This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Spring cleaning : check-up

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I just want to check to see if there was anything I can  remove safely, it's been a while so wanted to make sure system still runs smoothly. Below are the scan results

 

aswMBR version 1.0.1.2252 Copyright© 2014 AVAST Software
Run date: 2020-03-30 14:35:46
—————————–
14:35:46.536    OS Version: Windows x64 6.2.9200 
14:35:46.536    Number of processors: 4 586 0x3A09
14:35:46.536    ComputerName: DAN  UserName: 
14:35:58.235    Initialize success
14:35:58.266    VM: initialized successfully
14:35:58.266    VM: outdated driver version !
14:40:20.986    AVAST engine defs: 17030301
14:40:33.158    The log file has been saved successfully to "C:\Users\user name\Desktop\aswMBR.txt"
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 29-03-2020
Ran by [removed] (administrator) on DAN (Hewlett-Packard HP ENVY dv4 Notebook PC) (30-03-2020 14:41:17)
Running from C:\Users\[removed]\Desktop
[removed]
Platform: Windows 10 Home Version 1903 18362.295 (X64) Language: English (United States)
Default browser: Chrome
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files (x86)\AVAST Software\Browser\Update\1.4.154.333\AvastBrowserCrashHandler64.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswEngSrv.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Avast Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\Avast\wsc_proxy.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\SecureLine VPN\Vpn.exe
(AVAST Software s.r.o. -> AVAST Software) C:\Program Files\AVAST Software\SecureLine VPN\VpnSvc.exe
(CyberLink -> CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
(Dropbox, Inc -> Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler.exe
(Google LLC -> Google LLC) C:\Program Files (x86)\Google\Update\1.3.35.452\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.Windows.Photos_2020.19081.28230.0_x64__8wekyb3d8bbwe\Microsoft.Photos.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.YourPhone_1.20022.82.0_x64__8wekyb3d8bbwe\YourPhoneServer\YourPhoneServer.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.ZuneVideo_10.20022.11011.0_x64__8wekyb3d8bbwe\Video.UI.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\InputMethod\CHS\ChsIME.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\msiexec.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\smartscreen.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SrTasks.exe
(Microsoft Windows -> Microsoft Corporation) C:\Windows\System32\SrTasks.exe
(Piriform Software Ltd -> Piriform Software Ltd) C:\Program Files\CCleaner\CCleaner64.exe
 
==================== Registry (Whitelisted) ===================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\…\Run: [Classic Start Menu] => C:\Program Files\Classic Shell\ClassicStartMenu.exe [163640 2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
HKLM\…\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [277664 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
HKLM-x32\…\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [6261248 2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
HKLM-x32\…\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [601424 2018-12-16] (Oracle America, Inc. -> Oracle Corporation)
HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\Run: [CCleaner Smart Cleaning] => C:\Program Files\CCleaner\CCleaner64.exe [22245560 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\WINDOWS\system32\Mystify.scr [152576 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
HKLM\Software\Microsoft\Active Setup\Installed Components: [{8A69D345-D564-463c-AFF1-A69D9E530F96}] -> C:\Program Files (x86)\Google\Chrome\Application\80.0.3987.149\Installer\chrmstp.exe [2020-03-18] (Google LLC -> Google LLC)
HKLM\Software\Wow6432Node\Microsoft\Active Setup\Installed Components: [{A8504530-742B-42BC-895D-2BAD6406F698}] -> C:\Program Files (x86)\AVAST Software\Browser\Application\80.0.3619.133\Installer\chrmstp.exe [2020-03-19] (Avast Software s.r.o. -> AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast Cleanup Premium.lnk [2018-02-08]
ShortcutTarget: Avast Cleanup Premium.lnk -> C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe (AVAST Software s.r.o. -> AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast SecureLine VPN.lnk [2020-03-29]
ShortcutTarget: Avast SecureLine VPN.lnk -> C:\Program Files\AVAST Software\SecureLine VPN\Vpn.exe (AVAST Software s.r.o. -> AVAST Software)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft Office.lnk [2013-08-20]
ShortcutTarget: Microsoft Office.lnk -> C:\Program Files (x86)\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation -> Microsoft Corporation)
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
 
==================== Scheduled Tasks (Whitelisted) ============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {020B4E82-9E9E-4E53-8805-8E397E0E7217} - System32\Tasks\Microsoft\Office\Office Feature Updates => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158760 2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {085A3083-CB69-4136-AABC-97F80A1A5251} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-30] (Google Inc -> Google Inc.)
Task: {094CD275-5C71-4753-B57E-5566CA859498} - System32\Tasks\Microsoft\Windows\SideShow\AutoWake => {E51DFD48-AA36-4B45-BB52-E831F02E8316}
Task: {0E188287-D488-44E4-8313-4F0400E983A6} - System32\Tasks\Avast Secure Browser Heartbeat Task (Logon) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1868352 2020-03-09] (Avast Software s.r.o. -> AVAST Software)
Task: {0F6DBBD1-1FA5-490B-A482-1F43FCC689E6} - System32\Tasks\Microsoft\Windows\SideShow\SystemDataProviders => {7CCA6768-8373-4D28-8876-83E8B4E3A969}
Task: {10AD99B1-9990-4C73-B8E9-E6EA376A9E3D} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyUpload => {EBF00FCB-0769-4B81-9BEC-6C05514111AA}
Task: {18152454-EB59-4EC5-B78B-2562F2584617} - System32\Tasks\AvastUpdateTaskMachineUA => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-01-06] (AVAST Software s.r.o. -> AVAST Software)
Task: {25D9BC44-E029-49D6-BB4B-9EE5D05B2DB6} - System32\Tasks\Opera scheduled assistant Autoupdate 1582006308 => C:\Users\user name\AppData\Local\Programs\Opera\launcher.exe
Task: {29F7B74C-F041-4BF0-AF8A-B21D4B13C965} - System32\Tasks\HPCeeScheduleForDAN$ => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [99208 2016-06-24] (Hewlett-Packard Company -> HP Inc.)
Task: {2D864644-43EB-408F-A83A-8D2729BA9916} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe
Task: {325DF754-00B8-4FEC-B8B3-060BEEC4DCCA} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe
Task: {33CD285A-10CF-4AFC-B778-B1F4CF2205F2} - System32\Tasks\{4E29F2F4-295B-4771-A849-DFAAE916F4B4} => C:\WINDOWS\system32\pcalua.exe -a "C:\Users\user name\AppData\Roaming\v9\UninstallManager.exe" -c -ptid=cor
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {418EE1BA-416C-4386-9FF4-5C636964CE7F} - System32\Tasks\GyazoUpdateTaskMachineDaily => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6785448 2018-10-04] (Nota Inc. -> Nota Inc.)
Task: {4838156B-0807-4D81-B582-65A53838A87D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {499E139A-1CA4-4498-9548-3EFE66B5F295} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-12-18] (Dropbox, Inc -> Dropbox, Inc.)
Task: {5173EE34-55E1-4D30-A56E-0BBDD18518A4} - System32\Tasks\USER_ESRV_SVC_QUEENCREEK => "C:\WINDOWS\System32\Wscript.exe" //B //NoLogo "C:\Program Files\Intel\SUR\QUEENCREEK\task.vbs"
Task: {5A3FB241-0B11-4EA5-BC66-0D9F1B406040} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM => {C8367320-6F85-11E0-A1F0-0800200C9A66} C:\WINDOWS\System32\BthTelemetry.dll [32256 2019-03-18] (Microsoft Windows -> Microsoft Corporation)
Task: {5E16E82A-AD2E-4CC8-9928-72D8D9C4315D} - System32\Tasks\Opera scheduled Autoupdate 1582006300 => C:\Users\user name\AppData\Local\Programs\Opera\launcher.exe
Task: {603034F0-BF2D-46E5-BC40-CDE706118EC1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe
Task: {6282CFB4-8D63-4696-941C-E2F91190DDED} - System32\Tasks\Intel\Intel Telemetry 2 => C:\Program Files\Intel\Telemetry 2.0\lrio.exe [1741576 2016-03-17] (Intel(R) Software -> Intel Corporation)
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task => {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Task: {742E957D-6BA4-402D-8C70-865CD2C52DCA} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [56640 2015-08-11] (TechSmith Corporation -> TechSmith Corporation)
Task: {75DCF44C-FA4E-4C3C-B58E-CC804068DC8C} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [18227896 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {7D086C98-D4CD-431D-8DF5-C17202D6ECF9} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe
Task: {85AEA176-57F5-40EE-B87C-01342B6193FC} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe
Task: {85CBB540-F1A4-40C2-B9C1-7AB58C5C34AE} - System32\Tasks\Avast Secure Browser Heartbeat Task (Hourly) => C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe [1868352 2020-03-09] (Avast Software s.r.o. -> AVAST Software)
Task: {8701B942-EC3C-42B6-B850-2B2B52A50C2E} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [3894664 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task => {1B1F472E-3221-4826-97DB-2C2324D389AE}
Task: {88E008E2-C7F3-4222-9C39-862AEED4FC4D} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe
Task: {8B6759EE-1C08-4B8F-955C-774AB5A6544E} - System32\Tasks\Microsoft\Windows\SideShow\SessionAgent => {45F26E9E-6199-477F-85DA-AF1EDFE067B1}
Task: {97D9D861-4EF2-4B90-92FB-305857F56CEF} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018616 2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {9E1CB89F-F2A0-4E9C-ACA9-538BF89992C6} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [686384 2020-03-19] (Piriform Software Ltd -> Piriform Software Ltd)
Task: {A2B98582-514C-4870-A570-0C238CE86644} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-12-18] (Dropbox, Inc -> Dropbox, Inc.)
Task: {A3541AFD-FD6B-4ECC-92E6-91071E3A5833} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe
Task: {A8D333E7-4F22-4D1F-B88C-5530231D0DA9} - System32\Tasks\AvastUpdateTaskMachineCore => C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-01-06] (AVAST Software s.r.o. -> AVAST Software)
Task: {AF8FE9A5-1527-421E-9423-2E2EB6E63825} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018616 2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {B28EE8F5-A0C7-4780-9F4F-3AAEB4F47046} - System32\Tasks\GyazoUpdateTaskMachine => C:\Program Files (x86)\Gyazo\GyazoUpdate.exe [6785448 2018-10-04] (Nota Inc. -> Nota Inc.)
Task: {B3BC94E3-EFFE-4A1D-B7C5-1B6D07A854F0} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe
Task: {C9DCF59E-6B97-4C0C-8641-B8261089C8CA} - System32\Tasks\Microsoft\Windows\MobilePC\HotStart => {06DA0625-9701-43DA-BFD7-FBEEA2180A1E}
Task: {CE2DE968-E342-40D7-9566-427D45E4A886} - System32\Tasks\Microsoft\Windows\PerfTrack\BackgroundConfigSurveyor => {EA9155A3-8A39-40B4-8963-D3C761B18371}
Task: {CED84251-FE2B-45D5-A8E6-5188912200B8} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [144200 2015-08-30] (Google Inc -> Google Inc.)
Task: {D0C05C0D-F34E-4FB3-B7A9-D7F2E2F9ACCE} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [111120 2012-06-07] (CyberLink -> CyberLink)
Task: {D6252F63-17AE-4FF5-B388-7ABDB431E881} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24568696 2020-02-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {D8549DF4-71A4-4E0F-8E66-73398B92E94E} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task => {3519154C-227E-47F3-9CC9-12C3F05817F1}
Task: {D9EEA140-CFF4-4D38-8A20-07638ECBB343} - System32\Tasks\Avast SecureLine VPN Update => C:\Program Files\AVAST Software\SecureLine VPN\VpnUpdate.exe [1390472 2019-10-08] (AVAST Software s.r.o. -> AVAST Software)
Task: {DB21EF32-6BA9-4118-BBC1-BC4FF48961E5} - System32\Tasks\Microsoft\Windows\SideShow\GadgetManager => {FF87090D-4A9A-4F47-879B-29A80C355D61}
Task: {E4B5861A-38CC-40E6-91B9-2A1B32A4D889} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe
Task: {F0039BB7-F7A7-4F1B-B781-847FB31A41F0} - System32\Tasks\Microsoft\Office\Office Automatic Updates 2.0 => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [24568696 2020-02-12] (Microsoft Corporation -> Microsoft Corporation)
Task: {F014166E-6397-4661-AB0B-E56E946EA28E} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe
Task: {F1BD5127-59B9-4A3C-81EB-6D8BDBEE9063} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [1660520 2020-02-27] (Avast Software s.r.o. -> Avast Software)
Task: {F652244E-110D-4B9D-9738-F6FEBBCCC8CA} - System32\Tasks\Microsoft\Office\Office Feature Updates Logon => C:\Program Files\Microsoft Office\root\Office16\sdxhelper.exe [158760 2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
Task: {FDECD289-79E8-4665-864F-F67F2D00CDF1} - System32\Tasks\Avast TUNEUP Update => C:\Program Files (x86)\AVAST Software\Avast Cleanup\TUNEUpdate.exe [1659000 2019-07-25] (AVAST Software s.r.o. -> AVAST Software)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForDAN$.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
Task: C:\WINDOWS\Tasks\Synaptics TouchPad Enhancements.job => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] [removed] [removed]
Tcpip\..\Interfaces\{994fe428-8e82-4f5a-91ef-7f24ad807015}: [DhcpNameServer] [removed] [removed]
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ncr
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\OCHelper.dll [2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\ssv.dll [2019-07-24] (Oracle America, Inc. -> Oracle Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\jp2ssv.dll [2019-07-24] (Oracle America, Inc. -> Oracle Corporation)
Handler-x32: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files (x86)\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL [2001-01-22] (Microsoft Corporation) [File not signed]
Handler-x32: http - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: http - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: https - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: https - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: msdaipp - {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler-x32: msdaipp - {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\System\OLE DB\msdaipp.dll [2001-02-12] (Microsoft Corporation) [File not signed]
Handler: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\Office16\MSOSB.DLL [2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\MSOSB.DLL [2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
 
FireFox:
========
FF DefaultProfile: tj7rotxr.default
FF ProfilePath: C:\Users\user name\AppData\Roaming\PC-Doctor, Inc\PC-Doctor Service Center\Profiles\l0e0yppz.default [2013-08-13]
FF ProfilePath: C:\Users\user name\AppData\Roaming\Mozilla\Firefox\Profiles\tj7rotxr.default [2020-03-30]
FF Homepage: Mozilla\Firefox\Profiles\tj7rotxr.default -> hxxps://defaultsearch.co/homepage?hp=1&pId;=BT171001&iDate;=2019-12-23 06:19:00&bName;=&bitmask;=0600
FF NewTab: Mozilla\Firefox\Profiles\tj7rotxr.default -> hxxps://defaultsearch.co/homepage?hp=1&pId;=BT171001&iDate;=2019-12-23 06:19:00&bName;=&bitmask;=0600
FF Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\user name\AppData\Roaming\Mozilla\Firefox\Profiles\tj7rotxr.default\Extensions\[removed] [2019-01-08]
FF Extension: (Avast Online Security) - C:\Users\user name\AppData\Roaming\Mozilla\Firefox\Profiles\tj7rotxr.default\Extensions\[removed] [2018-06-12]
FF Extension: (Adblock Plus - free ad blocker) - C:\Users\user name\AppData\Roaming\Mozilla\Firefox\Profiles\tj7rotxr.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2019-04-25]
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\Office16\NPSPWRAP.DLL [2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.0 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.2 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.4 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.7.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin: @videolan.org/vlc,version=3.0.8 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2019-08-14] (VideoLAN -> VideoLAN)
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\WINDOWS\SysWOW64\Adobe\Director\np32dsw_1234204.dll [2018-06-06] (Adobe Systems, Inc.) [File not signed]
FF Plugin-x32: @baidu.com/npxbdsetup -> C:\Windows\Downloaded Program Files\241065234\npxbdsetup.dll [2012-12-26] (Baidu (China) Co., Ltd. -> )
FF Plugin-x32: @java.com/DTPlugin,version=11.221.2 -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\dtplugin\npDeployJava1.dll [2019-07-24] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.221.2 -> C:\Program Files (x86)\Java\jre1.8.0_221\bin\plugin2\npjp2.dll [2019-07-24] (Oracle America, Inc. -> Oracle Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office\root\VFS\ProgramFilesX86\Microsoft Office\Office16\NPSPWRAP.DLL [2020-03-04] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2012-03-08] (Microsoft Corporation -> Microsoft Corporation)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No File]
FF Plugin HKU\S-1-5-21-1826707760-3927084271-1880221454-1001: @unity3d.com/UnityPlayer,version=1.0 -> C:\Users\user name\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll [2015-02-24] (Unity Technologies SF -> Unity Technologies ApS)
FF Plugin HKU\S-1-5-21-1826707760-3927084271-1880221454-1001: @zoom.us/ZoomVideoPlugin -> C:\Users\user name\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2019-08-22] (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default [2020-03-30]
CHR Notifications: Default -> hxxps://checkisreal.com; hxxps://hdbest.net; hxxps://mail.yahoo.com; hxxps://maranhesduve.club; hxxps://p3.maranhesduve.club; hxxps://www.auslogics.com; hxxps://www.linetv.tw; hxxps://www.seraphimsl.com; hxxps://www.wrestlinginc.com
CHR Extension: (ProxFlow) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\aakchaleigkohafkfjfjbblobjifikek [2019-08-23]
CHR Extension: (Slides) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-11-16]
CHR Extension: (Docs) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-11-16]
CHR Extension: (Google Drive) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-08-09]
CHR Extension: (YouTube) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-08-09]
CHR Extension: (Adblock Plus - free ad blocker) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2020-02-19]
CHR Extension: (Tampermonkey) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2019-11-16]
CHR Extension: (Avast SafePrice | Comparison, deals, coupons) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\eofcbnmajmjmplflapaojjnihcjkigck [2020-03-19]
CHR Extension: (Sheets) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-11-16]
CHR Extension: (Google Docs Offline) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2020-03-12]
CHR Extension: (Avast Online Security) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2020-02-28]
CHR Extension: (Oberlo - Aliexpress.com Product Importer) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmanipjnbjnhoicdnooapcnfonebefel [2020-03-30]
CHR Extension: (Chrome Web Store Payments) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2019-09-30]
CHR Extension: (Unblock NetEase Music) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\okjlonpifkjbibipgioibfecnikmhfil [2018-02-25]
CHR Extension: (Gmail) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2019-04-15]
CHR Extension: (Chrome Media Router) - C:\Users\user name\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2020-03-20]
CHR Profile: C:\Users\user name\AppData\Local\Google\Chrome\User Data\Guest Profile [2019-07-19]
CHR Profile: C:\Users\user name\AppData\Local\Google\Chrome\User Data\System Profile [2019-07-19]
CHR HKLM-x32\…\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck]
CHR HKLM-x32\…\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki]
 
==================== Services (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [6046624 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
S4 avast; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-01-06] (AVAST Software s.r.o. -> AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [413472 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [428560 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
S4 avastm; C:\Program Files (x86)\AVAST Software\Browser\Update\AvastBrowserUpdate.exe [164984 2019-01-06] (AVAST Software s.r.o. -> AVAST Software)
S4 AvastSecureBrowserElevationService; C:\Program Files (x86)\AVAST Software\Browser\Application\80.0.3619.133\elevation_service.exe [973760 2020-03-09] (Avast Software s.r.o. -> AVAST Software)
R2 AvastWscReporter; C:\Program Files\AVAST Software\Avast\wsc_proxy.exe [57536 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
S4 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [11096648 2020-02-12] (Microsoft Corporation -> Microsoft Corporation)
S4 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-12-18] (Dropbox, Inc -> Dropbox, Inc.)
S4 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2017-12-18] (Dropbox, Inc -> Dropbox, Inc.)
S4 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [44552 2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
S4 ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\esrv_svc.exe [824592 2017-03-07] (Intel(R) Software Development Products -> )
S4 HfcDisableService; C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_6ca78a08b838e305\HfcDisableService.exe [1883856 2019-07-19] (Intel(R) Rapid Storage Technology -> Intel Corporation)
S4 hpqcaslwmiex; C:\Program Files (x86)\HP\Shared\hpqwmiex.exe [1031704 2016-06-03] (Hewlett-Packard Company -> HP)
S4 iaStorAfsService; C:\WINDOWS\System32\iaStorAfsService.exe [2873552 2019-07-19] (Intel(R) Rapid Storage Technology -> Intel Corporation)
S4 igfxCUIService1.0.0.0; C:\WINDOWS\system32\igfxCUIService.exe [320472 2018-01-02] (Intel(R) pGFX -> Intel Corporation)
S3 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6744288 2019-06-26] (Malwarebytes Corporation -> Malwarebytes)
S4 McAfee Vpn Service; C:\Program Files (x86)\McAfee Safe Connect\service\VpnService.exe [314368 2018-03-06] (AnchorFree Inc.) [File not signed]
S4 MyWiFiDHCPDNS; c:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268704 2016-05-03] (Intel Corporation-Wireless Connectivity Solutions -> )
S4 RstMwService; C:\WINDOWS\System32\DriverStore\FileRepository\iastorac.inf_amd64_6ca78a08b838e305\RstMwService.exe [2158592 2019-07-19] (Intel(R) Rapid Storage Technology -> Intel Corporation)
R2 SecureLine; C:\Program Files\AVAST Software\SecureLine VPN\VpnSvc.exe [6828424 2019-10-08] (AVAST Software s.r.o. -> AVAST Software)
S4 SynTPEnhService; C:\WINDOWS\System32\SynTPEnhService.exe [395696 2019-05-08] (Synaptics Incorporated -> Synaptics Incorporated)
S4 SystemUsageReportSvc_QUEENCREEK; C:\Program Files\Intel Driver Update Utility\SUR\SurSvc.exe [157456 2017-03-07] (Intel(R) Software Development Products -> )
S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [13206544 2020-02-14] (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
S4 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
S4 USER_ESRV_SVC_QUEENCREEK; C:\Program Files\Intel\SUR\QUEENCREEK\esrv_svc.exe [824592 2017-03-07] (Intel(R) Software Development Products -> )
S3 WdNisSvc; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\NisSrv.exe [3294680 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
S3 WinDefend; C:\ProgramData\Microsoft\Windows Defender\platform\4.18.2003.8-0\MsMpEng.exe [103168 2020-03-25] (Microsoft Windows Publisher -> Microsoft Corporation)
S4 ZeroConfigService; c:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3732896 2016-05-03] (Intel Corporation-Wireless Connectivity Solutions -> Intel® Corporation)
 
