000017408 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32profile.pyd
2017-12-31 15:00 - 2017-12-31 15:00 - 000022528 _____ () C:\Users\Bryan\AppData\Local\Temp\_MEI59562\win32ts.pyd
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\.DEFAULT\…\007guard.com -> install.007guard.com
IE restricted site: HKU\.DEFAULT\…\008i.com -> 008i.com
IE restricted site: HKU\.DEFAULT\…\008k.com -> www.008k.com
IE restricted site: HKU\.DEFAULT\…\00hq.com -> www.00hq.com
IE restricted site: HKU\.DEFAULT\…\010402.com -> 010402.com
IE restricted site: HKU\.DEFAULT\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\.DEFAULT\…\0scan.com -> www.0scan.com
IE restricted site: HKU\.DEFAULT\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\.DEFAULT\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\.DEFAULT\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\.DEFAULT\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\.DEFAULT\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\.DEFAULT\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\.DEFAULT\…\10sek.com -> www.10sek.com
IE restricted site: HKU\.DEFAULT\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\.DEFAULT\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\.DEFAULT\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\.DEFAULT\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\.DEFAULT\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\.DEFAULT\…\123simsen.com -> www.123simsen.com
There are 7865 more sites.
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\007guard.com -> install.007guard.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\008k.com -> www.008k.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\00hq.com -> www.00hq.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\010402.com -> 010402.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\032439.com -> 80gw6ry3i3x3qbrkwhxhw.032439.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\0scan.com -> www.0scan.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1-2005-search.com -> www.1-2005-search.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1-domains-registrations.com -> www.1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1000gratisproben.com -> www.1000gratisproben.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\1001namen.com -> www.1001namen.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\100888290cs.com -> mir.100888290cs.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\100sexlinks.com -> www.100sexlinks.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\10sek.com -> www.10sek.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\12-26.net -> user1.12-26.net
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\12-27.net -> user1.12-27.net
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123fporn.info -> www.123fporn.info
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123haustiereundmehr.com -> www.123haustiereundmehr.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123moviedownload.com -> www.123moviedownload.com
IE restricted site: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\123simsen.com -> www.123simsen.com
There are 7865 more sites.
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 18:34 - 2017-10-19 17:23 - 000498626 _____ C:\Windows\system32\Drivers\etc\hosts
0.0.0.0 fr.a2dfp.net
0.0.0.0 m.fr.a2dfp.net
0.0.0.0 mfr.a2dfp.net
0.0.0.0 ad.a8.net
0.0.0.0 asy.a8ww.net
0.0.0.0 static.a-ads.com
0.0.0.0 abcstats.com
0.0.0.0 a.abv.bg
0.0.0.0 adserver.abv.bg
0.0.0.0 adv.abv.bg
0.0.0.0 bimg.abv.bg
0.0.0.0 ca.abv.bg
0.0.0.0 track.acclaimnetwork.com
0.0.0.0 accuserveadsystem.com
0.0.0.0 www.accuserveadsystem.com
0.0.0.0 achmedia.com
0.0.0.0 csh.actiondesk.com
0.0.0.0 ads.activepower.net
0.0.0.0 ad.activesolutions.cz
0.0.0.0 app.activetrail.com
0.0.0.0 traffic.acwebconnecting.com
0.0.0.0 office.ad1.ru
0.0.0.0 cms.ad2click.nl
0.0.0.0 ad2games.com
0.0.0.0 content.ad20.net
0.0.0.0 core.ad20.net
0.0.0.0 banner.ad.nu
0.0.0.0 adadvisor.net
0.0.0.0 tag1.adaptiveads.com
0.0.0.0 www.adbanner.ro
There are 13118 more lines.
