Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 26-11-2017 Ran by Lorraine (administrator) on KITS-COMPUTER (26-11-2017 12:10:50) Running from C:\Users\Lorraine\Desktop Loaded Profiles: Lorraine & (Available Profiles: Lorraine) Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\ccsvchst.exe (Interactive Brands) C:\ProgramData\Interactive Brands\PDF Suite 2017 Manager\PDF Suite 2017\PDF Suite Manager.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (McAfee, Inc.) C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe (McAfee, Inc.) C:\Program Files\TrueKey\McTkSchedulerService.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\ccsvchst.exe (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe () C:\Users\Lorraine\AppData\Local\Amazon Music\Amazon Music Helper.exe (HP Inc.) C:\Program Files\HP\HP ENVY 4520 series\Bin\ScanToPCActivationApp.exe (Noteburner.com) C:\Program Files (x86)\NoteBurner\VTBurnerGUI.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VAIOTM\VTSvc.exe (HP Inc.) C:\Program Files\HP\HP ENVY 4520 series\Bin\HPNetworkCommunicatorCom.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VAIOTM\VTUsr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe () C:\Program Files (x86)\Sony\Keyboard Shortcuts\KeyboardShortcuts.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe () C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe (Lavasoft) C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe (Digital Delivery Networks, Inc.) C:\Program Files (x86)\DDNi\Oasis\VAIO Messenger.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [226672 2010-11-03] (Alps Electric Co., Ltd.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176952 2016-06-01] (Apple Inc.) HKLM-x32\...\Run: [NoteBurner] => C:\Program Files (x86)\NoteBurner\VTBurnerGUI.exe [5694792 2011-06-08] (Noteburner.com) Winlogon\Notify\igfxcui: C:\Windows\System32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-3240821568-1653635036-208495454-1005\...\Run: [Google Update] => C:\Users\Lorraine\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2017-11-16] (Google Inc.) HKU\S-1-5-21-3240821568-1653635036-208495454-1005\...\Run: [Amazon Music] => C:\Users\Lorraine\AppData\Local\Amazon Music\Amazon Music Helper.exe [3494376 2016-12-14] () HKU\S-1-5-21-3240821568-1653635036-208495454-1005\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [7680104 2017-11-26] (Lavasoft) HKU\S-1-5-21-3240821568-1653635036-208495454-1005\...\Run: [HP ENVY 4520 series (NET)] => C:\Program Files\HP\HP ENVY 4520 series\Bin\ScanToPCActivationApp.exe [3770504 2017-04-06] (HP Inc.) HKU\S-1-5-21-3240821568-1653635036-208495454-1005\...\Policies\Explorer: [HideSCAHealth] 1 HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147\...\Run: [Google Update] => C:\Users\Lorraine\AppData\Local\Google\Update\1.3.33.7\GoogleUpdateCore.exe [601680 2017-11-16] (Google Inc.) HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147\...\Run: [Amazon Music] => C:\Users\Lorraine\AppData\Local\Amazon Music\Amazon Music Helper.exe [3494376 2016-12-14] () HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147\...\Run: [Web Companion] => C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe [7680104 2017-11-26] (Lavasoft) HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147\...\Run: [HP ENVY 4520 series (NET)] => C:\Program Files\HP\HP ENVY 4520 series\Bin\ScanToPCActivationApp.exe [3770504 2017-04-06] (HP Inc.) HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147\...\Policies\Explorer: [HideSCAHealth] 1 Lsa: [Notification Packages] scecli C:\Program Files\TrueKey\McAfeeTrueKeyPasswordFilter Startup: C:\Users\Lorraine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2017-10-19] ShortcutTarget: Dropbox.lnk -> C:\Users\Lorraine\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12 Tcpip\..\Interfaces\{0BA8891A-38AC-4DD2-B432-8836DD878CBB}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12 Tcpip\..\Interfaces\{90C2DFB1-2AAB-4463-BDED-F724585427B0}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12 Internet Explorer: ================== HKU\S-1-5-21-3240821568-1653635036-208495454-1005\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://sony.msn.com HKU\S-1-5-21-3240821568-1653635036-208495454-1005\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://www.google.com/?gws_rd=ssl HKU\S-1-5-21-3240821568-1653635036-208495454-1005\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COSP&ptag=D080117-A9C56F9C6EA&form=CONMHP&conlogo=CT3335737 HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://sony.msn.com HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxps://www.google.com/?gws_rd=ssl HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com/?pc=COSP&ptag=D080117-A9C56F9C6EA&form=CONMHP&conlogo=CT3335737 SearchScopes: HKLM -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 -> DefaultScope {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406} URL = SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3240821568-1653635036-208495454-1005 -> DefaultScope {225C635E-5492-47A8-B23D-82876111F9CC} URL = hxxps://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-3240821568-1653635036-208495454-1005 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D080117-A9C56F9C6EA&form=CONBDF&conlogo=CT3335737&q={searchTerms} SearchScopes: HKU\S-1-5-21-3240821568-1653635036-208495454-1005 -> {225C635E-5492-47A8-B23D-82876111F9CC} URL = hxxps://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147 -> DefaultScope {225C635E-5492-47A8-B23D-82876111F9CC} URL = hxxps://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?pc=COSP&ptag=D080117-A9C56F9C6EA&form=CONBDF&conlogo=CT3335737&q={searchTerms} SearchScopes: HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147 -> {225C635E-5492-47A8-B23D-82876111F9CC} URL = hxxps://www.google.com/search?q={searchTerms} BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO-x32: MSS+ Identifier -> {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll [2013-02-05] (McAfee, Inc.) BHO-x32: True Key Helper -> {0F4B8786-5502-4803-8EBC-F652A1153BB6} -> C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-02-07] (Intel Security) BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2010-11-08] (CANON INC.) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\coIEPlg.dll [2014-11-28] (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\IPS\IPSBHO.DLL [2013-04-08] (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\ssv.dll [2015-03-14] (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\jp2ssv.dll [2015-03-14] (Oracle Corporation) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2010-11-08] (CANON INC.) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\coIEPlg.dll [2014-11-28] (Symantec Corporation) Toolbar: HKLM-x32 - True Key - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - C:\Program Files\Intel Security\True Key\MSIE\truekey_ie.dll [2017-02-07] (Intel Security) Toolbar: HKU\S-1-5-21-3240821568-1653635036-208495454-1005 -> No Name - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - No File Toolbar: HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147 -> No Name - {4BAAC1B8-0800-42C9-8FA6-08B211F356B8} - No File FireFox: ======== FF ProfilePath: C:\Users\Lorraine\AppData\Roaming\Mozilla\Firefox\Profiles\uv4j5qfq.default [2017-11-26] FF Homepage: Mozilla\Firefox\Profiles\uv4j5qfq.default -> hxxps://www.google.com/ FF NewTab: Mozilla\Firefox\Profiles\uv4j5qfq.default -> hxxp://www.bing.com/?pc=COSP&ptag=D080117-A9C56F9C6EA&form=CONMHP&conlogo=CT3335737 FF NetworkProxy: Mozilla\Firefox\Profiles\uv4j5qfq.default -> type", 4 FF Extension: (AmazonSmile 1Button for Firefox) - C:\Users\Lorraine\AppData\Roaming\Mozilla\Firefox\Profiles\uv4j5qfq.default\Extensions\smile1Button@amazon.com.xpi [2016-04-27] [Lagacy] FF Extension: (Adblock Plus) - C:\Users\Lorraine\AppData\Roaming\Mozilla\Firefox\Profiles\uv4j5qfq.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2017-11-12] FF Extension: (Disable Media WMF NV12 format) - C:\Users\Lorraine\AppData\Roaming\Mozilla\Firefox\Profiles\uv4j5qfq.default\features\{7a8676d9-5f1d-447b-80e4-a33677c187a8}\disable-media-wmf-nv12@mozilla.org.xpi [2017-11-21] [Lagacy] FF SearchPlugin: C:\Users\Lorraine\AppData\Roaming\Mozilla\Firefox\Profiles\uv4j5qfq.default\searchplugins\bing-lavasoft.xml [2017-11-16] FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\coFFPlgn FF Extension: (Norton Toolbar) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\coFFPlgn [2017-11-26] [Lagacy] [not signed] FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\IPSFFPlgn FF Extension: (Norton Vulnerability Protection) - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\IPSFFPlgn [2015-09-21] [Lagacy] [not signed] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_170.dll [2017-10-21] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_170.dll [2017-10-21] () FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-12-18] () FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2010-04-14] (CANON INC.) FF Plugin-x32: @java.com/DTPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\dtplugin\npDeployJava1.dll [2015-03-14] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.40.2 -> C:\Program Files (x86)\Java\jre1.8.0_40\bin\plugin2\npjp2.dll [2015-03-14] (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll [2013-02-05] (McAfee, Inc.) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-09-23] (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-02-17] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-11-04] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-3240821568-1653635036-208495454-1005: @tools.google.com/Google Update;version=3 -> C:\Users\Lorraine\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.) FF Plugin HKU\S-1-5-21-3240821568-1653635036-208495454-1005: @tools.google.com/Google Update;version=9 -> C:\Users\Lorraine\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.) FF Plugin HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147: @sony.com/Some -> C:\Program Files (x86)\Sony\Bloggie Software\npsome.dll [No File] FF Plugin HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147: @tools.google.com/Google Update;version=3 -> C:\Users\Lorraine\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.) FF Plugin HKU\S-1-5-21-3240821568-1653635036-208495454-1005-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-11262017115515147: @tools.google.com/Google Update;version=9 -> C:\Users\Lorraine\AppData\Local\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-16] (Google Inc.) Chrome: ======= CHR DefaultProfile: Default CHR StartupUrls: Default -> "hxxp://www.google.com/" CHR Profile: C:\Users\Lorraine\AppData\Local\Google\Chrome\User Data\Default [2017-11-26] CHR Extension: (Norton Security Toolbar) - C:\Users\Lorraine\AppData\Local\Google\Chrome\User Data\Default\Extensions\bejnhdlplbjhffionohbdnpcbobfejcc [2015-09-21] CHR Extension: (Norton Identity Safe) - C:\Users\Lorraine\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2015-09-21] CHR Extension: (Chrome Web Store Payments) - C:\Users\Lorraine\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-19] CHR Extension: (Chrome Media Router) - C:\Users\Lorraine\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-22] CHR HKLM\...\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\Exts\Chrome.crx [2014-12-11] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [ngpampappnmepgilojfohadhhmbhlaek] - C:\Program Files (x86)\Internet Download Manager\IDMGCExt.crx CHR HKLM-x32\...\Chrome\Extension: [bejnhdlplbjhffionohbdnpcbobfejcc] - C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\Exts\Chrome.crx [2014-12-11] CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx StartMenuInternet: Google Chrome - chrome.exe StartMenuInternet: Google Chrome.OW4SEEFYUCK62RIVQQAD3IP7MU - C:\Users\Lorraine\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S4 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes) S4 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) S4 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-01-05] () R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.6.0.27\ccSvcHst.exe [144368 2013-05-20] (Symantec Corporation) R2 PDF Suite 2017 Manager; C:\ProgramData\Interactive Brands\PDF Suite 2017 Manager\PDF Suite 2017\PDF Suite Manager.exe [986496 2016-07-12] (Interactive Brands) R2 TrueKey; C:\Program Files\TrueKey\McAfee.TrueKey.Service.exe [996824 2017-02-06] (McAfee, Inc.) R2 TrueKeyScheduler; C:\Program Files\TrueKey\McTkSchedulerService.exe [16248 2017-02-06] (McAfee, Inc.) S3 TrueKeyServiceHelper; C:\Program Files\TrueKey\McAfee.TrueKey.ServiceHelper.exe [86864 2017-02-06] (McAfee, Inc.) S4 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) S4 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [887000 2011-01-20] (Sony Corporation) R3 VUAgent; C:\Program Files\Sony\VAIO Update\vuagent.exe [1656600 2016-03-31] (Sony Corporation) R2 WCAssistantService; C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe [25704 2017-11-26] () R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) S2 InstallerService; C:\Program Files\TrueKey\Mcafee.TrueKey.InstallerService.exe -originalversion 4.4.127.0 [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R1 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\BASHDefs\20130322.001\BHDrvx64.sys [1387608 2013-03-21] (Symantec Corporation) R1 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1406000.01B\ccSetx64.sys [169048 2013-04-15] (Symantec Corporation) R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-01-13] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-01-13] (Symantec Corporation) R1 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\IPSDefs\20130412.001\IDSvia64.sys [513184 2013-01-13] (Symantec Corporation) R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [252232 2017-11-26] (Malwarebytes) S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130413.016\ENG64.SYS [126192 2013-01-16] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.2.0.19\Definitions\VirusDefs\20130413.016\EX64.SYS [2087664 2013-01-16] (Symantec Corporation) R0 ntcdrdrv; C:\Windows\System32\DRIVERS\ntcdrdrv.sys [25680 2011-01-06] (NoteBurn Software) U5 SDBus; C:\Windows\System32\Drivers\SDBus.sys [109056 2010-11-20] (Microsoft Corporation) S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1406000.01B\SRTSP64.SYS [796760 2013-05-15] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\NISx64\1406000.01B\SRTSPX64.SYS [36952 2013-03-04] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\NISx64\1406000.01B\SYMDS64.SYS [493656 2013-05-20] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\NISx64\1406000.01B\SYMEFA64.SYS [1139800 2013-05-22] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-18] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\NISx64\1406000.01B\Ironx64.SYS [224416 2013-03-04] (Symantec Corporation) R1 SymNetS; C:\Windows\System32\Drivers\NISx64\1406000.01B\SYMNETS.SYS [433752 2013-04-24] (Symantec Corporation) S3 semav6msr64; \??\C:\Windows\system32\drivers\semav6msr64.sys [X] S3 semav6thermal64ro; \??\C:\Windows\system32\drivers\semav6thermal64ro.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-11-26 12:10 - 2017-11-26 12:13 - 000024431 _____ C:\Users\Lorraine\Desktop\FRST.txt 2017-11-26 12:09 - 2017-11-26 12:09 - 002392576 _____ (Farbar) C:\Users\Lorraine\Desktop\FRST64.exe 2017-11-26 12:04 - 2017-11-26 12:04 - 000067240 _____ C:\Windows\system32\GDIPFONTCACHEV1.DAT 2017-11-26 11:44 - 2017-11-26 11:44 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-11-20 12:41 - 2017-10-18 00:31 - 000395976 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-11-20 12:41 - 2017-10-17 23:45 - 000347336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-11-20 12:41 - 2017-10-17 19:06 - 000344064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2017-11-20 12:41 - 2017-10-17 19:06 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2017-11-20 12:41 - 2017-10-17 19:06 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2017-11-20 12:41 - 2017-10-17 19:06 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2017-11-20 12:41 - 2017-10-17 19:06 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2017-11-20 12:41 - 2017-10-17 19:06 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2017-11-20 12:41 - 2017-10-17 19:06 - 000007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2017-11-20 12:41 - 2017-10-16 16:07 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2017-11-20 12:41 - 2017-10-16 15:34 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-11-20 12:41 - 2017-10-16 14:55 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll 2017-11-20 12:41 - 2017-10-14 01:38 - 025731584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-11-20 12:41 - 2017-10-14 01:23 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-11-20 12:41 - 2017-10-14 01:23 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-11-20 12:41 - 2017-10-14 01:13 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-11-20 12:41 - 2017-10-14 01:12 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-11-20 12:41 - 2017-10-14 01:11 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-11-20 12:41 - 2017-10-14 01:11 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-11-20 12:41 - 2017-10-14 01:11 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-11-20 12:41 - 2017-10-14 01:11 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-11-20 12:41 - 2017-10-14 01:09 - 005979648 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-11-20 12:41 - 2017-10-14 01:05 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-11-20 12:41 - 2017-10-14 01:04 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-11-20 12:41 - 2017-10-14 01:02 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-11-20 12:41 - 2017-10-14 01:01 - 000816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-11-20 12:41 - 2017-10-14 01:01 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-11-20 12:41 - 2017-10-14 01:01 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-11-20 12:41 - 2017-10-14 01:00 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-11-20 12:41 - 2017-10-14 00:55 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-11-20 12:41 - 2017-10-14 00:53 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-11-20 12:41 - 2017-10-14 00:47 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2017-11-20 12:41 - 2017-10-14 00:47 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-11-20 12:41 - 2017-10-14 00:46 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-11-20 12:41 - 2017-10-14 00:43 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-11-20 12:41 - 2017-10-14 00:43 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-11-20 12:41 - 2017-10-14 00:41 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-11-20 12:41 - 2017-10-14 00:40 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-11-20 12:41 - 2017-10-14 00:31 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-11-20 12:41 - 2017-10-14 00:30 - 015266816 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-11-20 12:41 - 2017-10-14 00:30 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-11-20 12:41 - 2017-10-14 00:29 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-11-20 12:41 - 2017-10-14 00:28 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-11-20 12:41 - 2017-10-14 00:27 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-11-20 12:41 - 2017-10-14 00:21 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-11-20 12:41 - 2017-10-14 00:14 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-11-20 12:41 - 2017-10-14 00:09 - 001544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-11-20 12:41 - 2017-10-14 00:03 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-11-20 12:41 - 2017-10-13 23:58 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-11-20 12:41 - 2017-10-13 23:53 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-11-20 12:41 - 2017-10-13 23:53 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-11-20 12:41 - 2017-10-13 23:52 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-11-20 12:41 - 2017-10-13 23:52 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-11-20 12:41 - 2017-10-13 23:51 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-11-20 12:41 - 2017-10-13 23:50 - 002293760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-11-20 12:41 - 2017-10-13 23:47 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-11-20 12:41 - 2017-10-13 23:47 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-11-20 12:41 - 2017-10-13 23:46 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-11-20 12:41 - 2017-10-13 23:45 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-11-20 12:41 - 2017-10-13 23:45 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-11-20 12:41 - 2017-10-13 23:45 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-11-20 12:41 - 2017-10-13 23:38 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-11-20 12:41 - 2017-10-13 23:35 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2017-11-20 12:41 - 2017-10-13 23:35 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-11-20 12:41 - 2017-10-13 23:34 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-11-20 12:41 - 2017-10-13 23:33 - 004542464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-11-20 12:41 - 2017-10-13 23:33 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-11-20 12:41 - 2017-10-13 23:32 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-11-20 12:41 - 2017-10-13 23:31 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-11-20 12:41 - 2017-10-13 23:30 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-11-20 12:41 - 2017-10-13 23:28 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-11-20 12:41 - 2017-10-13 23:25 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-11-20 12:41 - 2017-10-13 23:24 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-11-20 12:41 - 2017-10-13 23:23 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-11-20 12:41 - 2017-10-13 23:23 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-11-20 12:41 - 2017-10-13 23:10 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-11-20 12:41 - 2017-10-13 23:07 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-11-20 12:41 - 2017-10-13 23:04 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-11-20 12:41 - 2017-10-11 17:58 - 000382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 014635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 012574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2017-11-20 12:41 - 2017-10-11 17:55 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000151552 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2017-11-20 12:41 - 2017-10-11 17:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2017-11-20 12:41 - 2017-10-11 17:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2017-11-20 12:41 - 2017-10-11 17:40 - 000308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2017-11-20 12:41 - 2017-10-11 17:39 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2017-11-20 12:41 - 2017-10-11 17:38 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2017-11-20 12:41 - 2017-10-11 17:38 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2017-11-20 12:41 - 2017-10-11 17:37 - 012574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2017-11-20 12:41 - 2017-10-11 17:37 - 011410944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 000111104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 000070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2017-11-20 12:41 - 2017-10-11 17:37 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2017-11-20 12:41 - 2017-10-11 17:26 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2017-11-20 12:41 - 2017-10-11 17:26 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2017-11-20 12:41 - 2017-10-11 17:25 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2017-11-20 12:41 - 2017-10-11 17:25 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2017-11-20 12:41 - 2017-10-11 17:24 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2017-11-20 12:41 - 2017-10-11 17:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2017-11-20 12:41 - 2017-10-11 17:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2017-11-20 12:41 - 2017-10-11 17:20 - 000113152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\luafv.sys 2017-11-20 12:41 - 2017-10-11 17:16 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000995272 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2017-11-20 12:41 - 2017-09-07 06:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2017-11-16 07:21 - 2017-10-17 19:34 - 000134376 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2017-11-16 07:21 - 2017-10-17 19:30 - 000605184 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-11-16 07:21 - 2017-10-15 15:04 - 000407392 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2017-11-16 07:21 - 2017-10-04 06:04 - 002023936 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2017-11-16 07:21 - 2017-10-04 06:04 - 001570304 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-11-16 07:21 - 2017-10-04 06:04 - 000670208 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2017-11-16 07:21 - 2017-10-04 06:04 - 000603648 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2017-11-16 07:21 - 2017-10-04 06:04 - 000370688 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2017-11-16 07:21 - 2017-10-04 06:04 - 000241664 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2017-11-16 07:21 - 2017-10-04 06:04 - 000181760 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-11-16 07:15 - 2017-11-16 07:15 - 000000244 _____ C:\Prefs.js 2017-11-10 19:11 - 2017-11-10 19:15 - 000000000 ____D C:\8ea7f0c85e4f4733eec901342a628c 2017-10-29 09:51 - 2017-10-29 09:51 - 000415775 _____ C:\Users\Lorraine\Downloads\hoa letter2.pdf 2017-10-29 09:51 - 2017-10-29 09:51 - 000415775 _____ C:\Users\Lorraine\Downloads\hoa letter2(1).pdf 2017-10-29 09:49 - 2017-10-29 09:49 - 000415775 _____ C:\Users\Lorraine\Documents\hoa letter2.pdf 2017-10-29 09:41 - 2017-10-29 09:41 - 000003580 _____ C:\Windows\System32\Tasks\HPCustParticipation HP ENVY 4520 series 2017-10-29 09:41 - 2017-10-29 09:41 - 000001991 _____ C:\Users\Public\Desktop\HP Photo Creations.lnk 2017-10-29 09:41 - 2017-10-29 09:41 - 000000000 ____D C:\ProgramData\Visan 2017-10-29 09:41 - 2017-10-29 09:41 - 000000000 ____D C:\ProgramData\HP Photo Creations 2017-10-29 09:41 - 2017-10-29 09:41 - 000000000 ____D C:\Program Files (x86)\HP Photo Creations 2017-10-29 09:41 - 2017-04-06 22:23 - 000840328 ____N (HP Inc.) C:\Windows\system32\HPDiscoPMD711.dll 2017-10-29 09:40 - 2017-10-29 09:41 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP 2017-10-29 09:40 - 2017-10-29 09:41 - 000000000 ____D C:\Program Files (x86)\HP 2017-10-29 09:40 - 2017-10-29 09:40 - 000002176 _____ C:\Users\Public\Desktop\HP ENVY 4520 series.lnk 2017-10-29 09:40 - 2017-10-29 09:40 - 000001138 _____ C:\Users\Public\Desktop\Shop for Supplies - HP ENVY 4520 series.lnk 2017-10-29 09:39 - 2017-10-29 09:40 - 000000000 ____D C:\ProgramData\HP 2017-10-29 09:39 - 2017-10-29 09:39 - 000000000 ____D C:\Program Files\HP 2017-10-29 09:38 - 2017-10-29 09:42 - 000000000 ____D C:\Users\Lorraine\AppData\Local\HP 2017-10-29 09:31 - 2017-10-29 09:36 - 156129840 _____ C:\Users\Lorraine\Downloads\EN4520_Full_WebPack_1122.exe 2017-10-29 09:22 - 2017-10-29 09:22 - 000000561 _____ C:\Users\Lorraine\Desktop\moms email.txt ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-11-26 12:10 - 2015-09-18 13:11 - 000000000 ____D C:\FRST 2017-11-26 12:10 - 2009-07-13 21:45 - 000036576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-11-26 12:10 - 2009-07-13 21:45 - 000036576 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-11-26 12:09 - 2017-04-11 16:32 - 000103936 ___SH C:\Users\Lorraine\Desktop\Thumbs.db 2017-11-26 12:04 - 2016-11-19 16:47 - 000000000 ____D C:\Users\Lorraine\AppData\LocalLow\Mozilla 2017-11-26 12:04 - 2015-07-31 12:33 - 000000000 ____D C:\Windows\System32\Tasks\Remediation 2017-11-26 12:03 - 2012-01-04 08:24 - 000000000 ____D C:\Program Files (x86)\Sony 2017-11-26 12:02 - 2015-09-30 17:02 - 000067240 _____ C:\Users\Lorraine\AppData\Local\GDIPFONTCACHEV1.DAT 2017-11-26 11:56 - 2009-07-13 20:20 - 000000000 ____D C:\Windows\inf 2017-11-26 11:55 - 2012-06-02 07:49 - 000000000 ____D C:\Users\Lorraine\AppData\Local\CrashDumps 2017-11-26 11:53 - 2017-10-21 20:07 - 000252232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys 2017-11-26 11:51 - 2016-07-12 19:20 - 000000000 ____D C:\ProgramData\NoteBurner 2017-11-26 11:50 - 2009-07-13 22:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-11-26 11:44 - 2017-10-21 20:07 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-11-26 11:41 - 2012-01-11 15:25 - 000003958 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{3B70E440-F19E-41A1-BC51-AB275B5CC28E} 2017-11-22 09:35 - 2009-07-13 22:09 - 000000000 ____D C:\Windows\System32\Tasks\WPD 2017-11-22 09:35 - 2009-07-13 21:57 - 000001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2017-11-22 09:34 - 2009-07-13 21:45 - 000300184 _____ C:\Windows\system32\FNTCACHE.DAT 2017-11-20 14:55 - 2012-05-06 23:57 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2017-11-20 14:54 - 2015-09-22 16:57 - 000000000 ____D C:\Windows\system32\appraiser 2017-11-20 12:50 - 2012-05-29 21:27 - 000002408 _____ C:\Users\Lorraine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-11-20 12:31 - 2016-11-19 11:04 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox 2017-11-20 12:31 - 2012-01-11 15:28 - 000000000 ____D C:\Users\Lorraine\AppData\Roaming\Mozilla 2017-11-16 07:13 - 2015-11-01 16:41 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task 2017-11-16 07:11 - 2016-10-27 20:12 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk 2017-11-16 06:55 - 2016-12-16 15:35 - 000003240 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3240821568-1653635036-208495454-1005Core1d1ea937625a875 2017-11-16 06:55 - 2012-05-29 21:27 - 000003512 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3240821568-1653635036-208495454-1005UA 2017-11-02 14:25 - 2017-10-19 17:51 - 000000000 ____D C:\ProgramData\H2O 2017-11-02 14:25 - 2015-03-12 17:01 - 000000000 ____D C:\Users\Lorraine\AppData\Roaming\Dropbox 2017-10-29 09:00 - 2013-03-16 14:35 - 000000000 ___RD C:\Users\Lorraine\Documents\Scanned Documents ==================== Files in the root of some directories ======= 2014-03-20 09:10 - 2014-07-20 17:02 - 000000111 _____ () C:\Users\Lorraine\AppData\Roaming\WB.CFG 2017-10-21 20:04 - 2017-10-21 20:04 - 000007606 _____ () C:\Users\Lorraine\AppData\Local\Resmon.ResmonCfg Some files in TEMP: ==================== 2017-11-26 12:04 - 2017-11-26 12:04 - 000937664 _____ (adaware) C:\Users\Lorraine\AppData\Local\Temp\WCU008_FF.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-11-20 13:18 ==================== End of FRST.txt ============================