===================== Drivers (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R3 Accelerometer; C:\WINDOWS\system32\DRIVERS\Accelerometer.sys [43840 2012-09-24] (Hewlett-Packard Company -> Hewlett-Packard Company)
R3 aftap0901; C:\WINDOWS\System32\drivers\aftap0901.sys [48624 2018-03-06] (AnchorFree Inc -> The OpenVPN Project)
R3 AMPPAL; C:\WINDOWS\System32\drivers\AMPPAL.sys [165344 2013-05-21] (Intel Corporation-Mobile Wireless Group -> Windows (R) Win 7 DDK provider)
R1 aswArPot; C:\WINDOWS\System32\drivers\aswArPot.sys [205576 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R1 aswbidsdriver; C:\WINDOWS\System32\drivers\aswbidsdriver.sys [271120 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R0 aswbidsh; C:\WINDOWS\System32\drivers\aswbidsh.sys [206608 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R0 aswbuniv; C:\WINDOWS\System32\drivers\aswbuniv.sys [64272 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R0 aswElam; C:\WINDOWS\System32\drivers\aswElam.sys [16304 2020-02-25] (Microsoft Windows Early Launch Anti-malware Publisher -> AVAST Software)
R1 aswKbd; C:\WINDOWS\System32\drivers\aswKbd.sys [42976 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R2 aswMonFlt; C:\WINDOWS\System32\drivers\aswMonFlt.sys [175400 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R1 aswNetSec; C:\WINDOWS\System32\drivers\aswNetSec.sys [552576 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R1 aswRdr; C:\WINDOWS\System32\drivers\aswRdr2.sys [110560 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R0 aswRvrt; C:\WINDOWS\System32\drivers\aswRvrt.sys [84056 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R1 aswSnx; C:\WINDOWS\System32\drivers\aswSnx.sys [848672 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R1 aswSP; C:\WINDOWS\System32\drivers\aswSP.sys [458584 2020-03-11] (Avast Software s.r.o. -> AVAST Software)
R2 aswStm; C:\WINDOWS\System32\drivers\aswStm.sys [235184 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
S3 aswTap; C:\WINDOWS\System32\drivers\aswTap.sys [53904 2018-02-05] (AVAST Software s.r.o. -> The OpenVPN Project)
R0 aswVmm; C:\WINDOWS\System32\drivers\aswVmm.sys [316256 2020-02-25] (Avast Software s.r.o. -> AVAST Software)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink -> CyberLink)
S3 dg_ssudbus; C:\WINDOWS\system32\DRIVERS\ssudbus.sys [136040 2019-09-26] (Samsung Electronics Co., Ltd. -> Samsung Electronics Co., Ltd.)
R0 hpdskflt; C:\WINDOWS\System32\DRIVERS\hpdskflt.sys [31040 2012-09-24] (Hewlett-Packard Company -> Hewlett-Packard Company)
R0 iaStorAC; C:\WINDOWS\System32\drivers\iaStorAC.sys [1036288 2019-07-19] (Intel(R) Rapid Storage Technology -> Intel Corporation)
S3 iaStorAfs; C:\WINDOWS\System32\drivers\iaStorAfs.sys [75472 2019-07-19] (Intel(R) Rapid Storage Technology -> Intel Corporation)
S0 MbamElam; C:\WINDOWS\System32\DRIVERS\MbamElam.sys [20936 2019-06-26] (Microsoft Windows Early Launch Anti-malware Publisher -> Malwarebytes)
R3 NETwNe64; C:\WINDOWS\System32\drivers\NETwew01.sys [3354384 2015-05-04] (Intel Corporation-Wireless Connectivity Solutions -> Intel Corporation)
R3 rt640x64; C:\WINDOWS\System32\drivers\rt640x64.sys [1137928 2019-01-20] (Realtek Semiconductor Corp. -> Realtek )
S3 semav6msr64; C:\WINDOWS\system32\drivers\semav6msr64.sys [21984 2016-10-18] (Intel(R) Code Signing External -> )
S3 SmbDrv; C:\WINDOWS\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-10] (Synaptics Incorporated -> Synaptics Incorporated)
R3 SmbDrvI; C:\WINDOWS\system32\DRIVERS\Smb_driver_Intel.sys [40368 2019-05-08] (Synaptics Incorporated -> Synaptics Incorporated)
S3 tap0901; C:\WINDOWS\System32\drivers\tap0901.sys [31232 2018-02-23] (The OpenVPN Project) [File not signed]
S3 usb3Hub; C:\WINDOWS\System32\drivers\usb3Hub.sys [48096 2012-08-09] (Intel Wireless Display -> Windows (R) Win 7 DDK provider)
S3 WdBoot; C:\WINDOWS\system32\drivers\wd\WdBoot.sys [45960 2020-03-25] (Microsoft Windows Early Launch Anti-malware Publisher -> Microsoft Corporation)
S3 WdFilter; C:\WINDOWS\system32\drivers\wd\WdFilter.sys [391392 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
S3 WdNisDrv; C:\WINDOWS\System32\drivers\wd\WdNisDrv.sys [59104 2020-03-25] (Microsoft Windows -> Microsoft Corporation)
R3 WirelessButtonDriver64; C:\WINDOWS\System32\drivers\WirelessButtonDriver64.sys [34944 2018-05-11] (HP Inc. -> HP)
S3 XHCIPort; C:\WINDOWS\System32\drivers\XHCIPort.sys [188384 2012-08-09] (Intel Wireless Display -> Windows (R) Win 7 DDK provider)
U3 aswMBR; C:\Users\user name\AppData\Local\Temp\aswMBR.sys [62728 2020-03-30] (GMEREK Systemy Komputerowe Przemyslaw Gmerek -> ) [File not signed] <==== ATTENTION
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One month (created) ===================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-03-30 14:41 - 2020-03-30 14:44 - 000040536 _____ C:\Users\user name\Desktop\FRST.txt
2020-03-30 14:27 - 2020-03-30 14:27 - 000000000 ____D C:\Users\user name\AppData\Local\SlimWare Utilities Inc
2020-03-30 13:55 - 2020-03-30 14:41 - 000000000 ____D C:\Users\user name\Desktop\Test
2020-03-30 13:28 - 2020-03-30 14:43 - 000000000 ____D C:\FRST
2020-03-30 12:39 - 2020-03-30 12:40 - 002280448 _____ (Farbar) C:\Users\user name\Desktop\FRST64.exe
2020-03-27 12:34 - 2020-03-27 13:15 - 000000000 ____D C:\Users\user name\Downloads\2NE1 - CRUSH (2014) [FLAC] {YGK-0335} (PE)
2020-03-25 12:10 - 2020-02-25 11:11 - 000368056 _____ (AVAST Software) C:\WINDOWS\system32\aswBoot.exe
2020-03-24 13:01 - 2020-03-24 13:10 - 000000000 ____D C:\ac63d2df7c44d9ca8e066e2f06
2020-03-24 12:39 - 2020-03-24 12:41 - 000515392 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2020-03-23 13:15 - 2020-03-23 13:15 - 000000000 ____D C:\Users\user name\Downloads\Qu Wanting
2020-03-20 20:21 - 2020-03-20 20:22 - 077325289 _____ C:\Users\user name\Downloads\ps lis.rar
2020-03-20 20:17 - 2020-03-20 20:17 - 000000000 ____D C:\Users\user name\Downloads\Liu Ren Yu
2020-03-20 15:45 - 2020-03-20 15:45 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2020-03-20 10:35 - 2020-03-20 10:35 - 000000000 ____D C:\Users\user name\Downloads\Qi Yue
2020-03-19 11:19 - 2020-03-19 11:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2020-03-19 11:19 - 2020-03-19 11:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2020-03-19 11:19 - 2020-03-19 11:19 - 000047600 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2020-03-19 11:19 - 2020-03-19 11:19 - 000044552 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2020-03-16 10:45 - 2020-03-16 10:45 - 000000000 ____D C:\Users\user name\Downloads\Angela Chang
2020-03-10 20:31 - 2020-03-10 20:31 - 000000000 ____D C:\Users\user name\Downloads\Tarcy Su
2020-03-09 10:10 - 2020-03-30 14:20 - 000000000 ____D C:\Users\user name\AppData\LocalLow\uTorrent
2020-03-05 21:36 - 2020-03-25 12:14 - 000002088 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Premium Security.lnk
2020-03-05 21:36 - 2020-03-25 12:14 - 000002076 _____ C:\Users\Public\Desktop\Avast Premium Security.lnk
2020-03-05 21:36 - 2020-03-25 12:14 - 000002076 _____ C:\ProgramData\Desktop\Avast Premium Security.lnk
2020-03-03 23:04 - 2020-03-03 23:04 - 000010070 _____ C:\Users\user name\Documents\cc_20200303_220426.reg
 
==================== One month (modified) ==================
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2020-03-30 14:44 - 2019-03-18 21:52 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2020-03-30 14:20 - 2020-02-17 23:10 - 000000000 ____D C:\Users\user name\AppData\Roaming\uTorrent
2020-03-30 14:05 - 2020-02-17 23:14 - 000000000 ____D C:\Users\user name\AppData\Local\BitTorrentHelper
2020-03-30 13:28 - 2019-06-24 19:32 - 000000000 ____D C:\WINDOWS\system32\SleepStudy
2020-03-30 12:34 - 2019-03-22 19:30 - 000000000 ____D C:\Users\user name\AppData\Local\Firestorm_x64
2020-03-30 12:07 - 2019-03-18 21:37 - 000000000 ____D C:\WINDOWS\CbsTemp
2020-03-30 11:43 - 2017-08-09 20:34 - 000000000 ____D C:\Users\user name\Desktop\Misc
2020-03-30 11:15 - 2017-07-19 21:44 - 000000000 ____D C:\Users\user name\Downloads\Full Programs
2020-03-30 11:03 - 2019-03-18 21:50 - 000000000 ____D C:\WINDOWS\INF
2020-03-30 11:03 - 2015-07-18 17:34 - 000000000 ____D C:\Users\user name\AppData\Local\CrashDumps
2020-03-30 10:25 - 2019-06-24 20:24 - 000004150 _____ C:\WINDOWS\system32\Tasks\User_Feed_Synchronization-{CB50AC73-C0C0-4108-8351-6D47D1C8EA4A}
2020-03-30 10:20 - 2018-02-08 14:02 - 000000000 ____D C:\Users\user name\AppData\Local\AVAST Software
2020-03-30 10:15 - 2019-06-24 20:24 - 000000006 ____H C:\WINDOWS\Tasks\SA.DAT
2020-03-29 21:21 - 2019-03-18 21:37 - 000524288 _____ C:\WINDOWS\system32\config\BBI
2020-03-29 19:49 - 2019-06-24 20:24 - 000004264 _____ C:\WINDOWS\system32\Tasks\Avast Emergency Update
2020-03-29 19:48 - 2019-10-07 10:59 - 000004302 _____ C:\WINDOWS\system32\Tasks\Avast SecureLine VPN Update
2020-03-29 19:48 - 2019-06-24 20:24 - 000004210 _____ C:\WINDOWS\system32\Tasks\CCleaner Update
2020-03-29 16:19 - 2019-10-07 10:38 - 000001041 _____ C:\Users\Public\Desktop\Avast SecureLine VPN.lnk
2020-03-29 16:19 - 2019-10-07 10:38 - 000001041 _____ C:\ProgramData\Desktop\Avast SecureLine VPN.lnk
2020-03-29 16:19 - 2018-02-08 09:29 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2020-03-29 10:30 - 2018-02-05 12:23 - 000000000 ____D C:\ProgramData\AVAST Software
2020-03-29 10:25 - 2017-12-18 13:38 - 000000922 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job
2020-03-29 10:25 - 2017-12-18 13:38 - 000000918 _____ C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job
2020-03-29 10:25 - 2017-06-24 09:16 - 000000348 _____ C:\WINDOWS\Tasks\HPCeeScheduleForDAN$.job
2020-03-29 10:24 - 2020-02-17 23:11 - 000003842 _____ C:\WINDOWS\system32\Tasks\Opera scheduled assistant Autoupdate 1582006308
2020-03-29 10:24 - 2020-02-17 23:11 - 000003580 _____ C:\WINDOWS\system32\Tasks\Opera scheduled Autoupdate 1582006300
2020-03-29 10:24 - 2019-06-24 20:24 - 000003436 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachineUA
2020-03-29 10:24 - 2019-06-24 20:24 - 000003348 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineUA
2020-03-29 10:24 - 2019-06-24 20:24 - 000003124 _____ C:\WINDOWS\system32\Tasks\GoogleUpdateTaskMachineCore
2020-03-29 10:24 - 2019-06-24 20:24 - 000003110 _____ C:\WINDOWS\system32\Tasks\DropboxUpdateTaskMachineCore
2020-03-29 10:24 - 2019-06-24 20:24 - 000002862 _____ C:\WINDOWS\system32\Tasks\OneDrive Standalone Update Task-S-1-5-21-1826707760-3927084271-1880221454-1001
2020-03-29 10:24 - 2019-06-24 20:24 - 000002614 _____ C:\WINDOWS\system32\Tasks\HPCeeScheduleForDAN$
2020-03-29 10:24 - 2019-06-24 20:24 - 000002536 _____ C:\WINDOWS\system32\Tasks\CLMLSvc_P2G8
2020-03-29 10:24 - 2019-06-24 20:24 - 000002320 _____ C:\WINDOWS\system32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1826707760-3927084271-1880221454-500
2020-03-29 10:24 - 2019-06-24 20:24 - 000002290 _____ C:\WINDOWS\system32\Tasks\{4E29F2F4-295B-4771-A849-DFAAE916F4B4}
2020-03-29 10:24 - 2019-06-24 20:24 - 000002220 _____ C:\WINDOWS\system32\Tasks\CCleanerSkipUAC
2020-03-29 10:24 - 2019-06-24 20:24 - 000000000 ____D C:\WINDOWS\system32\Tasks\Avast Software
2020-03-29 10:23 - 2018-06-20 15:51 - 000000000 ____D C:\Users\user name\AppData\Local\D3DSCache
2020-03-29 10:21 - 2014-10-13 18:48 - 000000000 __SHD C:\Users\user name\IntelGraphicsProfiles
2020-03-28 13:16 - 2019-03-18 21:52 - 000000000 ___HD C:\Program Files\WindowsApps
2020-03-28 13:16 - 2019-03-18 21:52 - 000000000 ____D C:\WINDOWS\AppReadiness
2020-03-25 12:10 - 2019-03-18 21:52 - 000000000 ___HD C:\WINDOWS\ELAMBKUP
2020-03-25 11:48 - 2018-06-18 17:38 - 000000000 ____D C:\WINDOWS\system32\Drivers\wd
2020-03-24 19:41 - 2017-05-30 19:58 - 000000863 _____ C:\Users\Public\Desktop\CCleaner.lnk
2020-03-24 19:41 - 2017-05-30 19:58 - 000000863 _____ C:\ProgramData\Desktop\CCleaner.lnk
2020-03-24 09:21 - 2017-05-30 19:58 - 000000000 ____D C:\Program Files\CCleaner
2020-03-21 19:54 - 2015-08-04 18:39 - 000000000 ___RD C:\Users\user name\OneDrive
2020-03-21 19:53 - 2019-07-11 08:29 - 000002412 _____ C:\Users\user name\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2020-03-20 15:51 - 2017-12-18 13:38 - 000000000 ____D C:\Program Files (x86)\Dropbox
2020-03-19 13:44 - 2019-06-24 20:24 - 000003856 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Hourly)
2020-03-19 13:44 - 2019-06-24 20:24 - 000003272 _____ C:\WINDOWS\system32\Tasks\Avast Secure Browser Heartbeat Task (Logon)
2020-03-19 13:44 - 2019-01-06 14:37 - 000002498 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avast Secure Browser.lnk
2020-03-19 13:44 - 2019-01-06 14:37 - 000002463 _____ C:\Users\Public\Desktop\Avast Secure Browser.lnk
2020-03-19 13:44 - 2019-01-06 14:37 - 000002463 _____ C:\ProgramData\Desktop\Avast Secure Browser.lnk
2020-03-19 09:58 - 2019-06-24 19:59 - 000935220 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2020-03-18 16:54 - 2013-08-21 20:05 - 000002301 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2020-03-18 16:54 - 2013-08-21 20:05 - 000002260 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2020-03-18 16:54 - 2013-08-21 20:05 - 000002260 _____ C:\ProgramData\Desktop\Google Chrome.lnk
2020-03-13 20:39 - 2018-03-07 11:47 - 000000000 ____D C:\Users\user name\AppData\LocalLow\Mozilla
2020-03-13 10:07 - 2017-05-30 20:07 - 000000000 ____D C:\Users\user name\AppData\Local\ElevatedDiagnostics
2020-03-13 09:59 - 2019-03-18 21:37 - 000000000 ____D C:\WINDOWS\servicing
2020-03-13 09:39 - 2019-06-24 19:44 - 000000000 ____D C:\Users\user name
2020-03-12 10:20 - 2016-12-03 12:05 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2020-03-12 10:20 - 2015-01-02 16:38 - 000001175 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Firefox.lnk
2020-03-12 10:13 - 2020-02-23 16:43 - 000000000 ____D C:\ProgramData\boost_interprocess
2020-03-11 09:07 - 2017-04-25 17:26 - 000000000 ____D C:\Users\user name\AppData\Roaming\Firestorm_x64
2020-03-11 08:59 - 2018-02-05 12:57 - 000458584 _____ (AVAST Software) C:\WINDOWS\system32\Drivers\aswSP.sys
2020-03-10 20:35 - 2013-08-27 16:47 - 121542864 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2020-03-10 20:35 - 2013-08-27 16:47 - 000000000 ____D C:\WINDOWS\system32\MRT
2020-03-07 18:32 - 2017-12-18 13:37 - 000000000 ____D C:\Users\user name\AppData\Roaming\TeamViewer
2020-03-07 18:32 - 2017-12-18 13:36 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2020-03-07 18:32 - 2012-08-16 18:14 - 000000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos
2020-03-04 12:16 - 2019-03-18 21:52 - 000000000 ____D C:\Program Files\Common Files\microsoft shared
2020-03-04 12:14 - 2017-06-13 15:15 - 000000000 ____D C:\Program Files\Microsoft Office
2020-03-02 14:14 - 2016-06-28 20:16 - 000000000 ____D C:\Users\user name\AppData\Roaming\vlc
 
==================== Files in the root of some directories ========
 
2013-11-06 15:47 - 2013-11-06 15:47 - 000000132 _____ () C:\Users\user name\AppData\Roaming\Adobe Targa Format CS6 Prefs
2013-11-06 15:47 - 2013-11-06 15:47 - 000001456 _____ () C:\Users\user name\AppData\Local\Adobe Save for Web 13.0 Prefs
2014-11-04 18:50 - 2015-04-07 15:15 - 000005120 _____ () C:\Users\user name\AppData\Local\Databases.db
2018-03-13 13:02 - 2018-03-13 13:02 - 000000000 _____ () C:\Users\user name\AppData\Local\{939872F3-BE04-4C03-BE92-D24267E6E9E8}
 
==================== SigCheck ============================
 
(There is no automatic fix for files that do not pass verification.)
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 29-03-2020
Ran by [removed] (30-03-2020 14:46:08)
Running from C:\Users\[removed]\Desktop
Windows 10 Home Version 1903 18362.295 (X64) (2019-06-25 03:26:21)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-1826707760-3927084271-1880221454-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-1826707760-3927084271-1880221454-503 - Limited - Disabled)
Guest (S-1-5-21-1826707760-3927084271-1880221454-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1826707760-3927084271-1880221454-1003 - Limited - Enabled)
user name (S-1-5-21-1826707760-3927084271-1880221454-1001 - Administrator - Enabled) => C:\Users\user name
WDAGUtilityAccount (S-1-5-21-1826707760-3927084271-1880221454-504 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: Avast Antivirus (Enabled - Up to date) {EB19B86E-3998-C706-90EF-92B41EB091AF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
FW: Avast Antivirus (Enabled) {B693136B-F6EE-DD1C-A0EF-229B8B0B29C4}
FW: Avast Antivirus (Enabled) {D322394B-73F7-C65E-BBB0-3B81E063D6D4}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
. . (HKLM\…\{12B07FF1-29CB-45AC-B493-1DB88BE717BD}) (Version: 7.1 - Intel) Hidden
. . . (HKLM-x32\…\{C01175B6-6575-4526-A55B-2BC2F10BA083}) (Version: 2.7.2.4 - Intel) Hidden
µTorrent (HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\uTorrent) (Version: 3.5.5.45608 - BitTorrent Inc.)
4 Elements II (HKLM-x32\…\WTA-8f66c978-192d-49f4-a5c7-d1e31a499af7) (Version: 2.2.0.98 - WildTangent) Hidden
Adobe Shockwave Player 12.3 (HKLM-x32\…\Adobe Shockwave Player) (Version: 12.3.4.204 - Adobe Systems, Inc.)
Apple Application Support (HKLM-x32\…\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
Apple Software Update (HKLM-x32\…\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)
Avast Cleanup Premium (HKLM-x32\…\{075CC190-59EE-499F-828B-0B5C098C8C15}_is1) (Version: 19.1.7734 - AVAST Software)
Avast Premium Security (HKLM-x32\…\Avast Antivirus) (Version: 20.1.2397 - AVAST Software)
Avast Secure Browser (HKLM-x32\…\Avast Secure Browser) (Version: 80.0.3619.133 - AVAST Software)
Avast SecureLine VPN (HKLM\…\{2CD3C92F-EDC5-4B02-9B0A-9C1D37C58EF5}_is1) (Version: 5.5.522 - AVAST Software)
Bejeweled 3 (HKLM-x32\…\WTA-99adf316-0268-46ef-845d-27572ddcc66f) (Version: 2.2.0.98 - WildTangent) Hidden
Bonjour (HKLM\…\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Build-a-lot 4 - Power Source (HKLM-x32\…\WTA-f76b0e0a-87cf-4279-b77f-e9b1db84f508) (Version: 2.2.0.98 - WildTangent) Hidden
Canon MF240 Series (HKLM\…\{31DCD678-B363-43B7-AF3D-258D7376A129}) (Version: 5.2.0.0 - CANON INC.)
CCleaner (HKLM\…\CCleaner) (Version: 5.65 - Piriform)
Chuzzle Deluxe (HKLM-x32\…\WTA-bfbe24a3-c62e-4169-ad03-7b85e9ec1ee0) (Version: 2.2.0.95 - WildTangent) Hidden
Classic Shell (HKLM\…\{CABCE573-0A86-42FA-A52A-C7EA61D5BE08}) (Version: 4.3.1 - IvoSoft)
Cradle Of Egypt Collector's Edition (HKLM-x32\…\WTA-79b18580-9c44-4d82-ada3-f02dcac5ea43) (Version: 2.2.0.98 - WildTangent) Hidden
Cradle of Rome 2 (HKLM-x32\…\WTA-b0690451-0d4a-487d-91f4-80e48cdb5d1c) (Version: 2.2.0.98 - WildTangent) Hidden
CyberLink Media Suite 10 (HKLM-x32\…\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.1.1916 - CyberLink Corp.)
CyberLink PhotoDirector (HKLM-x32\…\InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}) (Version: 2.0.1.3119 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\…\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.1.1925 - CyberLink Corp.)
D3DX10 (HKLM-x32\…\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Discord (HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\Discord) (Version: 0.0.305 - Discord Inc.)
Dropbox (HKLM-x32\…\Dropbox) (Version: 93.4.273 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\…\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.295.1 - Dropbox, Inc.) Hidden
Energy Star (HKLM\…\{0FA995CC-C849-4755-B14B-5404CC75DC24}) (Version: 1.0.8 - Hewlett-Packard)
Farm Frenzy (HKLM-x32\…\WTA-bcfd825c-aa81-4cef-a5d4-e75c05f7307e) (Version: 2.2.0.98 - WildTangent) Hidden
FATE: The Cursed King (HKLM-x32\…\WTA-59763575-3bb2-4a55-9c50-56c3c19cb6c7) (Version: 2.2.0.97 - WildTangent) Hidden
Final Drive Fury (HKLM-x32\…\WTA-e1d0bbaa-624b-4d8c-b8f9-387f499d88a8) (Version: 2.2.0.95 - WildTangent) Hidden
Firestorm-Releasex64 (HKLM\…\Firestorm-Releasex64) (Version: 6.3.2.58052 - The Phoenix Firestorm Project, Inc.)
Google Chrome (HKLM-x32\…\Google Chrome) (Version: 80.0.3987.149 - Google LLC)
Google Update Helper (HKLM-x32\…\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.35.451 - Google LLC) Hidden
Google Update Helper (HKLM-x32\…\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (HKLM-x32\…\WTA-c403f162-ade4-4f6f-b5f5-457b8eefbf93) (Version: 2.2.0.95 - WildTangent) Hidden
Gyazo 3.4.1.0 (HKLM-x32\…\{6DB8C365-E719-4BA5-9594-10DFC244D3FD}_is1) (Version:  - Nota Inc.)
Hoyle Card Games (HKLM-x32\…\WTA-0021b7e4-62a5-474b-be1d-abb060a54392) (Version: 2.2.0.95 - WildTangent) Hidden
HP 3D DriveGuard (HKLM\…\{54CE68A8-4F2D-4328-B1F7-D6C720405F7F}) (Version: 4.2.9.1 - Hewlett-Packard Company)
HP Connected Music (Meridian - installer) (HKLM-x32\…\StartHPConnectedMusic) (Version: v1.0 - Meridian Audio Ltd)
HP Documentation (HKLM-x32\…\{A029F666-056B-4399-B72E-214C5990B684}) (Version: 1.1.0.0 - Hewlett-Packard)
HP Games (HKLM-x32\…\WildTangent hp Master Uninstall) (Version: 1.0.3.0 - WildTangent)
HP Quick Launch (HKLM-x32\…\{E5823036-6F09-4D0A-B05C-E2BAA129288A}) (Version: 3.0.6 - Hewlett-Packard Company)
HP Software Framework (HKLM-x32\…\{835B275B-F29B-464B-BD4B-097FD55FAB0A}) (Version: 4.6.8.1 - Hewlett-Packard Company)
HP Utility Center (HKLM-x32\…\{0C57987A-A03A-4B95-A309-D23F78F406CA}) (Version: 1.0.7 - Hewlett-Packard)
HP Wireless Button Driver (HKLM-x32\…\{30B2D1D8-0A07-4B71-9553-0710C5D31E35}) (Version: 1.1.2.1 - Hewlett-Packard Company)
IDT Audio (HKLM-x32\…\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6433.0 - IDT)
Intel(R) Chipset Device Software (HKLM-x32\…\{314d4c01-f54b-4125-a71f-1e2722c29050}) (Version: 10.1.1.40 - Intel(R) Corporation) Hidden
Intel(R) Management Engine Components (HKLM\…\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.6.1194 - Intel Corporation)
Intel(R) PRO/Wireless Driver (HKLM\…\{66afb482-3029-428f-8283-135d3c272132}) (Version: 19.00.0000.4496 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\…\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.4885 - Intel Corporation)
Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\…\{7854AA22-A2F0-4F29-A2E9-D0C5A2B685E7}) (Version: 2.5.0.0248 - Motorola Solutions, Inc)
Intel(R) SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\…\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel(R) WiDi (HKLM\…\{EDBA2433-0910-4C72-8C5B-8FEDAE3EF18E}) (Version: 3.5.34.0 - Intel Corporation)
Intel(R) Wireless Bluetooth(R) (HKLM-x32\…\{559FA847-377D-4926-80A3-ED9E014D363A}) (Version: 19.60.0 - Intel Corporation)
Intel® Driver Update Utility (HKLM-x32\…\{954190cd-c66c-4650-bd15-f3dd85f2ae15}) (Version: 2.7.2.4 - Intel)
Intel® PROSet/Wireless Software (HKLM-x32\…\{c9967fbd-e3c3-4ed0-992a-5b33260f2944}) (Version: 16.1.5 - Intel Corporation)
Java 8 Update 221 (HKLM-x32\…\{26A24AE4-039D-4CA4-87B4-2F32180221F0}) (Version: 8.0.2210.11 - Oracle Corporation)
Jewel Match 3 (HKLM-x32\…\WTA-7bd9220d-6e38-4bbc-8198-dfaa90822b19) (Version: 2.2.0.98 - WildTangent) Hidden
John Deere Drive Green (HKLM-x32\…\WTA-b10de435-2c1e-4e91-a70e-1920ef344345) (Version: 2.2.0.95 - WildTangent) Hidden
Luxor Evolved (HKLM-x32\…\WTA-61b1f9bc-659e-4e7f-820a-d48db6d1b8d4) (Version: 2.2.0.98 - WildTangent) Hidden
Mahjongg Dimensions Deluxe: Tiles in Time (HKLM-x32\…\WTA-7480ea9e-27e5-4346-9340-2c181369137d) (Version: 2.2.0.98 - WildTangent) Hidden
Malwarebytes version 3.8.3.2965 (HKLM\…\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.8.3.2965 - Malwarebytes)
McAfee Safe Connect (HKLM-x32\…\{8DF95C34-C5EB-4026-9C86-E49F2A94677A}) (Version: 1.6.0.223 - McAfee, Inc)
Microsoft Office Professional 2016 - en-us (HKLM\…\ProfessionalRetail - en-us) (Version: 16.0.12430.20288 - Microsoft Corporation)
Microsoft Office XP Professional with FrontPage (HKLM-x32\…\{90280409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2627.0 - Microsoft Corporation)
Microsoft OneDrive (HKU\.DEFAULT\…\OneDriveSetup.exe) (Version: 18.151.0729.0013 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\OneDriveSetup.exe) (Version: 19.232.1124.0010 - Microsoft Corporation)
Microsoft Publisher 2002 (HKLM-x32\…\{90190409-6000-11D3-8CFE-0050048383C9}) (Version: 10.0.2627.01 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\…\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\…\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\…\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\…\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\…\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\…\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\…\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\…\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\…\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\…\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\…\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\…\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\…\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Mortimer Beckett and the Crimson Thief Premium Edition (HKLM-x32\…\WTA-a0a624af-97a7-4626-8175-d6d675883c9d) (Version: 2.2.0.98 - WildTangent) Hidden
Mozilla Firefox 74.0 (x86 en-US) (HKLM-x32\…\Mozilla Firefox 74.0 (x86 en-US)) (Version: 74.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\…\MozillaMaintenanceService) (Version: 65.0.1.6981 - Mozilla)
Mystery P.I. - Curious Case of Counterfeit Cove (HKLM-x32\…\WTA-b390dfb2-801a-4bf3-b26a-5d1ad8b4265f) (Version: 2.2.0.98 - WildTangent) Hidden
Office 16 Click-to-Run Extensibility Component (HKLM\…\{90160000-008C-0000-1000-0000000FF1CE}) (Version: 16.0.12430.20288 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\…\{90160000-007E-0000-1000-0000000FF1CE}) (Version: 16.0.12430.20184 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM\…\{90160000-008C-0409-1000-0000000FF1CE}) (Version: 16.0.12430.20288 - Microsoft Corporation) Hidden
Peggle Nights (HKLM-x32\…\WTA-f1b24906-c39b-4fee-b604-fc7632274baa) (Version: 2.2.0.98 - WildTangent) Hidden
Penguins! (HKLM-x32\…\WTA-f5c7f5a0-dc7d-4b1e-872a-74f7f5336f74) (Version: 2.2.0.98 - WildTangent) Hidden
Pidgin (HKLM-x32\…\Pidgin) (Version: 2.13.0 - )
Polar Bowler (HKLM-x32\…\WTA-935bd0cc-26f5-4e83-926a-be8309d75733) (Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (HKLM-x32\…\WTA-eddbcbdb-0562-4ae6-9267-a4ebd7c379f9) (Version: 2.2.0.98 - WildTangent) Hidden
QuickTime 7 (HKLM-x32\…\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
RAR Opener version 1.0 (HKLM-x32\…\{DFC3E171-965F-4C07-AA42-05F6F5B7380B}_is1) (Version: 1.0 - raropener.com)
Realtek Ethernet Controller Driver (HKLM-x32\…\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 10.16.323.2017 - Realtek)
Realtek PCIE Card Reader (HKLM-x32\…\{C1594429-8296-4652-BF54-9DBE4932A44C}) (Version: 6.1.8400.29025 - Realtek Semiconductor Corp.)
Roads of Rome 3 (HKLM-x32\…\WTA-5e05ad85-18a2-47d5-857a-3c70261e1b98) (Version: 2.2.0.98 - WildTangent) Hidden
Snagit 12 (HKLM-x32\…\{4FC332FE-CBE3-4AE0-B531-35048FD81912}) (Version: 12.4.1 - TechSmith Corporation)
swMSM (HKLM-x32\…\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Tales of Lagoona (HKLM-x32\…\WTA-e5667b68-d539-4465-9471-bed396f3e709) (Version: 2.2.0.110 - WildTangent) Hidden
TAP-Windows 9.21.2 (HKLM\…\TAP-Windows) (Version: 9.21.2 - )
TeamViewer (HKLM-x32\…\TeamViewer) (Version: 15.3.2682 - TeamViewer)
Unity Web Player (HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\UnityWebPlayer) (Version: 5.0.0f4 - Unity Technologies ApS)
Update for CHS Microsoft IME HAP Dictionary (HKLM\…\{50822466-5571-4B7A-B3FC-A58760DDAEE9}) (Version: 16.0.1560.1 - Microsoft Corporation) Hidden
Update for Windows 10 for x64-based Systems (KB4023057) (HKLM\…\{F14FB68A-9188-4036-AD0D-D054BC9C9291}) (Version: 2.59.0.0 - Microsoft Corporation)
Vacation Quest™ - Australia (HKLM-x32\…\WTA-e518bf2c-172f-4701-876c-8cda2e0b06c7) (Version: 2.2.0.98 - WildTangent) Hidden
VLC media player (HKLM\…\VLC media player) (Version: 3.0.8 - VideoLAN)
Windows Live Essentials (HKLM-x32\…\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
WinRAR 5.71 (64-bit) (HKLM\…\WinRAR archiver) (Version: 5.71.0 - win.rar GmbH)
Zoom (HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\ZoomUMX) (Version: 4.4 - Zoom Video Communications, Inc.)
Zuma's Revenge (HKLM-x32\…\WTA-09aa637b-1587-4385-9fd4-ac54d832e459) (Version: 2.2.0.98 - WildTangent) Hidden
 
Packages:
=========
Candy Crush Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSaga_1.1730.2.0_x86__kgqvnymyfvs32 [2020-03-27] (king.com)
Candy Crush Soda Saga -> C:\Program Files\WindowsApps\king.com.CandyCrushSodaSaga_1.164.200.0_x86__kgqvnymyfvs32 [2020-03-20] (king.com)
Canon Office Printer Utility -> C:\Program Files\WindowsApps\34791E63.CanonOfficePrinterUtility_12.7.0.0_x64__6e5tt8cgb93ep [2019-06-13] (Canon Inc.)
Disney Magic Kingdoms -> C:\Program Files\WindowsApps\A278AB0D.DisneyMagicKingdoms_4.9.0.6_x86__h6adky7gbf63m [2020-03-13] (Gameloft SE)
Getting Started with Windows 8 -> C:\Program Files\WindowsApps\AD2F1837.GettingStartedwithWindows8_1.6.0.0_neutral__v10z8vjag6ke6 [2019-03-07] (Hewlett-Packard Company)
HP Explore -> C:\Program Files\WindowsApps\AD2F1837.HPWelcome_0.1.50.0_x64__v10z8vjag6ke6 [2019-03-07] (Hewlett-Packard Company)
HP Registration -> C:\Program Files\WindowsApps\AD2F1837.HPRegistration_1.2.1.166_neutral__v10z8vjag6ke6 [2019-03-07] (Hewlett-Packard Company)
iHeartRadio -> C:\Program Files\WindowsApps\ClearChannelRadioDigital.iHeartRadio_6.0.47.0_x64__a76a11dkgb644 [2020-02-27] (iHeartMedia.)
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x64__8wekyb3d8bbwe [2019-03-07] (Microsoft Corporation) [MS Ad]
Microsoft Advertising SDK for XAML -> C:\Program Files\WindowsApps\Microsoft.Advertising.Xaml_10.1811.1.0_x86__8wekyb3d8bbwe [2019-03-07] (Microsoft Corporation) [MS Ad]
Microsoft Mahjong -> C:\Program Files\WindowsApps\Microsoft.MicrosoftMahjong_3.10.2011.0_x64__8wekyb3d8bbwe [2020-03-04] (Microsoft Studios) [MS Ad]
Microsoft News -> C:\Program Files\WindowsApps\Microsoft.BingNews_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad]
Microsoft Solitaire Collection -> C:\Program Files\WindowsApps\Microsoft.MicrosoftSolitaireCollection_4.6.1224.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Studios) [MS Ad]
MSN Food & Drink -> C:\Program Files\WindowsApps\Microsoft.BingFoodAndDrink_3.0.4.336_x64__8wekyb3d8bbwe [2019-03-07] (Microsoft Corporation) [MS Ad]
MSN Health & Fitness -> C:\Program Files\WindowsApps\Microsoft.BingHealthAndFitness_3.0.4.336_x64__8wekyb3d8bbwe [2019-03-07] (Microsoft Corporation) [MS Ad]
MSN Money -> C:\Program Files\WindowsApps\Microsoft.BingFinance_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad]
MSN Sports -> C:\Program Files\WindowsApps\Microsoft.BingSports_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad]
MSN Travel -> C:\Program Files\WindowsApps\Microsoft.BingTravel_3.0.4.336_x64__8wekyb3d8bbwe [2019-03-07] (Microsoft Corporation) [MS Ad]
MSN Weather -> C:\Program Files\WindowsApps\Microsoft.BingWeather_4.36.20714.0_x64__8wekyb3d8bbwe [2020-03-25] (Microsoft Corporation) [MS Ad]
Netflix -> C:\Program Files\WindowsApps\4DF9E0F8.Netflix_6.95.602.0_x64__mcm4njqhnhss8 [2019-10-30] (Netflix, Inc.)
Norton Studio -> C:\Program Files\WindowsApps\SymantecCorporation.NortonStudio_2.2.0.0_x86__v68kp9n051hdp [2019-03-06] (Symantec Corporation)
Synaptics TouchPad -> C:\Program Files\WindowsApps\SynapticsIncorporated.SynHPConsumerDApp_19005.35054.0.0_x64__807d65c4rvak2 [2020-03-13] (Synaptics Incorporated)
Twitter -> C:\Program Files\WindowsApps\9E2F88E3.Twitter_6.1.4.1000_neutral__wgeqdkkx372wm [2019-03-07] (Twitter Inc.)
 
==================== Custom CLSID (Whitelisted): ==============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-1826707760-3927084271-1880221454-1001_Classes\CLSID\{820D63D5-8CFF-46DE-86AF-4997DEDD6DB5}\localserver32 -> C:\WINDOWS\system32\igfxEM.exe (Intel(R) pGFX -> Intel Corporation)
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-25] (Avast Software s.r.o. -> AVAST Software)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-25] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers1: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers1: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll [2015-08-14] (TechSmith Corporation -> TechSmith Corporation)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} =>  -> No File
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-25] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers4: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll [2015-08-14] (TechSmith Corporation -> TechSmith Corporation)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.36.0.dll [2020-03-19] (Dropbox, Inc -> Dropbox, Inc.)
ContextMenuHandlers5: [igfxDTCM] -> {9B5F5829-A529-4B12-814A-E81BCB8D93FC} => C:\WINDOWS\system32\igfxDTCM.dll [2018-01-02] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers5: [igfxOSP] -> {FA507C3F-30C6-4DCA-9EE5-2656072EEC14} => C:\WINDOWS\system32\igfxOSP.dll [2018-01-02] (Microsoft Windows Hardware Compatibility Publisher -> Intel Corporation)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2020-02-25] (Avast Software s.r.o. -> AVAST Software)
ContextMenuHandlers6: [StartMenuExt] -> {E595F05F-903F-4318-8B0A-7F633B520D2B} => C:\WINDOWS\system32\StartMenuHelper64.dll [2017-08-13] (Ivaylo Beltchev -> IvoSoft) [File not signed]
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2019-04-27] (win.rar GmbH -> Alexander Roshal)
 
==================== Codecs (Whitelisted) ====================
 
==================== Shortcuts & WMI ========================
 
==================== Loaded Modules (Whitelisted) =============
 
2018-02-08 09:29 - 2016-09-12 15:53 - 048936448 _____ () [File not signed] C:\Program Files (x86)\AVAST Software\Avast Cleanup\libcef.dll
2017-08-13 09:49 - 2017-08-13 09:49 - 000291128 _____ (Ivaylo Beltchev -> IvoSoft) [File not signed] C:\WINDOWS\system32\StartMenuHelper64.dll
2019-10-07 10:37 - 2018-09-07 09:07 - 002095104 _____ (The OpenSSL Project, hxxp://www.openssl.org/) [File not signed] C:\Program Files\AVAST Software\SecureLine VPN\libcrypto-1_1.dll
 
==================== Alternate Data Streams (Whitelisted) ========
 
==================== Safe Mode (Whitelisted) ==================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
 
==================== Association (Whitelisted) =================
 
==================== Internet Explorer trusted/restricted ==========
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\localhost -> localhost
IE trusted site: HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\webcompanion.com -> hxxp://webcompanion.com
 
==================== Hosts content: =========================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2015-07-23 14:06 - 2020-03-29 15:44 - 000000231 _____ C:\WINDOWS\system32\drivers\etc\hosts
0.0.0.0  telemetry.malwarebytes.com
0.0.0.0 test.bypclife
0.0.0.0 keystone.mwbsys.com
0.0.0.0 keystone-prod.elasticbeanstalk.com
0.0.0.0 serius.mwbsys.com
 
==================== Other Areas ===========================
 
(Currently there is no automatic fix for this section.)
 
HKLM\System\CurrentControlSet\Control\Session Manager\Environment\\Path -> C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\ProgramData\Oracle\Java\javapath;C:\Program Files (x86)\Intel\iCLS Client\;C:\Program Files\Intel\iCLS Client\;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\;C:\Program Files (x86)\Windows Live\Shared;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x86;C:\Program Files (x86)\Intel\OpenCL SDK\2.0\bin\x64;C:\Program Files\Intel\WiFi\bin\;C:\Program Files\Common Files\Intel\WirelessCommon\;C:\Program Files (x86)\QuickTime\QTSystem\;%SYSTEMROOT%\System32\OpenSSH\
HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\Control Panel\Desktop\\Wallpaper -> c:\windows\web\wallpaper\hewlett-packard backgrounds\backgrounddefault.jpg
DNS Servers: [removed] - [removed]
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
HKLM\software\microsoft\Windows\CurrentVersion\Telephony\Providers => ProviderFileName2 -> ndptsp.tsp (No File)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(If an entry is included in the fixlist, it will be removed.)
 
MSCONFIG\Services: avast => 2
MSCONFIG\Services: avastm => 3
MSCONFIG\Services: AvastSecureBrowserElevationService => 3
MSCONFIG\Services: CleanupPSvc => 2
MSCONFIG\Services: cphs => 3
MSCONFIG\Services: dbupdate => 2
MSCONFIG\Services: dbupdatem => 3
MSCONFIG\Services: DbxSvc => 2
MSCONFIG\Services: GoogleChromeElevationService => 3
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: hpsrv => 2
MSCONFIG\Services: iaStorAfsService => 3
MSCONFIG\Services: igfxCUIService1.0.0.0 => 2
MSCONFIG\Services: McAfee Vpn Service => 3
MSCONFIG\Services: RstMwService => 2
MSCONFIG\Services: SecureLine => 2
MSCONFIG\Services: SynTPEnhService => 2
HKLM\…\StartupApproved\StartupFolder: => "Microsoft Office.lnk"
HKLM\…\StartupApproved\Run: => "SecurityHealth"
HKLM\…\StartupApproved\Run: => "SynTPEnh"
HKLM\…\StartupApproved\Run: => "WindowsDefender"
HKLM\…\StartupApproved\Run: => "Classic Start Menu"
HKLM\…\StartupApproved\Run32: => "Dropbox"
HKLM\…\StartupApproved\Run32: => "SunJavaUpdateSched"
HKLM\…\StartupApproved\Run32: => "kwmusic"
HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\StartupApproved\Run: => "Gyazo"
HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\StartupApproved\Run: => "McAfeeSafeConnect"
HKU\S-1-5-21-1826707760-3927084271-1880221454-1001\…\StartupApproved\Run: => "Discord"
 
==================== FirewallRules (Whitelisted) ================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{7216BA0B-F049-4B57-AB25-EA5EDE46CED5}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{90AE451F-F854-4F2A-9297-4B23EDD0DB45}] => (Allow) C:\Program Files\CCleaner\CCUpdate.exe (Piriform Software Ltd -> Piriform Software Ltd)
FirewallRules: [{39FEB545-B459-4437-97CB-5C578CCF762F}] => (Allow) c:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe (Intel Corporation-Wireless Connectivity Solutions -> )
FirewallRules: [TCP Query User{AD657683-AE1A-4AD3-9899-CB73F5545132}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [UDP Query User{373AF378-DE5C-4810-A36B-08666E9BB270}C:\program files (x86)\google\chrome\application\chrome.exe] => (Allow) C:\program files (x86)\google\chrome\application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{00BD0139-2FDB-4822-9371-8DA8D964C0C0}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{21F02120-02FF-49A4-92F4-72E249150C5B}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation -> Mozilla Corporation)
FirewallRules: [{A77C6FDE-FDCC-469C-A88F-07A3524628A9}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{93C0173C-B2FC-407C-A019-BD0A35094708}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{127D4CAE-DF12-4A5C-969E-31F2DA72909A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{3686A626-EE37-4A78-8AC0-51431BEB0003}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{E2CF6F64-50A0-4A09-9618-86514F559765}] => (Allow) C:\Users\user name\AppData\Roaming\Zoom\bin\Zoom.exe (Zoom Video Communications, Inc. -> Zoom Video Communications, Inc.)
FirewallRules: [TCP Query User{1DFAB4CC-C6E8-408F-9ECD-70703826DBB8}C:\program files\firestorm-releasex64\slvoice.exe] => (Block) C:\program files\firestorm-releasex64\slvoice.exe (Mercer Road Corp -> )
FirewallRules: [UDP Query User{94333CF9-A8B0-49B2-BA19-BE8F7775EE43}C:\program files\firestorm-releasex64\slvoice.exe] => (Block) C:\program files\firestorm-releasex64\slvoice.exe (Mercer Road Corp -> )
FirewallRules: [{C7364D27-19C2-4879-AB31-6D0272E2D998}] => (Allow) C:\Program Files\Microsoft Office\root\Office16\outlook.exe (Microsoft Corporation -> Microsoft Corporation)
FirewallRules: [{A472DC9B-2940-4F3E-A7B8-6B6062D12E5E}] => (Allow) C:\Users\user name\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{0BF3D29C-7949-4306-805D-DEDD66FBE9DB}] => (Allow) C:\Users\user name\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc -> BitTorrent Inc.)
FirewallRules: [{AB2CB4AE-456E-4349-BF7D-BAF22ECCBE9B}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{9653EAE4-A331-4F9D-B73A-417A99D1E1BA}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{1E32C5E6-4C4E-483E-98B7-801FB90326A4}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{D65BDD4D-8A02-49BF-A79E-A5DFBF6BE1FF}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (TeamViewer Germany GmbH -> TeamViewer Germany GmbH)
FirewallRules: [{6937E6A9-C96F-4E57-BA2F-2F2F400B8B59}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google LLC -> Google LLC)
FirewallRules: [{5A51609C-FEB8-439B-B643-06F312C23320}] => (Allow) C:\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe (Avast Software s.r.o. -> AVAST Software)
FirewallRules: [{463E4601-2557-4652-8B29-43D51F220EA7}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe (Dropbox, Inc -> Dropbox, Inc.)
 
==================== Restore Points =========================
 
27-03-2020 17:55:32 Windows Update
30-03-2020 14:27:23 Removed Avast Driver Updater
30-03-2020 14:30:24 Removed Avast Driver Updater
 
==================== Faulty Device Manager Devices ============
 
 
==================== Event log errors: ========================
 
Application errors:
==================
Error: (03/30/2020 02:51:00 PM) (Source: ESENT) (EventID: 467) (User: )
Description: svchost (3752,D,23) SRUJet: Database C:\WINDOWS\system32\SRU\SRUDB.dat: Index AutoIncIdIndex of table {5C8CF1C7-7257-4F13-B223-970EF5939312} is corrupted (0).
 
Error: (03/30/2020 02:51:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (3752,D,22) SRUJet: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 12, PgnoRoot: 47) of database C:\WINDOWS\system32\SRU\SRUDB.dat (4256 => 2215, 2217).
 
Tag: BtSplitParentMismatchLast
 
Fatal: 1
 
Error: (03/30/2020 02:51:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (3752,D,22) SRUJet: A bad page link (error -327) has been detected in a B-Tree (ObjectId: 38, PgnoRoot: 176) of database C:\WINDOWS\system32\SRU\SRUDB.dat (8363 => 8364, 8200).
 
Tag: BtSplitBadLeafPgno
 
Fatal: 1
 
Error: (03/30/2020 02:50:00 PM) (Source: ESENT) (EventID: 467) (User: )
Description: svchost (3752,D,23) SRUJet: Database C:\WINDOWS\system32\SRU\SRUDB.dat: Index AutoIncIdIndex of table {5C8CF1C7-7257-4F13-B223-970EF5939312} is corrupted (0).
 
Error: (03/30/2020 02:50:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (3752,D,22) SRUJet: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 12, PgnoRoot: 47) of database C:\WINDOWS\system32\SRU\SRUDB.dat (4256 => 2215, 2217).
 
Tag: BtSplitParentMismatchLast
 
Fatal: 1
 
Error: (03/30/2020 02:50:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (3752,D,22) SRUJet: A bad page link (error -327) has been detected in a B-Tree (ObjectId: 38, PgnoRoot: 176) of database C:\WINDOWS\system32\SRU\SRUDB.dat (8363 => 8364, 8200).
 
Tag: BtSplitBadLeafPgno
 
Fatal: 1
 
Error: (03/30/2020 02:49:00 PM) (Source: ESENT) (EventID: 467) (User: )
Description: svchost (3752,D,23) SRUJet: Database C:\WINDOWS\system32\SRU\SRUDB.dat: Index AutoIncIdIndex of table {5C8CF1C7-7257-4F13-B223-970EF5939312} is corrupted (0).
 
Error: (03/30/2020 02:49:00 PM) (Source: ESENT) (EventID: 447) (User: )
Description: svchost (3752,D,22) SRUJet: A bad page link (error -338) has been detected in a B-Tree (ObjectId: 12, PgnoRoot: 47) of database C:\WINDOWS\system32\SRU\SRUDB.dat (4256 => 2215, 2217).
 
Tag: BtSplitParentMismatchLast
 
Fatal: 1
 
 
System errors:
=============
Error: (03/30/2020 12:07:17 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8007007e: 2020-02 Security Update for Adobe Flash Player for Windows 10 Version 1903 for x64-based Systems (KB4537759).
 
Error: (03/30/2020 11:44:34 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80073712: 2020-03 Cumulative Update for Windows 10 Version 1903 for x64-based Systems (KB4551762).
 
Error: (03/30/2020 10:21:30 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The System Guard Runtime Monitor Broker service hung on starting.
 
Error: (03/30/2020 10:19:27 AM) (Source: Service Control Manager) (EventID: 7022) (User: )
Description: The Downloaded Maps Manager service hung on starting.
 
Error: (03/30/2020 10:18:35 AM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {784E29F4-5EBE-4279-9948-1E8FE941646D} did not register with DCOM within the required timeout.
 
Error: (03/29/2020 07:47:52 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {784E29F4-5EBE-4279-9948-1E8FE941646D} did not register with DCOM within the required timeout.
 
Error: (03/29/2020 06:34:59 PM) (Source: DCOM) (EventID: 10010) (User: NT AUTHORITY)
Description: The server {784E29F4-5EBE-4279-9948-1E8FE941646D} did not register with DCOM within the required timeout.
 
Error: (03/29/2020 06:32:30 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The avast! Antivirus service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
 
Windows Defender:
===================================
Date: 2020-02-19 11:28:01.854
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen
ID: 2147593794
Severity: High
Category: Tool
Path: file:_C:\Users\user name\AppData\Roaming\uTorrent\msimg32.dll
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Users\user name\AppData\Roaming\uTorrent\uTorrent.exe
Security intelligence Version: AV: 1.309.987.0, AS: 1.309.987.0, NIS: 1.309.987.0
Engine Version: AM: 1.1.16700.3, NIS: 1.1.16700.3
 
Date: 2020-02-19 11:27:19.213
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen
ID: 2147593794
Severity: High
Category: Tool
Path: file:_C:\Users\user name\AppData\Roaming\uTorrent\msimg32.dll
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Users\user name\AppData\Roaming\uTorrent\uTorrent.exe
Security intelligence Version: AV: 1.309.987.0, AS: 1.309.987.0, NIS: 1.309.987.0
Engine Version: AM: 1.1.16700.3, NIS: 1.1.16700.3
 
Date: 2020-02-19 11:26:05.421
Description: 
Windows Defender Antivirus has detected malware or other potentially unwanted software.
For more information please see the following:
Name: HackTool:Win32/Keygen
ID: 2147593794
Severity: High
Category: Tool
Path: file:_C:\Users\user name\AppData\Roaming\uTorrent\msimg32.dll
Detection Origin: Local machine
Detection Type: Concrete
Detection Source: Real-Time Protection
Process Name: C:\Users\user name\AppData\Roaming\uTorrent\uTorrent.exe
Security intelligence Version: AV: 1.309.987.0, AS: 1.309.987.0, NIS: 1.309.987.0
Engine Version: AM: 1.1.16700.3, NIS: 1.1.16700.3
 
Date: 2020-03-22 10:00:38.382
Description: 
Windows Defender Antivirus has encountered an error trying to load security intelligence and will attempt reverting back to a known-good version.
Security intelligence Attempted: Backup
Error Code: 0x80004004
Error description: Operation aborted 
Security intelligence version: 1.311.1644.0;1.311.1644.0
Engine version: 1.1.16800.2
 
Date: 2020-03-22 10:00:34.404
Description: 
Windows Defender Antivirus has encountered an error trying to load security intelligence and will attempt reverting back to a known-good version.
Security intelligence Attempted: Current
Error Code: 0x80004004
Error description: Operation aborted 
Security intelligence version: 1.311.1712.0;1.311.1712.0
Engine version: 1.1.16800.2
 
Date: 2020-03-13 09:43:41.054
Description: 
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.311.625.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.16800.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved 
 
Date: 2020-03-13 09:43:41.053
Description: 
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.311.625.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiSpyware
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.16800.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved 
 
Date: 2020-03-13 09:43:41.052
Description: 
Windows Defender Antivirus has encountered an error trying to update security intelligence.
New security intelligence Version: 
Previous security intelligence Version: 1.311.625.0
Update Source: Microsoft Malware Protection Center
Security intelligence Type: AntiVirus
Update Type: Full
Current Engine Version: 
Previous Engine Version: 1.1.16800.2
Error code: 0x80072ee7
Error description: The server name or address could not be resolved 
 
CodeIntegrity:
===================================
 
Date: 2020-03-30 14:47:11.714
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.
 
Date: 2020-03-30 14:47:11.713
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.
 
Date: 2020-03-30 14:47:11.379
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.
 
Date: 2020-03-30 14:47:11.164
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.
 
Date: 2020-03-30 14:47:10.770
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.
 
Date: 2020-03-30 14:47:10.382
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.
 
Date: 2020-03-30 14:47:10.101
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.
 
Date: 2020-03-30 14:47:09.044
Description: 
Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files (x86)\AVAST Software\Browser\Application\AvastBrowser.exe) attempted to load \Device\HarddiskVolume4\Program Files\AVAST Software\Avast\x86\aswhook.dll that did not meet the Microsoft signing level requirements.
 
==================== Memory info =========================== 
 
BIOS: Insyde F.35 01/04/2013
Motherboard: Hewlett-Packard 1836
Processor: Intel(R) Core(TM) i5-3210M CPU @ 2.50GHz
Percentage of memory in use: 56%
Total physical RAM: 8085.96 MB
Available physical RAM: 3508.57 MB
Total Virtual: 14741.96 MB
Available Virtual: 9854.06 MB
 
==================== Drives ================================
 
Drive c: () (Fixed) (Total:671.86 GB) (Free:287.84 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (RECOVERY) (Fixed) (Total:24.66 GB) (Free:2.96 GB) NTFS ==>[system with boot components (obtained from drive)]
 
\\?\Volume{fe0903f6-9c02-4d3f-9b77-248704208238}\ (WINRE) (Fixed) (Total:0.39 GB) (Free:0.16 GB) NTFS
\\?\Volume{f6c84ca1-cdde-4d0d-8ed0-00f5c3a1150d}\ () (Fixed) (Total:0.9 GB) (Free:0.29 GB) NTFS
\\?\Volume{d83f9260-540d-4b78-a785-ae0d21ae965e}\ () (Fixed) (Total:0.44 GB) (Free:0.42 GB) NTFS
\\?\Volume{35bee8d3-4e83-46e9-b258-25d25329568b}\ () (Fixed) (Total:0.25 GB) (Free:0.15 GB) FAT32
 
==================== MBR & Partition Table ====================
 
==========================================================
Disk: 0 (Size: 698.6 GB) (Disk ID: 5FCA6C40)
 
Partition: GPT.
 
==================== End of Addition.txt =======================
 
 
==================== End of FRST.txt ========================

 

Things don't look to bad here, Windows Defender does point out that you have a HackTool:Win32/Keygen
It doesn't tell me what it's used for other then you have downloaded something illegally, maybe.

(uTorrent). I advise you avoid P2P file sharing programmes; they are a security risk which can make your computer susceptible to malware. File sharing networks are thoroughly infested with malware propagate via P2P file sharing networks, gaming, and underground sites. Users visiting such pages may see innocuous-looking banner ads containing code which can trigger pop-up ads and malicious Flash ads that install malware. The best way to reduce the risk of infection is to avoid these types of web sites and P2P programmes. Please read the following articles for more information.


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Start Farbar Recovery Scan Tool with Administrator privileges
(Right click on the FRST icon and select Run as administrator)

highlight on the text below and select Copy.
beginning with Start:: and finishing with End::
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Highlight the entire content of the quote box below and select Copy.

 

Start::
CloseProcesses:
CreateRestorePoint:
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No File]
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File
EmptyTemp:
C:\Windows\Temp\*.*
End::

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Start FRST (FRST64) with Administrator privileges
Press the Fix button. FRST will process the lines copied above from the clipboard.
When finished, a log file Fixlog.txt will pop up and saved in the same location the tool was ran from.

Please copy and paste its contents in your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~





Download and run AdwCleaner

Download AdwCleaner from here and save it to your desktop.

  • run AdwCleaner by clicking on Scan Now
  • when it has finished, leave everything that was found checked, (ticked), then click on Clean and Repair
  • if it asks to reboot, allow the reboot
  • on reboot, click on View Log File; please attach the content of the log to your next reply.

==================

Please post these 2 logs when finished.

Hi Juliet,

 

Thank you for your prompt response and here are the two logs you requested. I will read the links you provided regarding Utorrent. 

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 29-03-2020
Ran by [removed] (31-03-2020 09:34:57) Run:1
Running from C:\Users\[removed]\Desktop
[removed]
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CloseProcesses:
CreateRestorePoint:
FF HKLM\SOFTWARE\Policies\Mozilla\Firefox: Restriction <==== ATTENTION
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [No File]
ContextMenuHandlers1: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File
ContextMenuHandlers2: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => -> No File
EmptyTemp:
C:\Windows\Temp\*.*
 
*****************
 
Processes closed successfully.
Restore point was successfully created.
HKLM\SOFTWARE\Policies\Mozilla => removed successfully
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => value restored successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\"DefaultScope"="{0633EE93-D776-472f-A0FF-E1416B8B2E3A}" => value restored successfully
HKLM\Software\Wow6432Node\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0 => removed successfully
HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers\CLVDShellExt => removed successfully
HKLM\Software\Classes\Drive\ShellEx\ContextMenuHandlers\CLVDShellExt => removed successfully
 
=========== "C:\Windows\Temp\*.*" ==========
 
C:\Windows\Temp\MpCmdRun.log => moved successfully
C:\Windows\Temp\MpSigStub.log => moved successfully
C:\Windows\Temp\MSI14c7d.LOG => moved successfully
C:\Windows\Temp\MSI1bcab.LOG => moved successfully
C:\Windows\Temp\MSI2ce53.LOG => moved successfully
C:\Windows\Temp\MSI2f72e.LOG => moved successfully
C:\Windows\Temp\MSI3b6f6.LOG => moved successfully
C:\Windows\Temp\MSI4a43c.LOG => moved successfully
C:\Windows\Temp\MSI68703.LOG => moved successfully
C:\Windows\Temp\MSI72664.LOG => moved successfully
C:\Windows\Temp\MSI8853f.LOG => moved successfully
C:\Windows\Temp\MSI8a9d4.LOG => moved successfully
C:\Windows\Temp\MSI8eedd.LOG => moved successfully
C:\Windows\Temp\MSI9b551.LOG => moved successfully
C:\Windows\Temp\MSIacbca.LOG => moved successfully
C:\Windows\Temp\MSIbe07f.LOG => moved successfully
C:\Windows\Temp\MSIce44b.LOG => moved successfully
C:\Windows\Temp\MSIe68ef.LOG => moved successfully
C:\Windows\Temp\MSIfa7e4.LOG => moved successfully
C:\Windows\Temp\SecureLineSetup_2020-03-29_16-16-22.log => moved successfully
C:\Windows\Temp\Setup Log 2020-03-29 #001.txt => moved successfully
 
========= End -> "C:\Windows\Temp\*.*" ========
 
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 11558912 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 10739610 B
Java, Flash, Steam htmlcache => 0 B
Windows/system/drivers => 1893603 B
Edge => 58458 B
Chrome => 194280912 B
Firefox => 32542762 B
Opera => 139989 B
 
Temp, IE cache, history, cookies, recent:
Default => 0 B
Users => 0 B
ProgramData => 0 B
Public => 0 B
systemprofile => 0 B
systemprofile32 => 0 B
LocalService => 13848 B
NetworkService => 16386 B
user name => 401316179 B
 
RecycleBin => 0 B
EmptyTemp: => 622.3 MB temporary data Removed.
 
================================
 
 
The system needed a reboot.
 
 
# ——————————-
# Malwarebytes AdwCleaner 8.0.3.0
# ——————————-
# Build:    03-03-2020
# Database: 2020-03-02.1 (Local)
# Support:  https://www.malwarebytes.com/support
#
# ——————————-
# Mode: Clean
# ——————————-
# Start:    03-31-2020
# Duration: 00:00:07
# OS:       Windows 10 Home
# Cleaned:  15
# Failed:   0
 
 
***** [ Services ] *****
 
No malicious services cleaned.
 
***** [ Folders ] *****
 
Deleted       C:\Users\Public\Documents\Downloaded Installers
Deleted       C:\Users\user name\AppData\Local\slimware utilities inc
 
***** [ Files ] *****
 
No malicious files cleaned.
 
***** [ DLL ] *****
 
No malicious DLLs cleaned.
 
***** [ WMI ] *****
 
No malicious WMI cleaned.
 
***** [ Shortcuts ] *****
 
No malicious shortcuts cleaned.
 
***** [ Tasks ] *****
 
No malicious tasks cleaned.
 
***** [ Registry ] *****
 
Deleted       HKCU\Software\Lavasoft\Web Companion
Deleted       HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com
Deleted       HKLM\Software\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Deleted       HKLM\Software\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Deleted       HKLM\Software\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
Deleted       HKLM\Software\Reimage
Deleted       HKLM\Software\Wow6432Node\Lavasoft\Web Companion
Deleted       HKLM\Software\Wow6432Node\\Classes\Interface\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}
Deleted       HKLM\Software\Wow6432Node\\Classes\Interface\{BD51A48E-EB5F-4454-8774-EF962DF64546}
Deleted       HKLM\Software\Wow6432Node\\Classes\TypeLib\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}
 
***** [ Chromium (and derivatives) ] *****
 
No malicious Chromium entries cleaned.
 
***** [ Chromium URLs ] *****
 
Deleted       ????
 
***** [ Firefox (and derivatives) ] *****
 
No malicious Firefox entries cleaned.
 
***** [ Firefox URLs ] *****
 
Deleted       Bing Default Search
Deleted       https://defaultsearch.co/homepage?hp=1&pId=BT171001&iDate=2019-12-2306:19:00&bName=&bitmask=0600
 
***** [ Hosts File Entries ] *****
 
No malicious hosts file entries cleaned.
 
***** [ Preinstalled Software ] *****
 
No Preinstalled Software cleaned.
 
 
*************************
 
[+] Delete Tracing Keys
[+] Reset Winsock
 
*************************
 
AdwCleaner[S00].txt - [2666 octets] - [31/03/2020 10:06:30]
 
########## EOF - C:\AdwCleaner\Logs\AdwCleaner[C00].txt ##########
 
==== End of Fixlog 09:47:41 ====

ESET Online Scanner

Download ESET Online Scanner and save it to your desktop.

  • Right-click on esetonlinescanner_enu.exe and select Run as Administrator.
  • When the tool opens, click Get Started.
  • Read and accept the license agreement.
  • At the Welcome to ESET Online Scanner window, click Get Started.
  • Select whether you would like to send anonymous data to ESET.
  • Note: if you see the "Welcome Back to ESET Online Scanner" screen, click Computer Scan > Full Scan.
  • Click on the Full Scan option.
  • Select Enable ESET to detect and remove potentially unwanted applications, then click Start scan.
  • ESET will now begin scanning your computer. This may take some time.
  • When the scan is finished and if threats have been detected, select Save scan log. Save it to your desktop as eset.txt. Click on Continue.
  • ESET Online Scanner may ask if you'd like to turn on the Periodic Scan feature. Click on Continue.
  • On the next screen, you can leave feedback about the program if you wish. Check the box for Delete application data on closing. If you left feedback, click Submit and continue. If not, Close without feedback.
  • Open the scan log on your desktop (eset.txt) and copy and paste its contents into your next reply.

—————–

How is the computer at the moment?

The computer is running smoother now, thank you for your assistance so far. The scan results are below

 

3/31/2020 21:48:54 PM
Files scanned: 549466
Detected files: 13
Cleaned files: 9
Total scan time 06:26:16
Scan status: Finished
C:\Program Files\Adware-Removal-Tool\ARTP3.exe MSIL/FakeTool.PS trojan cleaned by deleting
 
C:\Program Files\AVAST Software\Avast\setup\New_1401095d\aswOfferTool.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application error while deleting (Access denied)
 
C:\Program Files\AVAST Software\Avast\setup\aswOfferTool.exe Win32/Bundled.Toolbar.Google.D potentially unsafe application error while deleting (Access denied)
 
C:\Program Files\AVAST Software\Avast\setup\offertool_x64_ais-95d.vpx Win32/Bundled.Toolbar.Google.D potentially unsafe application error while deleting (Access denied)
 
C:\ProgramData\RogueKiller\quarantine\5FA20507710E1BFC.vir\AVG Driver Updater.exe a variant of Win32/UwS.SlimDrivers.A application cleaned by deleting
 
C:\Users\user name\AppData\Local\AVAST Software\Avast Driver Updater\Updates\hdd.exe a variant of Win32/Slimware.A potentially unwanted application cleaned by deleting
 
C:\Users\user name\AppData\Roaming\uTorrent\updates\3.5.5_45395.exe a variant of Win32/uTorrent.C potentially unwanted application cleaned by deleting
 
C:\Users\user name\AppData\Roaming\uTorrent\updates\3.5.5_45574.exe a variant of Win32/uTorrent.C potentially unwanted application cleaned by deleting
 
C:\Users\user name\AppData\Roaming\uTorrent\updates\3.5.5_45608.exe a variant of Win32/uTorrent.C potentially unwanted application cleaned by deleting
 
C:\Users\user name\AppData\Roaming\uTorrent\uTorrent.exe a variant of Win32/uTorrent.C potentially unwanted application cleaned by deleting
 
C:\Users\user name\Desktop\Misc\Office 2016\Office 2016\1click.cmd BAT/RiskWare.HackTool.WinActivator.A application cleaned by deleting
 
C:\Users\user name\Desktop\Misc\office.cmd BAT/RiskWare.HackTool.WinActivator.A application cleaned by deleting
 
Autostart locations Win32/Bundled.Toolbar.Google.D potentially unsafe application

Glad the computer is better.

You need to stay away from Hack tools and Keygens, one day things could  possibly be non-fixable or worse, everything about you would/can be stolen.

~~~~~~~~~~~~~~~~~~~~~~

I think we can remove tools and quarantine folders now.

Use this tool to remove quarantined items:

Please download KpRm by Kernel-panik and save to your Desktop.

  • Click on KpRm.exe to run the tool.

Vista/Windows 7/8/10 users right-click and select Run As Administrator.

  • Put a check mark next to these items:

- Delete tools

  • Click the "Run" button.
  • When the tool has finished, it will create and open a log report and delete itself.

Thank you for your assistance and will definitely keep your wise words in mind, also the second link you provided for the uTorrent/p2p took me to a account  suspended page. 

Thank you for your assistance and will definitely keep your wise words in mind, also the second link you provided for the uTorrent/p2p took me to a account  suspended page. 

Thank you for the heads up,  safe surfing.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI