This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

firefox seems hijacked [Closed]

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

 

I am helping a friend with her computer which apparently has been infected with something. The symptoms are, that while browsing in firefox, then from time to time, a new tab opens with unwanted pages - typical porn- or datingsites.

 

I cant really find any system in it, but there is no doubt about that it must be infected with something.

 

I have tried to execute the tools aswMBR and FRST64 as instructed, but unfortunately I only managed to get reports from FRST64, as aswMBR causes the computer to crash. I also tried to run aswMBR from safemode, but the result was the same.

 

It might be worth to mention that I am an experienced software engineer, so you dont need to explain things extremely detailed.

 

 

Here follows the logs from FRST64:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 27.01.2018
Ran by [removed] (administrator) on BODIL (30-01-2018 19:18:28)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 10 Home Version 1709 16299.192 (X64) Language: Dansk (Danmark)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Garmin Ltd. or its subsidiaries) C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Intel Corporation) C:\Windows\System32\igfxEM.exe
(Intel Corporation) C:\Windows\System32\igfxHK.exe
(Intel Corporation) C:\Windows\System32\igfxTray.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
() C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkypeHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\backgroundTaskHost.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
(Acer) C:\Program Files (x86)\Acer Remote\ArcServer.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(CyberLink) C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Antivirus\AVGUI.exe
(WildTangent, Inc.) C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
(Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [630168 2017-09-29] (Microsoft Corporation)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12921488 2012-07-02] (Realtek Semiconductor)
HKLM\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-10-31] (AVG Technologies CZ, s.r.o.)
HKLM\…\Run: [AVGUI.exe] => C:\Program Files (x86)\AVG\Antivirus\AvLaunch.exe [295512 2018-01-05] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [239592 2017-10-31] (AVG Technologies CZ, s.r.o.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-09-05] (Oracle Corporation)
HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\…\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1421736 2017-03-28] (Garmin Ltd. or its subsidiaries)
HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\scrnsave.scr [36864 2017-09-29] (Microsoft Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer Remote.lnk [2013-06-27]
ShortcutTarget: Acer Remote.lnk -> C:\Program Files (x86)\Acer Remote\ArcServer.exe (Acer)
Startup: C:\Users\Bodil Qvist\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Overvåg blækadvarsler - HP Officejet Pro 6830.lnk [2015-12-09]
ShortcutTarget: Overvåg blækadvarsler - HP Officejet Pro 6830.lnk -> C:\Program Files\HP\HP Officejet Pro 6830\Bin\HPStatusBL.dll (Hewlett-Packard Development Company, LP)
Startup: C:\Users\Bodil Qvist\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Overvåg blækadvarsler - HP Photosmart 5510 series.lnk [2015-09-16]
ShortcutTarget: Overvåg blækadvarsler - HP Photosmart 5510 series.lnk -> C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Bodil Qvist\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PMB Media Check Tool.lnk [2015-03-22]
ShortcutTarget: PMB Media Check Tool.lnk -> C:\Program Files (x86)\Sony\Sony Picture Utility\PMBCore\SPUVolumeWatcher.exe (Sony Corporation)
Startup: C:\Users\Bodil Qvist\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send til OneNote.lnk [2018-01-05]
ShortcutTarget: Send til OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{97302e60-dfc5-47fb-8f73-8ff086034f56}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://mysearch.avg.com/?cid=%7B1CFC5432-3AAB-4DE1-A065-49B1455CC6A7%7D∣=c52fb3586a5b47cd9caca56eacb95508-823eaa8ee4e10acb741c51064ca753d1344fe360⟨=da&ds;=AVG&coid;=avgtbavg&cmpid;=0615pi≺=fr&d;=2015-07-27%2012:27:32&v;=4.2.4.155&pid;=wtu&sg;=&sap;=hp
HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer13.msn.com
SearchScopes: HKLM -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://dk.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp;=yhs-acer_001&p;={searchTerms}
SearchScopes: HKLM-x32 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://dk.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp;=yhs-acer_001&p;={searchTerms}
SearchScopes: HKU\S-1-5-21-3953898830-1776782895-4010043791-1001 -> DefaultScope {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={1CFC5432-3AAB-4DE1-A065-49B1455CC6A7}∣=c52fb3586a5b47cd9caca56eacb95508-823eaa8ee4e10acb741c51064ca753d1344fe360⟨=da&ds;=AVG&coid;=avgtbavg&cmpid;=0915tb≺=fr&d;=2015-07-27 12:27:32&v;=4.2.4.155&pid;=wtu&sg;=&sap;=dsp&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3953898830-1776782895-4010043791-1001 -> {95B7759C-8C7F-4BF1-B163-73684A933233} URL = hxxps://mysearch.avg.com/search?cid={1CFC5432-3AAB-4DE1-A065-49B1455CC6A7}∣=c52fb3586a5b47cd9caca56eacb95508-823eaa8ee4e10acb741c51064ca753d1344fe360⟨=da&ds;=AVG&coid;=avgtbavg&cmpid;=0915tb≺=fr&d;=2015-07-27 12:27:32&v;=4.2.4.155&pid;=wtu&sg;=&sap;=dsp&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-3953898830-1776782895-4010043791-1001 -> {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://dk.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp;=yhs-acer_001&p;={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2018-01-04] (Microsoft Corporation)
BHO: AVG Web TuneUp -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files\AVG Web TuneUp\4.3.8.510\AVG Web TuneUp.dll [2017-06-13] (AVG)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-05] (Google Inc.)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2018-01-04] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\ssv.dll [2017-11-27] (Oracle Corporation)
BHO-x32: No Name -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> No File
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-05] (Google Inc.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\jp2ssv.dll [2017-11-27] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-05] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-05] (Google Inc.)
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2018-01-04] (Microsoft Corporation)

FireFox:
========
FF ProfilePath: C:\Users\Bodil Qvist\AppData\Roaming\Mozilla\Firefox\Profiles\pvay76ue.default [2018-01-30]
FF Extension: (AVG Web TuneUp) - C:\Users\Bodil Qvist\AppData\Roaming\Mozilla\Firefox\Profiles\pvay76ue.default\Extensions\[removed] [2017-12-15]
FF SearchPlugin: C:\Users\Bodil Qvist\AppData\Roaming\Mozilla\Firefox\Profiles\pvay76ue.default\searchplugins\avg-secure-search.xml [2017-02-06]
FF HKLM-x32\…\Thunderbird\Extensions: [[removed]] - C:\Program Files\McAfee\MSK => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_28_0_0_137.dll [2018-01-09] ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_137.dll [2018-01-09] ()
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\40.3.8\\npsitesafety.dll [No File]
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-06-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\dtplugin\npDeployJava1.dll [2017-11-27] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.151.2 -> C:\Program Files (x86)\Java\jre1.8.0_151\bin\plugin2\npjp2.dll [2017-11-27] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2018-01-04] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-14] (Google Inc.)
FF Plugin-x32: @verimatrix.com/ViewRightWeb -> C:\Program Files (x86)\Verimatrix\ViewRight Web\\npViewRight.dll [2012-11-27] (Verimatrix, Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2012-10-12] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-3953898830-1776782895-4010043791-1001: @verimatrix.com/ViewRightWeb -> C:\Program Files (x86)\Verimatrix\ViewRight Web\\npViewRight.dll [2012-11-27] (Verimatrix, Inc.)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\defaults\pref\2529906.js [2018-01-04] <==== ATTENTION (Points to *.cfg file)
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\2529906.cfg [2018-01-04] <==== ATTENTION

Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> mysearch.avg.com
CHR DefaultSearchURL: Default -> hxxps://mysearch.avg.com/search?rvt=1&sap;=dsp&q;={searchTerms}
CHR DefaultSearchKeyword: Default -> hxxps://mysearch.avg.com
CHR DefaultSuggestURL: Default -> hxxps://toolbar.avg.com/acp?q={searchTerms}&o;=1
CHR Profile: C:\Users\Bodil Qvist\AppData\Local\Google\Chrome\User Data\Default [2018-01-30]
CHR Extension: (Google Dokumenter) - C:\Users\Bodil Qvist\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-07-27]
CHR Extension: (Google Drev) - C:\Users\Bodil Qvist\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-12-04]
CHR Extension: (YouTube) - C:\Users\Bodil Qvist\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-12-04]
CHR Extension: (AVG Secure Search) - C:\Users\Bodil Qvist\AppData\Local\Google\Chrome\User Data\Default\Extensions\chfdnecihphmhljaaejmgoiahnihplgn [2016-01-27]
CHR Extension: (Google-søgning) - C:\Users\Bodil Qvist\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-12-04]
CHR Extension: (Google Docs Offline) - C:\Users\Bodil Qvist\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-06-02]
CHR Extension: (Betalinger i Chrome Webshop) - C:\Users\Bodil Qvist\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-07-14]
CHR Extension: (Gmail) - C:\Users\Bodil Qvist\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-07-27]
CHR Extension: (Chrome Media Router) - C:\Users\Bodil Qvist\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-14]
CHR HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\SOFTWARE\Google\Chrome\Extensions\…\Chrome\Extension: [chfdnecihphmhljaaejmgoiahnihplgn] - hxxps://clients2.google.com/service/update2/crx

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-01-19] (Apple Inc.)
R2 AVG Antivirus; C:\Program Files (x86)\AVG\Antivirus\AVGSvc.exe [301720 2018-01-05] (AVG Technologies CZ, s.r.o.)
R3 avgbIDSAgent; C:\Program Files (x86)\AVG\Antivirus\x64\aswidsagenta.exe [7589200 2018-01-05] (AVG Technologies CZ, s.r.o.)
R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1428656 2017-10-31] (AVG Technologies CZ, s.r.o.)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-20] (Acer Incorporated)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058416 2017-09-05] (Microsoft Corporation)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [660040 2013-01-18] (Acer Incorporated)
R2 Garmin Device Interaction Service; C:\Program Files (x86)\Garmin\Device Interaction Service\GarminService.exe [1099280 2017-03-28] (Garmin Ltd. or its subsidiaries)
R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed]
R2 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [337888 2016-05-03] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165760 2012-07-17] (Intel Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10945264 2017-12-05] (TeamViewer GmbH)
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [5614592 2018-01-22] (AVG Technologies CZ, s.r.o.)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [355304 2017-09-29] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [105944 2017-09-29] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R1 avgArPot; C:\WINDOWS\System32\drivers\avgArPot.sys [177536 2018-01-05] (AVG Technologies CZ, s.r.o.)
R1 avgbdisk; C:\WINDOWS\System32\drivers\avgbdiska.sys [166624 2018-01-05] (AVG Technologies CZ, s.r.o.)
R1 avgbidsdriver; C:\WINDOWS\System32\drivers\avgbidsdrivera.sys [315152 2018-01-05] (AVG Technologies CZ, s.r.o.)
R0 avgbidsh; C:\WINDOWS\System32\drivers\avgbidsha.sys [193096 2018-01-05] (AVG Technologies CZ, s.r.o.)
R0 avgblog; C:\WINDOWS\System32\drivers\avgbloga.sys [337408 2018-01-05] (AVG Technologies CZ, s.r.o.)
R0 avgbuniv; C:\WINDOWS\System32\drivers\avgbuniva.sys [51336 2018-01-05] (AVG Technologies CZ, s.r.o.)
S3 avgHwid; C:\WINDOWS\System32\drivers\avgHwid.sys [39424 2018-01-05] (AVG Technologies CZ, s.r.o.)
R2 avgMonFlt; C:\WINDOWS\System32\drivers\avgMonFlt.sys [139112 2018-01-10] (AVG Technologies CZ, s.r.o.)
R1 avgRdr; C:\WINDOWS\System32\drivers\avgRdr2.sys [102792 2018-01-05] (AVG Technologies CZ, s.r.o.)
R0 avgRvrt; C:\WINDOWS\System32\drivers\avgRvrt.sys [76832 2018-01-05] (AVG Technologies CZ, s.r.o.)
R1 avgSnx; C:\WINDOWS\System32\drivers\avgSnx.sys [1017624 2018-01-05] (AVG Technologies CZ, s.r.o.)
R1 avgSP; C:\WINDOWS\System32\drivers\avgSP.sys [450360 2018-01-10] (AVG Technologies CZ, s.r.o.)
R2 avgStm; C:\WINDOWS\System32\drivers\avgStm.sys [196904 2018-01-05] (AVG Technologies CZ, s.r.o.)
R0 avgVmm; C:\WINDOWS\System32\drivers\avgVmm.sys [351128 2018-01-05] (AVG Technologies CZ, s.r.o.)
R3 e1cexpress; C:\WINDOWS\system32\DRIVERS\e1c63x64.sys [498032 2012-07-12] (Intel Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [32304 2017-02-21] (AVG Netherlands B.V.)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44608 2017-09-29] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [309144 2017-09-29] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [119192 2017-09-29] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-30 19:18 - 2018-01-30 19:18 - 000021405 _____ C:\Users\Bodil Qvist\Desktop\FRST.txt
2018-01-30 19:17 - 2018-01-30 19:18 - 000000000 ____D C:\FRST
2018-01-30 19:14 - 2018-01-30 19:15 - 000522956 _____ C:\WINDOWS\Minidump\013018-23156-01.dmp
2018-01-30 19:04 - 2018-01-30 19:06 - 000496884 _____ C:\WINDOWS\Minidump\013018-22000-01.dmp
2018-01-30 19:01 - 2018-01-30 19:14 - 666693797 _____ C:\WINDOWS\MEMORY.DMP
2018-01-30 19:01 - 2018-01-30 19:14 - 000000000 ____D C:\WINDOWS\Minidump
2018-01-30 19:01 - 2018-01-30 19:02 - 000785788 _____ C:\WINDOWS\Minidump\013018-22562-01.dmp
2018-01-30 18:59 - 2018-01-30 18:59 - 002393088 _____ (Farbar) C:\Users\Bodil Qvist\Desktop\FRST64.exe
2018-01-30 18:56 - 2018-01-30 18:56 - 005198336 _____ (AVAST Software) C:\Users\Bodil Qvist\Desktop\aswMBR.exe
2018-01-25 11:01 - 2018-01-25 11:01 - 000000000 ____D C:\Users\Bodil Qvist\AppData\Local\TeamViewer
2018-01-08 17:00 - 2018-01-08 17:00 - 000000000 __RHD C:\MSOCache
2018-01-05 17:17 - 2018-01-01 18:15 - 000956416 _____ (Microsoft Corporation) C:\WINDOWS\system32\Spectrum.exe
2018-01-05 17:17 - 2018-01-01 13:54 - 000924648 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2018-01-05 17:17 - 2018-01-01 13:53 - 001090984 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2018-01-05 17:17 - 2018-01-01 13:51 - 001414784 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2018-01-05 17:17 - 2018-01-01 13:51 - 001209240 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2018-01-05 17:17 - 2018-01-01 13:51 - 001055128 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2018-01-05 17:17 - 2018-01-01 13:51 - 000059800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bam.sys
2018-01-05 17:17 - 2018-01-01 13:50 - 005905752 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2018-01-05 17:17 - 2018-01-01 13:50 - 000780464 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2018-01-05 17:17 - 2018-01-01 13:50 - 000479912 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase_enclave.dll
2018-01-05 17:17 - 2018-01-01 13:49 - 008605080 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2018-01-05 17:17 - 2018-01-01 13:49 - 000319352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wow64.dll
2018-01-05 17:17 - 2018-01-01 13:48 - 007831760 _____ (Microsoft Corporation) C:\WINDOWS\system32\d3d10warp.dll
2018-01-05 17:17 - 2018-01-01 13:48 - 001954048 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2018-01-05 17:17 - 2018-01-01 13:48 - 000382360 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2018-01-05 17:17 - 2018-01-01 13:47 - 000082840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\volmgr.sys
2018-01-05 17:17 - 2018-01-01 13:46 - 002709704 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2018-01-05 17:17 - 2018-01-01 13:46 - 000898216 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2018-01-05 17:17 - 2018-01-01 13:46 - 000471960 _____ (Microsoft Corporation) C:\WINDOWS\system32\hal.dll
2018-01-05 17:17 - 2018-01-01 13:45 - 002395032 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2018-01-05 17:17 - 2018-01-01 13:45 - 001277848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2018-01-05 17:17 - 2018-01-01 13:45 - 000398744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fltMgr.sys
2018-01-05 17:17 - 2018-01-01 13:43 - 001173576 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcrt4.dll
2018-01-05 17:17 - 2018-01-01 13:42 - 000571288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\spaceport.sys
2018-01-05 17:17 - 2018-01-01 13:42 - 000184984 _____ (Microsoft Corporation) C:\WINDOWS\system32\sspicli.dll
2018-01-05 17:17 - 2018-01-01 13:41 - 007676296 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2018-01-05 17:17 - 2018-01-01 13:41 - 000559512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2018-01-05 17:17 - 2018-01-01 13:40 - 001206680 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2018-01-05 17:17 - 2018-01-01 13:39 - 000902416 _____ (Microsoft Corporation) C:\WINDOWS\system32\winhttp.dll
2018-01-05 17:17 - 2018-01-01 13:39 - 000677784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cng.sys
2018-01-05 17:17 - 2018-01-01 13:39 - 000508264 _____ (Microsoft Corporation) C:\WINDOWS\system32\systemreset.exe
2018-01-05 17:17 - 2018-01-01 13:39 - 000362904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pci.sys
2018-01-05 17:17 - 2018-01-01 13:39 - 000129432 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hvsocket.sys
2018-01-05 17:17 - 2018-01-01 13:38 - 003904808 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2018-01-05 17:17 - 2018-01-01 13:38 - 000519152 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2018-01-05 17:17 - 2018-01-01 13:37 - 001426664 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2018-01-05 17:17 - 2018-01-01 13:37 - 000461720 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifitask.exe
2018-01-05 17:17 - 2018-01-01 13:36 - 000374032 _____ (Microsoft Corporation) C:\WINDOWS\system32\vac.exe
2018-01-05 17:17 - 2018-01-01 13:36 - 000166296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\partmgr.sys
2018-01-05 17:17 - 2018-01-01 13:35 - 001170008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2018-01-05 17:17 - 2018-01-01 13:34 - 007385088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2018-01-05 17:17 - 2018-01-01 13:34 - 001336344 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2018-01-05 17:17 - 2018-01-01 13:33 - 002773400 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2018-01-05 17:17 - 2018-01-01 13:33 - 000603920 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2018-01-05 17:17 - 2018-01-01 13:32 - 004481240 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2018-01-05 17:17 - 2018-01-01 13:27 - 000713624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2018-01-05 17:17 - 2018-01-01 13:26 - 000428952 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rdbss.sys
2018-01-05 17:17 - 2018-01-01 13:25 - 000615768 _____ (Microsoft Corporation) C:\WINDOWS\system32\services.exe
2018-01-05 17:17 - 2018-01-01 13:25 - 000147864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2018-01-05 17:17 - 2018-01-01 13:23 - 021352144 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2018-01-05 17:17 - 2018-01-01 13:21 - 001103768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2018-01-05 17:17 - 2018-01-01 13:06 - 000311192 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2018-01-05 17:17 - 2018-01-01 13:03 - 000650328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2018-01-05 17:17 - 2018-01-01 13:03 - 000123512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sspicli.dll
2018-01-05 17:17 - 2018-01-01 12:53 - 001615712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2018-01-05 17:17 - 2018-01-01 12:49 - 000481464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\advapi32.dll
2018-01-05 17:17 - 2018-01-01 12:46 - 003485392 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2018-01-05 17:17 - 2018-01-01 12:45 - 006092152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2018-01-05 17:17 - 2018-01-01 12:45 - 005615968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2018-01-05 17:17 - 2018-01-01 12:45 - 002192624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2018-01-05 17:17 - 2018-01-01 12:43 - 020286120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2018-01-05 17:17 - 2018-01-01 12:42 - 006479552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2018-01-05 17:17 - 2018-01-01 12:42 - 004644912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2018-01-05 17:17 - 2018-01-01 12:42 - 001246432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2018-01-05 17:17 - 2018-01-01 12:42 - 001003152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2018-01-05 17:17 - 2018-01-01 12:42 - 000982528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2018-01-05 17:17 - 2018-01-01 12:37 - 025247232 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2018-01-05 17:17 - 2018-01-01 12:34 - 000703568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winhttp.dll
2018-01-05 17:17 - 2018-01-01 12:25 - 002905600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2018-01-05 17:17 - 2018-01-01 12:25 - 001008640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallService.dll
2018-01-05 17:17 - 2018-01-01 12:25 - 000475648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieui.dll
2018-01-05 17:17 - 2018-01-01 12:25 - 000344576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgeIso.dll
2018-01-05 17:17 - 2018-01-01 12:25 - 000097792 _____ C:\WINDOWS\system32\runexehelper.exe
2018-01-05 17:17 - 2018-01-01 12:24 - 003668480 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2018-01-05 17:17 - 2018-01-01 12:24 - 000202240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2018-01-05 17:17 - 2018-01-01 12:23 - 001313792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallService.dll
2018-01-05 17:17 - 2018-01-01 12:23 - 000561152 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2018-01-05 17:17 - 2018-01-01 12:23 - 000536576 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgeIso.dll
2018-01-05 17:17 - 2018-01-01 12:23 - 000250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2018-01-05 17:17 - 2018-01-01 12:21 - 000192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2018-01-05 17:17 - 2018-01-01 12:20 - 019337216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2018-01-05 17:17 - 2018-01-01 12:20 - 018917888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2018-01-05 17:17 - 2018-01-01 12:20 - 000524288 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2018-01-05 17:17 - 2018-01-01 12:20 - 000204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2018-01-05 17:17 - 2018-01-01 12:19 - 008014848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2018-01-05 17:17 - 2018-01-01 12:19 - 000461312 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansec.dll
2018-01-05 17:17 - 2018-01-01 12:19 - 000450048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TileDataRepository.dll
2018-01-05 17:17 - 2018-01-01 12:19 - 000416768 _____ (Microsoft Corporation) C:\WINDOWS\system32\html.iec
2018-01-05 17:17 - 2018-01-01 12:19 - 000369152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2018-01-05 17:17 - 2018-01-01 12:19 - 000365568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2018-01-05 17:17 - 2018-01-01 12:19 - 000334848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dusmsvc.dll
2018-01-05 17:17 - 2018-01-01 12:19 - 000073216 _____ (Microsoft Corporation) C:\WINDOWS\system32\provtool.exe
2018-01-05 17:17 - 2018-01-01 12:18 - 000699904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CPFilters.dll
2018-01-05 17:17 - 2018-01-01 12:18 - 000432640 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2018-01-05 17:17 - 2018-01-01 12:18 - 000431616 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2018-01-05 17:17 - 2018-01-01 12:18 - 000427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provhandlers.dll
2018-01-05 17:17 - 2018-01-01 12:18 - 000380928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EncDec.dll
2018-01-05 17:17 - 2018-01-01 12:18 - 000374784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\FirewallAPI.dll
2018-01-05 17:17 - 2018-01-01 12:18 - 000261632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\actxprxy.dll
2018-01-05 17:17 - 2018-01-01 12:17 - 011923968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2018-01-05 17:17 - 2018-01-01 12:17 - 006564864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2018-01-05 17:17 - 2018-01-01 12:17 - 000708096 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2018-01-05 17:17 - 2018-01-01 12:17 - 000616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2018-01-05 17:17 - 2018-01-01 12:17 - 000568832 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2018-01-05 17:17 - 2018-01-01 12:17 - 000559104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9diag.dll
2018-01-05 17:17 - 2018-01-01 12:17 - 000542208 _____ (Microsoft Corporation) C:\WINDOWS\system32\FirewallAPI.dll
2018-01-05 17:17 - 2018-01-01 12:16 - 005833216 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2018-01-05 17:17 - 2018-01-01 12:16 - 004839424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2018-01-05 17:17 - 2018-01-01 12:16 - 003676672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2018-01-05 17:17 - 2018-01-01 12:16 - 000815616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2018-01-05 17:17 - 2018-01-01 12:16 - 000812544 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2018-01-05 17:17 - 2018-01-01 12:16 - 000720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2018-01-05 17:17 - 2018-01-01 12:16 - 000664576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2018-01-05 17:17 - 2018-01-01 12:16 - 000594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2018-01-05 17:17 - 2018-01-01 12:16 - 000463360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2018-01-05 17:17 - 2018-01-01 12:15 - 012687872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmp.dll
2018-01-05 17:17 - 2018-01-01 12:15 - 006029312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2018-01-05 17:17 - 2018-01-01 12:15 - 002349568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2018-01-05 17:17 - 2018-01-01 12:15 - 000970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2018-01-05 17:17 - 2018-01-01 12:15 - 000951808 _____ (Microsoft Corporation) C:\WINDOWS\system32\usermgr.dll
2018-01-05 17:17 - 2018-01-01 12:15 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\actxprxy.dll
2018-01-05 17:17 - 2018-01-01 12:15 - 000434176 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDec.dll
2018-01-05 17:17 - 2018-01-01 12:14 - 023655936 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2018-01-05 17:17 - 2018-01-01 12:14 - 002465280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2018-01-05 17:17 - 2018-01-01 12:14 - 001495040 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2018-01-05 17:17 - 2018-01-01 12:14 - 001097728 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpbase.dll
2018-01-05 17:17 - 2018-01-01 12:14 - 001003008 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2018-01-05 17:17 - 2018-01-01 12:14 - 000917504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2018-01-05 17:17 - 2018-01-01 12:14 - 000870912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CPFilters.dll
2018-01-05 17:17 - 2018-01-01 12:13 - 013657600 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmp.dll
2018-01-05 17:17 - 2018-01-01 12:13 - 012830208 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2018-01-05 17:17 - 2018-01-01 12:13 - 003121664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2018-01-05 17:17 - 2018-01-01 12:13 - 002869760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2018-01-05 17:17 - 2018-01-01 12:13 - 001559552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2018-01-05 17:17 - 2018-01-01 12:12 - 002633216 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2018-01-05 17:17 - 2018-01-01 12:12 - 002208768 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2018-01-05 17:17 - 2018-01-01 12:12 - 001573376 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2018-01-05 17:17 - 2018-01-01 12:12 - 001547776 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsasrv.dll
2018-01-05 17:17 - 2018-01-01 12:12 - 001424896 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2018-01-05 17:17 - 2018-01-01 12:12 - 000464384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Core.TextInput.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 008108544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 004748288 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 003334144 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 003165696 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 002859520 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 001822208 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 001816576 _____ (Microsoft Corporation) C:\WINDOWS\system32\wevtsvc.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 001343488 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 001231872 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 000880640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 000812032 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2018-01-05 17:17 - 2018-01-01 12:11 - 000715776 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2018-01-05 17:17 - 2018-01-01 12:10 - 003126272 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2018-01-05 17:17 - 2018-01-01 12:09 - 001487872 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2018-01-05 17:17 - 2018-01-01 12:09 - 000925184 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2018-01-05 17:17 - 2018-01-01 12:09 - 000666624 _____ (Microsoft Corporation) C:\WINDOWS\system32\DbgModel.dll
2018-01-05 17:17 - 2018-01-01 12:09 - 000599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2018-01-05 17:17 - 2018-01-01 12:08 - 000963072 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2018-01-05 17:17 - 2018-01-01 12:08 - 000726016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2018-01-05 17:17 - 2018-01-01 12:08 - 000685056 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2018-01-05 17:17 - 2018-01-01 12:08 - 000424448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2018-01-05 17:17 - 2018-01-01 12:05 - 002510848 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2018-01-05 17:17 - 2018-01-01 12:05 - 001160704 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2018-01-05 17:16 - 2018-01-01 13:52 - 000066712 _____ (Microsoft Corporation) C:\WINDOWS\system32\iumcrypt.dll
2018-01-05 17:16 - 2018-01-01 13:51 - 000191816 _____ (Microsoft Corporation) C:\WINDOWS\system32\skci.dll
2018-01-05 17:16 - 2018-01-01 13:50 - 000077208 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.dll
2018-01-05 17:16 - 2018-01-01 13:49 - 000599448 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2018-01-05 17:16 - 2018-01-01 13:49 - 000292376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscapi.dll
2018-01-05 17:16 - 2018-01-01 13:47 - 000649304 _____ (Microsoft Corporation) C:\WINDOWS\system32\advapi32.dll
2018-01-05 17:16 - 2018-01-01 13:46 - 000733592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\acpi.sys
2018-01-05 17:16 - 2018-01-01 13:43 - 000367336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Storage.ApplicationData.dll
2018-01-05 17:16 - 2018-01-01 13:43 - 000062872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fsdepends.sys
2018-01-05 17:16 - 2018-01-01 13:42 - 001029016 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2018-01-05 17:16 - 2018-01-01 13:42 - 000494488 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcasvc.dll
2018-01-05 17:16 - 2018-01-01 13:42 - 000109976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbus.sys
2018-01-05 17:16 - 2018-01-01 13:41 - 000549552 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2018-01-05 17:16 - 2018-01-01 13:38 - 000727448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fvevol.sys
2018-01-05 17:16 - 2018-01-01 13:38 - 000103320 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\stornvme.sys
2018-01-05 17:16 - 2018-01-01 13:38 - 000038808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Diskdump.sys
2018-01-05 17:16 - 2018-01-01 13:36 - 000413888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll
2018-01-05 17:16 - 2018-01-01 13:36 - 000113560 _____ (Microsoft Corporation) C:\WINDOWS\system32\icfupgd.dll
2018-01-05 17:16 - 2018-01-01 13:36 - 000057752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbios.sys
2018-01-05 17:16 - 2018-01-01 13:35 - 000075160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthProxyStub.dll
2018-01-05 17:16 - 2018-01-01 13:34 - 000260896 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2018-01-05 17:16 - 2018-01-01 13:34 - 000087384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2018-01-05 17:16 - 2018-01-01 13:32 - 000617304 _____ (Microsoft Corporation) C:\WINDOWS\system32\TextInputFramework.dll
2018-01-05 17:16 - 2018-01-01 13:27 - 000163736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wfplwfs.sys
2018-01-05 17:16 - 2018-01-01 13:26 - 000081304 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmcl.sys
2018-01-05 17:16 - 2018-01-01 13:21 - 000614296 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\afd.sys
2018-01-05 17:16 - 2018-01-01 13:03 - 000777904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2018-01-05 17:16 - 2018-01-01 13:03 - 000566664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2018-01-05 17:16 - 2018-01-01 12:49 - 000258808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscapi.dll
2018-01-05 17:16 - 2018-01-01 12:46 - 000289816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Storage.ApplicationData.dll
2018-01-05 17:16 - 2018-01-01 12:45 - 000450928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2018-01-05 17:16 - 2018-01-01 12:42 - 000386424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll
2018-01-05 17:16 - 2018-01-01 12:42 - 000129184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfps.dll
2018-01-05 17:16 - 2018-01-01 12:42 - 000074992 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2018-01-05 17:16 - 2018-01-01 12:24 - 000240640 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboutSettingsHandlers.dll
2018-01-05 17:16 - 2018-01-01 12:24 - 000096256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontsub.dll
2018-01-05 17:16 - 2018-01-01 12:24 - 000038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2018-01-05 17:16 - 2018-01-01 12:23 - 000385024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\cldflt.sys
2018-01-05 17:16 - 2018-01-01 12:23 - 000232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\convertvhd.exe
2018-01-05 17:16 - 2018-01-01 12:23 - 000121344 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontsub.dll
2018-01-05 17:16 - 2018-01-01 12:23 - 000080384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vmbkmclr.sys
2018-01-05 17:16 - 2018-01-01 12:23 - 000047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2018-01-05 17:16 - 2018-01-01 12:22 - 000031744 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Management.Provisioning.ProxyStub.dll
2018-01-05 17:16 - 2018-01-01 12:22 - 000025600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Dumpstorport.sys
2018-01-05 17:16 - 2018-01-01 12:22 - 000017408 _____ (Microsoft Corporation) C:\WINDOWS\system32\VmApplicationHealthMonitorProxy.dll
2018-01-05 17:16 - 2018-01-01 12:21 - 000268288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2018-01-05 17:16 - 2018-01-01 12:21 - 000233984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppLockerCSP.dll
2018-01-05 17:16 - 2018-01-01 12:21 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\system32\wificonnapi.dll
2018-01-05 17:16 - 2018-01-01 12:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WcnApi.dll
2018-01-05 17:16 - 2018-01-01 12:21 - 000097280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\raspptp.sys
2018-01-05 17:16 - 2018-01-01 12:21 - 000080896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wanarp.sys
2018-01-05 17:16 - 2018-01-01 12:21 - 000062976 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndproxy.sys
2018-01-05 17:16 - 2018-01-01 12:20 - 000459776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2018-01-05 17:16 - 2018-01-01 12:20 - 000397824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtmsft.dll
2018-01-05 17:16 - 2018-01-01 12:20 - 000225792 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\winnat.sys
2018-01-05 17:16 - 2018-01-01 12:20 - 000215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\fwpolicyiomgr.dll
2018-01-05 17:16 - 2018-01-01 12:20 - 000212992 _____ (Microsoft Corporation) C:\WINDOWS\system32\container.dll
2018-01-05 17:16 - 2018-01-01 12:20 - 000186368 _____ (Microsoft Corporation) C:\WINDOWS\system32\ACPBackgroundManagerPolicy.dll
2018-01-05 17:16 - 2018-01-01 12:20 - 000175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fwpolicyiomgr.dll
2018-01-05 17:16 - 2018-01-01 12:20 - 000134656 _____ (Microsoft Corporation) C:\WINDOWS\system32\WcnApi.dll
2018-01-05 17:16 - 2018-01-01 12:20 - 000133632 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2018-01-05 17:16 - 2018-01-01 12:20 - 000104960 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasauto.dll
2018-01-05 17:16 - 2018-01-01 12:20 - 000082432 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardDlg.dll
2018-01-05 17:16 - 2018-01-01 12:20 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\RfxVmt.sys
2018-01-05 17:16 - 2018-01-01 12:20 - 000035328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nshhttp.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000795136 _____ (Microsoft Corporation) C:\WINDOWS\system32\NaturalAuth.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000675328 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000430080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000340480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\html.iec
2018-01-05 17:16 - 2018-01-01 12:19 - 000316928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netbt.sys
2018-01-05 17:16 - 2018-01-01 12:19 - 000188416 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000174592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\P2P.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000149504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\container.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000097792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msoert2.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000093696 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000063488 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll
2018-01-05 17:16 - 2018-01-01 12:19 - 000043008 _____ (Microsoft Corporation) C:\WINDOWS\system32\nshhttp.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000748032 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneProviders.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmsRouterSvc.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcncsvc.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000436224 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000425984 _____ (Microsoft Corporation) C:\WINDOWS\system32\vmrdvcore.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000369664 _____ (Microsoft Corporation) C:\WINDOWS\system32\APHostService.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000343040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000336896 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppLockerCSP.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000276480 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000259072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000210944 _____ (Microsoft Corporation) C:\WINDOWS\system32\P2P.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000144896 _____ (Microsoft Corporation) C:\WINDOWS\system32\appinfo.dll
2018-01-05 17:16 - 2018-01-01 12:18 - 000082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\provdatastore.dll
2018-01-05 17:16 - 2018-01-01 12:17 - 001485312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpserverbase.dll
2018-01-05 17:16 - 2018-01-01 12:17 - 000791552 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneService.dll
2018-01-05 17:16 - 2018-01-01 12:17 - 000594432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2018-01-05 17:16 - 2018-01-01 12:17 - 000555520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2018-01-05 17:16 - 2018-01-01 12:17 - 000456704 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtmsft.dll
2018-01-05 17:16 - 2018-01-01 12:17 - 000423936 _____ (Microsoft Corporation) C:\WINDOWS\system32\p2psvc.dll
2018-01-05 17:16 - 2018-01-01 12:17 - 000341504 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnrpsvc.dll
2018-01-05 17:16 - 2018-01-01 12:17 - 000228352 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2018-01-05 17:16 - 2018-01-01 12:17 - 000112640 _____ (Microsoft Corporation) C:\WINDOWS\system32\msoert2.dll
2018-01-05 17:16 - 2018-01-01 12:16 - 000966656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2018-01-05 17:16 - 2018-01-01 12:16 - 000956928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rdpbase.dll
2018-01-05 17:16 - 2018-01-01 12:16 - 000831488 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2018-01-05 17:16 - 2018-01-01 12:16 - 000668160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2018-01-05 17:16 - 2018-01-01 12:16 - 000624128 _____ (Microsoft Corporation) C:\WINDOWS\system32\SyncController.dll
2018-01-05 17:16 - 2018-01-01 12:16 - 000401920 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2018-01-05 17:16 - 2018-01-01 12:16 - 000235008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2018-01-05 17:16 - 2018-01-01 12:16 - 000086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2018-01-05 17:16 - 2018-01-01 12:16 - 000076288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2018-01-05 17:16 - 2018-01-01 12:15 - 001657856 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpserverbase.dll
2018-01-05 17:16 - 2018-01-01 12:15 - 001245184 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2018-01-05 17:16 - 2018-01-01 12:15 - 000756736 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2018-01-05 17:16 - 2018-01-01 12:15 - 000366080 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2018-01-05 17:16 - 2018-01-01 12:15 - 000258560 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2018-01-05 17:16 - 2018-01-01 12:14 - 000985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcomm.dll
2018-01-05 17:16 - 2018-01-01 12:13 - 002013184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2018-01-05 17:16 - 2018-01-01 12:13 - 001474560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2018-01-05 17:16 - 2018-01-01 12:13 - 000897024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcomm.dll
2018-01-05 17:16 - 2018-01-01 12:12 - 000760320 _____ (Microsoft Corporation) C:\WINDOWS\system32\spoolsv.exe
2018-01-05 17:16 - 2018-01-01 12:11 - 002082304 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2018-01-05 17:16 - 2018-01-01 12:11 - 001597952 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2018-01-05 17:16 - 2018-01-01 12:10 - 002528256 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2018-01-05 17:16 - 2018-01-01 12:10 - 000012800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wscproxystub.dll
2018-01-05 17:16 - 2018-01-01 12:08 - 000505344 _____ (Microsoft Corporation) C:\WINDOWS\system32\taskcomp.dll
2018-01-05 17:16 - 2018-01-01 12:06 - 000018944 _____ (Microsoft Corporation) C:\WINDOWS\system32\wscproxystub.dll
2018-01-05 17:16 - 2018-01-01 12:05 - 000050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\pcalua.exe
2018-01-05 16:48 - 2018-01-05 16:48 - 000366800 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\avgBoot.exe
2018-01-05 16:42 - 2018-01-05 16:42 - 000002486 _____ C:\Users\Bodil Qvist\Desktop\Word 2013.lnk
2018-01-05 16:42 - 2018-01-05 16:42 - 000002465 _____ C:\Users\Bodil Qvist\Desktop\PowerPoint 2013.lnk
2018-01-05 16:42 - 2018-01-05 16:42 - 000002446 _____ C:\Users\Bodil Qvist\Desktop\Outlook 2013.lnk
2018-01-05 16:42 - 2018-01-05 16:42 - 000002404 _____ C:\Users\Bodil Qvist\Desktop\Excel 2013.lnk
2018-01-05 16:37 - 2018-01-05 16:37 - 000000000 ____D C:\Users\Bodil Qvist\Documents\OneNote-notesbøger
2018-01-04 18:20 - 2018-01-04 18:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2018-01-04 18:17 - 2018-01-04 18:17 - 000000000 ____D C:\Program Files\Microsoft Office 15
2018-01-04 18:07 - 2018-01-04 18:07 - 001131224 _____ (Microsoft Corporation) C:\Users\Bodil Qvist\Downloads\Setup.x86.da-DK_HomeBusinessRetail_6WQ34-7NP6H-PWBQY-CJ6HW-K2B23_TX_PR_.exe
2018-01-04 17:36 - 2018-01-04 17:36 - 000950272 _____ C:\Users\Bodil Qvist\Downloads\Microsoft_Office_2013_Product_Key_Generator(1).iso
2018-01-04 17:35 - 2018-01-04 17:36 - 000950272 _____ C:\Users\Bodil Qvist\Downloads\Microsoft_Office_2013_Product_Key_Generator.iso

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2018-01-30 19:16 - 2016-11-15 22:56 - 000000000 ____D C:\Users\Bodil Qvist\AppData\LocalLow\Mozilla
2018-01-30 19:16 - 2014-11-09 13:10 - 000000000 __SHD C:\Users\Bodil Qvist\IntelGraphicsProfiles
2018-01-30 19:15 - 2017-12-08 00:28 - 000003668 _____ C:\WINDOWS\System32\Tasks\AVG EUpdate Task
2018-01-30 19:14 - 2017-12-08 00:28 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-01-30 19:14 - 2017-12-08 00:09 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-01-30 19:11 - 2017-12-08 00:27 - 003147134 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-01-30 19:11 - 2017-09-30 15:28 - 001342200 _____ C:\WINDOWS\system32\perfh006.dat
2018-01-30 19:11 - 2017-09-30 15:28 - 000350172 _____ C:\WINDOWS\system32\perfc006.dat
2018-01-30 19:02 - 2017-12-08 00:11 - 000000000 ____D C:\Users\Bodil Qvist
2018-01-30 19:02 - 2017-09-29 14:44 - 000000000 ____D C:\WINDOWS\INF
2018-01-30 19:01 - 2017-08-25 23:29 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-01-30 19:01 - 2013-12-10 19:28 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2018-01-30 18:35 - 2014-01-07 17:48 - 000000000 ____D C:\Users\Bodil Qvist\AppData\Local\Google
2018-01-30 17:57 - 2013-12-29 23:20 - 000000000 ____D C:\Users\Bodil Qvist\Documents\Outlook-filer
2018-01-30 17:38 - 2013-12-29 18:45 - 000000000 ____D C:\Users\Bodil Qvist\Documents\Diverse
2018-01-30 17:31 - 2017-12-08 01:17 - 000000000 ____D C:\Users\Bodil Qvist\AppData\Local\Deployment
2018-01-30 16:25 - 2014-01-04 14:20 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-01-30 15:19 - 2014-01-07 17:27 - 000000000 ____D C:\Users\Bodil Qvist\AppData\Local\CutePDF Writer
2018-01-30 12:37 - 2013-12-10 19:28 - 000001179 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2018-01-30 12:00 - 2017-12-08 00:28 - 000004158 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{26F82D92-CF66-4491-A8D4-BB5DB72FAD84}
2018-01-30 11:52 - 2013-12-29 18:45 - 000000000 ____D C:\Users\Bodil Qvist\Documents\Bank
2018-01-30 11:45 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\DeliveryOptimization
2018-01-30 10:28 - 2017-09-29 14:46 - 000000000 ___HD C:\Program Files\WindowsApps
2018-01-30 10:28 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-01-30 02:03 - 2017-09-29 09:45 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-01-22 14:52 - 2017-06-02 13:21 - 000045568 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\TURegOpt.exe
2018-01-19 15:05 - 2013-12-10 19:27 - 000000000 ____D C:\Users\Bodil Qvist\AppData\Local\Microsoft Help
2018-01-10 18:45 - 2017-12-07 14:13 - 000450360 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSP.sys
2018-01-10 18:45 - 2017-12-07 14:13 - 000139112 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgMonFlt.sys
2018-01-10 13:03 - 2017-10-10 10:51 - 000000000 ____D C:\Users\Bodil Qvist\Documents\Legatansøgning 2017
2018-01-10 10:57 - 2013-12-29 21:24 - 000000000 ____D C:\WINDOWS\system32\MRT
2018-01-10 10:55 - 2017-12-08 00:28 - 000003370 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-3953898830-1776782895-4010043791-1001
2018-01-10 10:55 - 2016-03-13 12:38 - 000002398 _____ C:\Users\Bodil Qvist\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-01-10 10:55 - 2016-03-13 12:38 - 000000000 ___RD C:\Users\Bodil Qvist\OneDrive
2018-01-10 10:54 - 2017-10-12 10:53 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT-KB890830.exe
2018-01-10 10:53 - 2017-09-29 14:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2018-01-10 10:53 - 2013-12-29 21:24 - 129365736 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2018-01-09 11:56 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Macromed
2018-01-09 11:56 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\Macromed
2018-01-06 15:57 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\rescache
2018-01-06 15:18 - 2014-01-07 17:49 - 000002288 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-05 17:32 - 2017-12-08 00:50 - 000000000 ___RD C:\Users\Bodil Qvist\3D Objects
2018-01-05 17:32 - 2013-06-27 03:23 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-01-05 17:31 - 2017-12-08 00:08 - 000462856 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2018-01-05 17:29 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\SysWOW64\F12
2018-01-05 17:29 - 2017-09-29 14:46 - 000000000 ___SD C:\WINDOWS\system32\F12
2018-01-05 17:29 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\TextInput
2018-01-05 17:29 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\SysWOW64\Dism
2018-01-05 17:29 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\oobe
2018-01-05 17:29 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\migwiz
2018-01-05 17:29 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\system32\appraiser
2018-01-05 17:29 - 2017-09-29 14:46 - 000000000 ____D C:\WINDOWS\Provisioning
2018-01-05 17:29 - 2017-09-29 09:45 - 000000000 ____D C:\WINDOWS\system32\Dism
2018-01-05 17:19 - 2017-09-29 14:41 - 000403968 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2018-01-05 17:19 - 2017-09-29 14:41 - 000140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2018-01-05 17:19 - 2017-09-29 14:41 - 000106496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2018-01-05 16:51 - 2017-09-29 09:45 - 000065536 _____ C:\WINDOWS\system32\config\ELAM
2018-01-05 16:48 - 2017-12-08 00:28 - 000004008 _____ C:\WINDOWS\System32\Tasks\Antivirus Emergency Update
2018-01-05 16:48 - 2017-12-07 14:13 - 000351128 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgVmm.sys
2018-01-05 16:48 - 2017-12-07 14:13 - 000196904 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgStm.sys
2018-01-05 16:48 - 2017-12-07 14:13 - 000177536 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgArPot.sys
2018-01-05 16:48 - 2017-12-07 14:13 - 000102792 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRdr2.sys
2018-01-05 16:48 - 2017-12-07 14:13 - 000076832 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgRvrt.sys
2018-01-05 16:48 - 2017-12-07 14:13 - 000039424 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgHwid.sys
2018-01-05 16:47 - 2017-12-07 14:13 - 001017624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgSnx.sys
2018-01-05 16:47 - 2017-12-07 14:13 - 000337408 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbloga.sys
2018-01-05 16:47 - 2017-12-07 14:13 - 000315152 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsdrivera.sys
2018-01-05 16:47 - 2017-12-07 14:13 - 000193096 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbidsha.sys
2018-01-05 16:47 - 2017-12-07 14:13 - 000166624 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbdiska.sys
2018-01-05 16:47 - 2017-12-07 14:13 - 000051336 _____ (AVG Technologies CZ, s.r.o.) C:\WINDOWS\system32\Drivers\avgbuniva.sys
2018-01-04 18:42 - 2017-09-29 14:46 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-01-04 18:16 - 2017-09-29 14:46 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2018-01-04 18:16 - 2015-10-30 19:30 - 000000000 ____D C:\WINDOWS\ShellNew
2018-01-04 18:16 - 2013-12-10 19:27 - 000000000 ____D C:\Program Files\Microsoft Office
2018-01-04 18:14 - 2017-09-29 14:46 - 000000000 ____D C:\Program Files\Common Files\system
2018-01-04 18:14 - 2012-07-26 06:26 - 000000108 _____ C:\WINDOWS\win.ini
2017-12-31 12:44 - 2013-12-29 18:45 - 000000000 ____D C:\Users\Bodil Qvist\Documents\Job Bodil

==================== Files in the root of some directories =======

2014-02-02 11:05 - 2014-02-02 11:06 - 000037446 _____ () C:\Users\Bodil Qvist\AppData\Roaming\Kommaseparerede værdier.ADR
2014-02-02 11:03 - 2014-11-18 12:20 - 000020911 _____ () C:\Users\Bodil Qvist\AppData\Roaming\Kommaseparerede værdier.EML
2015-03-04 10:57 - 2015-03-04 10:58 - 000000000 _____ () C:\Users\Bodil Qvist\AppData\Local\{DA239DC5-4C8C-4C41-A185-4A81FC9C688F}

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2018-01-28 14:13

==================== End of FRST.txt ============================

 

addition:

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 27.01.2018
Ran by [removed] (30-01-2018 19:19:23)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1709 16299.192 (X64) (2017-12-07 23:29:23)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-3953898830-1776782895-4010043791-500 - Administrator - Disabled)
Bodil Qvist (S-1-5-21-3953898830-1776782895-4010043791-1001 - Administrator - Enabled) => C:\Users\Bodil Qvist
DefaultAccount (S-1-5-21-3953898830-1776782895-4010043791-503 - Limited - Disabled)
Gæst (S-1-5-21-3953898830-1776782895-4010043791-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3953898830-1776782895-4010043791-1003 - Limited - Enabled)
WDAGUtilityAccount (S-1-5-21-3953898830-1776782895-4010043791-504 - Limited - Disabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: AVG Antivirus (Enabled - Up to date) {4D41356F-32AD-7C42-C820-63775EE4F413}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: AVG Antivirus (Enabled - Up to date) {F620D48B-1497-73CC-F290-58052563BEAE}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer Power Management (HKLM\…\{91F52DE4-B789-42B0-9311-A349F10E5479}) (Version: 7.00.3012 - Acer Incorporated)
Acer Recovery Management (HKLM\…\{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}) (Version: 6.00.3016 - Acer Incorporated)
Acer Remote (HKLM-x32\…\Acer Remote1.0) (Version: 1.0 - Acer Inc.)
AcerCloud Docs (HKLM-x32\…\{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}) (Version: 1.01.2008 - Acer Incorporated)
AcerCloud Portal (HKLM-x32\…\{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}) (Version: 2.02.2021 - Acer Incorporated)
Adobe Acrobat Reader DC - Dansk (HKLM-x32\…\{AC76BA86-7AD7-1030-7B44-AC0F074E4100}) (Version: 18.009.20050 - Adobe Systems Incorporated)
Adobe Connect 9 Add-in (HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\…\Adobe Connect 9 Add-in) (Version: 11,9,974,205 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 28.0.0.137 - Adobe Systems Incorporated)
ANT Drivers Installer x64 (HKLM\…\{7664AF65-7B0D-4171-9F0F-50455278B428}) (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Mobile Device Support (HKLM\…\{C4123106-B685-48E6-B9BD-E4F911841EB4}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Apple-programunderstøttelse (32 bit) (HKLM-x32\…\{AFA1153A-F547-409B-B837-3A0D6C5A3FEC}) (Version: 3.1.3 - Apple Inc.)
Apple-programunderstøttelse (64 bit) (HKLM\…\{D7B824DE-DA32-4772-9E5E-39C5158136A7}) (Version: 3.1.3 - Apple Inc.)
AVG (HKLM\…\{136B57DF-DA9E-4361-A165-09AB4422BCD1}) (Version: 1.231.3 - AVG Technologies) Hidden
AVG AntiVirus FREE (HKLM-x32\…\AVG Antivirus) (Version: 17.9.3040 - AVG Technologies)
AVG PC TuneUp (HKLM-x32\…\{9C775BB6-1453-45EB-8C78-A5CC5199113D}) (Version: 16.77.3 - AVG Technologies) Hidden
AVG PC TuneUp (HKLM-x32\…\AVG PC TuneUp) (Version: 16.77.3.23060 - AVG Technologies)
AVG Web TuneUp (HKLM-x32\…\AVG Web TuneUp) (Version: 4.3.8.510 - AVG Technologies)
Bejeweled 3 (HKLM-x32\…\WTA-ce66965d-5117-4f5b-ac76-2f79aa4dd782) (Version: 2.2.0.98 - WildTangent) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
clear.fi Media (HKLM-x32\…\{E9AF1707-3F3A-49E2-8345-4F2D629D0876}) (Version: 2.02.2012 - Acer Incorporated)
clear.fi Photo (HKLM-x32\…\{B5AD89F2-03D3-4206-8487-018298007DD0}) (Version: 2.02.2012 - Acer Incorporated)
clear.fi SDK - Video 2 (HKLM-x32\…\{EBA33CAD-E071-48d5-A168-FBA4EEB42E93}) (Version: 2.1.2606 - CyberLink Corp.) Hidden
clear.fi SDK- Movie 2 (HKLM-x32\…\{35DA427D-BB23-49B8-9AFD-CFFCFE3B708D}) (Version: 2.1.2606 - CyberLink Corp.) Hidden
CutePDF Writer 3.0 (HKLM\…\CutePDF Writer Installation) (Version:  3.0 - CutePDF.com)
CyberLink MediaEspresso 6.5 (HKLM-x32\…\InstallShield_{E3739848-5329-48E3-8D28-5BBD6E8BE384}) (Version: 6.5.3318_45364 - CyberLink Corp.)
D3DX10 (HKLM-x32\…\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Delicious: Emily's Childhood Memories Premium Edition (HKLM-x32\…\WTA-ddc1064d-2e22-4de1-a1b5-c35c89d3aeb7) (Version: 3.0.2.32 - WildTangent) Hidden
Elevated Installer (HKLM-x32\…\{1052502B-4C91-43F9-B160-AE39ED57C9F0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
FMW 1 (HKLM\…\{36133E9F-B129-4206-9FB4-13F707787542}) (Version: 1.226.3 - AVG Technologies) Hidden
Garmin Express (HKLM-x32\…\{BCC7CA85-E57F-452D-BB44-15A1CE018BD0}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (HKLM-x32\…\{bd8bd200-9a60-4969-b267-6b565f36e3da}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries)
Garmin Express Tray (HKLM-x32\…\{DA9C865D-6762-4931-8588-0B13B7A0796B}) (Version: 5.3.1.0 - Garmin Ltd or its subsidiaries) Hidden
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 63.0.3239.132 - Google Inc.)
Google Earth Pro (HKLM-x32\…\{ECF2E224-42F5-4E50-B58E-94CA70E85697}) (Version: 7.3.0.3832 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\…\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (HKLM-x32\…\WTA-a2d92771-6c0f-473f-a967-dc972ff0699f) (Version: 2.2.0.110 - WildTangent) Hidden
Hotkey Utility (HKLM-x32\…\{A6DC88AD-501A-44BC-884D-57435F972E2C}) (Version: 3.00.3004 - Acer Incorporated)
HP FWUpdateEDO2 (HKLM-x32\…\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Officejet Pro 6830 - basissoftware til enheden (HKLM\…\{01DDFE31-EB29-431C-8572-28C91DB6C244}) (Version: 33.1.73.49987 - Hewlett-Packard Co.)
HP Officejet Pro 6830 Hjælp (HKLM-x32\…\{FC778B3A-E1E4-416A-8BB8-4388C6FBA27D}) (Version: 34.0.0 - Hewlett Packard)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Photosmart 5510 series - basissoftware til enheden (HKLM\…\{4D71E96C-944D-4476-8437-C7915C47A390}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photosmart 5510 series - undersøgelse med henblik på produktforbedringer (HKLM\…\{FEADA2C7-9474-493A-8347-AB856DC2C018}) (Version: 28.0.1315.0 - Hewlett-Packard Co.)
HP Photosmart 5510 series Hjælp (HKLM-x32\…\{E02964EA-0E1B-4620-A26E-CBAB0341B1BB}) (Version: 140.0.2.2 - Hewlett Packard)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (HKLM-x32\…\{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}) (Version: 1.00.0001 - Microsoft) Hidden
I.R.I.S. OCR (HKLM-x32\…\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Identity Card (HKLM-x32\…\{3D9CB654-99AD-4301-89C6-0D12A790767C}) (Version: 2.00.3004 - Acer Incorporated)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.0.1252 - Intel Corporation)
Intel(R) Network Connections 17.2.153.0 (HKLM\…\PROSetDX) (Version: 17.2.153.0 - Intel)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4276 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.5.0.1207 - Intel Corporation)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Java 8 Update 151 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F32180151F0}) (Version: 8.0.1510.12 - Oracle Corporation)
Jewel Match 3 (HKLM-x32\…\WTA-281dff9b-2df8-43e1-bd6a-622c9e1a96d1) (Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (HKLM-x32\…\WTA-5325c9f8-ab95-464d-9101-7f05ed6c99e5) (Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (HKLM-x32\…\{F6F30C28-38AA-4DBA-AE0B-7E30238E61BB}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Live Updater (HKLM-x32\…\{EE26E302-876A-48D9-9058-3129E5B99999}) (Version: 2.00.8102 - Acer Incorporated)
Magic Academy (HKLM-x32\…\WTA-8687c51b-2852-4c45-9339-47372bbba88c) (Version: 2.2.0.98 - WildTangent) Hidden
Microsoft Office Home and Business 2013 - da-dk (HKLM\…\HomeBusinessRetail - da-dk) (Version: 15.0.4989.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\…\OneDriveSetup.exe) (Version: 17.3.7131.1115 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DAN (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64) Language Pack - DAN) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (HKLM-x32\…\{45898170-E68C-4F02-AA35-C2186BF347A3}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\…\{705C31EB-E0AB-4C1F-A834-993F9E08B085}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 58.0.1 (x64 da) (HKLM\…\Mozilla Firefox 58.0.1 (x64 da)) (Version: 58.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 58.0.1.6602 - Mozilla)
Music Transfer (HKLM-x32\…\{CE2121C6-C94D-4A73-8EA4-6943F33EE335}) (Version: 1.3.00.11130 - Sony Corporation)
Nero BackItUp 12 Essentials OEM.a01 (HKLM-x32\…\{4CA8F973-6377-4ABF-9ED5-CC2323B3C000}) (Version: 12.5.00500 - Nero AG)
Office 15 Click-to-Run Extensibility Component (HKLM-x32\…\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.4989.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (HKLM\…\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.4989.1000 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (HKLM-x32\…\{90150000-008C-0406-0000-0000000FF1CE}) (Version: 15.0.4989.1000 - Microsoft Corporation) Hidden
Office Addin (HKLM-x32\…\{6D2BBE1D-E600-4695-BA37-0B0E605542CC}) (Version: 2.02.2008 - Acer)
Plants vs. Zombies - Game of the Year (HKLM-x32\…\WTA-9b007d41-5cf7-4ade-b4f6-8809e1108379) (Version: 2.2.0.98 - WildTangent) Hidden
Prerequisite installer (HKLM-x32\…\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0003 - Nero AG) Hidden
Primo (HKLM-x32\…\{14291118-0C19-45EA-A4FA-5C1C0F5FDE09}) (Version: 1.00.0000 - Your Company Name) Hidden
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6680 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM-x32\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.8400.39030 - Realtek Semiconductor Corp.)
Runtime (HKLM-x32\…\{DABF43D9-1104-4764-927B-5BED1274A3B0}) (Version: 1.00.0000 - Your Company Name) Hidden
Shared C Run-time for x64 (HKLM\…\{EF79C448-6946-4D71-8134-03407888C054}) (Version: 10.0.0 - McAfee)
Sony Picture Utility (HKLM-x32\…\{D5068583-D569-468B-9755-5FBF5848F46F}) (Version: 4.2.01.15030 - Sony Corporation)
Spotify (HKLM-x32\…\Spotify) (Version: 0.8.4.99.ga249b5f1 - Spotify AB)
Tales of Lagoona (HKLM-x32\…\WTA-21fca457-e155-422a-a7fb-c0522834482d) (Version: 2.2.0.110 - WildTangent) Hidden
TeamViewer 13 (HKLM-x32\…\TeamViewer) (Version: 13.0.5640 - TeamViewer)
Undersøgelse med henblik på produktforbedringer til HP Officejet Pro 6830 (HKLM\…\{417D6E41-0ED5-4F7D-A15C-4224569B5632}) (Version: 33.1.73.49987 - Hewlett-Packard Co.)
Update Installer for WildTangent Games App (HKLM-x32\…\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version:  - WildTangent) Hidden
ViewRight Web PC (HKLM-x32\…\{9071C7BA-01BA-4BC9-8EE2-80AC742EDD01}) (Version: 3.3.0.0 - Verimatrix, Inc.)
Visual Studio 2005 Tools for Office Second Edition Runtime (HKLM-x32\…\Microsoft Visual Studio 2005 Tools for Office Runtime) (Version:  - Microsoft Corporation)
Visual Studio 2012 x64 Redistributables (HKLM\…\{8C775E70-A791-4DA8-BCC3-6AB7136F4484}) (Version: 14.0.0.1 - AVG Technologies)
Visual Studio 2012 x86 Redistributables (HKLM-x32\…\{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}) (Version: 14.0.0.1 - AVG Technologies CZ, s.r.o.)
Visual Studio Tools for the Office system 3.0 Runtime (HKLM-x32\…\Visual Studio Tools for the Office system 3.0 Runtime) (Version:  - Microsoft Corporation)
Visual Studio Tools for the Office system 3.0 Runtime Service Pack 1 (KB949258) (HKLM-x32\…\{8FB53850-246A-3507-8ADE-0060093FFEA6}.KB949258) (Version: 1 - Microsoft Corporation)
WildTangent Games (HKLM-x32\…\WildTangent wildgames Master Uninstall) (Version: 1.0.4.0 - WildTangent)
WildTangent Games App (HKLM-x32\…\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer) (Version: 4.0.10.5 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows-driverpakke - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\…\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows-driverpakke - Silicon Labs Software (DSI_SiUSBXp_3_1) USB  (02/06/2007 3.1) (HKLM\…\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
WinRAR 5.01 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

CustomCLSID: HKU\S-1-5-21-3953898830-1776782895-4010043791-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel Corporation)
ShellIconOverlayIdentifiers: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2018-01-05] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [AVG Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-x64.dll [2018-01-22] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-12-01] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-12-01] (Alexander Roshal)
ContextMenuHandlers3: [00avg] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers4: [AVG Disk Space Explorer Shell Extension] -> {4838CD50-7E5D-4811-9B17-C47A85539F28} => C:\Program Files (x86)\AVG\AVG PC TuneUp\DseShExt-x64.dll [2018-01-22] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers4: [AVG Shredder Shell Extension] -> {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} => C:\Program Files (x86)\AVG\AVG PC TuneUp\SDShelEx-x64.dll [2018-01-22] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} =>  -> No File
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2016-05-03] (Intel Corporation)
ContextMenuHandlers6: [AVG] -> {472083B1-C522-11CF-8763-00608CC02F24} => C:\Program Files (x86)\AVG\Antivirus\ashShA64.dll [2018-01-05] (AVG Technologies CZ, s.r.o.)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-12-01] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-12-01] (Alexander Roshal)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {148D681C-5B5F-4DE0-B1AA-5948B641FE97} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {1BBFACAB-E2D7-4FCB-8515-72D7E894B245} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-09-05] (Microsoft Corporation)
Task: {20F91E3A-1504-421B-A7CD-080C4D203FDF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-01-09] (Adobe Systems Incorporated)
Task: {22F80839-55AB-4CBA-AEE1-54C5EAF37971} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {257BFAD5-551C-4F68-9606-99F2EC22BE74} - \WPD\SqmUpload_S-1-5-21-3953898830-1776782895-4010043791-1001 -> No File <==== ATTENTION
Task: {25C9F326-C340-4742-8EE5-6EE3B2ED55DE} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {2ABDF28A-659B-4965-A630-98203E9E7BE4} - System32\Tasks\Power Management => C:\Program Files\Acer\Acer Power Management\ePowerTray.exe [2013-01-18] (Acer Incorporated)
Task: {3310A168-2861-4951-9624-48A66A4B606C} - System32\Tasks\HPCustParticipation HP Photosmart 5510 series => C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2012-10-17] (Hewlett-Packard Co.)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {38845E4A-5EDE-4132-83D9-98D00B1593FD} - System32\Tasks\AVGPCTuneUp_Task_BkGndMaintenance => C:\Program Files (x86)\AVG\AVG PC TuneUp\tuscanx.exe [2018-01-22] (AVG Technologies CZ, s.r.o.)
Task: {4196260D-4803-462F-AD3C-2E66F1DFFD1B} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {4884E182-A5FF-4CCB-B158-445B6106478A} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {49A1F445-2D47-4887-9452-A26A0E18B701} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-31] (Google Inc.)
Task: {505C49A9-D0DB-4C57-AD65-62587A78D07B} - System32\Tasks\HP AR Program Upload - 1fde158238e0461abdcd9a82777f3e4f4a421da21a464118ad35af85ce6288c6 => C:\Program Files\HP\HP Photosmart 5510 series\bin\HPRewards.exe [2012-10-17] (TODO: )
Task: {5F356DE4-4263-4076-B266-67AF8003C31F} - System32\Tasks\HPCustParticipation HP Officejet Pro 6830 => C:\Program Files\HP\HP Officejet Pro 6830\Bin\HPCustPartic.exe [2014-07-18] (Hewlett-Packard Development Company, LP)
Task: {6D19383E-BA6F-4427-8A0C-6DFB9CA6E0F3} - System32\Tasks\Java Platform SE Auto Updater => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2017-09-05] (Oracle Corporation)
Task: {6F69E212-F7AE-4734-8349-D203AFBD26B2} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {72A049FE-B0D9-4B76-8A36-D4006498722C} - System32\Tasks\HP AR Program Upload - 323fa43fea1b4a3db6ff8a2deb4713637ed5fc0f0ea24fd198c9ad6e6f217c3d => C:\Program Files\HP\HP Photosmart 5510 series\bin\HPRewards.exe [2012-10-17] (TODO: )
Task: {7DEE27C3-3116-4C20-B14B-28702FAE29D2} - System32\Tasks\ALU => C:\Program Files (x86)\Acer\Live Updater\updater.exe [2016-07-06] ()
Task: {84867ABD-187C-4AA4-86FE-0E5A96A5F661} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-09-05] (Microsoft Corporation)
Task: {8A889FBA-2D28-4143-A005-7AC39B2B447D} - System32\Tasks\Antivirus Emergency Update => C:\Program Files (x86)\AVG\Antivirus\AvEmUpdate.exe [2018-01-05] (AVG Technologies CZ, s.r.o.)
Task: {92B5CEB3-C12F-4457-AD4E-7F9D1BF4D7BD} - System32\Tasks\HP AR Program Upload - b30ca10862334dd481db958d95d4cbd3877e6a787cfb4947873e52d9c6f59702 => C:\Program Files\HP\HP Photosmart 5510 series\bin\HPRewards.exe [2012-10-17] (TODO: )
Task: {9589009A-17F6-40CD-8758-49BC24480979} - System32\Tasks\ALUAgent => C:\Program Files (x86)\Acer\Live Updater\liveupdater_agent.exe [2016-07-06] ()
Task: {96DADE76-5C78-472A-92C8-B1EAA048E8BF} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {980C1A51-E489-4C01-AFBE-C4FB9EB8868C} - System32\Tasks\AVG\Overseer => C:\Program Files\Common Files\AVG\Overseer\overseer.exe [2018-01-05] (AVG Technologies CZ, s.r.o.)
Task: {9B2A9CB0-73ED-495F-9435-F936932FED8E} - System32\Tasks\Hotkey Utility => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe [2012-09-20] (Acer Incorporated)
Task: {ABF672F6-D545-4A18-B49D-6B004ED669D7} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-09-27] (Adobe Systems Incorporated)
Task: {AC1DC833-2E10-4674-A9E9-30C749E1E4BE} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {AE5FE471-2BEB-409C-890B-1AE5D38122B7} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {AF70C342-A8E7-4994-9445-3B6EB10E1B89} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {B384A454-1502-4215-9FCC-0BD88E5DE528} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express SelfUpdater\ExpressSelfUpdater.exe [2017-03-28] ()
Task: {C8E41BF2-2C77-4AC2-8094-E2280F4EA189} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\BrowserChoice\browserchoice.exe
Task: {CA4FE860-E4AE-4F2E-AA9A-B177D44A1391} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {CC131B74-0C6A-487B-A29E-A2841968F0CA} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)
Task: {D4841DDF-7B1E-452A-8267-1CE3B278F454} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {D488CA20-E437-419B-8D15-BDA2DDCF4474} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {D94E2D00-0BB5-4634-9ED2-41B6DAD404CC} - System32\Tasks\AVG EUpdate Task => avgsetupx.exe
Task: {DCED6BB6-974A-494E-A89E-7983054585C1} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {DE2B93FB-9EC9-4A51-BED1-AECFA3057910} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2018-01-10] (Microsoft Corporation)
Task: {F5938800-FA23-4FB8-A23C-E4C11E375B02} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {F83B44E8-B335-4003-A13E-E3C5DDA63879} - System32\Tasks\DeviceDetector => C:\Program Files (x86)\CyberLink\MediaEspresso\DeviceDetector\DeviceDetector.exe [2012-09-20] (CyberLink)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)


Shortcut: C:\Users\Bodil Qvist\Favorites\Acer\Acer.lnk -> hxxp://www.acer.com

==================== Loaded Modules (Whitelisted) ==============

2017-09-29 14:41 - 2017-09-29 14:41 - 000184432 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2014-01-04 14:25 - 2013-10-23 15:24 - 000087600 _____ () C:\WINDOWS\System32\cpwmon64.dll
2015-03-20 17:12 - 2015-03-20 17:12 - 000085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-03-20 17:12 - 2015-03-20 17:12 - 001346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2018-01-04 18:17 - 2017-01-17 03:25 - 000117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2017-12-07 14:02 - 2017-12-07 14:02 - 011044864 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2017-12-07 14:02 - 2017-12-07 14:02 - 001804288 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-01-18 12:02 - 2018-01-18 12:03 - 000086528 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkypeHost.exe
2018-01-18 12:02 - 2018-01-18 12:03 - 000195072 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkypeBackgroundTasks.dll
2018-01-18 12:02 - 2018-01-18 12:03 - 024677376 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\SkyWrap.dll
2018-01-03 18:58 - 2018-01-03 18:59 - 002550272 _____ () C:\Program Files\WindowsApps\Microsoft.SkypeApp_12.13.274.0_x64__kzf8qxf38zg5c\skypert.dll
2018-01-30 10:27 - 2018-01-30 10:28 - 000061952 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11712.1001.16.0_x64__8wekyb3d8bbwe\WinStoreTasksWrapper.dll
2017-02-14 08:42 - 2017-02-14 08:42 - 000326144 _____ () C:\Program Files (x86)\Garmin\Device Interaction Service\GpsImgWrapper.dll
2017-03-28 14:32 - 2017-03-28 14:32 - 000073216 _____ () C:\Program Files (x86)\Garmin\Device Interaction Service\FixBootSector.dll
2016-12-04 15:52 - 2016-12-04 15:52 - 048920064 _____ () C:\Program Files (x86)\AVG\UiDll\2623\libcef.dll
2013-02-06 09:06 - 2013-02-06 06:14 - 000055368 _____ () C:\Program Files (x86)\Acer Remote\plugins\general.dll
2013-02-06 09:06 - 2013-02-06 06:14 - 000041032 _____ () C:\Program Files (x86)\Acer Remote\plugins\ITunesBase.dll
2013-02-06 09:06 - 2013-02-06 06:14 - 000040520 _____ () C:\Program Files (x86)\Acer Remote\plugins\WinEight.dll
2013-02-06 09:06 - 2013-02-06 06:14 - 000111176 _____ () C:\Program Files (x86)\Acer Remote\plugins\WMPBase.dll
2018-01-05 16:47 - 2018-01-05 16:47 - 000207272 _____ () C:\Program Files (x86)\AVG\Antivirus\JsonRpcServer.dll
2018-01-05 16:47 - 2018-01-05 16:47 - 000059136 _____ () C:\Program Files (x86)\AVG\Antivirus\module_lifetime.dll
2018-01-05 16:47 - 2018-01-05 16:47 - 000058624 _____ () C:\Program Files (x86)\AVG\Antivirus\dll_loader.dll
2013-02-06 09:06 - 2013-02-06 06:14 - 000041032 _____ () C:\Program Files (x86)\Acer Remote\plugins\YTBBase.dll
2018-01-04 18:17 - 2018-01-04 18:17 - 000325824 _____ () C:\Program Files\Microsoft Office 15\root\office15\AppVIsvStream32.dll
2017-07-03 19:20 - 2017-07-03 19:20 - 067109376 _____ () C:\Program Files (x86)\AVG\Antivirus\libcef.dll
2018-01-05 16:47 - 2018-01-05 16:47 - 000290392 _____ () C:\Program Files (x86)\AVG\Antivirus\tasks_core.dll
2013-06-27 00:59 - 2012-06-25 03:41 - 001198912 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)


==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ===============================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2013-08-22 14:25 - 2013-08-22 14:25 - 000000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\Control Panel\Desktop\\Wallpaper -> c:\users\bodil qvist\pictures\2010 03 08-11 jukkasjärvi ishotel\dsc00129.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

HKLM\…\StartupApproved\Run32: => "mobilegeni daemon"
HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\…\StartupApproved\StartupFolder: => "Overvåg blækadvarsler - HP Photosmart 5510 series.lnk"
HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\…\StartupApproved\StartupFolder: => "PMB Media Check Tool.lnk"
HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\…\StartupApproved\StartupFolder: => "Overvåg blækadvarsler - HP Officejet Pro 6830.lnk"
HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\…\StartupApproved\Run: => "DAEMON Tools Lite"
HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\…\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-3953898830-1776782895-4010043791-1001\…\StartupApproved\Run: => "GarminExpressTrayApp"

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{CACEA419-0811-403C-A635-48ABB401EB68}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{5C30A602-2F3D-4725-BAB1-F37465796FC8}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{031498B5-BD22-4F50-8EDC-3B57B0AC57D1}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{19B03B12-9657-4A5D-BBE5-96A0C4D4CD0D}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{5BB9F4BF-CEEA-4C4A-A298-0AD2885162A8}] => (Allow) LPort=1688
FirewallRules: [{0340DDEA-EB37-4C06-8021-70D536D6C668}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{13138A0C-913E-484D-A4BA-B3D285694FCB}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
FirewallRules: [{06E96FB0-5C7A-446D-8F6D-21CF7B2A5E2E}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{3EDF870D-E29F-471F-9AC2-14D92C0136A2}] => (Allow) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer.exe
FirewallRules: [{A2D9C178-E257-4615-A419-4287387C4BB7}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{90437529-942E-4CA9-AE70-3F22C07F79A2}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe
FirewallRules: [{6DB1245B-106C-46AC-A080-CDCBD5C09D92}] => (Allow) C:\Program Files\HP\HP Photosmart 5510 series\Bin\DeviceSetup.exe
FirewallRules: [{E25A50D7-EB92-4767-95F0-C8CB57C3727A}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{A5A0E8B3-7F3A-4D0C-8FD2-E1B55DB8B91F}] => (Allow) LPort=1900
FirewallRules: [{FB4532ED-F18B-462F-A186-5E1AAA575B52}] => (Allow) LPort=2869
FirewallRules: [{4D6AC667-F4DD-4025-9D03-2C9AAEFAB9F3}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{1DE8C92E-D5FE-42F3-9AD2-8CB772EBCA52}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{25600213-2501-48DC-A180-AC2884A2D6BE}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{29923CC0-45AF-431D-8E56-3BB36D66FB81}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{7E781AAA-7CB6-47D5-9E67-B5E975940DCF}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{87215447-0702-43E1-B9B1-07A9A63990A7}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\virtualdrive.exe
FirewallRules: [{4B730FB7-BE8B-42B5-AF0F-673872F600A6}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\virtualdrive.exe
FirewallRules: [{ABD75F96-3480-4AC3-B732-A658EB77C0B2}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\Sdd.exe
FirewallRules: [{F1FB8BC4-26E6-47CA-A810-A9EED3323E2B}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\Sdd.exe
FirewallRules: [{35937EDA-FFA5-4EAD-9AB2-2CFCDCEE4685}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\ccd.exe
FirewallRules: [{566ACFCA-F7A6-49CB-892D-4DA9BEA3F857}] => (Allow) C:\Program Files (x86)\Acer\Acer Cloud\ccd.exe
FirewallRules: [{40AE2506-00DA-4EF6-A286-87AC232911B6}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
FirewallRules: [{8395779D-83F5-4E02-B39A-00154D874BD2}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\WindowsUpnp.exe
FirewallRules: [{42D66C09-8E97-451B-9A54-6632312B01A2}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
FirewallRules: [{631AD1FA-F5BE-43E0-BC85-0587363DDB5E}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Photo\DMCDaemon.exe
FirewallRules: [{30E8012B-1099-4774-8B82-1A378FBDAF23}] => (Allow) C:\Program Files (x86)\Acer\clear.fi SDK21\Video\VideoPlayer.exe
FirewallRules: [{48DD48A8-D7C2-4197-A7A4-99C252532676}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
FirewallRules: [{5A0BE6AA-0787-4E50-B18B-8AE4CDB0F1CC}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\WindowsUpnpMV.exe
FirewallRules: [{6F7095FF-E100-41F0-AA85-605E3BE9877D}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
FirewallRules: [{48D80128-90C3-44EA-A525-93B9585D0F2B}] => (Allow) C:\Program Files (x86)\Acer\clear.fi Media\DMCDaemon.exe
FirewallRules: [{B081CB0E-D4D5-49D0-A62F-B38803E562E1}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{EA3D5257-2877-4F9E-BAF0-0C74A3E6B54C}] => (Allow) C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
FirewallRules: [{4622DCB9-41D6-42B0-B45B-FF2654E32224}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{C24D100E-343C-478D-B10B-D1DD1C0B88BA}] => (Allow) C:\Program Files (x86)\Spotify\spotify.exe
FirewallRules: [{BEB37BEB-E44A-4C7D-B1AD-8B05AE800563}] => (Allow) C:\Program Files (x86)\Acer Remote\ArcServer.exe
FirewallRules: [{6ACDE4E1-EBD5-446A-B0A4-1B4AD4B516A5}] => (Allow) C:\Program Files (x86)\Acer Remote\ArcServer.exe
FirewallRules: [{A04D9678-AA86-466B-9E6F-B969C467652A}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{D788FE3B-1CFC-4C1C-B95C-7F502AA5C218}] => (Allow) C:\Program Files (x86)\Nero\Nero 12\Nero BackItUp\BackItUp.exe
FirewallRules: [{0BBBB10E-EF86-4A0E-8924-88DAA202A974}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [{84713241-FB02-40AF-9313-0747BE6445A2}] => (Allow) C:\Windows\System32\KMSServer.exe
FirewallRules: [TCP Query User{DEC5C271-943D-4997-B571-11B1A310697A}C:\program files (x86)\acer remote\arcserver.exe] => (Allow) C:\program files (x86)\acer remote\arcserver.exe
FirewallRules: [UDP Query User{BBB57109-6E58-4ED7-B1F9-0155F3D8F0CE}C:\program files (x86)\acer remote\arcserver.exe] => (Allow) C:\program files (x86)\acer remote\arcserver.exe
FirewallRules: [{08F7658E-B158-4B8D-9A97-24B2375CE4B0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{6E489D5B-E5A9-480D-8606-C4F97E37789E}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{4F5E0529-97F2-424C-B687-B4303E21A70F}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{0E408F3A-ECD9-4A54-8B58-D2708C6A2AE2}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe
FirewallRules: [{70BC4424-3F11-4D23-9A05-742B8179C024}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{BE827CC0-2974-4336-8252-80C336FF7F02}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1D1C2F4E-3EFE-4BF8-A688-74B584572419}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{E13BD72E-6F21-4728-ADF8-9CACD9F43715}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{ECD62EFE-1F1F-43B9-BA17-B3449082C94D}] => (Allow) C:\Program Files\HP\HP Officejet Pro 6830\bin\FaxApplications.exe
FirewallRules: [{38574EB9-8BFE-4804-AE3F-56A2ACA09A7B}] => (Allow) C:\Program Files\HP\HP Officejet Pro 6830\bin\DigitalWizards.exe
FirewallRules: [{08019E9D-5FF5-42CC-9FC7-047FA452F107}] => (Allow) C:\Program Files\HP\HP Officejet Pro 6830\bin\SendAFax.exe
FirewallRules: [{3ABFFD8E-7335-414E-9032-B8CFAE14EF88}] => (Allow) C:\Program Files\HP\HP Officejet Pro 6830\Bin\DeviceSetup.exe
FirewallRules: [{5AA5BAFC-0795-406F-A74C-30AE1A589811}] => (Allow) LPort=5357
FirewallRules: [{21DD5BCA-4A27-41CC-B370-D358CDB8348F}] => (Allow) C:\Program Files\HP\HP Officejet Pro 6830\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{1EA9CEDF-A8E9-41B5-98EC-7AEEE5432063}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{C2B909DA-04BF-4368-85CF-B29ED61AAF9B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{2E8F90C2-C542-40BB-A42D-56BE51E329D1}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [{387328D0-52BB-4F88-AFE3-CC488B4FBF91}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Restore Points =========================

10-01-2018 10:53:10 Windows Update
18-01-2018 18:01:22 Planlagt kontrolpunkt
25-01-2018 19:29:25 Planlagt kontrolpunkt

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (01/30/2018 11:00:40 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1172

Error: (01/30/2018 11:00:40 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1172

Error: (01/30/2018 11:00:40 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (01/30/2018 10:27:12 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Navn på program med fejl: esu.exe, version: 1.0.0.0, tidsstempel: 0x58dac8d5
Navn på modul med fejl: KERNELBASE.dll, version: 10.0.16299.15, tidsstempel: 0x2cd1ce3d
Undtagelseskode: 0xe0434352
Forskydning med fejl 0x001008b2
Proces-id 0x24bc
Programmets starttidspunkt 0x01d399ac7d869db6
Programsti: C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe
Modulsti: C:\WINDOWS\System32\KERNELBASE.dll
Rapport-id: 3c2572e5-ac84-4718-b70a-64da94c9f685
Fuldt navn på program med fejl:
Relativt program-id for program med fejl:

Error: (01/30/2018 10:27:12 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Program: esu.exe
Framework-version: v4.0.30319
Beskrivelse: Denne proces blev afsluttet pga. en ubehandlet undtagelse.
Undtagelsesoplysninger: System.IO.FileNotFoundException
   ved Garmin.Omt.Service.Shared.Overrides+d__61.MoveNext()
   ved System.Runtime.CompilerServices.AsyncTaskMethodBuilder.Start[[Garmin.Omt.Service.Shared.Overrides+d__61, ExpressSelfUpdater, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]](d__61 ByRef)
   ved Garmin.Omt.Service.Shared.Overrides.UpdateDatacenterOverridesAsync(Boolean)
   ved Garmin.Omt.Service.Shared.Overrides..cctor()

Undtagelsesoplysninger: System.TypeInitializationException
   ved Garmin.Omt.Service.Shared.Overrides.get_OmtBaseUrl()
   ved Garmin.Omt.Express.SelfUpdater.Program.RealMain()
   ved Garmin.Omt.Express.SelfUpdater.Program.Main(System.String[])

Error: (01/29/2018 10:34:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Navn på program med fejl: esu.exe, version: 1.0.0.0, tidsstempel: 0x58dac8d5
Navn på modul med fejl: KERNELBASE.dll, version: 10.0.16299.15, tidsstempel: 0x2cd1ce3d
Undtagelseskode: 0xe0434352
Forskydning med fejl 0x001008b2
Proces-id 0x2300
Programmets starttidspunkt 0x01d398e45aae3c80
Programsti: C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe
Modulsti: C:\WINDOWS\System32\KERNELBASE.dll
Rapport-id: 8b7ce5e2-ca7c-4486-b057-bd1d8d956b61
Fuldt navn på program med fejl:
Relativt program-id for program med fejl:

Error: (01/29/2018 10:34:31 AM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Program: esu.exe
Framework-version: v4.0.30319
Beskrivelse: Denne proces blev afsluttet pga. en ubehandlet undtagelse.
Undtagelsesoplysninger: System.IO.FileNotFoundException
   ved Garmin.Omt.Service.Shared.Overrides+d__61.MoveNext()
   ved System.Runtime.CompilerServices.AsyncTaskMethodBuilder.Start[[Garmin.Omt.Service.Shared.Overrides+d__61, ExpressSelfUpdater, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]](d__61 ByRef)
   ved Garmin.Omt.Service.Shared.Overrides.UpdateDatacenterOverridesAsync(Boolean)
   ved Garmin.Omt.Service.Shared.Overrides..cctor()

Undtagelsesoplysninger: System.TypeInitializationException
   ved Garmin.Omt.Service.Shared.Overrides.get_OmtBaseUrl()
   ved Garmin.Omt.Express.SelfUpdater.Program.RealMain()
   ved Garmin.Omt.Express.SelfUpdater.Program.Main(System.String[])

Error: (01/28/2018 12:48:43 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Navn på program med fejl: esu.exe, version: 1.0.0.0, tidsstempel: 0x58dac8d5
Navn på modul med fejl: KERNELBASE.dll, version: 10.0.16299.15, tidsstempel: 0x2cd1ce3d
Undtagelseskode: 0xe0434352
Forskydning med fejl 0x001008b2
Proces-id 0xa84
Programmets starttidspunkt 0x01d3982df0580f72
Programsti: C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe
Modulsti: C:\WINDOWS\System32\KERNELBASE.dll
Rapport-id: 08cf71e6-337c-481c-842c-b2c237f3cdfc
Fuldt navn på program med fejl:
Relativt program-id for program med fejl:

Error: (01/28/2018 12:48:42 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Program: esu.exe
Framework-version: v4.0.30319
Beskrivelse: Denne proces blev afsluttet pga. en ubehandlet undtagelse.
Undtagelsesoplysninger: System.IO.FileNotFoundException
   ved Garmin.Omt.Service.Shared.Overrides+d__61.MoveNext()
   ved System.Runtime.CompilerServices.AsyncTaskMethodBuilder.Start[[Garmin.Omt.Service.Shared.Overrides+d__61, ExpressSelfUpdater, Version=1.0.0.0, Culture=neutral, PublicKeyToken=null]](d__61 ByRef)
   ved Garmin.Omt.Service.Shared.Overrides.UpdateDatacenterOverridesAsync(Boolean)
   ved Garmin.Omt.Service.Shared.Overrides..cctor()

Undtagelsesoplysninger: System.TypeInitializationException
   ved Garmin.Omt.Service.Shared.Overrides.get_OmtBaseUrl()
   ved Garmin.Omt.Express.SelfUpdater.Program.RealMain()
   ved Garmin.Omt.Express.SelfUpdater.Program.Main(System.String[])

Error: (01/27/2018 02:11:26 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Navn på program med fejl: esu.exe, version: 1.0.0.0, tidsstempel: 0x58dac8d5
Navn på modul med fejl: KERNELBASE.dll, version: 10.0.16299.15, tidsstempel: 0x2cd1ce3d
Undtagelseskode: 0xe0434352
Forskydning med fejl 0x001008b2
Proces-id 0x1a14
Programmets starttidspunkt 0x01d3977054633d6a
Programsti: C:\Program Files (x86)\Garmin\Express SelfUpdater\esu.exe
Modulsti: C:\WINDOWS\System32\KERNELBASE.dll
Rapport-id: bb346adc-ccd6-4a22-9a04-2b7bfdc5a798
Fuldt navn på program med fejl:
Relativt program-id for program med fejl:


System errors:
=============
Error: (01/30/2018 07:15:58 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Adgangsindstillingerne programspecifikke giver ikke Lokal Aktivering adgang til COM-serverprogrammet med CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 og APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 for brugeren NT AUTHORITY\LOKAL TJENESTE SID (S-1-5-19) fra adressen LocalHost (via LRPC), der kører i programbeholderen Ikke tilgængelig SID (Ikke tilgængelig). Denne sikkerhedstilladelse kan redigeres ved hjælp af administrationsværktøjet til komponenttjenester.

Error: (01/30/2018 07:15:58 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Adgangsindstillingerne programspecifikke giver ikke Lokal Aktivering adgang til COM-serverprogrammet med CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 og APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 for brugeren NT AUTHORITY\LOKAL TJENESTE SID (S-1-5-19) fra adressen LocalHost (via LRPC), der kører i programbeholderen Ikke tilgængelig SID (Ikke tilgængelig). Denne sikkerhedstilladelse kan redigeres ved hjælp af administrationsværktøjet til komponenttjenester.

Error: (01/30/2018 07:15:58 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Adgangsindstillingerne programspecifikke giver ikke Lokal Aktivering adgang til COM-serverprogrammet med CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 og APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 for brugeren NT AUTHORITY\LOKAL TJENESTE SID (S-1-5-19) fra adressen LocalHost (via LRPC), der kører i programbeholderen Ikke tilgængelig SID (Ikke tilgængelig). Denne sikkerhedstilladelse kan redigeres ved hjælp af administrationsværktøjet til komponenttjenester.

Error: (01/30/2018 07:15:58 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Adgangsindstillingerne programspecifikke giver ikke Lokal Aktivering adgang til COM-serverprogrammet med CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 og APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 for brugeren NT AUTHORITY\LOKAL TJENESTE SID (S-1-5-19) fra adressen LocalHost (via LRPC), der kører i programbeholderen Ikke tilgængelig SID (Ikke tilgængelig). Denne sikkerhedstilladelse kan redigeres ved hjælp af administrationsværktøjet til komponenttjenester.

Error: (01/30/2018 07:15:38 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: Computeren blev genstartet efter en fejlkontrol. Fejlkontrollen var: 0x000000d1 (0xfffff8022a852010, 0x00000000000000ff, 0x0000000000000000, 0xfffff802272f95ae). Der blev gemt et dump i: C:\WINDOWS\MEMORY.DMP. Rapport-id: b829a891-9577-492c-b2e5-69c12f124237.

Error: (01/30/2018 07:14:50 PM) (Source: EventLog) (EventID: 6008) (User: )
Description: Den foregående systemlukning kl. 19:13:28 d. ‎30-‎01-‎2018 var uventet.

Error: (01/30/2018 07:06:44 PM) (Source: BugCheck) (EventID: 1001) (User: )
Description: Computeren blev genstartet efter en fejlkontrol. Fejlkontrollen var: 0x00000050 (0xfffff6fb7dbedd08, 0x0000000000000000, 0xfffff8004e0478be, 0x0000000000000002). Der blev gemt et dump i: C:\WINDOWS\MEMORY.DMP. Rapport-id: 1b88e3f8-a50e-49e0-89bd-d90b5341c450.

Error: (01/30/2018 07:05:12 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Adgangsindstillingerne programspecifikke giver ikke Lokal Aktivering adgang til COM-serverprogrammet med CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 og APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 for brugeren NT AUTHORITY\LOKAL TJENESTE SID (S-1-5-19) fra adressen LocalHost (via LRPC), der kører i programbeholderen Ikke tilgængelig SID (Ikke tilgængelig). Denne sikkerhedstilladelse kan redigeres ved hjælp af administrationsværktøjet til komponenttjenester.

Error: (01/30/2018 07:05:12 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Adgangsindstillingerne programspecifikke giver ikke Lokal Aktivering adgang til COM-serverprogrammet med CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 og APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 for brugeren NT AUTHORITY\LOKAL TJENESTE SID (S-1-5-19) fra adressen LocalHost (via LRPC), der kører i programbeholderen Ikke tilgængelig SID (Ikke tilgængelig). Denne sikkerhedstilladelse kan redigeres ved hjælp af administrationsværktøjet til komponenttjenester.

Error: (01/30/2018 07:05:12 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: Adgangsindstillingerne programspecifikke giver ikke Lokal Aktivering adgang til COM-serverprogrammet med CLSID
{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
 og APPID
{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
 for brugeren NT AUTHORITY\LOKAL TJENESTE SID (S-1-5-19) fra adressen LocalHost (via LRPC), der kører i programbeholderen Ikke tilgængelig SID (Ikke tilgængelig). Denne sikkerhedstilladelse kan redigeres ved hjælp af administrationsværktøjet til komponenttjenester.


CodeIntegrity:
===================================
  Date: 2018-01-30 19:20:08.106
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

  Date: 2018-01-30 19:20:08.104
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

  Date: 2018-01-30 19:20:00.262
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

  Date: 2018-01-30 19:20:00.261
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

  Date: 2018-01-30 19:15:58.326
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

  Date: 2018-01-30 19:15:58.324
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

  Date: 2018-01-30 19:15:46.932
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

  Date: 2018-01-30 19:15:46.931
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

  Date: 2018-01-30 19:14:55.462
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.

  Date: 2018-01-30 19:14:55.461
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Windows\System32\svchost.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Microsoft signing level requirements.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i3-3240 CPU @ 3.40GHz
Percentage of memory in use: 39%
Total physical RAM: 6028.3 MB
Available physical RAM: 3630.32 MB
Total Virtual: 6988.3 MB
Available Virtual: 4781.66 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:456.22 GB) (Free:394.91 GB) NTFS
Drive d: (DATA) (Fixed) (Total:457.05 GB) (Free:456.9 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: 1DB6AE9F)

Partition: GPT.

==================== End of Addition.txt ============================

Hello Guffegris and welcome to WTT.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

===================================================

Note: Please complete these tasks in the order given in the instructions.

===================================================

Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean
  • if it asks to reboot, allow the reboot
  • on reboot a log will be produced; please attach the content of the log to your next reply.

===================================================

Run Malwarebytes Anti-Malware

Please download and run the installer for Malwarebytes 3.0.

  • follow the prompts to install the program, (Malwarebytes 3.0 will automatically upgrade Malwarebytes Anti-Malware 2.x to Malwarebytes 3.0)
  • at the end, be sure a checkmark is placed next to the following
    • Launch Malwarebytes Anti-Malware
    • a 14 day trial of the Premium features is pre-selected: deselect this if you don’t want it, (it won’t diminish the scanning and removal capabilities of the program).
  • click Finish.
  • on the Dashboard, click Update Now
  • after the update completes, click the Scan Now' button.
  • if an update is available, clicking the Update Now button will update it
  • a Threat Scan will begin.
  • when the scan is complete, if malware has been detected, click Apply Actions to allow MBAM to clean what was found
  • when the prompt to restart the computer appears, click Yes.
  • after the restart once you are back at your desktop, open MBAM once more
  • click on the ‘History’ tab, the ‘Application Logs’
  • double-click on the scan log which shows the date and time of the scan just performed.
  • click Copy to Clipboard
  • please paste the contents of the clipboard into your reply.

Logs to include with the next post:

AdwCleaner log
Mbam.txt


Thanks

Satchfan

 

Hi Satchfan!

 

Thanks for your advise! :-) - I followed your instructions, and I believe that Mbytes actually found the malware that caused the issue! - the name of a site that it blocked matched what we have seen, but I believe that the issue is not completely solved by this, as Mbytes now pops up instead, telling that it has blocked some unwanted content…

 

Here follows the logs:

 

# AdwCleaner 7.0.7.0 - Logfile created on Thu Feb 01 19:08:53 2018
# Updated on 2018/18/01 by Malwarebytes
# Database: 01-31-2018.1
# Running on Windows 10 Home (X64)
# Mode: scan
# Support: https://www.malwarebytes.com/support

***** [ Services ] *****

No malicious services found.

***** [ Folders ] *****

PUP.Optional.Legacy, C:\Program Files (x86)\Mobogenie
PUP.Optional.Legacy, C:\Users\Bodil Qvist\AppData\Local\Mobogenie
PUP.Optional.Legacy, C:\ProgramData\AVG Secure Search
PUP.Optional.Legacy, C:\ProgramData\Application Data\AVG Secure Search
PUP.Optional.Legacy, C:\Program Files\Common Files\AVG Secure Search
PUP.Optional.Legacy, C:\Program Files (x86)\Common Files\AVG Secure Search
PUP.Optional.Legacy, C:\Users\All Users\AVG Secure Search
PUP.Optional.Legacy, C:\avg web tuneup
PUP.Optional.Legacy, C:\ProgramData\avg web tuneup
PUP.Optional.Legacy, C:\ProgramData\Application Data\avg web tuneup
PUP.Optional.Legacy, C:\Program Files\avg web tuneup
PUP.Optional.Legacy, C:\Program Files (x86)\avg web tuneup
PUP.Optional.Legacy, C:\Users\All Users\avg web tuneup
PUP.Optional.Legacy, C:\Users\Bodil Qvist\AppData\Local\avg web tuneup
Rogue.ForcedExtension, C:\ProgramData\apn
Rogue.ForcedExtension, C:\ProgramData\Application Data\apn
Rogue.ForcedExtension, C:\Users\All Users\apn


***** [ Files ] *****

PUP.Optional.Legacy, C:\Users\Bodil Qvist\daemonprocess.txt
PUP.Optional.Legacy, C:\Users\Bodil Qvist\AppData\Roaming\Mozilla\Firefox\Profiles\pvay76ue.default\searchplugins\avg-secure-search.xml


***** [ DLL ] *****

No malicious DLLs found.

***** [ WMI ] *****

No malicious WMI found.

***** [ Shortcuts ] *****

No malicious shortcuts found.

***** [ Tasks ] *****

No malicious tasks found.

***** [ Registry ] *****

PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\DOMStorage\wajam.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\mysearch.avg.com
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\unicef.org
PUP.Optional.Legacy, [Key] - HKCU\Software\Microsoft\Internet Explorer\LowRegistry\DOMStorage\www.unicef.org
PUP.Optional.Legacy, [Data] - HKCU\Software\Microsoft\Internet Explorer\Main | Start Page [https:\\mysearch.avg.com\?cid=%7B1CFC5432-3AAB-4DE1-A065-49B1455CC6A7%7D&mid=c52fb3586a5b47cd9caca56eacb95508-823eaa8ee4e10acb741c51064ca753d1344fe360&lang=da&ds=AVG&coid=avgtbavg&cmpid=0615pi&pr=fr&d=2015-07-27%2012:27:32&v=4.2.4.155&pid=wtu&sg=&sap=hp]
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\AVG Tuneup
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Classes\TypeLib\{4BC8AD89-AC5F-4DBD-A38F-C355C7DD33D7}
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 | mobilegeni daemon
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\MozillaPlugins\@avg.com\AVG SiteSafety plugin,version=11.0.0.1,application\x-avg-sitesafety-plugin
PUP.Optional.Legacy, [Key] - HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
PUP.Optional.Legacy, [Value] - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run32 | mobilegeni daemon


***** [ Firefox (and derivatives) ] *****

No malicious Firefox entries.

***** [ Chromium (and derivatives) ] *****

PUP.Optional.Legacy, Plugin found: AVG Web TuneUp -

/!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271


*************************



########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt ##########

 

 

——————————————————————————————————————-

 

 

Malwarebytes
www.malwarebytes.com

-Logoplysninger-
Scanningsdato: 01/02/2018
Scanningstidspunkt: 20.19
Logfil: cc9f037a-0784-11e8-ae1f-7427ea5dbcfb.json
Administrator: Ja

-Softwareoplysninger-
Version: 3.3.1.2183
Komponentversion: 1.0.262
Opdatér pakkeversion: 1.0.3843
Licens: Prøveversion

-Systemoplysninger-
OS: Windows 10 (Build 16299.192)
CPU: x64
Filsystem: NTFS
Bruger: Bodil\Bodil Qvist

-Scanningsoversigt-
Scanningstype: Trusselsscanning
Resultat: Fuldført
Scannede objekter: 344654
Registrerede trusler: 4
Trusler i karantæne: 4
Forløbet tid: 7 min, 43 sek.

-Scanningsindstillinger-
Hukommelse: Aktiveret
Start: Aktiveret
Filsystem: Aktiveret
Arkiver: Aktiveret
Rootkits: Deaktiveret
Heuristik: Aktiveret
PUP: Registrér
PUM: Registrér

-Scanningsoplysninger-
Proces: 0
(Ingen skadelige elementer registreret)

Modul: 0
(Ingen skadelige elementer registreret)

Registreringsnøgle: 0
(Ingen skadelige elementer registreret)

Registreringsværdi: 0
(Ingen skadelige elementer registreret)

Registreringsdata: 0
(Ingen skadelige elementer registreret)

Datastrøm: 0
(Ingen skadelige elementer registreret)

Mappe: 0
(Ingen skadelige elementer registreret)

Fil: 4
PUP.Optional.FFHijacker, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\DEFAULTS\PREF\2529906.js, I karantæne, [1104], [484671],1.0.3843
PUP.Optional.FFHijacker, C:\PROGRAM FILES (X86)\MOZILLA FIREFOX\2529906.CFG, I karantæne, [1104], [345404],1.0.3843
PUP.Optional.InstallCore, C:\USERS\BODIL QVIST\DOWNLOADS\UPDATESTAR_ENU_INSTALLER.EXE, I karantæne, [2], [65139],1.0.3843
PUP.Optional.InstallCore, C:\USERS\BODIL QVIST\DOWNLOADS\UPDATESTAR_ENU_INSTALLER(1).EXE, I karantæne, [2], [65139],1.0.3843

Fysisk sektor: 0
(Ingen skadelige elementer registreret)


(end)

 

—————————————-

 

Malwarebytes
www.malwarebytes.com

-Logoplysninger-
Dato for beskyttelseshændelse: 01/02/2018
Tidspunkt for beskyttelseshændelse: 20.31
Logfil: 8a4204f9-0786-11e8-8e44-7427ea5dbcfb.json
Administrator: Ja

-Softwareoplysninger-
Version: 3.3.1.2183
Komponentversion: 1.0.262
Opdatér pakkeversion: 1.0.3843
Licens: Prøveversion

-Systemoplysninger-
OS: Windows 10 (Build 16299.192)
CPU: x64
Filsystem: NTFS
Bruger: System

-Oplysninger om blokeret websted-
Skadeligt websted: 1
, , Blokeret, [-1], [-1],0.0.0

-Webstedsdata-
Kategori: Uspecificeret
Domæne: pipeschannels.com
IP-adresse: 194.187.98.190
Port: [49863]
Type: Udgående
Fil: C:\Program Files (x86)\Mozilla Firefox\firefox.exe



(end)

 

———————–

 

Malwarebytes
www.malwarebytes.com

-Logoplysninger-
Dato for beskyttelseshændelse: 01/02/2018
Tidspunkt for beskyttelseshændelse: 20.31
Logfil: 8a4b8e88-0786-11e8-a4ac-7427ea5dbcfb.json
Administrator: Ja

-Softwareoplysninger-
Version: 3.3.1.2183
Komponentversion: 1.0.262
Opdatér pakkeversion: 1.0.3843
Licens: Prøveversion

-Systemoplysninger-
OS: Windows 10 (Build 16299.192)
CPU: x64
Filsystem: NTFS
Bruger: System

-Oplysninger om blokeret websted-
Skadeligt websted: 1
, , Blokeret, [-1], [-1],0.0.0

-Webstedsdata-
Kategori: Uspecificeret
Domæne: pipeschannels.com
IP-adresse: 194.187.98.190
Port: [49863]
Type: Udgående
Fil: C:\Program Files (x86)\Mozilla Firefox\firefox.exe



(end)

Sorry for the delay in responding but I must have missed the notification.

I think the best thing is to uninstall and reinstall Firefox; this will clear out all user data and plugins etc, so you are starting with a fresh install of Firefox.

You can backup your bookmarks if you need to but you will need to install any addins again.

Also note down any passwords etc.

Download a new copy of Firefox from here and save it to your desktop.

How to backup your bookmarks

  • open Firefox.
  • click the “Bookmarks” menu
  • click select Show All Bookmarks
  • in the “Library” window, click the Import and Backup button and then select Backup
  • in the “Bookmarks backup filename” window that opens, choose a location to save the file, which is named Bookmarks-"date".json by default
  • once the backup has run, close all windows and check location for backup file.

Remove Firefox and Mozilla Maintenance Service

  • click on Start, Run
  • in the open text entry box please copy/paste appwiz.cpl Then click Enter.
  • press the Remove or Change/Remove button to uninstall Firefox and Mozilla Maintenance Service

Delete folders in red

C:\Program Files (x86)\Mozilla Firefox
C:\Users\Bodil Qvist\AppData\Roaming\Mozilla
C:\Program Files (x86)\Mozilla Maintenance Service


Reboot and install the new copy of Firefox that you saved to the desktop.

Install the new copy of Firefox that you saved to the desktop.

Restore Bookmarks

  • open Firefox
  • click the “Bookmarks” menu
  • click Show All Bookmarks
  • in the “Library” window, click the “Import and Backup” button and then select Restore
  • in the “Bookmarks backup filename” window that opens, choose the location you saved the backup file to

When the restore has taken place, close all windows.

================================================

Please run FRST again and make sure there is a checkmark next to ‘Addition.txt’ before you hit Scan.

Logs to include with next post:

New Frst.txt
New Addition.txt


Thanks

Satchfan

Hi Satchfan,

 

I am sorry for the late answer, but I have been busy, - and I still am! - so I am sorry to say that I wont be able to try this out  for several days, maybe up to a week. :-( - I hope that this will not be a problem, but the matter is NOT forgotten. I will return with the results as soon as I get the chance. I hope that this will be acceptable. Sorry for the inconvenience…

No problem: I'll keep it open but in future please let me know if there will be a delay as I too am very busy. ;)

 

Hope all goes well.

 

Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI