Sorry I did run it at the same time -
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01.12.2018 01
Ran by [removed] (administrator) on KAREN-PC (02-12-2018 16:31:27)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Microsoft Windows 10 Home Version 1803 17134.345 (X86) Language: English (United States)
Internet Explorer Version 11 (Default browser: Edge)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(SUPERAntiSpyware.com) C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
(TOSHIBA Corporation) C:\Program Files\TOSHIBA\TECO\TecoService.exe
(Microsoft Corporation) C:\Windows\System32\WirelessKB850NotificationService.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(SUPERAntiSpyware) C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE
(Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
() C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\…\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [486816 2018-04-11] (Microsoft Corporation)
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12214528 2015-06-24] (Realtek Semiconductor)
HKLM\…\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [67896 2017-11-30] (Apple Inc.)
HKLM\…\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1160408 2017-03-28] (Adobe Systems Incorporated)
HKLM\…\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3527880 2015-06-12] (Synaptics Incorporated)
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-12-02] (AVAST Software)
HKLM Group Policy restriction on software: %systemroot%\system32\mrt.exe <==== ATTENTION
Winlogon\Notify\!SASWinLogon: C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [X]
HKU\S-1-5-19\…\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-20\…\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [516608 2018-04-11] (Microsoft Corporation)
HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\…\Run: [SUPERAntiSpyware] => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [7777200 2018-12-02] (SUPERAntiSpyware)
HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\…\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner.exe [14614416 2018-11-28] (Piriform Software Ltd)
HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\windows\system32\Ribbons.scr [136704 2018-04-11] (Microsoft Corporation)
ShellExecuteHooks: No Name - {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - -> No File
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 127.0.0.1 localhost
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{2b0fdf8f-4d77-4501-8838-7366a8b54de3}: [NameServer] 156.154.70.22,156.154.71.22
Tcpip\..\Interfaces\{2b0fdf8f-4d77-4501-8838-7366a8b54de3}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{55711e56-1aee-44be-9f0f-8ecf881bb57f}: [NameServer] 156.154.70.22,156.154.71.22
Internet Explorer:
==================
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=msnhome
HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar;=iesearch
HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.refdesk.com/
SearchScopes: HKLM -> {296E8C5C-968E-4C78-B9DC-D257F3E22442} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7TSNA
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2204413028-1142584163-2676527790-1001 -> {296E8C5C-968E-4C78-B9DC-D257F3E22442} URL = hxxp://www.google.com/search?sourceid=ie7&q;={searchTerms}&rls;=com.microsoft:{language}:{referrer:source?}&ie;={inputEncoding}&oe;={outputEncoding}&rlz;=1I7TSNA_enUS356
BHO: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll [2013-03-24] (Oracle Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-08-03] (Google Inc.)
BHO: No Name -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> No File
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll [2013-03-24] (Oracle Corporation)
BHO: Adblock Plus for IE Browser Helper Object -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files\Adblock Plus for IE\AdblockPlus32.dll [2015-02-25] (Eyeo GmbH)
Toolbar: HKLM - No Name - {8dcb7100-df86-4384-8842-8fa844297b3f} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2016-08-03] (Google Inc.)
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} hxxp://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos-beta/OnlineScanner.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - No File
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll [2009-07-26] (Microsoft Corporation)
FireFox:
========
FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] ()
FF Plugin: @java.com/DTPlugin,version=10.17.2 -> C:\windows\system32\npDeployJava1.dll [2013-03-24] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.17.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll [2013-03-24] (Oracle Corporation)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2009-07-10] (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-26] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-26] (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2017-03-28] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-2204413028-1142584163-2676527790-1001: @citrixonline.com/appdetectorplugin -> C:\Users\Karen\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-12-14] (Citrix Online)
Chrome:
=======
CHR DefaultProfile: Default
CHR StartupUrls: Default -> "hxxp://www.refdesk.com/"
CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search{google:pathWildcard}?ei={inputEncoding}&fr;=crmas&p;={searchTerms}
CHR DefaultSearchKeyword: Default -> yahoo.com
CHR DefaultSuggestURL: Default -> hxxps://search.yahoo.com/sugg/chrome?output=fxjson&appid;=crmas&command;={searchTerms}
CHR Profile: C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default [2018-12-02]
CHR Extension: (Docs) - C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-25]
CHR Extension: (Google Drive) - C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-11-02]
CHR Extension: (YouTube) - C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-11-02]
CHR Extension: (Google Search) - C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-11-02]
CHR Extension: (Google Docs Offline) - C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-10-24]
CHR Extension: (AdBlock) - C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-10-26]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-06]
CHR Extension: (Gmail) - C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-15]
CHR Extension: (Chrome Media Router) - C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-12-02]
CHR HKLM\…\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] -
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE.EXE [143776 2017-02-08] (SUPERAntiSpyware.com)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6799632 2018-12-02] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [324000 2018-12-02] (AVAST Software)
S3 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57504 2018-12-02] (AVAST Software)
S3 bgsvcgen; C:\Windows\System32\bgsvcgen.exe [145504 2007-06-15] (B.H.A Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [5073376 2018-09-19] (Malwarebytes)
S4 ssh-agent; C:\WINDOWS\System32\OpenSSH\ssh-agent.exe [353792 2018-03-19] ()
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [216776 2015-06-12] (Synaptics Incorporated)
S3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [51512 2009-08-17] (TOSHIBA Corporation)
R2 TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [185712 2009-08-11] (TOSHIBA Corporation)
S3 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [111960 2009-09-17] (TOSHIBA Corporation)
S3 TPCHSrv; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [685424 2009-08-06] (TOSHIBA Corporation)
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\NisSrv.exe [3805632 2018-06-06] (Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.16.17656.18052-0\MsMpEng.exe [81280 2018-06-06] (Microsoft Corporation)
R2 WirelessKB850NotificationService; C:\WINDOWS\system32\WirelessKB850NotificationService.exe [152560 2018-05-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [167480 2018-12-02] (AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriverx.sys [188976 2018-12-02] (AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidshx.sys [165384 2018-12-02] (AVAST Software)
R0 aswblog; C:\WINDOWS\System32\drivers\aswblogx.sys [284256 2018-12-02] (AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbunivx.sys [57904 2018-12-02] (AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [14840 2018-06-22] (AVAST Software)
R1 aswHdsKe; C:\WINDOWS\System32\drivers\aswHdsKe.sys [183176 2018-12-02] (AVAST Software)
S3 aswHwid; C:\WINDOWS\System32\drivers\aswHwid.sys [42736 2018-12-02] (AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [40688 2018-12-02] (AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [135200 2018-12-02] (AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [100984 2018-12-02] (AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [72800 2018-12-02] (AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [784560 2018-12-02] (AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [397992 2018-12-02] (AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [156936 2018-12-02] (AVAST Software)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [310200 2018-12-02] (AVAST Software)
R1 cdrbsdrv; C:\WINDOWS\system32\Drivers\cdrbsdrv.sys [33408 2006-02-20] (B.H.A Corporation) [File not signed]
R2 MBAMChameleon; C:\WINDOWS\System32\Drivers\MbamChameleon.sys [173496 2018-10-25] (Malwarebytes)
R3 MBAMSwissArmy; C:\WINDOWS\System32\Drivers\mbamswissarmy.sys [229568 2018-12-02] (Malwarebytes)
S3 PGEffect; C:\WINDOWS\System32\DRIVERS\pgeffect.sys [24064 2009-06-22] (TOSHIBA Corporation)
R3 rt640x86; C:\WINDOWS\System32\drivers\rt640x86.sys [504832 2018-04-11] (Realtek )
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [12880 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [67664 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R2 sbapifs; C:\WINDOWS\System32\DRIVERS\sbapifs.sys [69976 2010-06-14] (Sunbelt Software)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [35528 2015-06-12] (Synaptics Incorporated)
R3 Thotkey; C:\WINDOWS\System32\drivers\Thotkey.sys [50280 2015-08-10] (Toshiba Corporation)
R2 TVALZFL; C:\WINDOWS\System32\DRIVERS\TVALZFL.sys [12920 2009-06-19] (TOSHIBA Corporation)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [38912 2018-06-06] (Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [258600 2018-06-06] (Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [45608 2018-06-06] (Microsoft Corporation)
R3 WirelessKeyboardFilter; C:\WINDOWS\System32\drivers\WirelessKeyboardFilter.sys [44776 2016-07-22] (Microsoft Corporation)
U3 idsvc; no ImagePath
U5 vwifimp; C:\Windows\System32\Drivers\vwifimp.sys [31232 2018-04-11] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-12-02 16:31 - 2018-12-02 16:32 - 000017396 _____ C:\Users\Karen\Desktop\FRST.txt
2018-12-02 16:30 - 2018-12-02 16:31 - 000000000 ____D C:\FRST
2018-12-02 16:30 - 2018-12-02 16:30 - 001776128 _____ (Farbar) C:\Users\Karen\Desktop\FRST.exe
2018-12-02 16:05 - 2018-12-02 16:05 - 002417152 _____ (Farbar) C:\Users\Karen\Downloads\FRST64.exe
2018-12-02 16:04 - 2018-12-02 16:04 - 005198336 _____ (AVAST Software) C:\Users\Karen\Desktop\aswMBR (1).exe
2018-12-02 15:54 - 2018-12-02 15:54 - 000229568 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamswissarmy.sys
2018-12-02 15:39 - 2018-10-26 21:18 - 000453814 ____R C:\WINDOWS\system32\Drivers\etc\hosts.20181202-153918.backup
2018-12-02 15:35 - 2018-12-02 15:35 - 005198336 _____ (AVAST Software) C:\Users\Karen\Downloads\aswMBR.exe
2018-12-02 13:23 - 2018-12-02 13:20 - 000323288 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-12-02 16:23 - 2018-04-11 15:36 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-12-02 15:55 - 2018-04-11 15:36 - 000000000 ____D C:\WINDOWS\AppReadiness
2018-12-02 15:53 - 2018-05-29 06:54 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2018-12-02 15:52 - 2018-04-11 07:45 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2018-12-02 15:41 - 2017-11-24 08:59 - 000000079 _____ C:\WINDOWS\wininit.ini
2018-12-02 15:26 - 2018-05-29 06:22 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2018-12-02 14:37 - 2018-04-11 15:31 - 000000000 ____D C:\WINDOWS\INF
2018-12-02 14:35 - 2018-04-11 15:36 - 000000000 ___HD C:\Program Files\WindowsApps
2018-12-02 14:24 - 2018-01-04 22:17 - 000000000 ____D C:\Users\Karen\AppData\Local\Packages
2018-12-02 13:59 - 2018-05-29 06:28 - 000946108 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2018-12-02 13:45 - 2017-01-09 11:35 - 000000000 ____D C:\Program Files\SUPERAntiSpyware
2018-12-02 13:45 - 2016-12-14 18:35 - 000000652 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2204413028-1142584163-2676527790-1001.job
2018-12-02 13:45 - 2016-12-14 18:35 - 000000556 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2204413028-1142584163-2676527790-1001.job
2018-12-02 13:45 - 2012-06-22 14:43 - 000000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2018-12-02 13:40 - 2015-08-10 16:55 - 000000000 ____D C:\AdwCleaner
2018-12-02 13:37 - 2015-08-10 21:15 - 000002217 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-12-02 13:37 - 2014-08-24 22:06 - 000002258 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-12-02 13:34 - 2018-05-29 06:33 - 000002417 _____ C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2018-12-02 13:34 - 2015-08-10 21:27 - 000000000 ___RD C:\Users\Karen\OneDrive
2018-12-02 13:30 - 2011-05-30 10:32 - 000001049 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-12-02 13:27 - 2018-06-06 21:57 - 000183176 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHdsKe.sys
2018-12-02 13:23 - 2018-04-11 15:36 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2018-12-02 13:22 - 2018-06-06 21:57 - 000397992 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2018-12-02 13:22 - 2018-06-06 21:57 - 000310200 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswVmm.sys
2018-12-02 13:22 - 2018-06-06 21:57 - 000167480 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswArPot.sys
2018-12-02 13:22 - 2018-06-06 21:57 - 000156936 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswStm.sys
2018-12-02 13:22 - 2018-06-06 21:57 - 000135200 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswMonFlt.sys
2018-12-02 13:22 - 2018-06-06 21:57 - 000100984 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRdr2.sys
2018-12-02 13:22 - 2018-06-06 21:57 - 000072800 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswRvrt.sys
2018-12-02 13:22 - 2018-06-06 21:57 - 000042736 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswHwid.sys
2018-12-02 13:20 - 2018-10-24 21:59 - 000040688 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswKbd.sys
2018-12-02 13:20 - 2018-06-06 21:57 - 000784560 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSnx.sys
2018-12-02 13:20 - 2018-06-06 21:57 - 000284256 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswblogx.sys
2018-12-02 13:20 - 2018-06-06 21:57 - 000188976 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidsdriverx.sys
2018-12-02 13:20 - 2018-06-06 21:57 - 000165384 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbidshx.sys
2018-12-02 13:20 - 2018-06-06 21:57 - 000057904 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswbunivx.sys
2018-12-02 13:10 - 2018-01-04 22:40 - 000000000 ___RD C:\Users\Karen\3D Objects
2018-12-02 13:10 - 2015-08-10 21:24 - 000000000 __RHD C:\Users\Public\AccountPictures
2018-12-02 13:07 - 2018-05-29 06:33 - 000000000 ____D C:\Users\Karen
2018-12-02 13:05 - 2018-05-29 06:22 - 000310472 _____ C:\WINDOWS\system32\FNTCACHE.DAT
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-05-29 06:22
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 01.12.2018 01
Ran by [removed] (02-12-2018 16:32:44)
Running from C:\Users\[removed]\Desktop
Microsoft Windows 10 Home Version 1803 17134.345 (X86) (2018-05-29 11:55:16)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-2204413028-1142584163-2676527790-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2204413028-1142584163-2676527790-503 - Limited - Disabled)
Guest (S-1-5-21-2204413028-1142584163-2676527790-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2204413028-1142584163-2676527790-1006 - Limited - Enabled)
Karen (S-1-5-21-2204413028-1142584163-2676527790-1001 - Administrator - Enabled) => C:\Users\Karen
WDAGUtilityAccount (S-1-5-21-2204413028-1142584163-2676527790-504 - Limited - Disabled)
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adblock Plus for IE (32-bit) (HKLM\…\{A243D0E2-D027-4340-AA12-6B13B2A96AC0}) (Version: 1.4 - Eyeo GmbH)
Adobe AIR (HKLM\…\Adobe AIR) (Version: 28.0.0.127 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.20) (HKLM\…\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.20 - Adobe Systems Incorporated)
AnswerWorks 5.0 English Runtime (HKLM\…\{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}) (Version: 5.0.7 - Vantage Software Technologies)
Apple Application Support (32-bit) (HKLM\…\{F1D83CEA-2855-4224-9935-D981785AA75D}) (Version: 6.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\…\{A0BE60AA-7470-4F16-A5C5-D9F4A575B606}) (Version: 11.0.2.4 - Apple Inc.)
Apple Software Update (HKLM\…\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.)
Avast Free Antivirus (HKLM\…\Avast Antivirus) (Version: 18.8.2356 - AVAST Software)
Blackboard Collaborate Launcher (HKLM\…\{7D82D616-8BD8-4BE3-B19C-C4BC772E8426}) (Version: 1.2.0.0 - Blackboard)
Bonjour (HKLM\…\{D168AAD0-6686-47C1-B599-CDD4888B9D1A}) (Version: 3.1.0.1 - Apple Inc.)
Canon MX860 series MP Drivers (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX860_series) (Version: - )
CCleaner (HKLM\…\CCleaner) (Version: 5.50 - Piriform)
Cisco WebEx Meetings (HKLM\…\ActiveTouchMeetingClient) (Version: - Cisco WebEx LLC)
Citrix Online Launcher (HKLM\…\{48947098-A67C-46D4-90C5-9F2F6F0F96FE}) (Version: 1.0.449 - Citrix)
ExposurePlot 1.1.6 (HKLM\…\ExposurePlot_is1) (Version: - Paul van Andel)
ezManagerMax 2.0.14 (HKLM\…\ezManagerMax 2.0.14) (Version: - Animas Corporation)
Google Chrome (HKLM\…\Google Chrome) (Version: 70.0.3538.110 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\…\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM\…\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.24.15 - Google Inc.) Hidden
GoToMeeting 8.36.1.10903 (HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\…\GoToMeeting) (Version: 8.36.1.10903 - LogMeIn, Inc.)
iCloud (HKLM\…\{760BB327-3973-4608-85C8-88162E2FF3B6}) (Version: 4.0.6.28 - Apple Inc.)
Intel(R) Graphics Media Accelerator Driver (HKLM\…\HDMI) (Version: 8.15.10.1883 - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\…\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
iSEEK AnswerWorks English Runtime (HKLM\…\{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}) (Version: [removed] - Vantage Linguistics)
iTunes (HKLM\…\{3A9FE6B1-EE7F-40AC-B831-AC7C9ABB58A0}) (Version: 12.1.1.4 - Apple Inc.)
Java 7 Update 17 (HKLM\…\{26A24AE4-039D-4CA4-87B4-2F83217017FF}) (Version: 7.0.170 - Oracle)
Junk Mail filter update (HKLM\…\{E2DFE069-083E-4631-9B6C-43C48E991DE5}) (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Label@Once 1.0 (HKLM\…\{0D795777-9D60-4692-8386-F2B3F2B5E5BF}) (Version: 1.0 - Corel)
Malwarebytes version 3.6.1.2711 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
Microsoft Interactive Training (HKLM\…\Microsoft Press Interactive Training) (Version: - )
Microsoft Mouse and Keyboard Center (HKLM\…\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office XP Media Content (HKLM\…\{90300409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2619.0 - Microsoft Corporation)
Microsoft Office XP Standard for Students and Teachers (HKLM\…\{913D0409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.6626.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\…\OneDriveSetup.exe) (Version: 18.212.1021.0008 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server Compact 3.5 SP1 English (HKLM\…\{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}) (Version: 3.5.5692.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\…\{402ED4A1-8F5B-387A-8688-997ABF58B8F2}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
MyToshiba (HKLM\…\{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}) (Version: 2.2.0.3 - Toshiba)
OneTouch USB Driver (HKLM\…\{E08EC542-BC5F-4F26-BBB9-E426BA007A31}) (Version: 2.0 - LifeScan)
PHOTOfunSTUDIO 4.0 HD Edition (HKLM\…\{381D847E-7E56-4E82-B261-F799E0F40EB4}) (Version: 4.00.262 - Panasonic Corporation)
PL-2303 Vista Driver Installer (HKLM\…\{EEC010D0-1252-4E1D-BAD9-F1B8F414535C}) (Version: 3.0.1.0 - Prolific)
PlayReady PC Runtime x86 (HKLM\…\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Quicken 2013 (HKLM\…\{034DD4BB-F0D6-4ECF-B064-8E39E3EF7076}) (Version: 22.1.12.7 - Intuit)
QuickTime 7 (HKLM\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Realtek Ethernet Controller Driver (HKLM\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 1.00.0008 - Realtek)
Realtek High Definition Audio Driver (HKLM\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (HKLM\…\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30101 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (HKLM\…\{0FB630AB-7BD8-40AE-B223-60397D57C3C9}) (Version: 2.00.0006 - Realtek)
Revo Uninstaller 2.0.5 (HKLM\…\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.5 - VS Revo Group, Ltd.)
Safari (HKLM\…\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Skype Launcher (HKLM\…\{DA84ECBF-4B79-47F2-B34C-95C38484C058}) (Version: 2.01 - TOSHIBA Corporation)
Sonos Controller (HKLM\…\{7BBA9BF8-05DF-47D8-8880-82A9B99505B9}) (Version: 40.5.50020 - Sonos, Inc.)
SUPERAntiSpyware (HKLM\…\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1232 - SUPERAntiSpyware.com)
Synaptics Pointing Device Driver (HKLM\…\SynTPDeinstKey) (Version: 19.0.10.0 - Synaptics Incorporated)
Toshiba Application and Driver Installer (HKLM\…\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.0.9 - Toshiba)
TOSHIBA Assist (HKLM\…\{12B3A009-A080-4619-9A2A-C6DB151D8D67}) (Version: 2.01.11 - TOSHIBA)
TOSHIBA Disc Creator (HKLM\…\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.1 - TOSHIBA Corporation)
TOSHIBA DVD PLAYER (HKLM\…\{6C5F3BDC-0A1B-4436-A696-5939629D5C31}) (Version: 3.01.0.07-A - TOSHIBA Corporation)
TOSHIBA eco Utility (HKLM\…\InstallShield_{53536479-DFB0-47ED-9D10-43F3708C222D}) (Version: 1.1.7.0 - TOSHIBA Corporation)
TOSHIBA Extended Tiles for Windows Mobility Center (HKLM\…\InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}) (Version: 1.01.00 - TOSHIBA Corporation)
TOSHIBA Face Recognition (HKLM\…\InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}) (Version: 3.1.0.32 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM\…\{D0387727-C89D-4774-B643-B9333EAA09DE}) (Version: 2.00.11 - TOSHIBA Corporation)
TOSHIBA HDD/SSD Alert (HKLM\…\InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.0.2 - TOSHIBA Corporation)
Toshiba Online Backup (HKLM\…\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 1.2.0.35 - Toshiba)
TOSHIBA PC Health Monitor (HKLM\…\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.4.1.0 - TOSHIBA Corporation)
Toshiba Quality Application (HKLM\…\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.001.0000 - Toshiba)
TOSHIBA Recovery Media Creator (HKLM\…\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.0.2 - TOSHIBA Corporation)
TOSHIBA Service Station (HKLM\…\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.1.33 - TOSHIBA)
TOSHIBA Speech System Applications (HKLM\…\{EE033C1F-443E-41EC-A0E2-559B539A4E4D}) (Version: 1.00.2518 - )
TOSHIBA Speech System SR Engine(U.S.) Version1.0 (HKLM\…\{008D69EB-70FF-46AB-9C75-924620DF191A}) (Version: - )
TOSHIBA Speech System TTS Engine(U.S.) Version1.0 (HKLM\…\{3FBF6F99-8EC6-41B4-8527-0A32241B5496}) (Version: - )
TOSHIBA Supervisor Password (HKLM\…\{A208044D-A88B-4ACF-AE95-E4F213E6EDC0}) (Version: 2.00.09 - TOSHIBA Corporation)
TOSHIBA Value Added Package (HKLM\…\InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}) (Version: 1.2.25 - TOSHIBA Corporation)
TOSHIBA Web Camera Application (HKLM\…\{5E6F6CF3-BACC-4144-868C-E14622C658F3}) (Version: 1.1.1.4 - TOSHIBA Corporation)
ToshibaRegistration (HKLM\…\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.0.3 - Toshiba)
Visual C++ 2008 x86 Runtime - v9.0.30729.01 (HKLM\…\{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01) (Version: 9.0.30729.01 - Microsoft Corporation)
Windows 10 Update and Privacy Settings (HKLM\…\{542CC2C2-ABAF-4604-8723-DA296AF74540}) (Version: 1.0.14.0 - Microsoft Corporation)
Windows Driver Package - Realtek (RTL8167) Net (06/23/2010 7.023.0623.2010) (HKLM\…\B83979AAD779A87D4EABFA352AD12788E8DCF160) (Version: 06/23/2010 7.023.0623.2010 - Realtek)
Windows Driver Package - Realtek (RTL8167) Net (10/25/2010 7.031.1025.2010) (HKLM\…\6F716E5DEA3BCBCBFE8EF22B4AAE0CD808961B38) (Version: 10/25/2010 7.031.1025.2010 - Realtek)
Windows Driver Package - Realtek Semiconductor Corp. HD Audio Driver (11/02/2010 6.0.1.6235) (HKLM\…\2991A53EE1CFCD2DDF699EABB89005509779A145) (Version: 11/02/2010 6.0.1.6235 - Realtek Semiconductor Corp.)
Windows Live Essentials (HKLM\…\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Sign-in Assistant (HKLM\…\{45338B07-A236-4270-9A77-EBB4115517B5}) (Version: 5.000.818.5 - Microsoft Corporation)
Windows Live Sync (HKLM\…\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live Upload Tool (HKLM\…\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\…\ChromeHTML: -> <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-2204413028-1142584163-2676527790-1001_Classes\CLSID\{32E26FD9-F435-4A20-A561-35D4B987CFDC}\InprocServer32 -> C:\ProgramData\WebEx\WebEx\1225\atucfobj.dll (Cisco WebEx LLC)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-12-02] (AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-12-02] (AVAST Software)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams.dll [2014-11-21] (Apple Inc.)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-12-02] (AVAST Software)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-12-02] (AVAST Software)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {0E0F7218-618B-43FA-BDEA-970642EAF5E6} - System32\Tasks\Ad-Aware Update (Daily 2) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: {10C1CF29-8214-44FB-A0E6-F89F84D7D57D} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {1311E0AE-6469-4E6D-B945-1BDE2E8ED096} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-2204413028-1142584163-2676527790-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Task: {25B06D3B-9135-42FF-9FB4-1BFC5470D2D7} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-12-02] (AVAST Software)
Task: {2923A7A9-0FC2-4A34-A76F-9F6DE8E26C17} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\WINDOWS\ehome\ehrec.exe
Task: {2E971491-BB53-4C40-8749-8F0E2BACD0AF} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {31EAFBEC-864E-4630-9840-68B80675E404} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {37478F5A-6C57-421E-92B0-E14B90E11D93} - System32\Tasks\Ad-Aware Update (Daily 3) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: {403BC797-9793-401F-A1C4-3D49DB063922} - System32\Tasks\SidebarExecute => C:\Program Files\Windows Sidebar\sidebar.exe
Task: {44AD2F11-6F92-49A0-A321-4118D8BE048D} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-08-10] (Adobe Systems Incorporated)
Task: {4B863DF9-0363-4084-A196-A1B08F1675B5} - \Microsoft\Windows\UNP\RunCampaignManager -> No File <==== ATTENTION
Task: {50283549-1BBF-474F-AD47-FE23B114B414} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {521C7682-BEFD-40B9-8902-1B812B5E682C} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {530D901E-F101-4A02-B230-C0FBB6D9B8AA} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {543FA4AB-7477-4D70-9D2D-E0BA5F4AF32D} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\WINDOWS\ehome\mcupdate.exe
Task: {5A01021F-535F-43B1-AC86-25B089E25D5C} - System32\Tasks\AVG\PC Tuneup\Integrator\Start On Karen Logon => C:\Program Files\AVG\AVG PC Tuneup\BoostSpeed.exe
Task: {5DB1C7B1-41A0-4E6F-BCCC-E293EE82E3AC} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {5E03D080-8328-4FC1-AF23-1693001AE107} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {5EB7391F-A628-4FE3-8696-8CA96AD0C849} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {63790D7E-7E7B-4816-9DAB-EC79B82A0330} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-11-28] (Piriform Software Ltd)
Task: {6724BC59-D949-4548-9A09-F299D3B8F1D4} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6B6BDCD6-98A0-4A41-9F75-F0BD12760760} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
Task: {6C493A09-DBC7-479F-9140-9DFD175EBCAD} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {6C60A2F3-48E3-45A3-8FF4-2132589128B5} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2018-12-02] (AVAST Software)
Task: {7AF61B3B-7534-45B5-B072-52E49F735968} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {7BBF2CB6-134C-41F4-86A1-BDA881E63612} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {8303B704-1EF9-49F3-8CA4-81DB09215F4A} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8CD7B542-E4B0-403E-B955-7A14C2A0A27F} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {8F55CA2E-D792-4F78-AABC-D5FED182DEB8} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {9329B323-5C52-42DD-A7DB-8A94427BDCE4} - \Microsoft\Windows\Setup\gwx\runappraiser -> No File <==== ATTENTION
Task: {970C4DC2-CFBB-4818-B51B-9AA459EF507E} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\WINDOWS\ehome\MCUpdate.exe
Task: {9DADF5F9-D244-4CB7-BBB8-12DA19A2038A} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {9E28894A-4800-441D-8FA6-EFCDDAE3FF39} - System32\Tasks\G2MUploadTask-S-1-5-21-2204413028-1142584163-2676527790-1001 => C:\Users\Karen\AppData\Local\GoToMeeting\10903\g2mupload.exe [2018-10-24] (LogMeIn, Inc.)
Task: {AAC7B481-79F6-4535-ACFC-FD17F31FC9FB} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-11-28] (Piriform Ltd)
Task: {AB75C4AD-8A93-4162-B2EE-D0F773C51DCF} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {C213EF7B-5958-4F69-B15B-D4F929D4FE7C} - System32\Tasks\Microsoft\Windows\HelloFace\FODCleanupTask => C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe [2018-04-11] ()
Task: {C32A9CDE-049D-48AD-9DC4-4BB7AB1BB74C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2017-07-24] (Apple Inc.)
Task: {CC4185B8-5342-434B-90AA-32D2E685A25E} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\WINDOWS\ehome\ehrec.exe
Task: {D1099D08-98E8-4EDD-A7DA-3DC7879A1803} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {D1EAE4C8-7645-4A0F-8553-895A4F4D5C2B} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-2204413028-1142584163-2676527790-1001 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe
Task: {D544D7B9-F70E-42E4-BA62-E036734A37AD} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {D888C396-F5D4-498D-82F3-B7AE68405B01} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {DAA3187A-8B01-41A4-8639-AFCF0F9045A7} - System32\Tasks\Ad-Aware Update (Daily 1) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: {DE8005E8-BDC6-4C3E-A705-9DE62C900F4E} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {E136C967-D9E0-4842-8BEA-0EC89B9D09C8} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {E1F2C14D-74CA-4DB7-AE73-08300F617928} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\WINDOWS\ehome\mcupdate.exe
Task: {E3756DAE-650F-4149-B356-36F25407574A} - System32\Tasks\G2MUpdateTask-S-1-5-21-2204413028-1142584163-2676527790-1001 => C:\Users\Karen\AppData\Local\GoToMeeting\10903\g2mupdate.exe [2018-10-24] (LogMeIn, Inc.)
Task: {E4E51AA0-DEEE-4630-AF55-636DE26158CE} - \ConfigFree Startup Programs -> No File <==== ATTENTION
Task: {E9D63C21-C6AD-4BE0-AAF4-CBB72FF55B7C} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {EA14BC59-4FEC-4B66-8648-E1B384A1641F} - System32\Tasks\Ad-Aware Update (Daily 4) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: {EFA10ADC-1908-40C2-BFC8-161BF4A1030B} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\WINDOWS\ehome\ehPrivJob.exe
Task: {F120686E-AFDF-4188-B63E-D03D0E09415F} - System32\Tasks\Ad-Aware Update (Weekly) => C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe
Task: {F78C2B21-85B7-4A60-B92C-51E662D308A4} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\WINDOWS\ehome\mcupdate.exe
Task: {F8228E15-4324-4A15-949E-639FD499AB52} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-28] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2204413028-1142584163-2676527790-1001.job => C:\Users\Karen\AppData\Local\GoToMeeting\10903\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2204413028-1142584163-2676527790-1001.job => C:\Users\Karen\AppData\Local\GoToMeeting\10903\g2mupload.exe
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2017-11-30 18:55 - 2017-11-30 18:55 - 000076088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2017-11-30 18:55 - 2017-11-30 18:55 - 001042232 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2018-10-24 22:02 - 2018-10-25 02:37 - 002225368 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-04-11 15:29 - 2018-04-11 15:29 - 000364200 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2018-04-11 15:29 - 2018-04-11 15:29 - 000308224 _____ () C:\Windows\ShellExperiences\TileControl.dll
2018-04-11 15:29 - 2018-04-11 15:29 - 001670656 _____ () C:\Windows\ShellComponents\TaskFlowUI.dll
2018-10-26 21:18 - 2018-09-19 23:08 - 001609216 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2018-06-06 21:59 - 2018-06-06 21:59 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2018-12-02 13:20 - 2018-12-02 13:20 - 000596696 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2018-12-02 13:37 - 2018-11-16 01:34 - 004238168 _____ () C:\Program Files\Google\Chrome\Application\70.0.3538.110\libglesv2.dll
2018-12-02 13:37 - 2018-11-16 01:34 - 000096600 _____ () C:\Program Files\Google\Chrome\Application\70.0.3538.110\libegl.dll
2018-12-02 14:15 - 2018-12-02 14:18 - 000479232 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\Microsoft.Photos.exe
2018-12-02 14:15 - 2018-12-02 14:18 - 055959552 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\Microsoft.Photos.dll
2018-12-02 14:15 - 2018-12-02 14:18 - 000009216 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\RenderingPlugin.dll
2018-12-02 14:15 - 2018-12-02 14:18 - 003227648 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\MediaEngineCSWrapper.dll
2017-10-03 21:20 - 2017-10-03 21:21 - 002366464 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\UnityEngineDelegates.dll
2018-12-02 14:15 - 2018-12-02 14:18 - 000029184 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\WinMLWrapper.UWP.dll
2018-03-29 22:30 - 2018-03-29 23:09 - 001787904 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\TrackingDLLUWP.dll
2018-09-01 21:15 - 2018-09-01 21:16 - 001875968 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\opencv_imgproc320.dll
2018-09-01 21:15 - 2018-09-01 21:16 - 001818112 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\opencv_core320.dll
2018-12-02 14:15 - 2018-12-02 14:18 - 009068544 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\PhotosApp.Windows.dll
2018-12-02 14:15 - 2018-12-02 14:18 - 003131392 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\MediaEngine.dll
2018-12-02 14:14 - 2018-12-02 14:18 - 001759744 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\AppCore.Windows.dll
2018-09-01 21:15 - 2018-09-01 21:16 - 000645120 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\RuntimeConfiguration.dll
2018-08-16 11:08 - 2018-08-16 11:14 - 003565056 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2018-12-02 14:15 - 2018-12-02 14:18 - 000104448 _____ () C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2018.18091.17210.0_x86__8wekyb3d8bbwe\SKU.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
AlternateDataStreams: C:\WINDOWS\system32\mshtmlmedia.dll:$CmdTcID [64]
AlternateDataStreams: C:\WINDOWS\system32\wu.upgrade.ps.dll:$CmdTcID [64]
AlternateDataStreams: C:\ProgramData\TEMP:0B4227B4 [133]
AlternateDataStreams: C:\ProgramData\TEMP:5C321E34 [238]
AlternateDataStreams: C:\Users\Karen\Downloads\Addition (1).txt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Karen\Downloads\Addition.txt:$CmdZnID [26]
AlternateDataStreams: C:\Users\Karen\Downloads\ccsetup504.exe:$CmdTcID [64]
AlternateDataStreams: C:\Users\Karen\Downloads\ccsetup504.exe:$CmdZnID [26]
AlternateDataStreams: C:\Users\Karen\Downloads\exposureplot_116 (1).zip:$CmdZnID [26]
AlternateDataStreams: C:\Users\Karen\Downloads\exposureplot_116.zip:$CmdZnID [26]
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
IE restricted site: HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\…\fairsearcher.com -> www.fairsearcher.com
IE restricted site: HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\…\flirt-fever.de -> www.flirt-fever.de
IE restricted site: HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\…\softvisia.com -> avast.softvisia.com
IE restricted site: HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\…\vistaprint.com -> www.vistaprint.com
IE restricted site: HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\…\xxx.com -> www.xxx.com
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 21:04 - 2018-12-02 15:39 - 000000135 ____R C:\WINDOWS\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-2204413028-1142584163-2676527790-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Karen\AppData\Local\Microsoft\Windows\Themes\Penguins.jpg
DNS Servers: [removed] - [removed]
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
If an entry is included in the fixlist, it will be removed.
MSCONFIG\startupreg: 00TCrdMain => %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner.exe" /MONITOR
MSCONFIG\startupreg: HSON => %ProgramFiles%\TOSHIBA\TBS\HSON.exe
MSCONFIG\startupreg: SmoothView => %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
MSCONFIG\startupreg: Teco => "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
MSCONFIG\startupreg: TPwrMain => %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
MSCONFIG\startupreg: TWebCamera => "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
HKLM\…\StartupApproved\Run: => "APSDaemon"
HKLM\…\StartupApproved\Run: => "iTunesHelper"
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{78BABCB1-EA28-4CF7-BD7D-133E8B17E470}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{5F5C7BA8-5F80-4CEB-8382-D70F15C1F8E6}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{60B94360-879E-48E0-A32C-DE8E27F4FB23}] => (Allow) C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe
FirewallRules: [{38FBE47B-03C0-4368-9A0C-C052816E311E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{4438C9D8-8FCB-4D71-A493-58B32D2775B0}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [UDP Query User{20DAC881-9187-4E41-BBF6-765EB1CAA269}C:\program files\sonos\sonos.exe] => (Allow) C:\program files\sonos\sonos.exe
FirewallRules: [TCP Query User{A7576461-E963-40F1-A200-6AB4CF552D2D}C:\program files\sonos\sonos.exe] => (Allow) C:\program files\sonos\sonos.exe
FirewallRules: [{0AF84DEF-545C-4663-80F4-0671727C8BD1}] => (Allow) C:\Program Files\Windows Live\Messenger\wlcsdk.exe
FirewallRules: [{0E7582E8-717C-4ED0-97C6-8DBAA3098F08}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{5EE3F3C1-245A-45C1-BD2F-207E44258C9C}] => (Allow) svchost.exe
FirewallRules: [{A558E0B2-72C0-41AA-95BB-5519F588448F}] => (Allow) C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe
FirewallRules: [{ECFF94FB-4439-423D-9245-2B38471A1289}] => (Allow) C:\windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
FirewallRules: [TCP Query User{1D0DF6AB-B29C-4A36-91B4-B3C03DCC3105}C:\users\karen\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe] => (Allow) C:\users\karen\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe
FirewallRules: [UDP Query User{8A5A3268-D5BD-436E-8613-842DBC2ECCE1}C:\users\karen\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe] => (Allow) C:\users\karen\appdata\local\blackboard\blackboard collaborate launcher\embedded\java\jre1.7.0_40\bin\javaw.exe
FirewallRules: [{258126CD-FDF8-4E97-A2D9-C6313F7017F7}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{E2E21F20-0178-465A-B54C-49DBB9E9312D}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
FirewallRules: [{DC05698C-4BAE-4E14-B17A-A5D912532817}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe
FirewallRules: [{A9148570-B08E-4940-BC7E-A1A0D2E77CA4}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe
FirewallRules: [{B3F1958C-01A2-4129-A375-E5D3A9FA1BF7}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
24-10-2018 22:41:05 Windows Update
02-12-2018 15:11:05 Scheduled Checkpoint
==================== Faulty Device Manager Devices =============
Name: Canon MX860 ser Network
Description: Canon MX860 ser Network
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Canon
Service: StillCam
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/02/2018 03:41:41 PM) (Source: VSS) (EventID: 8193) (User: )
Description: Volume Shadow Copy Service error: Unexpected error calling routine QueryFullProcessImageNameW. hr = 0x80070006, The handle is invalid.
.
Operation:
Executing Asynchronous Operation
Context:
Current State: DoSnapshotSet
Error: (12/02/2018 03:40:53 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (12/02/2018 03:40:50 PM) (Source: VSS) (EventID: 8194) (User: )
Description: Volume Shadow Copy Service error: Unexpected error querying for the IVssWriterCallback interface. hr = 0x80070005, Access is denied.
.
This is often caused by incorrect security settings in either the writer or requestor process.
Operation:
Gathering Writer Data
Context:
Writer Class Id: {e8132975-6f93-4464-a53e-1050253ae220}
Writer Name: System Writer
Writer Instance ID: {aa655d3d-b7f6-436e-8dab-afbd556d69bc}
Error: (12/02/2018 03:11:16 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (10/24/2018 10:41:17 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (10/24/2018 10:40:05 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
Error: (10/24/2018 10:19:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: mbamservice.exe, version: 3.2.0.704, time stamp: 0x5b9acc47
Faulting module name: SelfProtectionSdk.dll, version: 3.0.0.360, time stamp: 0x5b995b6a
Exception code: 0xc0000409
Fault offset: 0x001201df
Faulting process id: 0x21ec
Faulting application start time: 0x01d46c0f3fbb2aaa
Faulting application path: C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe
Faulting module path: C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
Report Id: 3ec680fc-b374-4f88-915f-534ce87ab2ab
Faulting package full name:
Faulting package-relative application ID:
Error: (09/01/2018 10:27:03 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.
Details:
AddLegacyDriverFiles: Unable to back up image of binary Microsoft Link-Layer Discovery Protocol.
System Error:
Access is denied.
.
System errors:
=============
Error: (12/02/2018 04:32:56 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Push Notifications User Service_3eb23 service terminated unexpectedly. It has done this 9 time(s).
Error: (12/02/2018 04:32:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Push Notifications User Service_3eb23 service terminated unexpectedly. It has done this 8 time(s).
Error: (12/02/2018 04:31:55 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Push Notifications User Service_3eb23 service terminated unexpectedly. It has done this 7 time(s).
Error: (12/02/2018 04:31:25 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Push Notifications User Service_3eb23 service terminated unexpectedly. It has done this 6 time(s).
Error: (12/02/2018 04:30:53 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Push Notifications User Service_3eb23 service terminated unexpectedly. It has done this 5 time(s).
Error: (12/02/2018 04:30:22 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Push Notifications User Service_3eb23 service terminated unexpectedly. It has done this 4 time(s).
Error: (12/02/2018 04:30:22 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Sync Host_3eb23 service terminated unexpectedly. It has done this 4 time(s).
Error: (12/02/2018 04:30:02 PM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Push Notifications User Service_3eb23 service, but this action failed with the following error:
An instance of the service is already running.
Windows Defender:
===================================
Date: 2018-06-06 22:58:11.195
Description:
Windows Defender Antivirus scan has been stopped before completion.
Scan ID: {DDEA0732-BDD4-45CD-BF8B-48E017DEFB4A}
Scan Type: Antimalware
Scan Parameters: Quick Scan
CodeIntegrity:
===================================
Date: 2018-12-02 15:56:23.469
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\RuntimeBroker.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswhookx.dll that did not meet the Microsoft signing level requirements.
Date: 2018-12-02 14:42:50.989
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\RuntimeBroker.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswhookx.dll that did not meet the Microsoft signing level requirements.
Date: 2018-12-02 13:57:04.082
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\RuntimeBroker.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswhookx.dll that did not meet the Microsoft signing level requirements.
Date: 2018-12-02 13:13:11.982
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\Apple\Internet Services\ShellStreams.dll that did not meet the Microsoft signing level requirements.
Date: 2018-12-02 13:11:24.957
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\RuntimeBroker.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswhookx.dll that did not meet the Microsoft signing level requirements.
Date: 2018-10-26 23:07:47.353
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\RuntimeBroker.exe) attempted to load \Device\HarddiskVolume2\Program Files\AVAST Software\Avast\aswhookx.dll that did not meet the Microsoft signing level requirements.
Date: 2018-10-26 21:41:37.315
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\System32\browser_broker.exe) attempted to load \Device\HarddiskVolume2\Program Files\Common Files\Apple\Internet Services\ShellStreams.dll that did not meet the Microsoft signing level requirements.
Date: 2018-10-25 00:53:10.674
Description:
Code Integrity determined that a process (\Device\HarddiskVolume2\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\mbae.dll that did not meet the Store signing level requirements.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU T6500 @ 2.10GHz
Percentage of memory in use: 61%
Total physical RAM: 2939.98 MB
Available physical RAM: 1138.38 MB
Total Virtual: 5883.98 MB
Available Virtual: 3847.05 MB
==================== Drives ================================
Drive c: (TI102805W0E) (Fixed) (Total:222.92 GB) (Free:178.71 GB) NTFS ==>[system with boot components (obtained from drive)]
\\?\Volume{9e48286d-c34e-11de-a9b1-806e6f6e6963}\ (System) (Fixed) (Total:1.46 GB) (Free:1.26 GB) NTFS
\\?\Volume{1902c2af-0000-0000-0000-801838000000}\ () (Fixed) (Total:0.5 GB) (Free:0.04 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 232.9 GB) (Disk ID: 1902C2AF)
Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Not Active) - (Size=222.9 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=510 MB) - (Type=27)
Partition 4: (Not Active) - (Size=8 GB) - (Type=17)
==================== End of Addition.txt ============================