This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan:JS/Foretype.A!ml

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

 

I am running windows 7. My PC is set up with 3 user accounts plus guest access. Only 1 user has admin rights. All windows updates are automatically run. I am using Microsoft Security Essentials with Real Time protection and free Malwarebytes 3.6.1 to manually scan as needed. I also have Ccleaner on my PC which I run occasionally. I hope using those programs does not disqualify me from receiving any help.

 

Yesterday in a non-admin user account Microsoft Security Essentials detected Trojan:JS/Foretype.A!ml in a file named ATT0946788413.doc, quarantined it and I had it removed. I had MS security essentials do a quick scan which found nothing and I had MBAM scan the system but found nothing (it appeared to take less time than it usually would). I ran GMER 2.2 for Rootkits and Malware without any findings, too. Before going to bed I had MS Security Essentials run a full scan. Typically the result would be on screen the next morning - not today! The desktop didn't show any programs.

 

Strangely the desktop icons for GMER and link for this web site were moved from the right side of the desktop to the left. The same thing happened while I was at work today. This morningand just now again I looked into the event viewer and found a number of errors like "The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000009f (0x0000000000000004, 0x0000000000000258, 0xfffffa80036b3b50, 0xfffff80000b9c560). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 012319-22854-01." I am also seeing multiple warning "Reset to device, \Device\RaidPort0, was issued." from source ahcix64s which I have not seen before.

 

I only logged into the non-admin user account since the detection and performed everything in this accont.

 

 

I followed the malware removal guide instructions BUT after clicking FRST a window opened suggesting to use Avast! Free Antivirus for scanning which I declined. After clicking Yes to the diclaimer, also, a Warning! window showed up:

Error saving file

C:\FRST\HIVES\security !

Continue with the next file?

[ RegCreateKeyEx: 5 - Access is denied ]

Also the generated aswMBR.txt file was not located in the directory where aswMBR.exe was saved. It was saved onto the admin user Desktop. I reran aswMBR.exe and manually changed the location to the user desktop where the exe file is located. Not sure if this makes a difference at all.

 

When running FRST there was no option to check "All Users".

 

I apreciate if somebody could help me and let me know if my PC is safe to use.

 

The log files are attached

Let me pass onto you what I think is happening
The bugcheck was: 0x0000009f

It's possible you have a video or a graphics driver about to give out.

I do not have much experience in this field but I can direct to to another forum after we attempt to clean your computer.

~~~~~~~~~~~`

We will need to enable system restore to continue

Windows 7- Disable/Enable the System restore feature

Click the Windows logo(Start Button), right click on "Computer" then click "Properties":
Then click on "System Protection".
Click on "Configure".
To disable or enable System Restore, select "enable System Protection" then click "Apply". …
Confirm the operation.

~~~~~~~~~~~~~~~~~~~~~~~~~~~``
 

I only logged into the non-admin user account since the detection and performed everything in this accont
Only 1 user has admin rights

I will need you to login to an account that has admin privileges to use Farbar Recovery Scan Tool and a few other tools.
I forgot to add, after you enable system restore, use account that has admin privileges, please run Farbar Recovery Scan Tool
once again and post the 2 new logs.

Hello Juliet,
 
Thank you for your quick reply!.

When I logged into the admin account I was greeted by a window reading:
Windows has encountered from an unexpected shutdown
Windows can check online for a solution to the problem
View problem details


Problem signature:
  Problem Event Name:    BlueScreen
  OS Version:    6.1.7601.2.1.0.768.3
  Locale ID:    1033

Additional information about the problem:
  BCCode:    1000009f
  BCP1:    0000000000000004
  BCP2:    0000000000000258
  BCP3:    FFFFFA80036B3B50
  BCP4:    FFFFF80000B9C560
  OS Version:    6_1_7601
  Service Pack:    1_0
  Product:    768_1

Files that help describe the problem:
  C:\Windows\Minidump\012319-22854-01.dmp
  C:\Users\Dirk - Admin\AppData\Local\Temp\WER-31541483-0.sysdata.xml
 
The window had two options "cancel" and "check for solutions". I couldn't resist and clicked "check for solutions". The window disappeared after a while but nothing else happened. This probably wasn't good, right?
 
As far as enabling system restore, I am under the impression this is enabled already. I did the following:
Click the Windows logo(Start Button), right click on "Computer" then click "Properties":
Then click on "System Protection". (=> This window already shows an active "System Restore…" button and below in the Protection Settings it shows my C: drive as "On" for protection)
Click on "Configure".
=> On this screen I should see "enable System Protection" but I don't have this option. The System Protection window has a "Restore Settings" section which is set to "Restore system settings and previous versions of files". The other options would be "Only restore previous versions of files" or "Turn off system protection". I kept everything the way it is. Please let me know if this should be changed.
 
Okay, here are the 2 new logs. This time included into the post and not attached as files (sorry I messed this up in my 1st post)

 

Thank you again for your quick reply!

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.01.2019
Ran by [removed] (23-01-2019 17:58:17)
Running from C:\Users\[removed]\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-01-18 05:22:31)
Boot Mode: Normal
==========================================================


==================== Accounts: =============================

Administrator (S-1-5-21-2070708007-2879293845-838049191-500 - Administrator - Disabled)
Anita - Internet (S-1-5-21-2070708007-2879293845-838049191-1002 - Limited - Enabled) => C:\Users\Anita - Internet
Dirk - Admin (S-1-5-21-2070708007-2879293845-838049191-1000 - Administrator - Enabled) => C:\Users\Dirk - Admin
Eltern (S-1-5-21-2070708007-2879293845-838049191-1009 - Limited - Enabled) => C:\Users\Eltern
Guest (S-1-5-21-2070708007-2879293845-838049191-501 - Limited - Enabled) => C:\Users\Guest
HomeGroupUser$ (S-1-5-21-2070708007-2879293845-838049191-1008 - Limited - Enabled)

==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

==================== Installed Programs ======================

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

Acer eRecovery Management (HKLM-x32\…\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3505 - Acer Incorporated)
Acer Registration (HKLM-x32\…\Acer Registration) (Version: 1.04.3503 - Acer Incorporated)
Acer ScreenSaver (HKLM-x32\…\Acer Screensaver) (Version: 1.1.0609.2011 - Acer Incorporated)
Adobe Acrobat Reader DC (HKLM-x32\…\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 19.010.20069 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\…\Adobe AIR) (Version: 2.7.1.19610 - Adobe Systems Incorporated)
Adobe Flash Player 12 ActiveX (HKLM-x32\…\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 32 NPAPI (HKLM-x32\…\Adobe Flash Player NPAPI) (Version: 32.0.0.114 - Adobe Systems Incorporated)
Adobe SVG Viewer 3.0 (HKLM-x32\…\Adobe SVG Viewer) (Version:  3.0 - Adobe Systems, Inc.)
AlbumWeb (HKLM-x32\…\AlbumWeb) (Version:  - )
ArcSoft PhotoImpression 6 (HKLM-x32\…\{063E409E-3D7C-4A4A-95AB-2F124B9224B3}) (Version: 6.1.8.135 - ArcSoft)
ArcSoft PhotoStudio 5.5 (HKLM-x32\…\{85309D89-7BE9-4094-BB17-24999C6118FC}) (Version:  - ArcSoft)
ATI Catalyst Install Manager (HKLM\…\{D9B8D7C4-BE13-5877-6999-B076956AA3F9}) (Version: 3.0.829.0 - ATI Technologies, Inc.)
Canon CanoScan 8600F User Registration (HKLM-x32\…\Canon CanoScan 8600F User Registration) (Version:  - )
Canon CanoScan Toolbox 5.0 (HKLM-x32\…\CanoScan Toolbox 5.0) (Version:  - )
CanoScan 8600F (HKLM\…\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_CNQ4804) (Version:  - )
CCleaner (HKLM\…\CCleaner) (Version: 5.51 - Piriform)
clear.fi  (HKLM-x32\…\{14C4C3B6-F1F4-401F-8C86-03E8E19AAC8C}) (Version: 1.5.1717_38186 - CyberLink Corp.) Hidden
clear.fi  (HKLM-x32\…\{E8E37C4F-DE01-4286-AFB6-9FBEC8265A1A}) (Version: 9.0.8031 - CyberLink Corp.) Hidden
clear.fi (HKLM-x32\…\{37126D87-E4FD-4614-B908-A0BB7ECE3992}) (Version: 1.5.2212.35 - CyberLink Corp.) Hidden
clear.fi (HKLM-x32\…\InstallShield_{37126D87-E4FD-4614-B908-A0BB7ECE3992}) (Version: 1.5.2212.35 - CyberLink Corp.)
clear.fi Client (HKLM-x32\…\{43AAE145-83CF-4C96-9A5E-756CEFCE879F}) (Version: 1.05.3002 - Acer Incorporated)
D3DX10 (HKLM-x32\…\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Evernote v. 4.5.1 (HKLM-x32\…\{28921580-E4BB-11E0-9FD7-1CC1DEF07CBE}) (Version: 4.5.1.5451 - Evernote Corp.)
FileZilla Client 3.28.0 (HKU\S-1-5-21-2070708007-2879293845-838049191-1000\…\FileZilla Client) (Version: 3.28.0 - Tim Kosse)
Galerie de photos Windows Live (HKLM-x32\…\{488F0347-C4A7-4374-91A7-30818BEDA710}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.169 - Google Inc.) Hidden
Hotkey Utility (HKLM-x32\…\Hotkey Utility) (Version: 2.05.3505 - Acer Incorporated)
Junk Mail filter update (HKLM-x32\…\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Malwarebytes version 3.6.1.2711 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.6.1.2711 - Malwarebytes)
Mesh Runtime (HKLM-x32\…\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}) (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.7.2 (HKLM\…\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.03062 - Microsoft Corporation)
Microsoft Office 2000 Standard (HKLM-x32\…\{00020407-78E1-11D2-B60F-006097C998E7}) (Version: 9.00.2816 - Microsoft Corporation)
Microsoft Office 97, Professional Edition (HKLM-x32\…\Office8.0) (Version:  - )
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\…\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\…\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\…\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50918.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Moorhuhn WE AYCS (HKLM-x32\…\{F92CDFEB-DB96-4589-B88C-BE181D153445}) (Version:  - )
Moorhuhn X - XS (HKLM-x32\…\{21BBAD12-C75F-4F06-A9B0-6F8BEEAF3846}) (Version:  - )
Mozilla Firefox 64.0.2 (x64 en-US) (HKLM\…\Mozilla Firefox 64.0.2 (x64 en-US)) (Version: 64.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 64.0.2.6947 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\…\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\…\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MyWinLocker (HKLM\…\{0B78ECB0-1A6B-4E6D-89D7-0E7CE77F0427}) (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker 4 (HKLM-x32\…\{39F15B50-A977-4CA6-B1C3-6A8724CDA025}) (Version: 4.0.14.27 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\…\{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.18 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\…\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.18 - Egis Technology Inc.)
Nero DiscSpeed 10 (HKLM-x32\…\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG)
Nero Express 10 (HKLM-x32\…\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12000.21.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\…\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.5.10300 - Nero AG)
Nero StartSmart 10 (HKLM-x32\…\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
Nero Update (HKLM-x32\…\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
NOOK for PC (HKLM-x32\…\BN_DesktopReader) (Version: 2.5.4.7070 - Barnesandnoble.com)
OVTScanner_Vista64 (HKLM-x32\…\{AE09704D-9051-4C25-B940-77F889F0C93F}) (Version: 1.00.0000 - OVT)
Presto! PageManager 7.15.14 (HKLM-x32\…\{D2D6B9EB-C6DC-4DAA-B4DE-BB7D9735E7DA}) (Version: 7.15.14E - NewSoft)
RAIDXpert (HKLM-x32\…\{8B76B8E9-F773-4B75-A08C-120079EB765E}) (Version: 3.3.1540.3 - AMD) Hidden
RAIDXpert (HKLM-x32\…\InstallShield_{8B76B8E9-F773-4B75-A08C-120079EB765E}) (Version: 3.3.1540.3 - AMD)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\…\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6392 - Realtek Semiconductor Corp.)
Samsung ML-1740 Series (HKLM-x32\…\Samsung ML-1740 Series) (Version:  - )
Seagate Dashboard (HKLM-x32\…\{EA266F00-A8E7-43A0-8DED-FBFE3F076934}) (Version: 4.8.5.0 - Seagate)
Shredder (HKLM\…\{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}) (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
Shredder (HKLM-x32\…\{C2695E83-CF1D-43D1-84FE-B3BEC561012A}) (Version: 2.0.8.9 - Egis Technology Inc.) Hidden
SimpleOCR 3.1 (HKLM-x32\…\SimpleOCR 3.1) (Version:  - )
Skype™ 7.3 (HKLM-x32\…\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.3.101 - Skype Technologies S.A.)
SPC 700NC PC Camera (HKLM-x32\…\{9C5B9ED6-0344-4550-A4AB-C4499EB36053}) (Version:  - )
Times Reader (HKLM-x32\…\{491ADA37-04EE-2ECE-9F86-DDC0106047AC}) (Version: 2.055 - The New York Times Company) Hidden
Times Reader (HKLM-x32\…\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1) (Version: 2.055 - The New York Times Company)
Welcome Center (HKLM-x32\…\Acer Welcome Center) (Version: 1.02.3504 - Acer Incorporated)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)

==================== Custom CLSID (Whitelisted): ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)
ContextMenuHandlers3: [MWLIVShellExt] -> {B1B294FE-EC1E-4fef-AF68-D34CE3E38157} => C:\Program Files (x86)\EgisTec MyWinLocker\x64\MWLIVShellExt.dll [2011-06-21] (Egis Technology Inc. )
ContextMenuHandlers3: [ShredderContextMenu] -> {521065F1-DE6C-4E46-BBCB-89B0D0BE860D} => C:\Program Files (x86)\EgisTec Shredder\x64\ShredderContextMenu.dll [2011-03-29] (Egis Technology Inc.)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2011-06-30] (Advanced Micro Devices, Inc.)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-09-19] (Malwarebytes)

==================== Scheduled Tasks (Whitelisted) =============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

Task: {06035DF2-530E-4496-9898-EEFBED27623F} - System32\Tasks\Dirk - Admin DBAgent 2 0 => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [2017-07-21] (Seagate Technology LLC)
Task: {263277E9-780A-4E84-881E-95ABD849DECD} - System32\Tasks\Adobe ARM => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-13] (Adobe Systems Incorporated)
Task: {395F1744-1258-41C3-A243-1F79D99F4816} - System32\Tasks\{4C991ED6-1192-4E4B-B01A-13FB0F69F92A} => C:\Windows\system32\pcalua.exe -a "c:\Programme\Adobe\Adobe Version Cue CS2\ControlPanel\VersionCueCS2.cpl"
Task: {492943FC-FF1C-447A-94A9-CBC953B51D1F} - System32\Tasks\Dirk - Admin => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\NBCore.exe [2017-07-21] (Seagate Technology LLC)
Task: {4B09DC83-20A4-4C7D-8E0D-D62B847F2EE4} - System32\Tasks\clear.fi => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe [2011-10-12] (Acer Incorporated)
Task: {68F37FFC-99C6-40DE-9BED-F5283F3B2B2A} - System32\Tasks\Dirk - Admin Merge => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\NBCore.exe [2017-07-21] (Seagate Technology LLC)
Task: {6D5D176B-6984-4D76-AEA4-0CF49A2378BF} - System32\Tasks\DMREngine => C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe [2011-10-12] (CyberLink)
Task: {7A8B34EF-4B61-4982-B948-374B01712E0A} - System32\Tasks\EgisUpdate => C:\Program Files\EgisTec IPS\EgisUpdate.exe [2011-03-28] (Egis Technology Inc.)
Task: {7EE9AAFA-7BDD-420A-A22D-8C051CCD7E49} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {8791FB2C-073E-4C0B-A2A9-2BF66A8D3C80} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-12-10] (Piriform Ltd)
Task: {9321A095-4551-49F7-81BF-250AEE318C36} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2019-01-12] (Adobe Systems Incorporated)
Task: {98529759-2F1F-430E-BCF0-7F4E86A59CFE} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-12-10] (Piriform Software Ltd)
Task: {9AFA21EF-3DEA-472C-9D60-0626106A5F8E} - System32\Tasks\Adobe Reader Speed Launcher => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe
Task: {A4508248-103D-4882-8870-003B15CD07C8} - System32\Tasks\clear.fiAgent => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe [2011-10-12] (CyberLink Corp.)
Task: {B2296870-87C4-4FEE-95CA-3A4AF664C1D7} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_32_0_0_114_Plugin.exe [2019-01-12] (Adobe Systems Incorporated)
Task: {B4877E14-C89D-4161-99B4-2EB5F161288E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-08-13] (Adobe Systems Incorporated)
Task: {BC151342-9981-4D04-ACAB-08C64BB55D51} - System32\Tasks\Dirk - Internet DBAgent 2 0 => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [2017-07-21] (Seagate Technology LLC)
Task: {E1B33DEF-05C7-4BF5-B942-7BC21767CA4B} - System32\Tasks\Anita - Internet DBAgent 2 0 => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\DBAgent.exe [2017-07-21] (Seagate Technology LLC)
Task: {E8334DD1-CF38-43BD-886C-CD1C4DF1FFE4} - System32\Tasks\Seagate_Install_Launch => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Dashboard.exe [2017-07-21] (Seagate Technology LLC)
Task: {F7CEA5AD-30B0-4ED7-91E7-45016026368E} - System32\Tasks\PMMUpdate => C:\Program Files\EgisTec IPS\PMMUpdate.exe [2011-03-28] (Egis Technology Inc.)

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)


==================== Shortcuts & WMI ========================

(The entries could be listed to be restored or removed.)

WMI:subscription\__FilterToConsumerBinding->CommandLineEventConsumer.Name=\"BVTConsumer\"",Filter="__EventFilter.Name=\"BVTFilter\":
WMI:subscription\__EventFilter->BVTFilter:
WMI:subscription\CommandLineEventConsumer->BVTConsumer:

==================== Loaded Modules (Whitelisted) ==============

2010-11-10 01:30 - 2010-11-10 01:30 - 000071560 _____ () C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
2018-10-12 05:30 - 2019-01-01 09:01 - 002712432 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2010-11-10 01:30 - 2010-11-10 01:30 - 000128904 _____ () C:\Windows\SysWOW64\WinMsgBalloonServer.exe
2017-09-29 04:32 - 2017-09-29 04:32 - 000076456 _____ () C:\Program Files\FileZilla FTP Client\fzshellext_64.dll
2009-01-21 17:45 - 2009-01-21 17:45 - 001401856 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll
2013-02-01 00:20 - 2006-09-20 08:35 - 000020480 _____ () C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
2013-02-01 00:20 - 2006-09-19 16:05 - 000024576 _____ () C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
2010-10-26 20:00 - 2010-10-26 20:00 - 000516096 _____ () C:\Program Files (x86)\AMD\RAIDXpert\bin\libxml2.dll
2017-07-21 08:20 - 2017-07-21 08:20 - 000729792 _____ () C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\PocoNet.dll
2012-12-07 17:46 - 2011-10-12 04:22 - 000370984 _____ () C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLNetMediaDMA.dll

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)


==================== Safe Mode (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

==================== Association (Whitelisted) ===============

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

HKLM\…\.reg: Regedit.Document =>  <==== ATTENTION

==================== Internet Explorer trusted/restricted ===============

(If an entry is included in the fixlist, it will be removed from the registry.)


==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 20:34 - 2013-02-21 00:38 - 000582443 _____ C:\Windows\system32\drivers\etc\hosts

127.0.0.1  localhost
127.0.0.1  fr.a2dfp.net
127.0.0.1  m.fr.a2dfp.net
127.0.0.1  ad.a8.net
127.0.0.1  asy.a8ww.net
127.0.0.1  abcstats.com
127.0.0.1  a.abv.bg
127.0.0.1  adserver.abv.bg
127.0.0.1  adv.abv.bg
127.0.0.1  bimg.abv.bg
127.0.0.1  ca.abv.bg
127.0.0.1  www2.a-counter.kiev.ua
127.0.0.1  track.acclaimnetwork.com
127.0.0.1  accuserveadsystem.com
127.0.0.1  www.accuserveadsystem.com
127.0.0.1  achmedia.com
127.0.0.1  aconti.net
127.0.0.1  secure.aconti.net
127.0.0.1  www.aconti.net #[Dialer.Aconti]
127.0.0.1  csh.actiondesk.com
127.0.0.1  www.activemeter.com #[Tracking.Cookie]
127.0.0.1  ads.activepower.net
127.0.0.1  stat.active24stats.nl #[Tracking.Cookie]
127.0.0.1  cms.ad2click.nl
127.0.0.1  ad2games.com
127.0.0.1  ads.ad2games.com
127.0.0.1  content.ad20.net
127.0.0.1  core.ad20.net
127.0.0.1  banner.ad.nu
127.0.0.1  cl21.v4.adaction.se

There are 13941 more lines.


==================== Other Areas ============================

(Currently there is no automatic fix for this section.)

HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path: C:\Program Files (x86)\AMD APP\bin\x86_64;C:\Program Files\Common Files\Microsoft Shared\Windows Live;C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\EgisTec MyWinLocker\x64;C:\Program Files (x86)\EgisTec MyWinLocker\;C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static;C:\Program Files (x86)\Skype\Phone\
HKU\S-1-5-21-2070708007-2879293845-838049191-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Dirk - Admin\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 192.168.1.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 0) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.

==================== MSCONFIG/TASK MANAGER disabled items ==

If an entry is included in the fixlist, it will be removed.

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^TrayMin700.exe.lnk => C:\Windows\pss\TrayMin700.exe.lnk.CommonStartup
MSCONFIG\startupreg: Hotkey Utility => C:\Program Files (x86)\Acer\Hotkey Utility\HotkeyUtility.exe
MSCONFIG\startupreg: Uploader => C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.Uploader.exe

==================== FirewallRules (Whitelisted) ===============

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

FirewallRules: [{D428928D-4443-4CDB-971B-869AACF1A0BF}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe (Skype Technologies S.A.)
FirewallRules: [{29702C1A-B98B-4C74-AB8E-51C6E201F05F}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Microsoft Corporation)
FirewallRules: [{A0860F8B-F6A1-4140-8AC7-60BE0C7EAF27}] => (Allow) LPort=2869
FirewallRules: [{5775AA85-7FC2-435C-87C7-DE1AB1E37848}] => (Allow) LPort=1900
FirewallRules: [{D2F56A7D-0BA0-4525-94C7-1B372E460CB6}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
FirewallRules: [{56A28D6D-352E-4F61-B19D-0BC0C90ED34B}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe (Microsoft Corporation)
FirewallRules: [{CED49B05-1A03-4070-876B-9742C4356694}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe (Acer Incorporated)
FirewallRules: [{5C45F758-A7E1-452B-8F4D-CA0D7F083876}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe (CyberLink Corp.)
FirewallRules: [{458BCDD6-32B9-4ABF-AAFA-15D9D3004532}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe (CyberLink Corp.)
FirewallRules: [{AF87EB21-7AED-42B5-AB21-ABDB6136D851}] => (Block) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe (CyberLink Corp.)
FirewallRules: [{680A2454-528A-4359-BB8B-837FCEAB0BA5}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\CLML\CLMLSvc.exe (CyberLink Corp.)
FirewallRules: [{DC9432CE-F376-411D-A0CF-C3E9E646DEA6}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe (CyberLink)
FirewallRules: [{37E0442F-B5BD-47E2-974F-239E6A4FA35A}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe (CyberLink)
FirewallRules: [{6610DE0C-B29F-4349-A0E6-52DE88510D97}] => (Block) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe (CyberLink)
FirewallRules: [{87571274-7B1A-4463-9943-CC06DE0C0C80}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLMSService.exe (CyberLink)
FirewallRules: [{27720A71-E3B0-4B3B-877A-26C9129BBA0B}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\PlayMovie.exe (CyberLink Corp.)
FirewallRules: [{711942A8-FBF4-4D49-8E13-B05B99608ABD}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
FirewallRules: [{508DF50C-5361-432F-B20A-B7BB4093C944}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
FirewallRules: [TCP Query User{353E1F12-878E-4C9A-94E0-6AC3907312DA}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation)
FirewallRules: [UDP Query User{BB508C6E-7D28-4050-A388-00FCF5C93628}C:\program files (x86)\mozilla firefox\firefox.exe] => (Block) C:\program files (x86)\mozilla firefox\firefox.exe (Mozilla Corporation)
FirewallRules: [TCP Query User{98F1C3B1-E50B-4747-8FF4-378EA0B17810}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe (Seagate Technology LLC)
FirewallRules: [UDP Query User{9757428D-1F1F-433D-892B-8D0990ABD36C}C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe] => (Allow) C:\program files (x86)\seagate\seagate dashboard 2.0\dashboard.exe (Seagate Technology LLC)
FirewallRules: [{C18456C1-0967-4F24-8666-3B3993DBC20F}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
FirewallRules: [{1ABE63A5-ECC2-4DD5-85D0-F4B1781DFCE4}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
FirewallRules: [{82C612EA-48CC-4F47-87AA-F085F569AB0A}] => (Allow) LPort=8888
FirewallRules: [{3B743302-922E-44C0-B023-23BB5C047602}] => (Allow) LPort=8888
FirewallRules: [{B5F624CF-5EBE-4269-8B51-23D219499A1E}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Ltd)
FirewallRules: [{DB049030-E1F6-4AC6-AFE9-97F3FA9F906B}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Ltd)

==================== Restore Points =========================

12-01-2019 18:43:13 Windows Update
13-01-2019 16:06:10 Windows Update
16-01-2019 09:30:51 Windows Update
20-01-2019 08:52:13 Windows Update

==================== Faulty Device Manager Devices =============

Name: J:\
Description: MS/MS-Pro/HG    
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Generic-
Service: WUDFRd
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.

Name: I:\
Description: SD/MMC          
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Generic-
Service: WUDFRd
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.

Name: K:\
Description: SD/MMC/MS/MSPRO
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Generic-
Service: WUDFRd
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.

Name: H:\
Description: SM/xD-Picture   
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Generic-
Service: WUDFRd
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/23/2019 08:47:12 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (01/23/2019 01:54:32 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (01/22/2019 08:04:45 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (01/22/2019 03:03:35 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (01/21/2019 05:02:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (01/21/2019 11:07:01 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

Error: (01/21/2019 03:25:37 AM) (Source: Windows Backup) (EventID: 4103) (User: )
Description: The backup did not complete because of an error writing to the backup location E:\. The error is: The backup location cannot be found or is not valid. Review your backup settings and check the backup location. (0x81000006).

Error: (01/21/2019 03:16:28 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.


System errors:
=============
Error: (01/23/2019 01:47:05 PM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: The platform firmware has corrupted memory across the previous system power transition.  Please check for updated firmware for your system.

Error: (01/23/2019 08:46:51 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The DgiVecp service failed to start due to the following error:
The system cannot find the device specified.

Error: (01/23/2019 08:46:48 AM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000009f (0x0000000000000004, 0x0000000000000258, 0xfffffa80036b3b50, 0xfffff80000b9c560). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 012319-22854-01.

Error: (01/23/2019 08:46:44 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 8:45:06 AM on ‎1/‎23/‎2019 was unexpected.

Error: (01/23/2019 01:54:18 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The DgiVecp service failed to start due to the following error:
The system cannot find the device specified.

Error: (01/23/2019 01:54:05 AM) (Source: BugCheck) (EventID: 1001) (User: )
Description: The computer has rebooted from a bugcheck.  The bugcheck was: 0x0000009f (0x0000000000000004, 0x0000000000000258, 0xfffffa80036a5040, 0xfffff80000b9c560). A dump was saved in: C:\Windows\MEMORY.DMP. Report Id: 012319-19359-01.

Error: (01/23/2019 01:54:03 AM) (Source: EventLog) (EventID: 6008) (User: )
Description: The previous system shutdown at 1:51:59 AM on ‎1/‎23/‎2019 was unexpected.

Error: (01/22/2019 03:40:52 PM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: )
Description: The platform firmware has corrupted memory across the previous system power transition.  Please check for updated firmware for your system.


Windows Defender:
===================================
Date: 2013-12-01 22:28:43.721
Description:
Windows Defender scan has been stopped before completion.
Scan ID:{CE1FFBB5-CF94-473B-BBD8-62EC55ED7F76}
Scan Type:AntiSpyware
Scan Parameters:Full Scan

==================== Memory info ===========================

Processor: AMD A6-3620 APU with Radeonâ„¢ HD Graphics
Percentage of memory in use: 58%
Total physical RAM: 3475.7 MB
Available physical RAM: 1459.25 MB
Total Virtual: 6949.55 MB
Available Virtual: 4199.73 MB

==================== Drives ================================

Drive c: (Acer) (Fixed) (Total:448.66 GB) (Free:268.63 GB) NTFS

\\?\Volume{0d0e7b7f-40c5-11e2-bbb5-806e6f6e6963}\ (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS
\\?\Volume{0d0e7b7e-40c5-11e2-bbb5-806e6f6e6963}\ (PQSERVICE) (Fixed) (Total:17 GB) (Free:5.68 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 7B4D19A1)
Partition 1: (Not Active) - (Size=17 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=448.7 GB) - (Type=07 NTFS)

==================== End of Addition.txt ============================

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.01.2019
Ran by [removed] (administrator) on BRUCES-ACER-PC (23-01-2019 17:57:17)
Running from C:\Users\[removed]\Desktop
[removed] Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(AMD) C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpertService.exe
() C:\Program Files (x86)\AMD\RAIDXpert\bin\RAIDXpert.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe
(Seagate Technology LLC) C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
() C:\Windows\SysWOW64\WinMsgBalloonServer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
() C:\Windows\System32\spool\drivers\x64\3\WrtMon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
() C:\Windows\System32\spool\drivers\x64\3\WrtProc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLMSService.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe
(Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe
(Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\…\Run: [WrtMon.exe] => C:\Windows\system32\spool\drivers\x64\3\WrtMon.exe [20480 2006-09-20] ()
HKLM\…\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11860072 2011-06-08] (Realtek Semiconductor)
HKLM\…\Run: [OOTag] => C:\Program Files (x86)\Acer\OOBEOffer\ootag.exe [13856 2010-02-22] (Microsoft)
HKLM\…\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKLM-x32\…\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [341360 2011-06-21] (Egis Technology Inc.)
HKLM-x32\…\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-06-30] (Advanced Micro Devices, Inc.)
HKLM-x32\…\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\…\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [185640 2011-08-31] (CyberLink Corp.)
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-21-2070708007-2879293845-838049191-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\WLXPGSS.SCR [302448 2011-05-13] (Microsoft Corporation)
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-18\…A8F59079A8D5}\localserver32:  <==== ATTENTION
HKLM\…\Drivers32: [VIDC.I420] => msh263.drv
HKLM\…\Drivers32-x32: [msacm.l3codecp] => C:\Windows\SysWOW64\l3codecp.acm [220672 2009-07-13] (Fraunhofer Institut Integrierte Schaltungen IIS)
HKLM\…\Drivers32-x32: [msacm.sl_anet] => C:\Windows\SysWOW64\sl_anet.acm [89088 1998-10-29] (Sipro Lab Telecom Inc.)
HKLM\…\Drivers32-x32: [VIDC.MP42] => C:\Windows\SysWOW64\mpg4c32.dll [254272 1998-10-29] (Microsoft Corporation)
HKLM\…\Drivers32-x32: [VIDC.MPG4] => C:\Windows\SysWOW64\mpg4c32.dll [254272 1998-10-29] (Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{2D46B6DC-2207-486B-B523-A557E6D54B47}] -> C:\Windows\system32\cmd.exe /D /C start C:\Windows\system32\ie4uinit.exe -ClearIconCache
HKLM\Software\…\Authentication\Credential Providers: [{F8A0B131-5F68-486c-8040-7E8FC3C85BB6}] -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDCREDPROV.DLL [2011-03-28] (Microsoft Corp.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2013-01-31]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{6E1DBCEC-EFCE-4884-8CAE-292050240415}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{9F01F276-E98F-4F23-BC28-766FDDE6AD68}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKU\S-1-5-21-2070708007-2879293845-838049191-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID;=131428234770874288&GUID;=F6907AB4-84A9-414C-B040-1DF12B37E132
HKU\S-1-5-21-2070708007-2879293845-838049191-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&pver;=6&ar;=msnhome
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form;=AARTDF&pc;=MAAR&src;=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-2070708007-2879293845-838049191-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
Handler-x32: http - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: http - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: https - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: https - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: ipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF42-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)
Handler-x32: msdaipp - {E1D2BF40-A96B-11D1-9C6B-0000F875AC61} - C:\PROGRA~2\COMMON~1\System\OLEDB~1\MSDAIPP.DLL [1999-02-03] (Microsoft Corporation)

FireFox:
========
FF DefaultProfile: 1th82jzp.default-1410789010024-1531041996955
FF ProfilePath: C:\Users\Dirk - Admin\AppData\Roaming\Mozilla\Firefox\Profiles\1th82jzp.default-1410789010024-1531041996955 [2019-01-23]
FF Extension: (German Dictionary, classical spelling standards) - C:\Users\Dirk - Admin\AppData\Roaming\Mozilla\Firefox\Profiles\1th82jzp.default-1410789010024-1531041996955\Extensions\[removed] [2018-11-29]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_32_0_0_114.dll [2019-01-12] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_32_0_0_114.dll [2019-01-12] ()
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50918.0\npctrl.dll [2018-10-23] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-12-04] (Adobe Systems Inc.)

==================== Services (Whitelisted) ====================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6347056 2018-09-19] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 Seagate Dashboard Services; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\Seagate.Dashboard.DASWindowsService.exe [16120 2017-03-27] (Seagate Technology LLC)
R2 Seagate MobileBackup Service; C:\Program Files (x86)\Seagate\Seagate Dashboard 2.0\MobileService.exe [143560 2017-07-21] (Seagate Technology LLC)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)

===================== Drivers (Whitelisted) ======================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-03-02] (Samsung Electronics Co., Ltd.)
S3 dg_ssudbus; C:\Windows\System32\DRIVERS\ssudbus.sys [131984 2017-05-18] (Samsung Electronics Co., Ltd.)
R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [261032 2019-01-23] (Malwarebytes)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
S3 OV550I; C:\Windows\System32\Drivers\ov550ivx.sys [196992 2008-02-22] (Omnivision Technologies, Inc.)
R3 phc700; C:\Windows\System32\DRIVERS\phc700.sys [867712 2006-10-16] ()
U3 aswMBR; \??\C:\Users\DIRK-A~1\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\DIRK-A~1\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
U3 awdyiaoc; \??\C:\Users\DIRK-A~1\AppData\Local\Temp\awdyiaoc.sys [X] <==== ATTENTION

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


==================== One month (created) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-01-23 17:57 - 2019-01-23 17:57 - 000013714 _____ C:\Users\Dirk - Admin\Desktop\FRST.txt
2019-01-23 17:56 - 2019-01-23 17:56 - 002428416 _____ (Farbar) C:\Users\Dirk - Admin\Desktop\FRST64.exe
2019-01-23 17:33 - 2019-01-23 17:54 - 000001796 _____ C:\Users\Dirk - Admin\Desktop\unexpected-shut-down.txt
2019-01-23 17:10 - 2019-01-23 17:10 - 000000260 _____ C:\Users\Dirk - Admin\Desktop\Virus, Spyware & Malware Removal - What the Tech.URL
2019-01-23 15:12 - 2019-01-23 17:57 - 000000000 ____D C:\FRST
2019-01-23 08:46 - 2019-01-23 08:46 - 000455328 _____ C:\Windows\Minidump\012319-22854-01.dmp
2019-01-23 01:53 - 2019-01-23 08:46 - 588701090 _____ C:\Windows\MEMORY.DMP
2019-01-23 01:53 - 2019-01-23 01:54 - 000455328 _____ C:\Windows\Minidump\012319-19359-01.dmp
2019-01-22 08:04 - 2019-01-23 08:48 - 000261032 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2019-01-13 16:04 - 2019-01-13 16:04 - 000000746 _____ C:\Users\Dirk - Admin\Desktop\trailer-decal.txt
2019-01-13 15:02 - 2019-01-13 15:02 - 000000271 _____ C:\Users\Dirk - Admin\Desktop\Lighthouses - northernimages.URL
2019-01-11 18:15 - 2019-01-11 18:15 - 000000000 ____D C:\Users\Guest\AppData\Local\mbamtray
2019-01-11 18:05 - 2019-01-11 18:05 - 000000736 _____ C:\Users\Dirk - Admin\Documents\cc_20190111_180459.reg
2019-01-11 18:05 - 2019-01-11 18:05 - 000000184 _____ C:\Users\Dirk - Admin\Documents\cc_20190111_180511.reg
2019-01-11 18:04 - 2019-01-11 18:04 - 000011002 _____ C:\Users\Dirk - Admin\Documents\cc_20190111_180443.reg
2019-01-11 18:02 - 2019-01-11 18:02 - 000000254 _____ C:\Users\Anita - Internet\Documents\cc_20190111_180219.reg
2019-01-11 17:13 - 2019-01-11 17:13 - 000001111 _____ C:\Users\Public\Desktop\Firefox.lnk
2019-01-11 16:43 - 2019-01-11 16:43 - 019299120 _____ (Piriform Software Ltd) C:\Users\Dirk - Admin\Downloads\ccsetup551.exe
2019-01-09 08:44 - 2018-12-28 17:42 - 000396888 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2019-01-09 08:44 - 2018-12-28 16:52 - 000348760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2019-01-09 08:44 - 2018-12-28 14:03 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2019-01-09 08:44 - 2018-12-28 14:02 - 005552360 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2019-01-09 08:44 - 2018-12-28 14:02 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2019-01-09 08:44 - 2018-12-28 14:02 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2019-01-09 08:44 - 2018-12-28 14:02 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2019-01-09 08:44 - 2018-12-28 14:02 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2019-01-09 08:44 - 2018-12-28 14:02 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2019-01-09 08:44 - 2018-12-28 14:01 - 001664360 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 001472512 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 001211904 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:51 - 004055272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2019-01-09 08:44 - 2018-12-28 13:51 - 003960552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2019-01-09 08:44 - 2018-12-28 13:50 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000275968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:34 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2019-01-09 08:44 - 2018-12-28 13:34 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2019-01-09 08:44 - 2018-12-28 13:34 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2019-01-09 08:44 - 2018-12-28 13:34 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2019-01-09 08:44 - 2018-12-28 13:31 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2019-01-09 08:44 - 2018-12-28 13:31 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2019-01-09 08:44 - 2018-12-28 13:31 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2019-01-09 08:44 - 2018-12-28 13:30 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2019-01-09 08:44 - 2018-12-28 13:28 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2019-01-09 08:44 - 2018-12-28 13:28 - 000161280 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2019-01-09 08:44 - 2018-12-28 13:28 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2019-01-09 08:44 - 2018-12-28 13:27 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2019-01-09 08:44 - 2018-12-28 13:27 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdk8.sys
2019-01-09 08:44 - 2018-12-28 13:27 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\intelppm.sys
2019-01-09 08:44 - 2018-12-28 13:27 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\processr.sys
2019-01-09 08:44 - 2018-12-28 13:27 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\amdppm.sys
2019-01-09 08:44 - 2018-12-28 13:27 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2019-01-09 08:44 - 2018-12-28 13:27 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2019-01-09 08:44 - 2018-12-28 13:27 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2019-01-09 08:44 - 2018-12-28 13:26 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2019-01-09 08:44 - 2018-12-28 13:26 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:26 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2019-01-09 08:44 - 2018-12-28 13:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2019-01-09 08:44 - 2018-12-27 18:01 - 025738240 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2019-01-09 08:44 - 2018-12-27 17:38 - 002902016 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2019-01-09 08:44 - 2018-12-27 17:36 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2019-01-09 08:44 - 2018-12-27 17:31 - 005778944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2019-01-09 08:44 - 2018-12-27 17:25 - 020279808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2019-01-09 08:44 - 2018-12-27 17:25 - 000790016 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2019-01-09 08:44 - 2018-12-27 17:17 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2019-01-09 08:44 - 2018-12-27 17:05 - 000498176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2019-01-09 08:44 - 2018-12-27 17:02 - 002295808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2019-01-09 08:44 - 2018-12-27 16:55 - 000663040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2019-01-09 08:44 - 2018-12-27 16:50 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2019-01-09 08:44 - 2018-12-27 16:48 - 015284224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2019-01-09 08:44 - 2018-12-27 16:48 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2019-01-09 08:44 - 2018-12-27 16:48 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2019-01-09 08:44 - 2018-12-27 16:46 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2019-01-09 08:44 - 2018-12-27 16:45 - 002135552 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2019-01-09 08:44 - 2018-12-27 16:33 - 004860416 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2019-01-09 08:44 - 2018-12-27 16:33 - 004494848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2019-01-09 08:44 - 2018-12-27 16:31 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2019-01-09 08:44 - 2018-12-27 16:29 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2019-01-09 08:44 - 2018-12-27 16:29 - 002060288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2019-01-09 08:44 - 2018-12-27 16:29 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2019-01-09 08:44 - 2018-12-27 16:28 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2019-01-09 08:44 - 2018-12-27 16:22 - 001555968 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2019-01-09 08:44 - 2018-12-27 16:11 - 004386816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2019-01-09 08:44 - 2018-12-27 16:07 - 001329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2019-01-09 08:44 - 2018-12-07 21:08 - 000047104 _____ (Microsoft Corporation) C:\Windows\system32\kmddsp.tsp
2019-01-09 08:44 - 2018-12-07 20:47 - 000088576 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\wanarp.sys
2019-01-09 08:44 - 2018-12-07 20:41 - 000038912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kmddsp.tsp
2019-01-09 08:44 - 2018-12-07 09:33 - 000352768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrd3x40.dll
2019-01-09 08:43 - 2018-12-28 13:59 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2019-01-09 08:43 - 2018-12-28 13:59 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2019-01-09 08:43 - 2018-12-28 13:59 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2019-01-09 08:43 - 2018-12-28 13:59 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2019-01-09 08:43 - 2018-12-28 13:59 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2019-01-09 08:43 - 2018-12-28 13:48 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2019-01-09 08:43 - 2018-12-28 13:48 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2019-01-09 08:43 - 2018-12-28 13:48 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2019-01-09 08:43 - 2018-12-28 13:48 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2019-01-09 08:43 - 2018-12-28 13:48 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2019-01-09 08:43 - 2018-12-28 13:27 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2019-01-09 08:43 - 2018-12-28 13:27 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2019-01-09 08:43 - 2018-12-28 12:09 - 000419608 _____ C:\Windows\SysWOW64\locale.nls
2019-01-09 08:43 - 2018-12-28 12:09 - 000419608 _____ C:\Windows\system32\locale.nls
2019-01-09 08:43 - 2018-12-27 17:50 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2019-01-09 08:43 - 2018-12-27 17:50 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2019-01-09 08:43 - 2018-12-27 17:37 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2019-01-09 08:43 - 2018-12-27 17:36 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2019-01-09 08:43 - 2018-12-27 17:36 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2019-01-09 08:43 - 2018-12-27 17:36 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2019-01-09 08:43 - 2018-12-27 17:29 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2019-01-09 08:43 - 2018-12-27 17:28 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2019-01-09 08:43 - 2018-12-27 17:26 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2019-01-09 08:43 - 2018-12-27 17:25 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2019-01-09 08:43 - 2018-12-27 17:25 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2019-01-09 08:43 - 2018-12-27 17:24 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2019-01-09 08:43 - 2018-12-27 17:17 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2019-01-09 08:43 - 2018-12-27 17:14 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2019-01-09 08:43 - 2018-12-27 17:07 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2019-01-09 08:43 - 2018-12-27 17:07 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2019-01-09 08:43 - 2018-12-27 17:06 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2019-01-09 08:43 - 2018-12-27 17:05 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2019-01-09 08:43 - 2018-12-27 17:04 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2019-01-09 08:43 - 2018-12-27 17:04 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2019-01-09 08:43 - 2018-12-27 17:03 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2019-01-09 08:43 - 2018-12-27 17:03 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2019-01-09 08:43 - 2018-12-27 17:03 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2019-01-09 08:43 - 2018-12-27 17:01 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2019-01-09 08:43 - 2018-12-27 16:59 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2019-01-09 08:43 - 2018-12-27 16:59 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2019-01-09 08:43 - 2018-12-27 16:58 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2019-01-09 08:43 - 2018-12-27 16:56 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2019-01-09 08:43 - 2018-12-27 16:55 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2019-01-09 08:43 - 2018-12-27 16:55 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2019-01-09 08:43 - 2018-12-27 16:47 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2019-01-09 08:43 - 2018-12-27 16:43 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2019-01-09 08:43 - 2018-12-27 16:42 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2019-01-09 08:43 - 2018-12-27 16:42 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2019-01-09 08:43 - 2018-12-27 16:39 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2019-01-09 08:43 - 2018-12-27 16:39 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2019-01-09 08:43 - 2018-12-27 16:37 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2019-01-09 08:43 - 2018-12-27 16:36 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2019-01-09 08:43 - 2018-12-27 16:11 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2019-01-09 08:43 - 2018-12-27 16:06 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2019-01-09 08:43 - 2018-12-07 21:08 - 000095744 _____ (Microsoft Corporation) C:\Windows\system32\rascfg.dll
2019-01-09 08:43 - 2018-12-07 21:08 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\rasdiag.dll
2019-01-09 08:43 - 2018-12-07 21:08 - 000060928 _____ (Microsoft Corporation) C:\Windows\system32\ndptsp.tsp
2019-01-09 08:43 - 2018-12-07 21:08 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\rasmxs.dll
2019-01-09 08:43 - 2018-12-07 21:08 - 000029696 _____ (Microsoft Corporation) C:\Windows\system32\rasser.dll
2019-01-09 08:43 - 2018-12-07 20:56 - 000081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rascfg.dll
2019-01-09 08:43 - 2018-12-07 20:56 - 000061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasdiag.dll
2019-01-09 08:43 - 2018-12-07 20:56 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ndptsp.tsp
2019-01-09 08:43 - 2018-12-07 20:47 - 000058368 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndproxy.sys
2019-01-09 08:43 - 2018-12-07 20:47 - 000024064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndistapi.sys
2019-01-09 08:43 - 2018-12-07 20:41 - 000033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasmxs.dll
2019-01-09 08:43 - 2018-12-07 20:41 - 000022528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rasser.dll
2019-01-09 03:54 - 2019-01-09 03:54 - 000000322 _____ C:\Users\Dirk - Admin\Desktop\Every Successful Relationship Is Successful for the Same Exact Reasons - Mark Manson - Pocket.URL
2019-01-06 08:54 - 2019-01-06 08:54 - 000021052 _____ C:\Users\Anita - Internet\Downloads\Facts_Death_Worksheet-14.pdf
2019-01-04 12:34 - 2019-01-04 12:34 - 000904301 _____ C:\Users\Anita - Internet\Downloads\kent allison fort snelling.pdf
2019-01-03 09:54 - 2019-01-03 09:54 - 000000000 ____D C:\Users\Anita - Internet\AppData\Local\{6DDAE684-0053-4454-BFAA-F563392F2ABB}
2019-01-02 16:59 - 2019-01-02 17:57 - 000056076 _____ C:\Users\Anita - Internet\Desktop\2019-01-02_Benefits-election_Anita.pdf
2018-12-31 09:51 - 2018-12-31 09:51 - 000002181 _____ C:\Users\Anita - Internet\Desktop\index.jpeg
2018-12-29 15:26 - 2018-12-29 15:26 - 000004234 _____ C:\Users\Anita - Internet\Desktop\Anita's house and whatnot's 001 - Shortcut.lnk
2018-12-29 15:25 - 2018-12-29 15:25 - 000117785 _____ C:\Users\Anita - Internet\Desktop\IMG_411390720772932.jpeg
2018-12-29 15:09 - 2018-12-29 15:09 - 001519836 _____ C:\Users\Anita - Internet\Desktop\pics.themepack
2018-12-28 15:01 - 2018-12-28 15:01 - 000000000 ____D C:\Users\Anita - Internet\AppData\Local\{9C259D7E-AFBB-4742-B31D-3D970E271917}

==================== One month (modified) ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2019-01-23 17:46 - 2009-07-13 22:45 - 000024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2019-01-23 17:46 - 2009-07-13 22:45 - 000024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2019-01-23 17:40 - 2016-11-23 03:24 - 000000000 ____D C:\Users\Dirk - Admin\AppData\LocalLow\Mozilla
2019-01-23 17:31 - 2016-11-19 05:45 - 000000000 ____D C:\Users\Anita - Internet\AppData\LocalLow\Mozilla
2019-01-23 08:46 - 2013-03-27 20:21 - 000000000 ____D C:\Windows\Minidump
2019-01-23 08:46 - 2009-07-13 23:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2019-01-21 20:04 - 2018-05-21 07:26 - 000000000 ____D C:\Users\Eltern\AppData\LocalLow\Mozilla
2019-01-16 12:33 - 2017-03-20 00:53 - 000000000 ____D C:\Program Files\Microsoft Silverlight
2019-01-16 12:33 - 2017-03-20 00:53 - 000000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2019-01-16 09:33 - 2017-03-20 00:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2019-01-13 16:07 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\inf
2019-01-13 16:05 - 2015-11-28 19:51 - 000000000 ____D C:\Users\Dirk - Admin\AppData\Local\Windows Live
2019-01-13 15:07 - 2018-11-17 21:49 - 000147456 ___SH C:\Users\Dirk - Admin\Desktop\Thumbs.db
2019-01-12 18:40 - 2018-09-22 08:00 - 000004488 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2019-01-12 18:40 - 2014-08-20 08:48 - 000000000 ____D C:\Users\Dirk - Admin\AppData\Local\Adobe
2019-01-12 18:40 - 2013-06-14 14:44 - 000004314 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2019-01-12 18:40 - 2013-01-20 23:01 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2019-01-12 18:40 - 2013-01-20 23:01 - 000000000 ____D C:\Windows\system32\Macromed
2019-01-12 18:40 - 2011-08-03 00:31 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2019-01-12 18:40 - 2011-08-03 00:31 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2019-01-11 18:15 - 2018-05-14 18:18 - 000000000 ____D C:\Users\Guest\AppData\Local\CrashDumps
2019-01-11 17:58 - 2014-01-27 07:04 - 000000000 ____D C:\Users\Anita - Internet\AppData\Local\CrashDumps
2019-01-11 17:18 - 2014-01-27 05:26 - 000000000 ____D C:\Users\Dirk - Admin\AppData\Local\CrashDumps
2019-01-11 17:13 - 2018-03-20 14:52 - 000000000 ____D C:\Users\Dirk - Admin\AppData\Local\Google
2019-01-11 17:13 - 2018-03-20 14:52 - 000000000 ____D C:\Program Files (x86)\Google
2019-01-11 16:50 - 2017-05-05 17:51 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2019-01-11 16:50 - 2013-12-06 23:57 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2019-01-11 16:49 - 2011-08-03 00:18 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acer
2019-01-11 16:49 - 2011-08-03 00:18 - 000000000 ____D C:\Program Files (x86)\Acer
2019-01-11 16:47 - 2018-05-09 16:32 - 000003870 _____ C:\Windows\System32\Tasks\CCleaner Update
2019-01-11 16:47 - 2018-05-09 16:32 - 000000826 _____ C:\Users\Public\Desktop\CCleaner.lnk
2019-01-11 16:47 - 2018-05-09 16:31 - 000000000 ____D C:\Program Files\CCleaner
2019-01-11 07:53 - 2017-06-30 02:31 - 000002600 _____ C:\Windows\wininit.ini
2019-01-10 05:24 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\rescache
2019-01-10 03:28 - 2009-07-13 23:13 - 000782510 _____ C:\Windows\system32\PerfStringBackup.INI
2019-01-09 13:41 - 2013-11-28 19:41 - 000774632 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2019-01-09 13:37 - 2013-07-31 13:19 - 000000000 ____D C:\Windows\system32\MRT
2019-01-09 13:34 - 2013-01-18 00:17 - 132790320 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2019-01-04 12:44 - 2015-07-14 21:28 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2019-01-03 09:58 - 2013-06-20 15:49 - 000000000 ____D C:\Users\Anita - Internet\Desktop\Wedding Edited Color
2019-01-01 17:20 - 2009-07-13 21:20 - 000000000 ____D C:\Windows\system32\NDF
2019-01-01 09:02 - 2018-10-12 05:30 - 000152688 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbae64.sys
2018-12-28 16:41 - 2015-01-11 03:31 - 000000000 ____D C:\Users\Anita - Internet\AppData\Local\Windows Live

==================== Files in the root of some directories =======

2013-02-01 00:12 - 1996-12-14 00:00 - 000000002 _____ () C:\Users\Dirk - Admin\AppData\Roaming\Microsoft\ArtGalry.cag
2013-11-28 19:59 - 2014-02-11 06:01 - 000007613 ____R () C:\Users\Dirk - Admin\AppData\Local\Resmon.ResmonCfg
2017-05-14 09:07 - 2017-05-14 09:07 - 000000000 ____R () C:\Users\Dirk - Admin\AppData\Local\{E3839958-E45A-45A4-9631-6BE5D303B42C}

==================== Bamital & volsnap ======================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\dllhost.exe => File is digitally signed
C:\Windows\SysWOW64\dllhost.exe => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2019-01-23 00:57

==================== End of FRST.txt ============================

There were a few errors recorded that I tried to research for

These crashes are usually related to memory corruption (probably caused by a driver).
Have you checked for any updates for your graphics/video card?

Description: MS/MS-Pro/HG Do you have a memory sticks connected to your computer at the moment?
SD OR MMC Cards?, SD/SM/MMC/MS/MS Pro to CF Card Adapter: Memory Card Adapters? SM/xd - Picture flash memory card format

Please disconnect anything you may have plugged in, it's possible what ever is plugged in is causing the issues.

Please proceed.

Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
HKLM\…\.reg: Regedit.Document => <==== ATTENTION
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-18\…A8F59079A8D5}\localserver32: <==== ATTENTION
URLSearchHook: [S-1-5-21-2070708007-2879293845-838049191-1000] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-2070708007-2879293845-838049191-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2070708007-2879293845-838049191-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
U3 aswMBR; \??\C:\Users\DIRK-A~1\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\DIRK-A~1\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
U3 awdyiaoc; \??\C:\Users\DIRK-A~1\AppData\Local\Temp\awdyiaoc.sys [X] <==== ATTENTION
C:\Windows\Temp\*.*
Emptytemp:
End::



Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

[external image: RQKuhw1.png]RogueKiller
  • Download the right version of RogueKiller for your Windows version (32 or 64-bit)
  • Once done, move the executable file to your Desktop, right-click on it and select [external image: Spcusrh.png]Run as Administrator (for Windows Vista, 7, 8, 8.1 and 10 users)
  • Click on the Start Scan button in the right panel, which will bring you to another tab, and click on it again (this time it'll be in the bottom right corner)
  • Wait for the scan to complete
  • On completion, the results will be displayed
  • Check every single entry (threat found), and click on the Remove Selected button
  • On completion, the results will be displayed. Click on the Open Report button in the bottom left corner, followed by the Open TXT button (also in the bottom left corner)
  • This will open the report in Notepad. Copy/paste its content in your next reply
Please post these 2 logs when finished.

Also, it's late here and I wont be back till morning.

Hello Juliet,
 
I had no memory card or memory stick or memory card in my PC. There are multiple memory card slots on the PC but nothing in any of them. I had a webcam pluged into one of the USB slots which is now removed.

The only devices plugged in are mouse, keyboard, printer (off), a scanner (off) and a router.
 
I do remember windows kept trying to update a driver for my graphic card with every update and it kept failing. Each attempt took about 20 minutes or so. This went on from May 2017 till end of October 2017 when a friend removed it from the windows auto updates. I probably should find out if I can get this updated some other way. I found this in the Windows update history:
Advanced Micro Devices, Inc driver update for AMD SMBus
Installation date…
Installation status: Failed
Error Code 80070103
Update Type: Important
…

I also have a "Catalyst Control Center" window show up every time I log in to the admin account but never in any of the other accounts. It reads:
Catalyst Control Center: Host application has stopped working
Windows is checking for a solution to the problem…
This window goes away after a couple seconds.
 
Here are the two log files:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 20.01.2019
Ran by [removed] (23-01-2019 20:41:22) Run:1
Running from C:\Users\[removed]\Desktop
[removed] Boot Mode: Normal
==============================================

fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
HKLM\…\.reg: Regedit.Document => <==== ATTENTION
HKU\S-1-5-18\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-19\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-20\…\RunOnce: [IsMyWinLockerReboot] => msiexec.exe /qn /x{voidguid}
HKU\S-1-5-18\…A8F59079A8D5}\localserver32: <==== ATTENTION
URLSearchHook: [S-1-5-21-2070708007-2879293845-838049191-1000] ATTENTION => Default URLSearchHook is missing
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope value is missing
SearchScopes: HKU\S-1-5-21-2070708007-2879293845-838049191-1002 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-2070708007-2879293845-838049191-1002 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
U3 aswMBR; \??\C:\Users\DIRK-A~1\AppData\Local\Temp\aswMBR.sys [X] <==== ATTENTION
U3 aswVmm; \??\C:\Users\DIRK-A~1\AppData\Local\Temp\aswVmm.sys [X] <==== ATTENTION
U3 awdyiaoc; \??\C:\Users\DIRK-A~1\AppData\Local\Temp\awdyiaoc.sys [X] <==== ATTENTION
C:\Windows\Temp\*.*
Emptytemp:

*****************

Processes closed successfully.
Restore point was successfully created.
HKLM\Software\Classes\.reg\\Default => value restored successfully
"HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce\\IsMyWinLockerReboot" => removed successfully
"HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\IsMyWinLockerReboot" => removed successfully
"HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\IsMyWinLockerReboot" => removed successfully
HKU\S-1-5-18\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}\localserver32 => not found
HKU\S-1-5-18\Software\Classes\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5} => removed successfully
Could not restore Default URLSearchHook.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => removed successfully
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
"HKU\S-1-5-21-2070708007-2879293845-838049191-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope" => not found
"HKU\S-1-5-21-2070708007-2879293845-838049191-1002\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => not found
HKLM\Software\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} => not found
aswMBR => service not found.
aswVmm => service not found.
awdyiaoc => service not found.

=========== "C:\Windows\Temp\*.*" ==========

C:\Windows\Temp\MpCmdRun.log => moved successfully
C:\Windows\Temp\MpSigStub.log => moved successfully
C:\Windows\Temp\Silverlight0.log => moved successfully
C:\Windows\Temp\SilverlightMSI.log => moved successfully
C:\Windows\Temp\WER3757.tmp.appcompat.txt => moved successfully

========= End -> "C:\Windows\Temp\*.*" ========


=========== EmptyTemp: ==========

BITS transfer queue => 8388608 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 12559680 B
Java, Flash, Steam htmlcache => 1080 B
Windows/system/drivers => 0 B
Edge => 0 B
Chrome => 0 B
Firefox => 1095303145 B
Opera => 0 B

Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 160249 B
systemprofile32 => 105939 B
LocalService => 141488 B
NetworkService => 122748800 B
Dirk - Admin => 2541939 B
Anita - Internet => 987052 B
Eltern => 1750452 B
Guest => 53700 B

RecycleBin => 8096399 B
EmptyTemp: => 1.2 GB temporary data Removed.

================================


The system needed a reboot.

==== End of Fixlog 20:43:18 ====

 

RogueKiller Anti-Malware V13.1.2.0 (x64) [Jan 23 2019] (Free) by Adlice Software
mail : https://adlice.com/contact/
Website : https://adlice.com/download/roguekiller/
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits
Started in : Normal mode
User : Dirk - Admin [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Signatures : 20181112_000000, Driver : Loaded
Mode : Standard Scan, Delete – Date : 2019/01/23 21:17:18 (Duration : 00:20:27)

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤ Delete ¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
[PUM.Policies (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin –  -> Replaced (2)
[PUM.Policies (Potentially Malicious)] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System|ConsentPromptBehaviorAdmin –  -> Replaced (2)
 

I also have a "Catalyst Control Center" window show up

Catalyst Control Center is a part of ATI Catalyst Control and it is related to your graphics card.

 
If memory serves me right, Windows updates isn't the best place to get updates for drivers.
I think,
Intel Driver Update utility is where you should check.

From here I don't really think this is malware related but rather internal system functions.
Let me refer you here https://forums.whatthetech.com/index.php?showforum=126
start a new topic along with the link to this one. They will need to see the discussion here and what points to your blue screen errors.
Juliet,

I guess I was worried for no reason and it must have been a coincidence that these issues came up right after Security Essentials detected Trojan:JS/Foretype.A!ml 

Thank you very much for your quick help. I truly appreciate it.
Juliet,

Before you are closing my posting, would you mind telling me what to do about the 2 items RogueKiller had detected which are quarantined?
It wasn't actually malware but a policy set by you or your security protection. Some times it can be related to malware but wasn't here with your machine.
Group Policy registry keys detected as PUMs, here I think it might have applied to
User Account Control

software detects Group Policy registry keys as Potentially Unwanted Modifications (PUMs).
If you have a Group Policy enforced on your network, RogueKiller software assumes the Group Policy registry keys are Potentially Unwanted Modifications. If these registry keys were added with your permission, you may treat the detection's as false positives.
  • Please download DelFix or from Here and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
  • Activate UAC
  • Remove disinfection tools
  • Click the Run button.
  • – This will remove the specialized tools we used to disinfect your system.
    Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete
    ).
*****************

Keeping your programs up-to-date

Like keeping Windows updated, keeping your installed programs up-to-date is another important step in having a safe and secure system.
Outdated programs can be exploited by hackers and malware to infect a system and take it over. This is especially true today with the rise of Exploit Kits (and also 0-days) which is one of the biggest attack vectors to distribute malware.
Therefore, you should always keep vulnerable programs like Adobe Flash Player, Adobe Shockwave Player, Java, Silverlight, Google Chrome, Mozilla Firefox, VLC Media Player, etc. updated to their most recent version (even better, you don't have to install them if you don't use them).
Programs like 🖼Click to load external image (eF2jhaz.png)UCheck, SUMo and 🖼Click to load external image (y5YE7At.png)Heimdal Free will scan your system for outdated programs, and help you identify them, as well as update them.
  • Answers to common security questions - Best Practices by quietman7
  • How Malware Spreads - How did I get infected by quietman7
  • Simple and easy ways to keep your computer safe and secure on the Internet by Lawrence Abrams (aka Grinler)
  • How to Prevent Malware by miekiemoes
  • Tips & Advice on StaySafeOnline.org
Juliet,

I removed the specialized tools. I used U check to fix expired programs and I started reading thru some of the links on how to stay safe. I also started a thread on the other forum you referred me to where I am being helped, too.

Thank you so very much for all your help. I truly appreciate it!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI