So I make my kids use the guest account on this PC just for this reason, but they have inadvertently contracted some malware that I can't even locate at this point. Luckily the effects seem to be confined to the guest account only, but it's so bad they can no longer run games so I need to jump in and fix it. I ran malwarebytes and it didn't help, so now I'm here to ask some professionals.
I've run all these scans (as administrator) while logged into the guest account hoping that helps identify issues.
17:20:23.434 Disk 0 Vendor: WDC_WD1600AAJS-00WAA0 58.01D58 Size: 152627MB BusType: 11
17:20:23.437 Disk 1 Vendor: INTEL_SSDSC2CT060A3 300i Size: 57241MB BusType: 11
17:20:23.438 Disk 2 (boot) \Device\Harddisk2\DR2 -> \Device\Ide\IdeDeviceP1T0L0-1
17:20:23.440 Disk 2 Vendor: ST1000DM005_HD103SJ 1AJ100E5 Size: 953869MB BusType: 11
17:20:23.759 Disk 2 Partition 1 80 (A) 07 HPFS/NTFS NTFS 953867 MB offset 2048
17:21:04.267 ntoskrnl.exe CLASSPNP.SYS disk.sys ataport.SYS PCIIDEX.SYS hal.dll msahci.sys
17:21:04.272 3 CLASSPNP.SYS[fffff880017b643f] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0xfffffa80078fe680]
17:44:10.370 File: C:\Users\Ian\AppData\Local\Temp\cpnprt2.cid **INFECTED** Win32:Adware-gen [Adw]
18:21:39.596 Disk 2 MBR has been saved successfully to "C:\Users\Ian\Desktop\MBR.dat"
18:21:39.600 The log file has been saved successfully to "C:\Users\Ian\Desktop\aswMBR.txt"
18:51:43.292 Disk 2 MBR has been saved successfully to "C:\Users\Ian\Desktop\MBR.dat"
18:51:43.294 The log file has been saved successfully to "C:\Users\Ian\Desktop\aswMBR.txt"
18:52:06.699 Disk 2 MBR has been saved successfully to "C:\Users\Ian\Documents\MBR.dat"
18:52:06.701 The log file has been saved successfully to "C:\Users\Ian\Documents\aswMBR.txt"
18:53:24.453 Disk 2 MBR has been saved successfully to "C:\Users\Ian\Desktop\MBR.dat"
18:53:24.456 The log file has been saved successfully to "C:\Users\Ian\Desktop\aswMBR_1.txt"
18:54:00.255 The log file has been saved successfully to "C:\Users\Ian\aswMBR.txt"
[removed]
Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe
(BlueStack Systems, Inc.) C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe
(LeapFrog Enterprises, Inc.) C:\Program Files (x86)\LeapFrog\LeapFrog Connect\CommandService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Edimax\Common\RaRegistry.exe
(Ralink Technology, Corp.) C:\Program Files (x86)\Edimax\Common\RaRegistry64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Valve Corporation) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intuit Inc.) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(AVAST Software) C:\Users\Guest\Desktop\aswMBR.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297784 2017-09-11] (Apple Inc.)
HKLM-x32\…\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-26] (Intel Corporation)
HKLM-x32\…\Run: [Monitor] => C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe [124544 2016-02-11] (LeapFrog Enterprises, Inc.)
HKLM-x32\…\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\…\Run: [] => [X]
HKLM-x32\…\Run: [BlueStacks Agent] => C:\Program Files (x86)\BlueStacks\HD-Agent.exe [896608 2015-12-01] (BlueStack Systems, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2017-09-18] (Apple Inc.)
HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\Run: [Dropbox Update] => C:\Users\Ian\AppData\Local\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\Run: [HP Officejet 5740 series (NET)] => C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe [3483656 2014-08-22] (Hewlett-Packard Development Company, LP)
HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\Run: [BingSvc] => C:\Users\Ian\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2016-01-22] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\Run: [Cricut Design Space3] => C:\Users\Ian\AppData\Roaming\CricutDesignSpace3\BRIDGE\CricutLauncher4.exe [459784 2018-06-15] (Provo Craft & Novelty, Inc.)
HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\MountPoints2: {c2a7ef15-f7e3-11e1-80be-806e6f6e6963} - D:\setup.exe
HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…409d6c4515e9\InprocServer32: [Default-shell32] C:\$Recycle.Bin\S-1-5-21-997336396-1215893520-3887361402-1000\$414aefbca990bda5922c7721d5f6cb3a\n. ATTENTION
HKU\S-1-5-21-997336396-1215893520-3887361402-501\…\MountPoints2: D - D:\setup.exe
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{676D0AFB-E013-490C-BFFA-528D57C272FE}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{72117F9C-8D0F-4FD0-8673-B3FADD424C86}: [DhcpNameServer] 192.168.1.1
Internet Explorer:
==================
HKU\S-1-5-21-997336396-1215893520-3887361402-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <==== ATTENTION
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
SearchScopes: HKLM -> DefaultScope {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B} URL =
SearchScopes: HKLM -> {fcd9f10e-0daa-405f-bca0-0dd3f37c59d9} URL =
SearchScopes: HKLM-x32 -> DefaultScope {EEE6C360-6118-11DC-9C72-001320C79847} URL =
SearchScopes: HKU\S-1-5-21-997336396-1215893520-3887361402-1000 -> DefaultScope {AC03D255-2F86-43A4-869C-CB466B114318} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC;=IC05&PTAG;=ICO-0205893b&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-997336396-1215893520-3887361402-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-997336396-1215893520-3887361402-1000 -> {91607fa7-3c2f-4f90-93e3-d5337a6b0ac2} URL = Playbryte-fa-v/search/redirect/?type=default&user;_id=bb4d5d7b-bf6d-4876-8d94-a458174d7f55&query;={searchTerms}
SearchScopes: HKU\S-1-5-21-997336396-1215893520-3887361402-1000 -> {AC03D255-2F86-43A4-869C-CB466B114318} URL = hxxp://www.bing.com/search?FORM=INCOH2&PC;=IC05&PTAG;=ICO-0205893b&q;={searchTerms}
SearchScopes: HKU\S-1-5-21-997336396-1215893520-3887361402-1000 -> {fcd9f10e-0daa-405f-bca0-0dd3f37c59d9} URL = hxxp://www.bing.com/search?FORM=U218DF&PC;=U218&q;={searchTerms}&src;=IE-SearchBox
SearchScopes: HKU\S-1-5-21-997336396-1215893520-3887361402-501 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08] (CANON INC.)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2015-01-14] (Oracle Corporation)
BHO-x32: ArcPluginIEBHO Class -> {84BFE29A-8139-402a-B2A4-C23AE9E1A75F} -> C:\Program Files (x86)\Arc\plugins\ArcPluginIE.dll [2018-07-03] (Perfect World Entertainment Inc)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> c:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-08-18] (Microsoft Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-28] (Google Inc.)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2015-01-14] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08] (CANON INC.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-04-28] (Google Inc.)
Toolbar: HKU\S-1-5-21-997336396-1215893520-3887361402-1000 -> No Name - {2E924F4F-67F0-4BD8-9560-49F468E843D2} - No File
Toolbar: HKU\S-1-5-21-997336396-1215893520-3887361402-501 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Toolbar: HKU\S-1-5-21-997336396-1215893520-3887361402-501 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-04-28] (Google Inc.)
DPF: HKLM-x32 {6A060448-60F9-11D5-A6CD-0002B31F7455}
DPF: HKLM-x32 {A4150320-98EC-4DB6-9BFB-EBF4B6FBEB16} hxxp://192.168.2.129:3658/codebase/DVM_IPCam2.ocx
DPF: HKLM-x32 {BEA7310D-06C4-4339-A784-DC3804819809} hxxp://images3.pnimedia.com/ProductAssets/costcous/activex/v3_0_0_7/PhotoCenter_ActiveX_Control.cab
DPF: HKLM-x32 {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} hxxp://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.5.9.0.cab
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
DPF: HKLM-x32 {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} hxxp://3dlifeplayer.dl.3dvia.com/player/install/3DVIA_player_installer.exe
DPF: HKLM-x32 {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
FireFox:
========
FF ProfilePath: C:\Users\Ian\AppData\Roaming\Mozilla\Firefox\Profiles\6xn0s77d.default [2018-01-27]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll [2014-01-27] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin: provocraft.com/Cricut -> C:\Program Files (x86)\CricutDesignSpace\npCricut64.dll [2014-09-12] (Provo Craft)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll [2014-02-05] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-09-21] (CANON INC.)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2015-01-14] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2015-01-14] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50901.0\npctrl.dll [2016-08-31] ( Microsoft Corporation)
FF Plugin-x32: @perfectworld.com/npArcPlayNowPlugin -> C:\Program Files (x86)\Arc\plugins\npArcPluginFF.dll [2018-07-03] (Perfect World Entertainment Inc)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.8 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2013-07-30] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-08-05] (Adobe Systems Inc.)
FF Plugin-x32: provocraft.com/Cricut -> C:\Program Files (x86)\CricutDesignSpace\npCricut32.dll [2014-09-12] (Provo Craft)
FF Plugin HKU\S-1-5-21-997336396-1215893520-3887361402-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Ian\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-10-08] (Citrix Online)
FF Plugin ProgramFiles/Appdata: C:\Users\Ian\AppData\Roaming\mozilla\plugins\npatgpc.dll [2014-02-28] (Cisco WebEx LLC)
StartMenuInternet: FIREFOX.EXE - firefox.exe
FF ExtraCheck: C:\Program Files (x86)\mozilla firefox\firefox.cfg [2013-08-01] <==== ATTENTION
Chrome:
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxp://google.com/
CHR StartupUrls: Default -> "hxxp://www.bing.com/search?FORM=INCOH1&PC;=IC03&PTAG;=ICO-0205893b"
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=INCOH2&PC;=IC03&PTAG;=ICO-0205893b&q;={searchTerms}
CHR DefaultSearchKeyword: Default -> search provided by bing.com
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?client=chrome&hl;={language}&q;={searchTerms}
CHR Profile: C:\Users\Ian\AppData\Local\Google\Chrome\User Data\Default [2018-09-09]
CHR Extension: (Docs) - C:\Users\Ian\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-23]
CHR Extension: (Google Drive) - C:\Users\Ian\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-01-08]
CHR Extension: (YouTube) - C:\Users\Ian\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-01-08]
CHR Extension: (Google Search) - C:\Users\Ian\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2016-01-08]
CHR Extension: (Google Docs Offline) - C:\Users\Ian\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-09-01]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Ian\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-11]
CHR Extension: (Gmail) - C:\Users\Ian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-01-08]
CHR Extension: (Chrome Media Router) - C:\Users\Ian\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-09-09]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-09-07] (Apple Inc.)
S3 ArcService; C:\Program Files (x86)\Arc\ArcService.exe [88696 2018-07-03] (Perfect World Entertainment Inc)
S3 BstHdAndroidSvc; C:\Program Files (x86)\BlueStacks\HD-Service.exe [433760 2015-12-01] (BlueStack Systems, Inc.)
R2 BstHdLogRotatorSvc; C:\Program Files (x86)\BlueStacks\HD-LogRotatorService.exe [413280 2015-12-01] (BlueStack Systems, Inc.)
R2 BstHdUpdaterSvc; C:\Program Files (x86)\BlueStacks\HD-UpdaterService.exe [855648 2015-12-01] (BlueStack Systems, Inc.)
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [121344 2012-02-07] () [File not signed]
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
S4 lxduCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\lxduserv.exe [29184 2009-10-16] (Lexmark International, Inc.)
S4 lxdu_device; C:\Windows\system32\lxducoms.exe [1039360 2009-10-16] ( )
S4 lxdu_device; C:\Windows\SysWOW64\lxducoms.exe [589824 2009-10-16] ( )
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
S4 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 NVDisplay.ContainerLocalSystem; "C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe" -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000
R2 NvTelemetryContainer; "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe" -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugins" -r
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-11-10] (AVG Technologies)
R2 BstHdDrv; C:\Program Files (x86)\BlueStacks\HD-Hypervisor-amd64.sys [146016 2015-12-01] (BlueStack Systems)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [259360 2018-09-10] (Malwarebytes)
S4 nvvad_WaveExtensible; system32\drivers\nvvad64v.sys [X]
S1 SBRE; \??\C:\Windows\system32\drivers\SBREdrv.sys [X]
U3 aswMBR; \??\C:\Users\Ian\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\Ian\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-09-10 17:06 - 2018-09-10 17:08 - 000021241 _____ C:\Users\Guest\Desktop\FRST.txt
2018-09-10 17:06 - 2018-09-10 17:06 - 000000000 ____D C:\FRST
2018-09-10 17:04 - 2018-09-10 17:05 - 000005271 _____ C:\Users\Ian\Documents\aswMBR.txt
2018-09-10 17:04 - 2018-09-10 17:05 - 000000512 _____ C:\Users\Ian\Documents\MBR.dat
2018-09-10 17:01 - 2018-09-10 17:01 - 000000512 _____ C:\Users\Ian\Desktop\MBR.dat
2018-09-10 16:55 - 2018-09-10 17:01 - 000002352 _____ C:\Users\Ian\Desktop\aswMBR.txt
2018-09-10 16:51 - 2018-09-10 16:51 - 002413568 _____ (Farbar) C:\Users\Guest\Desktop\FRST64.exe
2018-09-10 16:44 - 2018-09-10 16:44 - 005198336 _____ (AVAST Software) C:\Users\Guest\Desktop\aswMBR.exe
2018-09-09 22:37 - 2018-09-09 22:37 - 000000000 ____D C:\Program Files (x86)\VulkanRT
2018-09-09 22:37 - 2018-08-21 05:08 - 000001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2018-09-09 22:36 - 2018-09-09 22:36 - 000000000 ____D C:\Windows\system32\unknown
2018-09-09 22:36 - 2018-09-09 22:36 - 000000000 ____D C:\Windows\system32\Drivers\NVIDIA Corporation
2018-09-09 22:36 - 2018-08-21 03:15 - 000001951 _____ C:\Windows\NvContainerRecovery.bat
2018-09-09 22:36 - 2018-08-21 03:14 - 005947600 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll
2018-09-09 22:36 - 2018-08-21 03:14 - 002612264 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll
2018-09-09 22:36 - 2018-08-21 03:14 - 001767632 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll
2018-09-09 22:36 - 2018-08-21 03:14 - 000634352 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshext.dll
2018-09-09 22:36 - 2018-08-21 03:14 - 000450768 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll
2018-09-09 22:36 - 2018-08-21 03:14 - 000124216 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll
2018-09-09 22:36 - 2018-08-21 03:14 - 000083440 _____ (NVIDIA Corporation) C:\Windows\system32\nv3dappshextr.dll
2018-09-09 22:36 - 2018-08-02 15:32 - 008273432 _____ C:\Windows\system32\nvcoproc.bin
2018-09-09 22:34 - 2018-08-22 09:12 - 040189616 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll
2018-09-09 22:34 - 2018-08-22 09:12 - 032457736 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll
2018-09-09 22:34 - 2018-08-22 09:12 - 017014632 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys
2018-09-09 22:34 - 2018-08-22 09:12 - 000628560 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFROpenGL.dll
2018-09-09 22:34 - 2018-08-22 09:12 - 000519120 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFROpenGL.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 040346976 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 035250176 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 031248576 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 025964944 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 023305232 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 020330616 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 019088480 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 017755768 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 015699512 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 015169920 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 013732120 _____ (NVIDIA Corporation) C:\Windows\system32\nvptxJitCompiler.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 011276424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvptxJitCompiler.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 004616904 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 004085328 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 003967304 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 003504968 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 002015184 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6439907.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 001564136 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 001467728 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6439907.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 001420296 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 001217352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 001159096 _____ (NVIDIA Corporation) C:\Windows\system32\nvfatbinaryLoader.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 001093456 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 000906608 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvfatbinaryLoader.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 000546880 _____ (NVIDIA Corporation) C:\Windows\system32\nvEncodeAPI64.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 000505592 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 000464536 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvEncodeAPI.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 000420032 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 000182624 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 000164792 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 000159736 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvinit.dll
2018-09-09 22:34 - 2018-08-22 09:11 - 000142656 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll
2018-09-09 22:34 - 2018-08-21 05:08 - 000041866 _____ C:\Windows\system32\nvinfo.pb
2018-09-09 22:34 - 2018-08-21 05:08 - 000000669 _____ C:\Windows\SysWOW64\nv-vk32.json
2018-09-09 22:34 - 2018-08-21 05:08 - 000000669 _____ C:\Windows\system32\nv-vk64.json
2018-09-09 22:11 - 2018-09-09 22:15 - 459279728 _____ (NVIDIA Corporation) C:\Users\Ian\Downloads\399.07-desktop-win8-win7-64bit-international-whql.exe
2018-09-09 21:50 - 2018-09-09 21:51 - 087630520 _____ (NVIDIA Corporation) C:\Users\Ian\Downloads\GeForce_Experience_v3.14.1.48.exe
2018-09-09 20:25 - 2018-09-09 20:25 - 000000000 ____D C:\Users\Ian\AppData\Local\mbam
2018-09-09 19:53 - 2018-09-10 14:52 - 000259360 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-09-09 19:53 - 2018-09-09 19:53 - 000000000 ____D C:\Users\Guest\AppData\Local\mbam
2018-09-09 19:52 - 2018-09-09 19:52 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-09-09 19:52 - 2018-09-09 19:52 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-09-09 19:52 - 2018-07-12 08:42 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2018-09-05 19:44 - 2018-09-05 19:44 - 000000000 ____D C:\Program Files (x86)\localdata
2018-09-04 18:16 - 2018-09-04 18:16 - 000000000 ____D C:\Users\Ian\AppData\Roaming\CricutDesignSpace3
2018-09-04 18:13 - 2018-09-04 18:16 - 000002001 _____ C:\Users\Ian\Desktop\Cricut Design Space.lnk
2018-09-04 18:13 - 2018-09-04 18:13 - 011289872 _____ (Provo Craft & Novelty, Inc.) C:\Users\Ian\Downloads\CricutDesignSpace-5.8.1806.151932 (1).exe
2018-09-04 18:12 - 2018-09-04 18:13 - 011289872 _____ (Provo Craft & Novelty, Inc.) C:\Users\Ian\Downloads\CricutDesignSpace-5.8.1806.151932.exe
2018-09-01 18:52 - 2018-09-01 18:52 - 000000000 ____D C:\Users\Ian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-08-19 09:10 - 2018-09-05 17:39 - 000001310 _____ C:\Users\Guest\Desktop\Roblox Player.lnk
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-09-10 16:51 - 2015-06-17 19:44 - 000000910 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-997336396-1215893520-3887361402-1000UA.job
2018-09-10 16:20 - 2016-10-08 08:17 - 000000522 _____ C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-997336396-1215893520-3887361402-1000.job
2018-09-10 15:41 - 2016-10-08 08:17 - 000000618 _____ C:\Windows\Tasks\G2MUploadTask-S-1-5-21-997336396-1215893520-3887361402-1000.job
2018-09-10 15:01 - 2009-07-13 21:45 - 000017120 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-09-10 15:01 - 2009-07-13 21:45 - 000017120 _____ C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-09-10 14:57 - 2015-12-05 05:12 - 000000000 ____D C:\ProgramData\BlueStacksSetup
2018-09-10 14:53 - 2012-09-09 08:38 - 000000000 ____D C:\Program Files (x86)\Steam
2018-09-10 14:52 - 2012-09-06 19:14 - 000000000 ____D C:\ProgramData\NVIDIA
2018-09-10 14:51 - 2009-07-13 22:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-09-09 22:50 - 2018-02-11 16:14 - 000000000 ____D C:\Users\Guest\AppData\Roaming\Opera Software
2018-09-09 22:50 - 2018-02-11 16:14 - 000000000 ____D C:\Users\Guest\AppData\Local\Opera Software
2018-09-09 22:37 - 2012-09-06 19:14 - 000000000 ____D C:\ProgramData\NVIDIA Corporation
2018-09-09 22:37 - 2012-09-06 19:14 - 000000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2018-09-09 22:37 - 2012-09-06 19:02 - 000000000 ____D C:\Program Files\NVIDIA Corporation
2018-09-09 22:36 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\inf
2018-09-09 22:36 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\Help
2018-09-09 21:53 - 2014-04-08 21:33 - 000000000 ____D C:\Users\Ian\AppData\Local\NVIDIA Corporation
2018-09-09 19:51 - 2012-09-05 22:35 - 000000000 ____D C:\Users\Ian
2018-09-09 19:28 - 2018-02-24 09:39 - 000000000 ____D C:\ProgramData\Package Cache
2018-09-09 19:12 - 2018-07-23 09:55 - 000000000 ____D C:\Users\Guest\Documents\My Games
2018-09-09 18:50 - 2015-06-17 19:44 - 000000858 _____ C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-997336396-1215893520-3887361402-1000Core.job
2018-09-08 10:06 - 2017-06-15 19:19 - 000000000 ____D C:\Program Files (x86)\Neverwinter_en
2018-09-08 10:06 - 2017-05-17 17:49 - 000000000 ____D C:\Program Files (x86)\Arc
2018-09-05 17:39 - 2017-07-27 17:29 - 000001129 _____ C:\Users\Guest\Desktop\Roblox Studio.lnk
2018-09-05 17:39 - 2017-07-27 17:29 - 000000000 ____D C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Roblox
2018-09-04 18:09 - 2013-10-28 13:42 - 000002224 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-09-04 18:09 - 2013-10-28 13:42 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-09-01 19:25 - 2013-08-01 11:20 - 000027772 _____ C:\Users\Ian\Documents\CHECKBOOK-Main Checking.xlsx
2018-09-01 19:20 - 2017-07-08 18:23 - 000000000 ____D C:\Users\Ian\AppData\Local\GoToMeeting
2018-09-01 19:15 - 2016-10-08 08:17 - 000003628 _____ C:\Windows\System32\Tasks\G2MUploadTask-S-1-5-21-997336396-1215893520-3887361402-1000
2018-09-01 19:15 - 2016-10-08 08:17 - 000003532 _____ C:\Windows\System32\Tasks\G2MUpdateTask-S-1-5-21-997336396-1215893520-3887361402-1000
2018-09-01 18:53 - 2013-11-18 13:12 - 000000000 ____D C:\Users\Ian\AppData\Roaming\Dropbox
2018-09-01 18:46 - 2015-06-17 19:44 - 000003876 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-997336396-1215893520-3887361402-1000UA
2018-09-01 18:45 - 2015-06-17 19:44 - 000003480 _____ C:\Windows\System32\Tasks\DropboxUpdateTaskUserS-1-5-21-997336396-1215893520-3887361402-1000Core
2018-08-22 09:12 - 2012-09-06 17:29 - 000553200 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll
2018-08-22 09:12 - 2012-09-06 17:29 - 000458480 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll
2018-08-19 09:10 - 2017-07-27 17:29 - 000000252 _____ C:\Users\Guest\AppData\LocalLow\rbxcsettings.rbx
==================== Files in the root of some directories =======
2012-10-08 15:35 - 2012-10-08 15:35 - 001228616 _____ (Adobe Systems Incorporated) C:\Users\Ian\Photoshop_12_1_LS1.exe
2013-06-26 16:56 - 2013-08-14 23:53 - 000003689 _____ () C:\Program Files (x86)\Mozilla Firefoxavg-secure-search.xml
2013-08-19 14:49 - 2013-09-28 15:11 - 000000132 _____ () C:\Users\Ian\AppData\Roaming\Adobe IllExport Filter CS5 Prefs
2013-09-11 15:44 - 2013-09-11 15:44 - 000000132 _____ () C:\Users\Ian\AppData\Roaming\Adobe PNG Format CS5 Prefs
2013-09-22 09:17 - 2014-02-14 09:17 - 000000127 _____ () C:\Users\Ian\AppData\Roaming\WB.CFG
2013-08-19 15:20 - 2013-08-19 15:20 - 000001456 _____ () C:\Users\Ian\AppData\Local\Adobe Save for Web 12.0 Prefs
2012-09-14 20:53 - 2012-09-14 20:53 - 000000091 _____ () C:\Users\Ian\AppData\Local\fusioncache.dat
2012-10-01 13:43 - 2012-10-01 13:43 - 000007605 _____ () C:\Users\Ian\AppData\Local\Resmon.ResmonCfg
2016-07-21 15:48 - 2016-07-21 15:48 - 000000000 _____ () C:\Users\Ian\AppData\Local\{FC8905DC-9EA8-4AD4-9FC5-082067371178}
Some files in TEMP:
====================
2018-03-17 18:22 - 2018-03-17 18:22 - 002153984 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180318012259401.dll
2018-03-17 18:22 - 2018-03-17 18:22 - 002153984 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180318012259464.dll
2018-03-17 18:22 - 2018-03-17 18:22 - 002153984 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180318012259599.dll
2018-03-17 18:22 - 2018-03-17 18:22 - 002153984 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180318012259705.dll
2018-03-17 18:23 - 2018-03-17 18:23 - 002153984 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180318012301445.dll
2018-03-17 18:23 - 2018-03-17 18:23 - 002153984 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180318012301539.dll
2018-03-17 18:23 - 2018-03-17 18:23 - 002153984 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180318012302134.dll
2018-04-07 08:06 - 2018-04-07 08:06 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180407150638657.dll
2018-04-07 08:06 - 2018-04-07 08:06 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180407150638806.dll
2018-04-07 08:06 - 2018-04-07 08:06 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180407150638905.dll
2018-04-07 08:06 - 2018-04-07 08:06 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180407150638957.dll
2018-04-07 08:06 - 2018-04-07 08:06 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180407150639041.dll
2018-04-07 08:06 - 2018-04-07 08:06 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180407150639291.dll
2018-04-07 08:06 - 2018-04-07 08:06 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180407150649430.dll
2018-04-13 18:26 - 2018-04-13 18:26 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180414012636479.dll
2018-04-13 18:26 - 2018-04-13 18:26 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180414012636572.dll
2018-04-13 18:26 - 2018-04-13 18:26 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180414012636884.dll
2018-04-13 18:26 - 2018-04-13 18:26 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180414012636962.dll
2018-04-13 18:26 - 2018-04-13 18:26 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180414012637009.dll
2018-04-13 18:26 - 2018-04-13 18:26 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180414012637071.dll
2018-04-13 18:26 - 2018-04-13 18:26 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180414012637711.dll
2018-05-06 19:13 - 2018-05-06 19:13 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180507021314205.dll
2018-05-06 19:13 - 2018-05-06 19:13 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180507021314387.dll
2018-05-06 19:13 - 2018-05-06 19:13 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180507021314639.dll
2018-05-06 19:13 - 2018-05-06 19:13 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180507021314756.dll
2018-05-06 19:13 - 2018-05-06 19:13 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180507021315102.dll
2018-05-06 19:13 - 2018-05-06 19:13 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180507021315349.dll
2018-05-06 19:13 - 2018-05-06 19:13 - 002183680 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_180507021317086.dll
2018-03-02 19:21 - 2018-03-02 19:21 - 002149376 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_2018332122407.dll
2018-03-02 19:21 - 2018-03-02 19:21 - 002149376 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_2018332125357.dll
2018-03-02 19:21 - 2018-03-02 19:21 - 002149376 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_2018332125767.dll
2018-03-02 19:21 - 2018-03-02 19:21 - 002149376 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_2018332126305.dll
2018-03-02 19:21 - 2018-03-02 19:21 - 002149376 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_2018332126869.dll
2018-03-02 19:21 - 2018-03-02 19:21 - 002149376 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_2018332127704.dll
2018-03-02 19:21 - 2018-03-02 19:21 - 002149376 _____ (Opera Software) C:\Users\Guest\AppData\Local\Temp\Opera_installer_2018332132879.dll
2016-01-26 19:27 - 2015-06-14 20:38 - 000047928 _____ () C:\Users\Ian\AppData\Local\Temp\ACLMInstaller.exe
2016-01-22 12:31 - 2016-01-22 12:31 - 000144008 _____ (© 2015 Microsoft Corporation) C:\Users\Ian\AppData\Local\Temp\BingSvc.exe
2016-01-22 12:30 - 2016-01-22 12:31 - 001118360 _____ (© 2015 Microsoft Corporation) C:\Users\Ian\AppData\Local\Temp\BSvcProcessor.exe
2016-01-22 12:30 - 2016-01-22 12:31 - 000170128 _____ (© 2015 Microsoft Corporation) C:\Users\Ian\AppData\Local\Temp\BSvcUpdater.exe
2016-01-22 12:20 - 2016-01-22 12:20 - 002612880 _____ (Microsoft Corporation) C:\Users\Ian\AppData\Local\Temp\DefaultPack.EXE
2015-12-09 16:57 - 2015-12-09 16:57 - 000071168 _____ () C:\Users\Ian\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpaw9acy.dll
2016-01-21 08:59 - 2017-03-07 00:16 - 010574256 _____ () C:\Users\Ian\AppData\Local\Temp\HPPSdr.exe
2013-05-02 22:38 - 2013-05-02 22:38 - 000089248 ___SH (Adobe Systems, Inc.) C:\Users\Ian\AppData\Local\Temp\InstallFlashPlayer.exe
2018-04-01 17:46 - 2018-03-22 20:03 - 068724528 _____ (Malwarebytes ) C:\Users\Ian\AppData\Local\Temp\mb3-setup-consumer-3.4.4.2398-1.0.322-1.0.4190.exe
2014-06-14 15:42 - 2014-05-19 16:10 - 001203248 _____ (NVIDIA Corporation) C:\Users\Ian\AppData\Local\Temp\nvSCPAPI.dll
2018-09-09 21:52 - 2014-05-19 16:10 - 000822216 _____ (NVIDIA Corporation) C:\Users\Ian\AppData\Local\Temp\nvStInst.exe
2006-10-27 22:28 - 2006-10-27 22:28 - 000145184 ____R (Microsoft Corporation) C:\Users\Ian\AppData\Local\Temp\ose00000.exe
2013-02-11 16:13 - 2011-09-20 10:32 - 000351864 ____R (CANON INC.) C:\Users\Ian\AppData\Local\Temp\uninstall.exe
2017-05-17 18:06 - 2018-09-09 19:51 - 004670968 _____ (NCSOFT) C:\Users\Ian\AppData\Local\Temp\Wildstar.exe
2010-12-26 19:51 - 2010-12-26 19:51 - 000455600 ____R (Macrovision Corporation) C:\Users\Ian\AppData\Local\Temp\_isB0A8.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2012-11-23 14:09
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09.09.2018
Ran by [removed] (10-09-2018 17:09:07)
Running from C:\Users\[removed]\Desktop
Windows 7 Professional Service Pack 1 (X64) (2012-09-06 05:34:57)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-997336396-1215893520-3887361402-500 - Administrator - Disabled)
ASPNET (S-1-5-21-997336396-1215893520-3887361402-1005 - Limited - Enabled)
Guest (S-1-5-21-997336396-1215893520-3887361402-501 - Limited - Enabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-997336396-1215893520-3887361402-1002 - Limited - Enabled)
Ian (S-1-5-21-997336396-1215893520-3887361402-1000 - Administrator - Enabled) => C:\Users\Ian
Tammy (S-1-5-21-997336396-1215893520-3887361402-1006 - Administrator - Enabled) => C:\Users\Tammy
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (x64 edition) (HKLM\…\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Acrobat.com (HKLM-x32\…\{628C2C7D-8AD1-E614-E8E2-6EEAD8D5F2D0}) (Version: 2.0.0 - Adobe Systems Incorporated) Hidden
Acrobat.com (HKLM-x32\…\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 2.0.0.0 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 30.0.0.107 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\…\Adobe Flash Player Plugin) (Version: 12.0.0.44 - Adobe Systems Incorporated)
Adobe Flash Player 22 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 22.0.0.192 - Adobe Systems Incorporated)
Adobe Photoshop CS5.1 (HKLM-x32\…\{9158FF30-78D7-40EF-B83E-451AC5334640}) (Version: 12.1 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.08) (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.08 - Adobe Systems Incorporated)
Akamai NetSession Interface (HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\Akamai) (Version: - Akamai Technologies, Inc)
Apple Application Support (32-bit) (HKLM-x32\…\{3D1290E6-1F77-46D5-A715-A56679C8D4E3}) (Version: 6.0.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\…\{D0E45DEC-F4B9-4370-A9DF-66837789C2EF}) (Version: 6.0.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{E3C4B99B-BE71-4C27-8E3C-4FAE3C46E1D5}) (Version: 11.0.0.30 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.)
Arc (HKLM-x32\…\{CED8E25B-122A-4E80-B612-7F99B93284B3}) (Version: 1.0.0.9668 - Perfect World Entertainment)
Asmedia ASM104x USB 3.0 Host Controller Driver (HKLM-x32\…\{E4FB0B39-C991-4EE7-95DD-1A1A7857D33D}) (Version: 1.10.1.0 - Asmedia Technology)
Asmedia ASM106x SATA Host Controller Driver (HKLM-x32\…\{61942EF5-2CD8-47D4-869C-2E9A8BB085F1}) (Version: 1.3.1.000 - Asmedia Technology)
BlueStacks App Player (HKLM-x32\…\{D080F290-4B2A-4C67-9757-63DA0C6E8855}) (Version: 2.0.0.1011 - BlueStack Systems, Inc.)
Bonjour (HKLM\…\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Broadcom NetLink Controller (HKLM\…\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.8.5.1 - Broadcom Corporation)
Canon Easy-PhotoPrint EX (HKLM-x32\…\Easy-PhotoPrint EX) (Version: - )
Canon Easy-WebPrint EX (HKLM-x32\…\Easy-WebPrint EX) (Version: - )
Canon IJ Network Scanner Selector EX (HKLM-x32\…\Canon_IJ_Network_Scanner_Selector_EX) (Version: - )
Canon IJ Network Tool (HKLM-x32\…\Canon_IJ_Network_UTILITY) (Version: - )
Canon My Printer (HKLM-x32\…\CanonMyPrinter) (Version: - )
Canon RAW Image Task for ZoomBrowser EX (HKLM-x32\…\RAW Image Task) (Version: 3.3.0.5 - Canon Inc.)
Canon Solution Menu EX (HKLM-x32\…\CanonSolutionMenuEX) (Version: - )
Canon Speed Dial Utility (HKLM-x32\…\Speed Dial Utility) (Version: - )
Canon Utilities CameraWindow (HKLM-x32\…\CameraWindowLauncher) (Version: 7.1.0.2 - Canon Inc.)
Canon Utilities CameraWindow DC_DV 6 for ZoomBrowser EX (HKLM-x32\…\CameraWindowDVC6) (Version: 6.4.2.16 - Canon Inc.)
Canon Utilities Digital Photo Professional 3.4 (HKLM-x32\…\DPP) (Version: 3.4.0.0 - Canon Inc.)
Canon Utilities EOS Utility (HKLM-x32\…\EOS Utility) (Version: 2.4.0.1 - Canon Inc.)
Canon Utilities MyCamera (HKLM-x32\…\MyCamera) (Version: 6.4.0.5 - Canon Inc.)
Canon Utilities PhotoStitch (HKLM-x32\…\PhotoStitch) (Version: 3.1.21.45 - Canon Inc.)
Canon Utilities Picture Style Editor (HKLM-x32\…\Picture Style Editor) (Version: 1.3.0.0 - Canon Inc.)
Canon Utilities RemoteCapture Task for ZoomBrowser EX (HKLM-x32\…\RemoteCaptureTask) (Version: 1.7.1.9 - Canon Inc.)
Canon Utilities WFT-E1/E2/E3 Utility (HKLM-x32\…\WFTK) (Version: 3.2.1.1 - Canon Inc.)
Canon Utilities ZoomBrowser EX (HKLM-x32\…\ZoomBrowser EX) (Version: 6.1.1.21 - Canon Inc.)
Canon ZoomBrowser EX Memory Card Utility (HKLM-x32\…\ZoomBrowser EX Memory Card Utility) (Version: 1.1.0.8 - Canon Inc.)
Cisco EAP-FAST Module (HKLM-x32\…\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.)
Cisco LEAP Module (HKLM-x32\…\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.)
Cisco PEAP Module (HKLM-x32\…\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.)
Citrix Online Launcher (HKLM-x32\…\{09DA5EE2-7E46-4DC4-96F9-BFEE50D40659}) (Version: 1.0.408 - Citrix)
Coupon Printer for Windows (HKLM-x32\…\Coupon Printer for Windows5.0.0.1) (Version: 5.0.0.1 - Coupons.com Incorporated)
Cricut (TM) Driver v2.01 (HKLM-x32\…\Cricut (TM) Driver v2.01) (Version: 2.01 - Provo Craft & Novelty, Inc.)
Cricut Craft Room® (HKLM-x32\…\{C99E1908-FDFE-8B4D-2E14-E836ECC4D880}) (Version: 1.0.183 - Provo Craft & Novelty, Inc.) Hidden
Cricut Craft Room® (HKLM-x32\…\com.cricut.Cricut-CraftRoom) (Version: v1.0 build-183 - Provo Craft & Novelty, Inc.)
Cricut Design Space (HKLM-x32\…\Cricut Design Space 1.000) (Version: 1.000 - Provo Craft & Novelty, Inc.)
Cricut Design Space Client (HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\Cricut Design Space Client) (Version: 5.8.1806.151932 - Provo Craft)
Debut Video Capture Software (HKU\S-1-5-21-997336396-1215893520-3887361402-501\…\Debut) (Version: 5.09 - NCH Software)
DisplayDriverAnalyzer (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_DisplayDriverAnalyzer) (Version: 399.07 - NVIDIA Corporation) Hidden
doPDF 7.3 printer (HKLM\…\doPDF 7 printer_is1) (Version: - Softland)
Dropbox (HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\Dropbox) (Version: 56.4.94 - Dropbox, Inc.)
Edimax Wireless LAN (HKLM-x32\…\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.6.0 - Edimax)
Expert PDF 7 Reader (HKLM-x32\…\{FC279721-37A6-4777-AFD8-7A56681EBA14}) (Version: 7.0.1370.0 - Avanquest software)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 69.0.3497.81 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\…\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
GoToMeeting 8.34.0.9446 (HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\GoToMeeting) (Version: 8.34.0.9446 - LogMeIn, Inc.)
HP Officejet 5740 series Basic Device Software (HKLM\…\{7FAA9D15-FF0B-4593-8D4A-0B941FD1977A}) (Version: 34.2.117.50647 - Hewlett-Packard Co.)
HP Officejet 5740 series Help (HKLM-x32\…\{F17D53C7-DCE8-469C-9690-CF8F5903519C}) (Version: 34.0.0 - Hewlett Packard)
HP Photo Creations (HKLM-x32\…\HP Photo Creations) (Version: 1.0.0.7702 - HP)
HP Update (HKLM-x32\…\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (HKLM-x32\…\{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}) (Version: 1.00.0001 - Microsoft) Hidden
I.R.I.S. OCR (HKLM-x32\…\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
iCloud (HKLM\…\{7464D896-C63C-412E-8ED3-3261C9F14E21}) (Version: 7.0.1.210 - Apple Inc.)
Intel(R) Control Center (HKLM-x32\…\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\…\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation)
Intel(R) Management Engine Components (HKLM-x32\…\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation)
Intel(R) OpenCL CPU Runtime (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2761 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM-x32\…\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation)
Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\…\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.3.214 - Intel Corporation)
Intel® Trusted Connect Service Client (HKLM\…\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation)
iTunes (HKLM\…\{94E81D4F-FB5A-4B29-B385-33896CC9BE7E}) (Version: 12.7.0.166 - Apple Inc.)
Java 8 Update 25 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
JNLP (HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\JNLP) (Version: - JNLP)
LeapFrog Connect (HKLM-x32\…\{97CD1D2B-20BD-40E8-825E-B4BDA5071B73}) (Version: 7.0.7.20035 - LeapFrog) Hidden
LeapFrog Connect (HKLM-x32\…\UPCShell) (Version: 7.0.7.20035 - LeapFrog)
LeapFrog LeapPad Explorer Plugin (HKLM-x32\…\{50B93E1B-EBA1-46AE-909F-10F6F97E1505}) (Version: 7.0.6.19846 - LeapFrog) Hidden
Lexmark 5600-6600 Series (HKLM\…\Lexmark 5600-6600 Series) (Version: - Lexmark International, Inc.)
Malwarebytes version 3.5.1.2522 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
Microsoft .NET Framework 1.1 (HKLM-x32\…\Microsoft .NET Framework 1.1 (1033)) (Version: - )
Microsoft .NET Framework 4.5.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Games for Windows - LIVE Redistributable (HKLM-x32\…\{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}) (Version: 3.5.92.0 - Microsoft Corporation)
Microsoft Games for Windows Marketplace (HKLM-x32\…\{4CB0307C-565E-4441-86BE-0DF2E4FB828C}) (Version: 3.5.50.0 - Microsoft Corporation)
Microsoft HealthVault Connection Center (HKLM-x32\…\HealthVault Connection Center) (Version: 4.1.3438.8024 - Microsoft Corporation)
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)
Microsoft Office File Validation Add-In (HKLM-x32\…\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (HKLM-x32\…\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50901.0 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP1 English (HKLM-x32\…\{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}) (Version: 3.5.5692.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{A49F249F-0C91-497F-86DF-B2585E8E76B7}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\…\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\…\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\…\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\…\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Millers Designer Plus (HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\Millers Designer Plus) (Version: Millers Designer Plus 3.5.0 - Millers Inc)
Mozilla Firefox 15.0.1 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 15.0.1 (x86 en-US)) (Version: 15.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 15.0.1 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Mumble 1.2.4 (HKLM-x32\…\{E0955568-4353-4C85-8988-285A8C0F5E87}) (Version: 1.2.4 - Thorvald Natvig)
NVIDIA Graphics Driver 399.07 (HKLM\…\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 399.07 - NVIDIA Corporation)
Omron Drivers for HealthVault (HKLM\…\{1CF4F87D-7710-4CC2-99F2-7946BD1FE8F4}) (Version: 1.7.1.0 - Omron)
PDF Settings CS5 (HKLM-x32\…\{A78FE97A-C0C8-49CE-89D0-EDD524A17392}) (Version: 10.0 - Adobe Systems Incorporated) Hidden
Pin It (HKLM-x32\…\Pin It_is1) (Version: 0.0.4 - Pinterest)
Product Improvement Study for HP Officejet 5740 series (HKLM\…\{308C7555-5D43-4D9A-BDC0-14B2948EF438}) (Version: 34.2.117.50647 - Hewlett-Packard Co.)
QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6559 - Realtek Semiconductor Corp.)
Revo Uninstaller Pro 3.0.5 (HKLM\…\{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1) (Version: 3.0.5 - VS Revo Group, Ltd.)
Roblox Player for Guest (HKU\S-1-5-21-997336396-1215893520-3887361402-501\…\{373B1718-8CC5-4567-8EE2-9033AD08A680}) (Version: - Roblox Corporation)
Roblox Player for Guest (HKU\S-1-5-21-997336396-1215893520-3887361402-501\…\roblox-player) (Version: - Roblox Corporation)
Roblox Studio for Guest (HKU\S-1-5-21-997336396-1215893520-3887361402-501\…\{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}) (Version: - Roblox Corporation)
Sid Meier's Civilization V (HKLM-x32\…\steam app 8930) (Version: - 2K Games, Inc.)
Spelling Dictionaries Support For Adobe Reader 9 (HKLM-x32\…\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
Steam (HKLM-x32\…\{048298C9-A4D3-490B-9FF9-AB023A9238F3}) (Version: 1.0.0.0 - Valve Corporation)
Sure Cuts a Lot 2 (HKLM-x32\…\Sure Cuts a Lot 2) (Version: 2 - Craft Edge)
System Requirements Lab for Intel (HKLM-x32\…\{C71067FC-288F-4E0B-88C6-44DFDA8311E2}) (Version: 4.5.9.0 - Husdawg, LLC)
TeamSpeak 3 Client (HKLM-x32\…\TeamSpeak 3 Client) (Version: 3.0.14 - TeamSpeak Systems GmbH)
TurboTax 2012 (HKLM-x32\…\TurboTax 2012) (Version: 2012.0 - Intuit, Inc)
TurboTax 2013 (HKLM-x32\…\TurboTax 2013) (Version: 2013.0 - Intuit, Inc)
TurboTax 2014 (HKLM-x32\…\TurboTax 2014) (Version: 2014.0 - Intuit, Inc)
TurboTax 2015 (HKLM-x32\…\TurboTax 2015) (Version: 2015.0 - Intuit, Inc)
TurboTax 2016 (HKLM-x32\…\TurboTax 2016) (Version: 2016.0 - Intuit, Inc)
TurboTax 2017 (HKLM-x32\…\TurboTax 2017) (Version: 2017.0 - Intuit, Inc)
UGRS2 OCX (HKLM-x32\…\{261E53FA-DCD6-4A8C-89BF-B85AD4F43238}) (Version: 2.0.7 - UGRS2)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\…\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)
Use the entry named LeapFrog Connect to uninstall (LeapFrog LeapPad Explorer Plugin) (HKLM-x32\…\LeapPadExplorerPlugin) (Version: - LeapFrog)
Ventrilo Client for Windows x64 (HKLM\…\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}) (Version: 3.0.8.0 - Flagship Industries, Inc.)
VideoPad Video Editor (HKU\S-1-5-21-997336396-1215893520-3887361402-501\…\VideoPad) (Version: 6.01 - NCH Software)
VLC media player 2.0.8 (HKLM-x32\…\VLC media player) (Version: 2.0.8 - VideoLAN)
WebEx Support Manager for Internet Explorer (HKLM-x32\…\{C34FAEF3-4241-4C4E-9CFF-7BBD8BCEABE7}) (Version: 6.5.47 - WebEx Communications Inc.)
WildStar (HKLM-x32\…\WildStar) (Version: 1.0.0.6512 - NCSOFT)
Windows Driver Package - FTDI CDM Driver Package - Bus/D2XX Driver (04/10/2012 2.08.24) (HKLM\…\4C8545EEB6143B6AD3858B5D1E0AEE76040B1435) (Version: 04/10/2012 2.08.24 - FTDI)
Windows Driver Package - FTDI CDM Driver Package - VCP Driver (04/10/2012 2.08.24) (HKLM\…\6849F67BACD4DA5A5B9D46803E6850D0BE8B3826) (Version: 04/10/2012 2.08.24 - FTDI)
Windows Driver Package - Leapfrog (Leapfrog-USBLAN) Net (09/10/2009 02.03.05.012) (HKLM\…\8F14F2ECEDE68D26EA515B48DC25B39103C4FE8D) (Version: 09/10/2009 02.03.05.012 - Leapfrog)
Windows Live ID Sign-in Assistant (HKLM\…\{9B48B0AC-C813-4174-9042-476A887592C7}) (Version: 6.500.3165.0 - Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\Ian\AppData\Local\Citrix\GoToMeeting\5530\G2MOutlookAddin64.dll => No File
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{FB314EDD-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{FB314EDE-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{FB314EDF-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{FB314EE0-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{FB314EE1-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{FB314EE2-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{FBC9D74C-AF55-4309-9FB2-C426E071637F}\InprocServer32 -> C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-997336396-1215893520-3887361402-1000_Classes\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32 -> C:\$Recycle.Bin ()
ShellIconOverlayIdentifiers: ["DropboxExt1"] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt2"] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt3"] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt4"] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt5"] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt6"] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt7"] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: ["DropboxExt8"] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2017-09-18] (Apple Inc.)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2012-05-21] (Intel Corporation)
ContextMenuHandlers5: [NvCplDesktopContext] -> {3D1975AF-48C6-4f8e-A182-BE0E08FA86A9} => C:\Windows\system32\nvshext.dll [2018-08-21] (NVIDIA Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers6: [RUShellExt] -> {2C5515DC-2A7E-4BFD-B813-CACC2B685EB7} => C:\Program Files\VS Revo Group\Revo Uninstaller Pro\RUExt.dll [2012-12-29] (VS Revo Group)
ContextMenuHandlers1_S-1-5-21-997336396-1215893520-3887361402-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ContextMenuHandlers4_S-1-5-21-997336396-1215893520-3887361402-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
ContextMenuHandlers5_S-1-5-21-997336396-1215893520-3887361402-1000: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Users\Ian\AppData\Roaming\Dropbox\bin\DropboxExt64.23.0.dll [2018-08-28] (Dropbox, Inc.)
FolderExtensions: [ShellFolder for CD Burning] -> {fbeb8a05-beee-4442-804e-409d6c4515e9} => C:\$Recycle.Bin [2015-02-14] ()
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0749C0F4-A240-4940-816D-8A6CD2DB30A7} - System32\Tasks\G2MUploadTask-S-1-5-21-997336396-1215893520-3887361402-1000 => C:\Users\Ian\AppData\Local\GoToMeeting\9446\g2mupload.exe [2018-09-01] (LogMeIn, Inc.)
Task: {1172F791-3973-4E4E-999A-1227D65E5A50} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: {170D3451-7660-41DA-9E1A-AE0C5336D3D7} - System32\Tasks\HPCustPartic.exe_{62EA4D5B-D9E0-4AE9-9E1D-2A1A36093058} => C:\Program Files\HP\HP Officejet 5740 series\Bin\HPCustPartic.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {193EDF11-15C3-42D1-95F5-B7487F0DB037} - System32\Tasks\PinItAutoUpdate => C:\Program Files (x86)\Pinterest\Pin It\AutoUpdater.exe [2013-10-17] ()
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {3D15316E-D6F0-4D4B-8594-71E12312F700} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe
Task: {57D75FEF-1296-4671-A5D2-A7247E7E4560} - System32\Tasks\HPCustParticipation HP Officejet 5740 series => C:\Program Files\HP\HP Officejet 5740 series\Bin\HPCustPartic.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {609F0AB9-C058-4B15-A668-37739E9A7F36} - System32\Tasks\{1E3F8F03-4DA5-48B1-AAAA-BA69CE4E8A7F} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\NCSOFT\WildStar\Wildstar.exe" -c /uninstall
Task: {6934902A-8304-485F-9CF8-030CD088F84D} - System32\Tasks\Installation App Launcher => C:\Program Files (x86)\Lexmark 5600-6600 Series\lxduamon.exe [2010-02-04] ()
Task: {6B73574A-8780-4AAD-9771-DE4DF4CE2F0B} - System32\Tasks\{C9B993C5-7F1A-4EB9-A7AE-AA57B428C334} => C:\Windows\system32\pcalua.exe -a "C:\Remote Programs\7 Wonders 2\GPlrLanc.exe" -c -LOpCode 2 /RemoveContent cid=586350;name=7 Wonders II;dir=C:\Remote Programs\7 Wonders 2\;prvid=143;cmdid=1;prvdir=Default
Task: {74FE3988-5747-4FB2-963F-9C2594365F7B} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {7775CADD-42D8-478E-8440-A945EADBDBF8} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\Windows\TEMP\{16BB69F1-DC7C-4326-9ECA-F58FF3E9FE9C}.exe <==== ATTENTION
Task: {7A052B7B-1142-407B-B1F6-7903F662CF1D} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2017-03-16] (Apple Inc.)
Task: {7C0D4D93-5B3E-47AC-B33F-207BB8D908A3} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-04] (Google Inc.)
Task: {9620BC44-9F23-412A-AFEA-1E9CA1ED477F} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-04] (Google Inc.)
Task: {98AD2D5D-5089-463D-9CEA-7EC8BE4131A0} - System32\Tasks\ScanToPCActivationApp.exe_{59A1FA7E-F00F-41E2-9821-8FE0FBD619E4} => C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe
Task: {9E988204-3138-457D-B4C1-4D3CF77ED9DE} - System32\Tasks\{9DF9FC2E-A136-41C0-8E3E-C1BD496C430A} => C:\Windows\system32\pcalua.exe -a C:\\WildStar\Wildstar.exe -c /uninstall
Task: {A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D} - System32\Tasks\Microsoft\Windows\Location\Notifications => C:\Windows\System32\LocationNotificationWindows.exe
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {B7C8560F-B67B-4F69-BBC9-5B41B1416A4E} - System32\Tasks\FaxApplications.exe_{14B706BB-D431-43AE-8816-2FAE42683C69} => C:\Program Files\HP\HP Officejet 5740 series\Bin\FaxApplications.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {BD5F15F1-5EAB-435E-B274-CADB378D0D1E} - System32\Tasks\GoogleUpdateTaskMachineCore1d15d3da7feeb7b => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-04] (Google Inc.)
Task: {C12CAF99-9E99-4C12-BC72-8517500A6606} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {C2B0EDB6-7343-4AF4-AA9B-34CAFE84DD1D} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-997336396-1215893520-3887361402-1000UA => C:\Users\Ian\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
Task: {C6289299-BDD9-4341-8AB2-A211894A857C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-07-09] (Adobe Systems Incorporated)
Task: {CB836ABE-580C-427B-B997-0CDD3E4E0E30} - System32\Tasks\ScanToPCActivationApp.exe_{BFAA078F-D515-4E20-BDB1-8C4E2B012243} => C:\Program Files\HP\HP Officejet 5740 series\Bin\ScanToPCActivationApp.exe [2014-08-22] (Hewlett-Packard Development Company, LP)
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {D141EFA4-9070-44B6-9C14-A818897D7AAC} - System32\Tasks\AdobeAAMUpdater-1.0-PC-Ian => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2011-03-15] (Adobe Systems Incorporated)
Task: {D4B18153-A341-48ED-BBA1-8047335EF02C} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation)
Task: {D633CCFA-1E73-4B4C-A76B-7EC03ECC43BF} - System32\Tasks\G2MUpdateTask-S-1-5-21-997336396-1215893520-3887361402-1000 => C:\Users\Ian\AppData\Local\GoToMeeting\9446\g2mupdate.exe [2018-09-01] (LogMeIn, Inc.)
Task: {D9864335-FBAB-4279-9894-640477162991} - System32\Tasks\DropboxUpdateTaskUserS-1-5-21-997336396-1215893520-3887361402-1000Core => C:\Users\Ian\AppData\Local\Dropbox\Update\DropboxUpdate.exe [2016-11-04] (Dropbox, Inc.)
Task: {E29FCC45-1DA5-43C8-B921-2EA5D993251D} - System32\Tasks\GoogleUpdateTaskMachineUA1d15d3da8a259cf => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-04] (Google Inc.)
Task: {F4D560FA-5B69-4D1F-9465-B32BB7EA2A29} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-07-24] (Apple Inc.)
Task: {F5F0C797-241E-416A-8D19-24BDB8329084} - System32\Tasks\{D1CF6A3F-4248-4856-BE93-343C660EB258} => C:\Windows\system32\pcalua.exe -a "C:\Program Files (x86)\Turbine\The Lord of the Rings Online\CleanUninstall.exe" -d "C:\Program Files (x86)\Turbine\The Lord of the Rings Online"
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\Windows\TEMP\{16BB69F1-DC7C-4326-9ECA-F58FF3E9FE9C}.exe <==== ATTENTION
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-997336396-1215893520-3887361402-1000Core.job => C:\Users\Ian\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\DropboxUpdateTaskUserS-1-5-21-997336396-1215893520-3887361402-1000UA.job => C:\Users\Ian\AppData\Local\Dropbox\Update\DropboxUpdate.exe
Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-997336396-1215893520-3887361402-1000.job => C:\Users\Ian\AppData\Local\GoToMeeting\9446\g2mupdate.exe
Task: C:\Windows\Tasks\G2MUploadTask-S-1-5-21-997336396-1215893520-3887361402-1000.job => C:\Users\Ian\AppData\Local\GoToMeeting\9446\g2mupload.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
ShortcutWithArgument: C:\Users\Ian\Desktop\Bay Photo Economy.lnk -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/BayPhotoEconomy/launch.jnlp "C:\Users\Ian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\6599c28-32dc6ea8"
ShortcutWithArgument: C:\Users\Ian\Desktop\Connect Innovations.lnk -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/ConnectBrowser/launch.jnlp "C:\Users\Ian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\48a0c828-2f4f6cd4"
ShortcutWithArgument: C:\Users\Ian\Desktop\Miller's ROES.lnk -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/Millers/launch.jnlp "C:\Users\Ian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\6650bfb4-7fc42811"
ShortcutWithArgument: C:\Users\Ian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Miller's ROES\Miller's ROES.lnk -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/Millers/launch.jnlp "C:\Users\Ian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52\6650bfb4-7fc42811"
ShortcutWithArgument: C:\Users\Ian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Connect Innovations\Connect Innovations.lnk -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/ConnectBrowser/launch.jnlp "C:\Users\Ian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\48a0c828-2f4f6cd4"
ShortcutWithArgument: C:\Users\Ian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bay Photo Emerge\Bay Photo Emerge.lnk -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/BayPhotoEmerge/launch.jnlp "C:\Users\Ian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47\2bfd02ef-5a7c96a9"
ShortcutWithArgument: C:\Users\Ian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bay Photo Economy\Bay Photo Economy.lnk -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\javaws.exe (Oracle Corporation) -> -localfile -J-Djnlp.application.href=hxxp://www.roeslaunch.com/ROES/labs/BayPhotoEconomy/launch.jnlp "C:\Users\Ian\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40\6599c28-32dc6ea8"
==================== Loaded Modules (Whitelisted) ==============
2009-08-27 09:36 - 2009-08-27 09:36 - 002265600 _____ () C:\Windows\System32\drivers\UMDF\Omron\OmronWpdDriver.dll
2012-09-06 20:18 - 2009-10-16 12:07 - 000186880 _____ () C:\Windows\system32\spool\PRTPROCS\x64\lxdudrpp.dll
2012-09-06 17:29 - 2012-03-19 00:09 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2017-09-11 14:45 - 2017-09-11 14:45 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll
2017-09-11 14:45 - 2017-09-11 14:45 - 000092472 _____ () C:\Program Files\iTunes\zlib1.dll
2018-09-03 14:28 - 2018-08-27 12:41 - 001054496 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\SDL2.dll
2018-09-03 14:28 - 2018-08-27 13:52 - 098006816 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libcef.dll
2018-09-03 14:28 - 2018-08-27 13:52 - 004443424 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libglesv2.dll
2018-09-03 14:28 - 2018-08-27 13:52 - 000100128 _____ () C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\libegl.dll
2012-09-06 17:35 - 2012-02-07 17:27 - 000121344 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
2018-09-09 19:52 - 2018-07-24 12:32 - 002681424 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-09-04 18:09 - 2018-09-03 14:04 - 005110616 _____ () C:\Program Files (x86)\Google\Chrome\Application\69.0.3497.81\libglesv2.dll
2018-09-04 18:09 - 2018-09-03 14:04 - 000116056 _____ () C:\Program Files (x86)\Google\Chrome\Application\69.0.3497.81\libegl.dll
2018-08-16 17:57 - 2018-08-03 10:30 - 031303168 _____ () C:\Users\Guest\AppData\Local\Google\Chrome\User Data\PepperFlash\30.0.0.154\pepflashplayer.dll
2014-11-24 09:46 - 2014-11-24 09:46 - 000879104 _____ () C:\Program Files (x86)\LeapFrog\LeapFrog Connect\platforms\qwindows.dll
2013-05-29 16:21 - 2018-08-27 12:41 - 000874784 _____ () C:\Program Files (x86)\Steam\SDL2.dll
2015-12-03 18:08 - 2016-08-31 18:02 - 004969248 _____ () C:\Program Files (x86)\Steam\v8.dll
2015-12-03 18:08 - 2016-08-31 18:02 - 001563936 _____ () C:\Program Files (x86)\Steam\icui18n.dll
2015-12-03 18:08 - 2016-08-31 18:02 - 001195296 _____ () C:\Program Files (x86)\Steam\icuuc.dll
2014-07-06 13:42 - 2018-08-29 14:17 - 002646304 _____ () C:\Program Files (x86)\Steam\video.dll
2018-02-23 17:35 - 2017-12-19 18:43 - 005137696 _____ () C:\Program Files (x86)\Steam\libavcodec-57.dll
2018-02-23 17:35 - 2017-12-19 18:43 - 000847136 _____ () C:\Program Files (x86)\Steam\libavutil-55.dll
2018-02-23 17:35 - 2017-12-19 18:43 - 000695584 _____ () C:\Program Files (x86)\Steam\libavformat-57.dll
2018-02-23 17:35 - 2017-12-19 18:43 - 000351520 _____ () C:\Program Files (x86)\Steam\libavresample-3.dll
2018-02-23 17:35 - 2017-12-19 18:43 - 000783648 _____ () C:\Program Files (x86)\Steam\libswscale-4.dll
2013-05-03 15:35 - 2018-08-29 14:17 - 001015584 _____ () C:\Program Files (x86)\Steam\bin\chromehtml.DLL
2018-02-23 17:35 - 2016-07-04 15:17 - 000266560 _____ () C:\Program Files (x86)\Steam\openvr_api.dll
2017-03-06 20:21 - 2017-03-06 20:21 - 000172032 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\5a8eeeddc97028a9f94d0518c22f4c2c\IsdiInterop.ni.dll
2012-09-06 17:33 - 2011-11-29 20:00 - 000059392 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2012-09-06 17:35 - 2012-02-07 17:39 - 001198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 [105]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE trusted site: HKU\.DEFAULT\…\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\.DEFAULT\…\freerealms.com -> freerealms.com
IE trusted site: HKU\.DEFAULT\…\soe.com -> soe.com
IE trusted site: HKU\.DEFAULT\…\sony.com -> sony.com
IE trusted site: HKU\S-1-5-19\…\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-19\…\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-19\…\soe.com -> soe.com
IE trusted site: HKU\S-1-5-19\…\sony.com -> sony.com
IE trusted site: HKU\S-1-5-20\…\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-20\…\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-20\…\soe.com -> soe.com
IE trusted site: HKU\S-1-5-20\…\sony.com -> sony.com
IE trusted site: HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\clonewarsadventures.com -> clonewarsadventures.com
IE trusted site: HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\freerealms.com -> freerealms.com
IE trusted site: HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\soe.com -> soe.com
IE trusted site: HKU\S-1-5-21-997336396-1215893520-3887361402-1000\…\sony.com -> sony.com
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 19:34 - 2018-01-29 18:00 - 000002092 _____ C:\Windows\system32\Drivers\etc\hosts
0.0.0.0 0.0.0.0 # fix for traceroute and netstat display anomaly
0.0.0.0 tracking.opencandy.com.s3.amazonaws.com
0.0.0.0 media.opencandy.com
0.0.0.0 cdn.opencandy.com
0.0.0.0 tracking.opencandy.com
0.0.0.0 api.opencandy.com
0.0.0.0 api.recommendedsw.com
0.0.0.0 rp.yefeneri2.com
0.0.0.0 os.yefeneri2.com
0.0.0.0 os2.yefeneri2.com
0.0.0.0 installer.betterinstaller.com
0.0.0.0 installer.filebulldog.com
0.0.0.0 d3oxtn1x3b8d7i.cloudfront.net
0.0.0.0 inno.bisrv.com
0.0.0.0 nsis.bisrv.com
0.0.0.0 cdn.file2desktop.com
0.0.0.0 cdn.goateastcach.us
0.0.0.0 cdn.guttastatdk.us
0.0.0.0 cdn.inskinmedia.com
0.0.0.0 cdn.insta.oibundles2.com
0.0.0.0 cdn.insta.playbryte.com
0.0.0.0 cdn.llogetfastcach.us
0.0.0.0 cdn.montiera.com
0.0.0.0 cdn.msdwnld.com
0.0.0.0 cdn.mypcbackup.com
0.0.0.0 cdn.ppdownload.com
0.0.0.0 cdn.riceateastcach.us
0.0.0.0 cdn.shyapotato.us
0.0.0.0 cdn.solimba.com
0.0.0.0 cdn.tuto4pc.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-997336396-1215893520-3887361402-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Ian\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-997336396-1215893520-3887361402-501\Control Panel\Desktop\\Wallpaper -> C:\Users\Guest\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: Apple Mobile Device => 2
MSCONFIG\Services: Bonjour Service => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: IntuitUpdateServiceV4 => 2
MSCONFIG\Services: iPod Service => 3
MSCONFIG\Services: LeapFrog Connect Device Service => 2
MSCONFIG\Services: lxduCATSCustConnectService => 2
MSCONFIG\Services: lxdu_device => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: nvUpdatusService => 2
MSCONFIG\Services: Steam Client Service => 3
MSCONFIG\Services: SwitchBoard => 3
MSCONFIG\Services: vToolbarUpdater17.1.2 => 2
MSCONFIG\startupfolder: C:^Users^Ian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup
MSCONFIG\startupfolder: C:^Users^Ian^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk => C:\Windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AdobeBridge => "C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe" -stealth
MSCONFIG\startupreg: AdobeCS5.5ServiceManager => "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
MSCONFIG\startupreg: Akamai NetSession Interface => "C:\Users\Ian\AppData\Local\Akamai\netsession_win.exe"
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
MSCONFIG\startupreg: IAStorIcon => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
MSCONFIG\startupreg: iCloudServices => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
MSCONFIG\startupreg: IJNetworkScannerSelectorEX => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: lxduamon => "C:\Program Files (x86)\Lexmark 5600-6600 Series\lxduamon.exe"
MSCONFIG\startupreg: lxdumon.exe => "C:\Program Files (x86)\Lexmark 5600-6600 Series\lxdumon.exe"
MSCONFIG\startupreg: Monitor => "C:\Program Files (x86)\LeapFrog\LeapFrog Connect\Monitor.exe"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RTHDVCPL => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s
MSCONFIG\startupreg: SBRegRebootCleaner => "C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe"
MSCONFIG\startupreg: Steam => "C:\Program Files (x86)\Steam\Steam.exe" -silent
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: SwitchBoard => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [TCP Query User{A01CF0C0-D1B3-4266-A530-682C3BDF1EE8}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [UDP Query User{9C0562F8-58C9-406E-A693-FBE9177B31AC}C:\program files (x86)\google\chrome\application\chrome.exe] => (Block) C:\program files (x86)\google\chrome\application\chrome.exe
FirewallRules: [TCP Query User{9F1D47D7-5E52-4D84-A397-3C7DE79643C1}C:\program files\hp\hp officejet 5740 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp officejet 5740 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [UDP Query User{435B607D-DC32-40AE-83EE-19F6651C4A2F}C:\program files\hp\hp officejet 5740 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp officejet 5740 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [TCP Query User{8B2E2F55-3FD2-4793-943E-7A9DDEBA6436}C:\program files\hp\hp officejet 5740 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp officejet 5740 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [UDP Query User{5BB7035F-761F-45E9-941A-D932D3116916}C:\program files\hp\hp officejet 5740 series\bin\hpnetworkcommunicatorcom.exe] => (Block) C:\program files\hp\hp officejet 5740 series\bin\hpnetworkcommunicatorcom.exe
FirewallRules: [TCP Query User{FE921A6D-326B-49DC-AB59-5E4F54D5BA50}C:\program files (x86)\arc\arcchat.exe] => (Block) C:\program files (x86)\arc\arcchat.exe
FirewallRules: [UDP Query User{0646937A-8AA7-4966-A44C-5527446F03C3}C:\program files (x86)\arc\arcchat.exe] => (Block) C:\program files (x86)\arc\arcchat.exe
FirewallRules: [TCP Query User{EB83850E-781A-49B8-80C2-A809A055C788}C:\program files (x86)\neverwinter_en\neverwinter\live\x86\gameclient.exe] => (Block) C:\program files (x86)\neverwinter_en\neverwinter\live\x86\gameclient.exe
FirewallRules: [UDP Query User{75E26206-9F4F-4BF8-BC2C-F569832CA9C3}C:\program files (x86)\neverwinter_en\neverwinter\live\x86\gameclient.exe] => (Block) C:\program files (x86)\neverwinter_en\neverwinter\live\x86\gameclient.exe
FirewallRules: [{6C20820E-6DFD-42BE-8BD3-30FF20D1B29B}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{33190DA5-3033-4A5E-B193-96C49FD558A6}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe
FirewallRules: [{57BE4DB5-D33B-4D39-8E75-218FABC161D9}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{0F06CCA3-C2C1-485C-9E87-92325859C511}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe
FirewallRules: [{483BEFDF-10B9-4912-9318-E8851C204D2F}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{75B9F24E-E6E3-42D0-9264-97F2E10F402B}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe
FirewallRules: [{2DC331A8-A4A7-49AE-A567-C0C41DF9507A}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Subnautica\Subnautica.exe
FirewallRules: [{A910E142-8E02-4752-A0A6-87CCE70EC96F}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Subnautica\Subnautica.exe
FirewallRules: [TCP Query User{BB898266-41F3-4AD5-81F9-C7454E4A8EA8}C:\program files (x86)\cricut-craft room\ccrbridge.exe] => (Allow) C:\program files (x86)\cricut-craft room\ccrbridge.exe
FirewallRules: [UDP Query User{FD7C00C7-0C40-4591-9740-9D7D79127CA1}C:\program files (x86)\cricut-craft room\ccrbridge.exe] => (Allow) C:\program files (x86)\cricut-craft room\ccrbridge.exe
FirewallRules: [{AB383E6C-3BD6-48FA-824A-89A6D82F2F9B}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdater.exe
FirewallRules: [{F3C620C5-67C2-40CA-BDAF-6B5C07233B2F}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{672D05B3-5FEB-431F-8EB6-2868A0FEF308}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{24D02AE0-CC1B-4950-B7EB-32CF8235D618}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{F9B88973-7851-4FBD-807E-2DD9D1986B0E}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [{A87B18F8-6723-4188-A9B8-4B897ACED621}] => (Allow) C:\Program Files (x86)\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe
FirewallRules: [TCP Query User{73900FB7-578D-4C93-9251-DB5243943D90}C:\program files (x86)\neverwinter_en\neverwinter\live\x64\gameclient.exe] => (Block) C:\program files (x86)\neverwinter_en\neverwinter\live\x64\gameclient.exe
FirewallRules: [UDP Query User{EED1DF68-08FD-48A6-8A6B-30113F6679E5}C:\program files (x86)\neverwinter_en\neverwinter\live\x64\gameclient.exe] => (Block) C:\program files (x86)\neverwinter_en\neverwinter\live\x64\gameclient.exe
FirewallRules: [TCP Query User{08BF642B-EE0A-4858-ADDD-7584B4755BE9}C:\users\guest\appdata\local\programs\opera\53.0.2907.68\opera.exe] => (Block) C:\users\guest\appdata\local\programs\opera\53.0.2907.68\opera.exe
FirewallRules: [UDP Query User{005255E1-B2A7-4C30-A48C-9E9449EBDEFD}C:\users\guest\appdata\local\programs\opera\53.0.2907.68\opera.exe] => (Block) C:\users\guest\appdata\local\programs\opera\53.0.2907.68\opera.exe
FirewallRules: [{C4ACC85E-64D8-4E22-A9FC-164917596A8B}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Cuphead\Cuphead.exe
FirewallRules: [{9042E68E-BFB2-48A9-80C2-BC82F6BE4762}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Cuphead\Cuphead.exe
FirewallRules: [TCP Query User{D30A3BEA-D32E-4F6F-A4D7-701535FAE60A}C:\users\guest\appdata\local\programs\opera\53.0.2907.99\opera.exe] => (Block) C:\users\guest\appdata\local\programs\opera\53.0.2907.99\opera.exe
FirewallRules: [UDP Query User{F930EC23-BC4D-4980-B4B7-679E8589663D}C:\users\guest\appdata\local\programs\opera\53.0.2907.99\opera.exe] => (Block) C:\users\guest\appdata\local\programs\opera\53.0.2907.99\opera.exe
FirewallRules: [TCP Query User{5C2DA655-8FC2-4B0F-8D6B-C0AB5118586D}C:\users\guest\appdata\local\programs\opera\53.0.2907.99\opera.exe] => (Block) C:\users\guest\appdata\local\programs\opera\53.0.2907.99\opera.exe
FirewallRules: [UDP Query User{271DB6C8-FF2E-4EFC-9FFC-28B90263C355}C:\users\guest\appdata\local\programs\opera\53.0.2907.99\opera.exe] => (Block) C:\users\guest\appdata\local\programs\opera\53.0.2907.99\opera.exe
FirewallRules: [{A2D31457-56D2-4295-AB26-8DE5D82421CA}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Cryptic Studios\Neverwinter.exe
FirewallRules: [{3E5E7E8F-24F1-42E5-854D-9FB19E3CB8CF}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Cryptic Studios\Neverwinter.exe
FirewallRules: [TCP Query User{95F1B9CD-2270-4709-8C82-188C2C44EE4D}C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\x64\gameclient.exe] => (Block) C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\x64\gameclient.exe
FirewallRules: [UDP Query User{FFCC4AE1-CAEF-45E4-BA2A-8BE491DD938A}C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\x64\gameclient.exe] => (Block) C:\program files (x86)\steam\steamapps\common\cryptic studios\neverwinter\live\x64\gameclient.exe
FirewallRules: [{A20627B3-499F-48A9-8D30-3A9E0BCACD7E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Ultimate Custom Night\Ultimate Custom Night.exe
FirewallRules: [{EFD35C1C-82C6-4D86-9E2E-88F6A8D3CB8E}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Ultimate Custom Night\Ultimate Custom Night.exe
FirewallRules: [{9B36A11C-7E93-4464-820B-C5DE5453FBC9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [{357770EF-44CB-4B19-85C5-DAEBF2EF7D1C}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Sid Meier's Civilization V\Launcher.exe
FirewallRules: [TCP Query User{14231660-84C0-4E09-9E08-3C2E929BCB23}C:\users\guest\appdata\local\programs\opera\54.0.2952.71\opera.exe] => (Block) C:\users\guest\appdata\local\programs\opera\54.0.2952.71\opera.exe
FirewallRules: [UDP Query User{41CC905D-5DB7-427F-800E-ADDA73718F09}C:\users\guest\appdata\local\programs\opera\54.0.2952.71\opera.exe] => (Block) C:\users\guest\appdata\local\programs\opera\54.0.2952.71\opera.exe
FirewallRules: [{827D99B0-1B56-4B9A-9356-977D64333CBF}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [TCP Query User{F56F83B2-903D-4CD6-8191-A28C381E0253}C:\users\ian\appdata\roaming\cricutdesignspace3\bridge\cricutbridge4.exe] => (Allow) C:\users\ian\appdata\roaming\cricutdesignspace3\bridge\cricutbridge4.exe
FirewallRules: [UDP Query User{8F99E6C4-E376-4071-9EB7-0BABB4312223}C:\users\ian\appdata\roaming\cricutdesignspace3\bridge\cricutbridge4.exe] => (Allow) C:\users\ian\appdata\roaming\cricutdesignspace3\bridge\cricutbridge4.exe
FirewallRules: [{8070F8C3-5D9C-4CEE-BC27-62D1675F21BF}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
FirewallRules: [{3F19F695-6E2C-40ED-97FA-31CEAC62ADF7}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7x64\steamwebhelper.exe
FirewallRules: [{8D408E05-8E6B-4EDF-8008-22757D0C10D9}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim Special Edition\SkyrimSELauncher.exe
FirewallRules: [{DC6E6D85-B8B1-40A2-83DF-E50209B88D9D}] => (Allow) C:\Program Files (x86)\Steam\SteamApps\common\Skyrim Special Edition\SkyrimSELauncher.exe
==================== Restore Points =========================
09-09-2018 19:20:37 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215
09-09-2018 19:28:14 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215
09-09-2018 22:24:55 Windows Update
==================== Faulty Device Manager Devices =============
Name:
Description:
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: NETGEAR R6700 802.11ac Wireless Router
Description: NETGEAR R6700 802.11ac Wireless Router
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: SBRE
Description: SBRE
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: SBRE
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (09/10/2018 02:26:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1997
Error: (09/10/2018 02:26:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1997
Error: (09/10/2018 02:26:02 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/10/2018 02:26:01 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 998
Error: (09/10/2018 02:26:01 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 998
Error: (09/10/2018 02:26:01 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (09/10/2018 11:39:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1997
Error: (09/10/2018 11:39:17 AM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1997
System errors:
=============
Error: (09/10/2018 04:59:16 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (09/10/2018 04:59:16 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (09/10/2018 04:59:16 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (09/10/2018 04:59:16 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (09/10/2018 04:59:16 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (09/10/2018 04:59:16 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (09/10/2018 04:59:16 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 40.
Error: (09/10/2018 04:59:16 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
Windows Defender:
===================================
Date: 2014-02-14 19:03:29.941
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
Name:TrojanDropper:Win32/Sirefef.gen!G
ID:197961
Severity:Severe
Category:Trojan Dropper
Path Found:file:C:\Users\Ian\AppData\Local\Temp\msimg32.dll
Detection Type:Generic
Detection Source:System
Status:Unknown
Process Name:
Date: 2014-02-14 18:58:50.801
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
Name:TrojanDropper:Win32/Sirefef.gen!G
ID:197961
Severity:Severe
Category:Trojan Dropper
Path Found:file:C:\Users\Ian\AppData\Local\Temp\msimg32.dll
Detection Type:Generic
Detection Source:System
Status:Unknown
Process Name:
Date: 2014-02-14 18:54:13.609
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
Name:TrojanDropper:Win32/Sirefef.gen!G
ID:197961
Severity:Severe
Category:Trojan Dropper
Path Found:file:C:\Users\Ian\AppData\Local\Temp\msimg32.dll
Detection Type:Generic
Detection Source:System
Status:Unknown
Process Name:
Date: 2014-02-11 02:39:15.171
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
Name:TrojanDropper:Win32/Sirefef.gen!G
ID:197961
Severity:Severe
Category:Trojan Dropper
Path Found:file:C:\Users\Ian\AppData\Local\Temp\msimg32.dll
Detection Type:Generic
Detection Source:System
Status:Unknown
Process Name:
Date: 2014-01-30 13:11:49.462
Description:
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
Name:TrojanDropper:Win32/Sirefef.gen!G
ID:197961
Severity:Severe
Category:Trojan Dropper
Path Found:file:C:\Users\Ian\AppData\Local\Temp\msimg32.dll
Detection Type:Generic
Detection Source:System
Status:Unknown
Process Name:
Date: 2015-10-07 02:30:57.566
Description:
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source:User
Signature Type:
Update Type:
Current Engine Version:
Previous Engine Version:1.1.12101.0
Error code:0x8050a003
Error description:This package does not contain up-to-date definition files for this program. For more information, see Help and Support.
Date: 2014-01-27 13:08:54.733
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified.
Signature version:0.0.0.0
Engine version:0.0.0.0
Date: 2012-10-01 20:57:09.414
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified.
Signature version:0.0.0.0
Engine version:0.0.0.0
CodeIntegrity:
===================================
Date: 2012-09-06 18:24:52.441
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Ian\Downloads\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2012-09-06 18:24:52.441
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Ian\Downloads\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2012-09-06 18:24:52.426
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Ian\AppData\Local\Temp\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2012-09-06 18:24:52.426
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Ian\AppData\Local\Temp\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2012-09-06 18:24:44.549
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Ian\Downloads\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2012-09-06 18:24:44.549
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Ian\Downloads\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2012-09-06 18:24:44.534
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Ian\AppData\Local\Temp\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2012-09-06 18:24:44.534
Description:
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume1\Users\Ian\AppData\Local\Temp\PCIUtil.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i5-3570K CPU @ 3.40GHz
Percentage of memory in use: 54%
Total physical RAM: 8086.02 MB
Available physical RAM: 3717.97 MB
Total Virtual: 16170.22 MB
Available Virtual: 10863.71 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:931.51 GB) (Free:552.19 GB) NTFS ==>[drive with boot components (obtained from BCD)]
Drive d: (TurboTax 2017) (CDROM) (Total:0.48 GB) (Free:0 GB) CDFS
Drive e: () (Fixed) (Total:149.04 GB) (Free:0.13 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows XP) (Size: 149.1 GB) (Disk ID: 0B940B93)
Partition 1: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
Partition 2: (Active) - (Size=10 MB) - (Type=17)ATTENTION ===> Suspicious partition bootkit on partition 2
Could not read MBR for disk 1.
========================================================
Disk: 2 (MBR Code: Windows 7/8/10) (Size: 931.5 GB) (Disk ID: 04EE0BCF)
Partition 1: (Active) - (Size=931.5 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================