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\Services: AdobeARMservice => 3
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{8C3230A9-3B37-4AB0-BF07-F92E56E6D000}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [UDP Query User{C5ECB86D-D992-4133-85A8-E2375ADBE977}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [{C1131851-AE0D-47EC-985D-3B54FFB37410}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{A2186EEF-31C0-4771-8F5C-20057A62313F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{1F0A2EEF-2338-4C46-B282-735BCF6E757B}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [UDP Query User{EEF57E84-7427-4683-9F0A-911AF23E417E}C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp deskjet 2540 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [{B3DA051D-830C-4383-97B3-86C0DDE059B8}] => (Allow) C:\Users\Bryan\Downloads\solutoinstaller.exe
FirewallRules: [{012249DF-E899-4E68-ADA6-4099377F6DD7}] => (Allow) C:\Users\Bryan\Downloads\solutoinstaller.exe
FirewallRules: [{044001A0-E716-4D0D-81B1-70E9FD015F95}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{9283772B-511B-4821-B133-BED4BF4AB2AC}] => (Allow) LPort=2869
FirewallRules: [{DCDC16A6-6A0C-4C05-AA19-AFE390FD2405}] => (Allow) LPort=1900
FirewallRules: [{2260B718-D95B-4B4D-95FA-609C9FBB7636}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{695FD75E-C711-464D-BAB3-B87FFB5CB693}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{39F77321-AFFB-49F6-9E20-BB09C6108758}] => (Allow) C:\Windows\SysWOW64\PnkBstrA.exe
FirewallRules: [{5FE532DA-7DCE-4498-B1D7-2EA7839AA5AE}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{8C3A945E-2263-4351-957B-7DB970A38D0C}] => (Allow) C:\Windows\SysWOW64\PnkBstrB.exe
FirewallRules: [{984BB3F6-E964-4B8E-9BA2-E6A1510F0A5E}] => (Allow) C:\Program Files\HP\HP ENVY 4510 series\Bin\DeviceSetup.exe
FirewallRules: [{3BDD8F22-9012-4F6D-9C1A-BED6890F1F1F}] => (Allow) LPort=5357
FirewallRules: [{C7ED9287-EAE5-4029-85CD-CBC94782DC03}] => (Allow) C:\Program Files\HP\HP ENVY 4510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{A00F1B2E-031B-480F-AE27-B72AF2D5E08A}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
FirewallRules: [{AEF819C4-15BE-4827-A80D-FEFD9DAD7A9A}] => (Allow) C:\Program Files (x86)\GlassWire\GWCtlSrv.exe
FirewallRules: [{B326A035-C568-49CB-9E50-76E0EFF2B618}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\3.55.2393.609_0\SZBrowser.exe
FirewallRules: [{1BB3A128-9ED2-4075-8B9B-054202B01FD9}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909\SZBrowser.exe
FirewallRules: [{FE3FEE4A-20A0-4D61-9837-1918F395CFD5}] => (Allow) C:\Program Files\AVAST Software\SZBrowser\4.58.2552.909_0\SZBrowser.exe
FirewallRules: [{848EC14F-D659-461D-BB25-938940165944}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
11-10-2017 02:00:50 Windows Update
15-11-2017 03:04:09 Windows Update
29-11-2017 03:00:18 Windows Update
14-12-2017 03:01:26 Windows Update
==================== Faulty Device Manager Devices =============
Name: Teredo Tunneling Pseudo-Interface
Description: Microsoft Teredo Tunneling Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: tunnel
Problem: : This device cannot start. (Code10)
Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.
On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/27/2017 11:49:52 AM) (Source: ESENT) (EventID: 455) (User: )
Description: DllHost (5124) WebCacheLocal: Error -1032 (0xfffffbf8) occurred while opening logfile C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.log.
Error: (12/27/2017 11:49:52 AM) (Source: ESENT) (EventID: 489) (User: )
Description: DllHost (5124) WebCacheLocal: An attempt to open the file "C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read only access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).
Error: (12/27/2017 11:49:42 AM) (Source: ESENT) (EventID: 455) (User: )
Description: DllHost (5124) WebCacheLocal: Error -1032 (0xfffffbf8) occurred while opening logfile C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.log.
Error: (12/27/2017 11:49:42 AM) (Source: ESENT) (EventID: 489) (User: )
Description: DllHost (5124) WebCacheLocal: An attempt to open the file "C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read only access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).
Error: (12/27/2017 11:49:32 AM) (Source: ESENT) (EventID: 455) (User: )
Description: DllHost (5124) WebCacheLocal: Error -1032 (0xfffffbf8) occurred while opening logfile C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.log.
Error: (12/27/2017 11:49:31 AM) (Source: ESENT) (EventID: 489) (User: )
Description: DllHost (5124) WebCacheLocal: An attempt to open the file "C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read only access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).
Error: (12/27/2017 11:49:21 AM) (Source: ESENT) (EventID: 455) (User: )
Description: DllHost (5124) WebCacheLocal: Error -1032 (0xfffffbf8) occurred while opening logfile C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.log.
Error: (12/27/2017 11:49:21 AM) (Source: ESENT) (EventID: 489) (User: )
Description: DllHost (5124) WebCacheLocal: An attempt to open the file "C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.log" for read only access failed with system error 32 (0x00000020): "The process cannot access the file because it is being used by another process. ". The open file operation will fail with error -1032 (0xfffffbf8).
Error: (12/14/2017 03:01:27 AM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine ConvertStringSidToSid(S-1-5-21-1069211171-1032678597-3133260682-1003.bak). hr = 0x80070539, The security ID structure is invalid.
.
Operation:
OnIdentify event
Gathering Writer Data
Context:
Execution Context: Shadow Copy Optimization Writer
Writer Class Id: {4dc3bdd4-ab48-4d07-adb0-3bee2926fd7f}
Writer Name: Shadow Copy Optimization Writer
Writer Instance ID: {b7c97424-9d40-4af2-bb8f-154b7b849709}
Error: (12/10/2017 08:56:05 AM) (Source: ESENT) (EventID: 455) (User: )
Description: taskhost (2212) WebCacheLocal: Error -1032 (0xfffffbf8) occurred while opening logfile C:\Users\Bryan\AppData\Local\Microsoft\Windows\WebCache\V01.log.
System errors:
=============
Error: (01/02/2018 10:51:00 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.
Error: (01/02/2018 08:11:24 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.
Error: (12/31/2017 05:43:01 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.
Error: (12/31/2017 02:57:45 PM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Windows Update service hung on starting.
Error: (12/31/2017 02:55:43 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.
Error: (12/30/2017 09:00:30 AM) (Source: DCOM) (EventID: 10005) (User: )
Description: DCOM got error "1053" attempting to start the service WSearch with arguments "" in order to run the server:
{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Error: (12/30/2017 09:00:29 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Windows Search service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
Error: (12/30/2017 09:00:29 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.
Error: (12/30/2017 08:59:58 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).
Error: (12/30/2017 08:59:09 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The NTI IScheduleSvc service failed to start due to the following error:
The service did not respond to the start or control request in a timely fashion.
==================== Memory info ===========================
Processor: AMD Athlon™ II X2 215 Processor
Percentage of memory in use: 65%
Total physical RAM: 3838.55 MB
Available physical RAM: 1338.69 MB
Total Virtual: 7675.29 MB
Available Virtual: 3853.63 MB
==================== Drives ================================
Drive c: (Acer) (Fixed) (Total:698.63 GB) (Free:592.51 GB) NTFS ==>[drive with boot components (obtained from BCD)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 698.6 GB) (Disk ID: 6E286E28)
Partition 1: (Active) - (Size=698.6 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02.01.2018
Ran by [removed] (administrator) on ARTADI-PC (03-01-2018 10:14:33)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GregHSRW.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\wtoolex\wpsupdatesvr.exe
(NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe
() C:\Windows\SysWOW64\PnkBstrA.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
() C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe
(Greenshot) C:\Program Files\Greenshot\Greenshot.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 4510 series\Bin\ScanToPCActivationApp.exe
() C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe
(Flux Software LLC) C:\Users\Bryan\AppData\Local\FluxSoftware\Flux\flux.exe
(Hewlett-Packard Development Company, LP) C:\Program Files\HP\HP ENVY 4510 series\Bin\HPNetworkCommunicatorCom.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Facebook) C:\Users\Bryan\AppData\Local\Facebook\Games\FacebookGameroom.exe
() C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(The CefSharp Authors) C:\Users\Bryan\AppData\Local\Facebook\Games\Facebook Gameroom Browser.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
() C:\Program Files (x86)\Google\Drive\googledrivesync.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Zhuhai Kingsoft Office Software Co.,Ltd) C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\office6\ktpcntr.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [NvBackend] => C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvBackend.exe [2585744 2015-01-15] (NVIDIA Corporation)
HKLM\…\Run: [mwlDaemon] => C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-09-10] (Egis Technology Inc.)
HKLM\…\Run: [Greenshot] => C:\Program Files\Greenshot\Greenshot.exe [552368 2016-12-15] (Greenshot)
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [246120 2017-12-31] (AVAST Software)
HKLM\…\Run: [BoxSync] => C:\Program Files\Box\Box Sync\BoxSync.exe [5088872 2017-08-07] (Box, Inc.)
HKLM-x32\…\Run: [Hotkey Utility] => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [629280 2009-08-17] ()
HKLM-x32\…\Run: [] => [X]
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [Google Update] => C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2017-11-13] (Google Inc.)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [9532120 2017-04-10] (Piriform Ltd)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [HP ENVY 4510 series (NET)] => C:\Program Files\HP\HP ENVY 4510 series\Bin\ScanToPCActivationApp.exe [3651080 2015-03-09] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [OpenDNS Updater] => C:\Program Files (x86)\OpenDNS Updater\OpenDNSUpdater.exe [839680 2010-06-16] ()
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [f.lux] => C:\Users\Bryan\AppData\Local\FluxSoftware\Flux\flux.exe [1017224 2013-10-23] (Flux Software LLC)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [GoogleDriveSync] => C:\Program Files (x86)\Google\Drive\googledrivesync.exe [41061856 2017-11-20] ()
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\…\Run: [GoogleChromeAutoLaunch_3400C23A6B141E1ABEFD3ADCF3EF95F3] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1592664 2017-12-05] (Google Inc.)
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-13] (Microsoft Corporation)
Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2016-05-06]
ShortcutTarget: Dropbox.lnk -> C:\Users\Bryan\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Bryan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Gameroom.lnk [2017-04-17]
ShortcutTarget: Facebook Gameroom.lnk -> C:\Users\Bryan\AppData\Local\Facebook\Games\FacebookGameroom.exe (Facebook)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{C9178436-B2FA-4276-BD10-820A7192F6DA}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Internet Explorer:
==================
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://duckduckgo.com/
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver;=6&ar;=msnhome
HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
SearchScopes: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> {1711FC25-F05A-40CE-B859-A0C1CF01FD18} URL = hxxps://us.search.yahoo.com/yhs/search?hspart=omr&hsimp;=yhs-001&type;=86311297¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC0XAR2xMZ6ScXcT7%2F%2FIjG3qdZgIFLDCDI8cWoMbH2hBNJ4lPjATYuWoH3FHeADhXVYkEaeB5T2sLET4h6dhpGL1mpSZr%2B5Y9hTzsHuxQGqCMPbk34SFCNgTnf0k2mYTmRkSrl1Hz7IO3PUlsfqbOE1JX42QG070bbBT8TgxgjKo1lsQ4he2WYdHdvQo8Fd%2F29BsM4nW2jLEG6ySn5wUlCeQGMCT0AuoI4IQSYc2cUnwhw%3D%3D&p;={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-11-21] (Microsoft Corporation)
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2017-11-10] (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2017-11-21] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-11-21] (Microsoft Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2017-11-10] (AVAST Software)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-28] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2017-11-21] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
Toolbar: HKU\S-1-5-21-1069211171-1032678597-3133260682-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-07-18] (Microsoft Corporation)
FireFox:
========
FF ProfilePath: C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default [2017-10-26]
FF Homepage: Mozilla\Firefox\Profiles\MrxppWE4.default -> hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp;=yhs-001&type;=86311297¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC0XAR2xMZ6ScXcT7%2F%2FIjG3qQ9bILO2aZNrJVu9Ujcp29BJYCzLOzAw6%2FiledhFfewtiOItkOc01fWj0xzRY2NioMWO%2B910zAGVJHrnANVEay7eJPWbzTLZCKoUjmmO0g67Bf0KG%2FwAvPTt2JBg39T0kEiuxmrAGwcTC7EdSMf49jOmM9pBioCju1qM%2B0lP2urdPu9rZGMsQN8JEDQxnImjJ26UICoOXPDvowCoGOt7sXg%3D%3D
FF NewTab: Mozilla\Firefox\Profiles\MrxppWE4.default -> hxxps://us.search.yahoo.com/yhs/web?hspart=omr&hsimp;=yhs-001&type;=86311297¶m1=y6bdVFVIsvuYsgEClQfz8HyFH9tZCHsOZFHNP%2BYwJC0XAR2xMZ6ScXcT7%2F%2FIjG3qMsvLILeyT3DnNR7seDal0p9tPvFhRiHS9BL6toINpXQYH%2FEIUoAVX8JLUeUYIvmtGIkIBHG5iLiUr2swKq%2Bz2IoumZ%2FrsxubO4rCnxYy8vxPJQRfCGD9IkdP%2Fz6%2BHpLMrlfI93Fs%2BboEA3Cz6oVWoLHAckMXtazUCC5b5lRsln5A9L8PsaBCU0v1XaQDhYxJeVhe6xXdHLceaHY42%2B2WRw%3D%3D
FF Extension: (Avira Browser Safety) - C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default\Extensions\[removed] [2015-09-21] [Legacy] [not signed]
FF SearchPlugin: C:\Users\Bryan\AppData\Roaming\Mozilla\Firefox\Profiles\MrxppWE4.default\searchplugins\Yahoo powered search.xml [2017-07-17]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_26_0_0_151.dll [2017-08-30] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_26_0_0_151.dll [2017-08-30] ()
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit PhantomPDF Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit PhantomPDF\plugins\npFoxitPhantomPDFPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xdp -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.xfdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll [No File]
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-10-13] (Google, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2015-02-15] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll [2015-02-03] (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll [2015-02-03] (NVIDIA Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1069211171-1032678597-3133260682-1001: @tools.google.com/Google Update;version=3 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
FF Plugin HKU\S-1-5-21-1069211171-1032678597-3133260682-1001: @tools.google.com/Google Update;version=9 -> C:\Users\Bryan\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.)
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com","hxxp://xfinity.comcast.net/?cid=insDate09172012","","file:///usr/share/doc/home.htm"
CHR DefaultSearchURL: Default -> hxxps://duckduckgo.com/?q={searchTerms}
CHR DefaultSearchKeyword: Default -> duckduckgo.com
CHR DefaultSuggestURL: Default -> hxxps://duckduckgo.com/ac/?q={searchTerms}&type;=list
CHR Profile: C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default [2018-01-03]
CHR Extension: (Slides) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-14]
CHR Extension: (Docs) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-14]
CHR Extension: (Google Drive) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-21]
CHR Extension: (WOT: Web of Trust, Website Reputation Ratings) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2017-12-30]
CHR Extension: (DuckDuckGo Search) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkdgflcldnnnapblkhphbgpggdiikppg [2017-05-06]
CHR Extension: (YouTube) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-09-25]
CHR Extension: (uBlock Origin) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpalhdlnbpafiamejdnhcphjbkeiagm [2017-12-26]
CHR Extension: (Google Search) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-27]
CHR Extension: (Dropbox for Gmail) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpdmhfocilnekecfjgimjdeckachfbec [2017-03-16]
CHR Extension: (Avast Passwords) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2017-12-26]
CHR Extension: (Sheets) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-14]
CHR Extension: (Avira Browser Safety) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\flliilndjeohchalpbbcdekjklbdgfkk [2017-06-09]
CHR Extension: (Google Docs Offline) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-15]
CHR Extension: (AdBlock) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-12-14]
CHR Extension: (Avast Online Security) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2017-10-09]
CHR Extension: (Privacy Cleaner) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\liiikhhbkpmpomjmdofandjmdgapiahi [2017-11-17]
CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2017-07-17]
CHR Extension: (Contest Lobby - DraftKings) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\loelnclfphlfeopbkllhhjjkdnnioacd [2016-11-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-23]
CHR Extension: (Gmail) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-28]
CHR Extension: (Chrome Media Router) - C:\Users\Bryan\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-12-26]
CHR HKLM\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1069211171-1032678597-3133260682-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [flliilndjeohchalpbbcdekjklbdgfkk] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7538536 2017-12-31] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [301168 2017-12-31] (AVAST Software)
S3 BoxSyncUpdateService; C:\Program Files\Box\Box Sync\SyncUpdaterService.exe [36680 2017-08-07] (Box, Inc.)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058416 2017-09-05] (Microsoft Corporation)
R2 ForceWare Intelligent Application Manager (IAM); C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe [625184 2009-04-19] ()
S3 GfExperienceService; C:\Program Files\NVIDIA Corporation\GeForce Experience Service\GfExperienceService.exe [1148560 2015-01-15] (NVIDIA Corporation)
S3 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [28552 2016-04-26] (Hewlett-Packard Company)
R2 Kingsoft_WPS_UpdateService; C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\10.1.0.5656\wtoolex\wpsupdatesvr.exe [133376 2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
S2 LiveUpdateSvc; C:\Program Files (x86)\IObit\LiveUpdate\LiveUpdate.exe [3046688 2016-07-29] (IObit)
S3 MF NTFS Monitor; C:\Users\Bryan\AppData\Local\MediaFire Desktop\MFUsnMonitorService.exe [456504 2015-03-23] ()
S3 MWLService; C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe [305448 2009-09-10] (Egis Technology Inc.)
R2 nSvcIp; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe [207904 2009-04-19] ()
R2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1706128 2015-01-15] (NVIDIA Corporation)
S3 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21833360 2015-01-15] (NVIDIA Corporation)
R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76152 2016-05-24] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
S3 wpscloudsvr; C:\Users\Bryan\AppData\Local\Kingsoft\WPS Office\wpscloudsvr.exe [162048 2016-08-04] (Zhuhai Kingsoft Office Software Co.,Ltd)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 AndnetBus; C:\Windows\System32\DRIVERS\lgandnetbus64.sys [30208 2016-08-31] (LG Electronics Inc.)
S3 AndNetDiag; C:\Windows\System32\DRIVERS\lgandnetdiag64.sys [30720 2016-08-24] (LG Electronics Inc.)
S3 ANDNetModem; C:\Windows\System32\DRIVERS\lgandnetmodem64.sys [37376 2016-08-24] (LG Electronics Inc.)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [185096 2017-12-31] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdrivera.sys [321512 2017-12-31] (AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidsha.sys [199448 2017-12-31] (AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswbloga.sys [343768 2017-12-31] (AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbuniva.sys [57696 2017-12-31] (AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [149344 2017-12-31] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [46976 2017-12-31] (AVAST Software)
R1 aswKbd; C:\Windows\system32\drivers\aswKbd.sys [41832 2017-08-31] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [146664 2017-12-31] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [110336 2017-12-31] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [84384 2017-12-31] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [1025176 2017-12-31] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [457400 2017-12-31] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [204456 2017-12-31] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [358672 2017-12-31] (AVAST Software)
S3 DigiartyVirtualCDBus; C:\Windows\System32\drivers\DigiartyVirtualCDBus.sys [276256 2017-10-26] (Digiarty Software, Inc.)
U5 FontCache3.0.0.0; C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe [42856 2010-11-04] (Microsoft Corporation)
R3 hsCDFiDrv; C:\Windows\System32\DRIVERS\hsCDFiDrv.sys [7168 2010-07-16] ()
S3 MDA_NTDRV; C:\Windows\system32\MDA_NTDRV.sys [21208 2013-02-25] ()
R2 mfmonitor; C:\Windows\System32\DRIVERS\mfmonitor_x64.sys [20696 2015-03-23] (Windows (R) Win 7 DDK provider)
R2 npf; C:\Windows\System32\drivers\npf.sys [36600 2015-11-15] (Riverbed Technology, Inc.)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [19600 2015-01-15] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [38032 2014-11-22] (NVIDIA Corporation)
S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2014-11-28] (Secunia)
R0 pwdrvio; C:\Windows\System32\pwdrvio.sys [19152 2013-09-30] ()
S3 pwdspio; C:\Windows\system32\pwdspio.sys [12504 2013-09-30] ()
R1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [92848 2016-08-19] ()
R1 Uim_DEVIM; C:\Windows\System32\DRIVERS\uim_devim.sys [26800 2016-08-19] ()
R1 Uim_IM; C:\Windows\System32\DRIVERS\uim_im.sys [484528 2016-08-19] ()
S3 uvhid; C:\Windows\System32\DRIVERS\uvhid.sys [25592 2015-07-25] (Windows (R) Win 7 DDK provider)
R1 VBoxNetAdp; C:\Windows\System32\DRIVERS\VBoxNetAdp6.sys [117768 2015-08-13] (Oracle Corporation)
R1 VBoxNetLwf; C:\Windows\System32\DRIVERS\VBoxNetLwf.sys [146072 2015-08-13] (Oracle Corporation)
S3 andnetadb; System32\Drivers\lgandnetadb.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-01-03 10:14 - 2018-01-03 10:15 - 000026221 _____ C:\Users\Bryan\Desktop\FRST.txt
2018-01-03 10:13 - 2018-01-03 10:13 - 002393088 _____ (Farbar) C:\Users\Bryan\Desktop\FRST64.exe
2017-12-31 14:53 - 2017-12-31 14:53 - 000000000 ____D C:\ProgramData\SWCUTemp
2017-12-31 14:49 - 2017-12-31 14:49 - 000045704 _____ () C:\Windows\system32\Drivers\staport.sys
2017-12-31 14:49 - 2017-12-31 14:47 - 000149344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2017-12-31 14:48 - 2017-12-31 14:48 - 000365680 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2017-12-22 19:12 - 2017-12-22 19:12 - 004581992 _____ (Bad Wolf Software ) C:\Users\Bryan\Downloads\PageFour.exe
2017-12-13 07:18 - 2017-11-16 20:23 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-12-13 07:18 - 2017-11-14 17:27 - 000395968 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2017-12-13 07:18 - 2017-11-14 16:36 - 000347336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2017-12-13 07:18 - 2017-11-13 19:57 - 025731072 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-12-13 07:18 - 2017-11-13 19:43 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2017-12-13 07:18 - 2017-11-13 19:43 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2017-12-13 07:18 - 2017-11-13 19:32 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2017-12-13 07:18 - 2017-11-13 19:31 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2017-12-13 07:18 - 2017-11-13 19:31 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2017-12-13 07:18 - 2017-11-13 19:30 - 000577024 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-12-13 07:18 - 2017-11-13 19:30 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2017-12-13 07:18 - 2017-11-13 19:30 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2017-12-13 07:18 - 2017-11-13 19:25 - 005925888 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-12-13 07:18 - 2017-11-13 19:24 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2017-12-13 07:18 - 2017-11-13 19:24 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2017-12-13 07:18 - 2017-11-13 19:21 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2017-12-13 07:18 - 2017-11-13 19:20 - 000817152 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-12-13 07:18 - 2017-11-13 19:20 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2017-12-13 07:18 - 2017-11-13 19:20 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2017-12-13 07:18 - 2017-11-13 19:20 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2017-12-13 07:18 - 2017-11-13 19:15 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2017-12-13 07:18 - 2017-11-13 19:12 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2017-12-13 07:18 - 2017-11-13 19:06 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2017-12-13 07:18 - 2017-11-13 19:06 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2017-12-13 07:18 - 2017-11-13 19:05 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2017-12-13 07:18 - 2017-11-13 19:03 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2017-12-13 07:18 - 2017-11-13 19:02 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2017-12-13 07:18 - 2017-11-13 19:00 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2017-12-13 07:18 - 2017-11-13 18:59 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2017-12-13 07:18 - 2017-11-13 18:51 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2017-12-13 07:18 - 2017-11-13 18:48 - 015267328 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-12-13 07:18 - 2017-11-13 18:48 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-12-13 07:18 - 2017-11-13 18:48 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2017-12-13 07:18 - 2017-11-13 18:47 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2017-12-13 07:18 - 2017-11-13 18:46 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2017-12-13 07:18 - 2017-11-13 18:39 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-12-13 07:18 - 2017-11-13 18:27 - 001544192 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-12-13 07:18 - 2017-11-13 18:16 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-12-13 07:18 - 2017-11-13 17:37 - 013679616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-12-13 07:18 - 2017-11-13 17:15 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2017-12-13 07:18 - 2017-11-13 17:15 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2017-12-13 07:18 - 2017-11-13 17:15 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2017-12-13 07:18 - 2017-11-13 17:10 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-12-13 07:18 - 2017-11-13 16:32 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-12-13 07:18 - 2017-11-13 16:31 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2017-12-13 07:18 - 2017-11-07 12:56 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2017-12-13 07:18 - 2017-11-07 12:46 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2017-12-13 07:18 - 2017-11-07 12:46 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2017-12-13 07:18 - 2017-11-07 12:46 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2017-12-13 07:18 - 2017-11-07 12:44 - 002293760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2017-12-13 07:18 - 2017-11-07 12:41 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2017-12-13 07:18 - 2017-11-07 12:41 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2017-12-13 07:18 - 2017-11-07 12:40 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2017-12-13 07:18 - 2017-11-07 12:39 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-12-13 07:18 - 2017-11-07 12:38 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2017-12-13 07:18 - 2017-11-07 12:38 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2017-12-13 07:18 - 2017-11-07 12:29 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2017-12-13 07:18 - 2017-11-07 12:28 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2017-12-13 07:18 - 2017-11-07 12:28 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2017-12-13 07:18 - 2017-11-07 12:27 - 004509696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-12-13 07:18 - 2017-11-07 12:26 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2017-12-13 07:18 - 2017-11-07 12:24 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2017-12-13 07:18 - 2017-11-07 12:19 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2017-12-13 07:18 - 2017-11-07 12:18 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-12-13 07:18 - 2017-11-07 12:17 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2017-12-13 07:18 - 2017-11-07 12:17 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2017-12-13 07:18 - 2017-11-07 12:04 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-12-13 07:18 - 2017-11-07 12:01 - 001313280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-12-13 07:18 - 2017-11-07 11:58 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-12-13 07:18 - 2017-11-07 08:31 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2017-12-13 07:18 - 2017-11-07 08:13 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2017-12-13 07:18 - 2017-11-04 07:31 - 000194048 _____ (Microsoft Corporation) C:\Windows\system32\itircl.dll
2017-12-13 07:18 - 2017-11-04 07:31 - 000170496 _____ (Microsoft Corporation) C:\Windows\system32\itss.dll
2017-12-13 07:18 - 2017-11-04 07:10 - 000158720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itircl.dll
2017-12-13 07:18 - 2017-11-04 07:10 - 000142336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\itss.dll
2017-12-13 07:18 - 2017-11-02 08:55 - 000281600 _____ (Microsoft Corporation) C:\Windows\system32\iprtrmgr.dll
2017-12-13 07:18 - 2017-11-02 08:55 - 000138240 _____ (Microsoft Corporation) C:\Windows\system32\rtm.dll
2017-12-13 07:18 - 2017-11-02 08:55 - 000097792 _____ (Microsoft Corporation) C:\Windows\system32\mprdim.dll
2017-12-13 07:18 - 2017-11-02 08:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\iprtprio.dll
2017-12-13 07:18 - 2017-11-02 07:11 - 000271360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtrmgr.dll
2017-12-13 07:18 - 2017-11-02 07:11 - 000115200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rtm.dll
2017-12-13 07:18 - 2017-11-02 07:11 - 000075264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mprdim.dll
2017-12-13 07:18 - 2017-11-02 06:56 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iprtprio.dll
2017-12-13 07:18 - 2017-10-16 15:04 - 001001984 _____ (Microsoft Corporation) C:\Windows\system32\gpedit.dll
2017-12-13 07:18 - 2017-10-16 14:46 - 000953344 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gpedit.dll
2017-12-13 07:18 - 2017-10-11 16:20 - 000317440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdbss.sys
2017-12-06 13:05 - 2017-12-06 13:05 - 000000000 ____D C:\Program Files\Common Files\Avast Software
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-01-03 10:15 - 2009-07-13 20:45 - 000018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-01-03 10:15 - 2009-07-13 20:45 - 000018736 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-01-03 10:14 - 2017-04-20 21:24 - 000000000 ____D C:\FRST
2018-01-03 10:01 - 2016-08-04 17:37 - 000000706 _____ C:\Windows\Tasks\WpsKtpcntrQingTask_Bryan.job
2018-01-03 10:01 - 2016-08-04 17:37 - 000000412 _____ C:\Windows\Tasks\WpsExternal_20160804183703.job
2018-01-01 16:34 - 2017-04-26 14:30 - 000004172 _____ C:\Windows\System32\Tasks\Avast Emergency Update
2017-12-31 15:00 - 2017-07-17 09:27 - 000000000 ___RD C:\Users\Bryan\Google Drive
2017-12-31 14:52 - 2014-09-12 18:01 - 000000000 ____D C:\ProgramData\NVIDIA
2017-12-31 14:52 - 2009-07-13 21:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-12-31 14:48 - 2017-11-10 13:05 - 000185096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2017-12-31 14:48 - 2017-04-26 14:29 - 000457400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2017-12-31 14:48 - 2017-04-26 14:29 - 000358672 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2017-12-31 14:48 - 2017-04-26 14:29 - 000204456 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2017-12-31 14:48 - 2017-04-26 14:29 - 000146664 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2017-12-31 14:48 - 2017-04-26 14:29 - 000110336 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2017-12-31 14:48 - 2017-04-26 14:29 - 000084384 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2017-12-31 14:48 - 2017-04-26 14:29 - 000046976 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2017-12-31 14:47 - 2017-04-26 14:29 - 001025176 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2017-12-31 14:47 - 2017-04-26 14:29 - 000343768 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbloga.sys
2017-12-31 14:47 - 2017-04-26 14:29 - 000321512 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdrivera.sys
2017-12-31 14:47 - 2017-04-26 14:29 - 000199448 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsha.sys
2017-12-31 14:47 - 2017-04-26 14:29 - 000057696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbuniva.sys
2017-12-30 16:02 - 2015-02-18 13:36 - 000000000 ____D C:\Users\Bryan\AppData\Local\PokerStars
2017-12-18 15:29 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\rescache
2017-12-14 09:19 - 2016-12-19 19:25 - 000000000 ____D C:\Users\Bryan\AppData\Local\Greenshot
2017-12-14 09:15 - 2017-09-06 11:13 - 000374816 _____ C:\Windows\system32\FNTCACHE.DAT
2017-12-14 09:12 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\SysWOW64\Setup
2017-12-14 09:12 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\system32\Setup
2017-12-14 03:16 - 2014-09-12 20:01 - 000000000 ____D C:\Windows\system32\MRT
2017-12-14 03:04 - 2017-10-11 02:08 - 133326408 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2017-12-14 03:03 - 2014-09-12 20:01 - 133326408 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-12-11 23:51 - 2014-09-12 19:37 - 000002199 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-12-08 20:35 - 2017-07-17 09:15 - 000002046 _____ C:\Users\Public\Desktop\Google Slides.lnk
2017-12-08 20:35 - 2017-07-17 09:15 - 000002044 _____ C:\Users\Public\Desktop\Google Sheets.lnk
2017-12-08 20:35 - 2017-07-17 09:15 - 000002034 _____ C:\Users\Public\Desktop\Google Docs.lnk
2017-12-08 20:35 - 2017-07-17 09:15 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Backup and Sync from Google
2017-12-06 13:05 - 2017-04-26 14:30 - 000000000 ____D C:\Windows\System32\Tasks\AVAST Software
Some files in TEMP:
====================
2017-11-17 09:52 - 2017-11-01 09:08 - 000863696 _____ (Malwarebytes) C:\Users\Bryan\AppData\Local\Temp\mb-clean.exe
2017-11-17 09:52 - 2017-11-17 02:06 - 078346672 _____ (Malwarebytes ) C:\Users\Bryan\AppData\Local\Temp\mb3-setup-consumer-3.3.1.2183.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-12-29 18:02
==================== End of FRST.txt ============================