Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Could use Help with a fixlist as soon as possible [Closed]


  • This topic is locked This topic is locked

#1
mistywjd

mistywjd

    Member

  • Member
  • PipPip
  • 12 posts

Ive been having trouble with my laptop since my daughter accidently downloaded some Maleware. Ive tried to get it all out of my system but clearly its not all gone. From what I could tell it was the following programs: ShopperZ, YTDownloader, Flashbeat, PCCleanerPro, Wordsurfer

 

I manually deleted most of the files and my computer seemed better however last week internet explorer stopped working and the error code says something about using a proxy server. ive also noticed a few digital certificates that clearly don't belong and aren't legit. The most recent scan from Windows Defender quarantined dnsapi.dll and i am stuck on what to do from here.

 

Also, ive tried to run system file cleaner and it always ends with "found corrupt files, unable to fix".

 

Ive pasted my FRST log and i believe i am in need of a fixlist now? i was trying to figure out how to create my own because I am leery about posting this info but it seems to complex. Could someone verify that no one can use this information to make my system worse?  any help is greatly appreciated as i have much work to do this weekend and cant do it on a laptop that isn't secure and safe.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:08-10-2015
Ran by Wendy (administrator) on NOTEBOOK (09-10-2015 23:45:37)
Running from C:\Users\Wendy\Desktop
Loaded Profiles: Wendy (Available Profiles: Wendy)
Platform: Windows 10 Home (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(AVerMedia TECHNOLOGIES, Inc.) C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
() C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.10.5.0_x64__8wekyb3d8bbwe\WinStore.Mobile.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6306.42251.0_x64__8wekyb3d8bbwe\HxMail.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6306.42251.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe
(Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
 

==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-23] (Acer Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3935912 2015-08-03] (Synaptics Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340336 2010-09-27] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-09-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-09-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-02-18] (CyberLink Corp.)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [79192 2011-02-18] (Research In Motion Limited)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [InstaLAN] => C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe [1885088 2012-02-23] (Affinegy, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
HKLM-x32\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [ComcastAntispyClient] => C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe [1589208 2009-08-19] ()
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [KSS] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202080 2014-06-15] (Kaspersky Lab ZAO)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\RunOnce: [Uninstall C:\Users\Wendy\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Wendy\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64"
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [805888 2015-07-10] (Microsoft Corporation)
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => No File
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => No File
Startup: C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2012-08-02]
ShortcutTarget: Dropbox.lnk -> C:\Users\Wendy\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2014-04-05]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyServer: [HKLM] => 127.0.0.1:9091
ProxyServer: [HKLM-x32] => 127.0.0.1:9091
AutoConfigURL: [HKLM] => 127.0.0.1:9091
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{5b4fc3c7-a4fe-466a-ad1a-8982deeffde7}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{ec165e47-7983-45dc-b201-36594d8a9bc9}: [DhcpNameServer] 192.168.2.1
 
Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237268288&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237273679&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237285619&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
URLSearchHook: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 - (No Name) - {0633EE93-D776-472f-A0FF-E1416B8B2E3D} - No File
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL =
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 -> {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL =
SearchScopes: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 -> {D62E54FD-024A-4A46-BB39-0AEECC058C51} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-08-04] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-24] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-11] (Microsoft Corporation)
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} ->  No File
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-25] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-25] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-24] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-03-03] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2011-05-26] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\7\NP_wtapp.dll [2013-12-27] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
 
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AffinegyService; C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe [563104 2012-02-23] (Affinegy, Inc.)
S4 AntiSpywareService; C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [616408 2009-06-17] ()
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 AVerRECentral; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe [373248 2014-01-16] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2774104 2015-09-11] (Microsoft Corporation)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2013-12-16] (WildTangent)
S3 ITMRTSVC; C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe [283912 2007-09-26] (CA, Inc.)
R2 KSS; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202080 2014-06-15] (Kaspersky Lab ZAO)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-03] (Microsoft Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2015-08-03] (Synaptics Incorporated)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-03] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-03] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S4 BrsHelper; C:\PROGRA~2\YTDOWN~1\BROWSE~2.EXE [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-20] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-03] (Microsoft Corporation)
R3 RimVSerPort; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
S1 rncmaqih; C:\WINDOWS\system32\drivers\rncmaqih.sys [55168 2015-10-06] (Microsoft Corporation)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2015-08-03] (Synaptics Incorporated)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S1 nqvxuyue; \??\C:\WINDOWS\system32\drivers\nqvxuyue.sys [X]
S2 sbmntr; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 

==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-10-09 23:13 - 2015-10-09 23:13 - 00016148 _____ C:\WINDOWS\system32\NOTEBOOK_Wendy_HistoryPrediction.bin
2015-10-09 22:37 - 2015-10-09 22:37 - 00000000 ____D C:\Users\Wendy\Downloads\FRST-OlderVersion
2015-10-08 06:09 - 2015-10-08 06:09 - 00159298 _____ C:\Users\Wendy\Desktop\Shortcut.txt
2015-10-08 06:07 - 2015-10-09 21:09 - 00053875 _____ C:\Users\Wendy\Desktop\Addition.txt
2015-10-08 06:02 - 2015-10-09 23:45 - 00023801 _____ C:\Users\Wendy\Desktop\FRST.txt
2015-10-08 06:01 - 2015-10-08 06:01 - 02870984 _____ (ESET) C:\Users\Wendy\Desktop\esetsmartinstaller_enu.exe
2015-10-08 05:59 - 2015-10-09 23:45 - 00000000 ____D C:\FRST
2015-10-08 05:59 - 2015-10-09 22:37 - 02194944 _____ (Farbar) C:\Users\Wendy\Desktop\FRST64.exe
2015-10-06 22:00 - 2015-10-06 22:00 - 00055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rncmaqih.sys
2015-10-06 20:15 - 2015-10-06 20:15 - 00000000 ___HD C:\OneDriveTemp
2015-10-05 00:08 - 2015-10-05 00:08 - 00000017 _____ C:\Users\Wendy\AppData\Local\resmon.resmoncfg
2015-10-04 13:49 - 2015-10-04 14:03 - 2421989376 _____ C:\Users\Wendy\Downloads\O365HomePremRetail.img
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v4.5 Classic
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v4.5
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v2.0
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Local\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Local\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Local\Adobe
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v4.5\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v4.5 Classic\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v2.0\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 __RSD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 __RSD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\Classic .NET AppPool
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0 Classic
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Macromedia
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Intel Corporation
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\InstallShield
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Windows Live
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Downloaded Installations
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Macromedia
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Intel Corporation
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\InstallShield
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Local\Windows Live
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Local\Adobe
2015-10-04 13:30 - 2011-04-06 16:20 - 00057560 _____ C:\Users\Classic .NET AppPool\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:30 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v2.0 Classic\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:29 - 2015-10-04 13:29 - 00000000 ____D C:\Program Files\Windows Identity Foundation
2015-10-04 12:31 - 2015-10-04 12:31 - 00000000 ____D C:\Users\Wendy\AppData\Local\Google
2015-10-04 11:36 - 2015-10-04 11:36 - 00997927 _____ C:\Users\Wendy\Downloads\O15CTRRemove.diagcab
2015-10-03 22:22 - 2015-10-03 22:22 - 00000000 ____D C:\Program Files\DisplayLink Graphics
2015-10-03 22:20 - 2015-10-05 22:10 - 00000000 ____D C:\Program Files\DisplayLink Core Software
2015-10-03 22:20 - 2015-10-03 22:21 - 00002930 _____ C:\WINDOWS\system32\MsiExec.log
2015-10-03 21:02 - 2015-10-03 21:02 - 00000000 ____D C:\$SysReset
2015-10-03 19:20 - 2015-10-03 19:20 - 00038563 _____ C:\Users\Wendy\Downloads\cssemerg69697.diagcab
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files\Microsoft Security Client
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files (x86)\System Cleaner Pro
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files (x86)\Itibiti Soft Phone
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files (x86)\Broadcom
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\be8106b9bc95323fd268ba6235ad69
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\bd9118d39e1f207ee9cd6dcd0939
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\b9c13b78d128895b6e52
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\776e24d3f6aba141bb9c83b3fe63ae77
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\65b66254bc6a4f7c7497ac9d8307
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\4f4fa18d4dd8f99f0ea6a6420281251a
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\419a2caadd4290847864
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\318cab8197d210aa5c5e
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\3089b6a24ef724d145
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\04bf7963418bedcfdde09dca48
2015-09-20 18:39 - 2015-09-20 18:39 - 00001040 _____ C:\Users\Wendy\Desktop\9-20-15.txt
2015-09-17 18:55 - 2015-09-17 18:55 - 00003780 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0e826fa18e252
2015-09-13 15:51 - 2015-09-01 21:20 - 00077400 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-09-13 15:51 - 2015-09-01 20:25 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-09-13 15:51 - 2015-09-01 20:25 - 01382912 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-09-13 15:51 - 2015-08-27 02:36 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-13 15:51 - 2015-08-27 02:32 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-13 15:51 - 2015-08-27 02:04 - 21874688 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-09-13 15:51 - 2015-08-27 01:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-13 15:51 - 2015-08-27 01:55 - 24594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-09-13 15:51 - 2015-08-27 01:54 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-13 15:51 - 2015-08-27 01:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-13 15:51 - 2015-08-27 01:51 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-13 15:51 - 2015-08-27 01:51 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-13 15:51 - 2015-08-27 01:49 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-13 15:51 - 2015-08-27 01:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-13 15:51 - 2015-08-27 01:43 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-13 15:51 - 2015-08-27 01:43 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-09-13 15:51 - 2015-08-27 01:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-13 15:51 - 2015-08-27 01:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-13 15:51 - 2015-08-27 01:23 - 19324416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-09-13 15:51 - 2015-08-27 01:23 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-13 15:51 - 2015-08-27 01:16 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-09-13 15:51 - 2015-08-27 01:16 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-13 15:51 - 2015-08-27 01:16 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-13 15:51 - 2015-08-27 01:12 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-13 15:51 - 2015-08-27 01:12 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-13 15:51 - 2015-08-27 01:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-13 15:51 - 2015-08-27 01:11 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-13 15:51 - 2015-08-27 01:09 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-13 15:51 - 2015-08-27 01:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2015-09-09 01:46 - 2015-09-09 01:46 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-10-09 23:29 - 2012-06-17 10:30 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-09 23:09 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-09 23:06 - 2015-07-10 08:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-09 23:00 - 2013-02-21 22:12 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-09 20:11 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-09 20:09 - 2015-08-03 17:35 - 01006528 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-09 20:08 - 2011-12-25 20:30 - 00004154 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896}
2015-10-08 19:00 - 2015-09-05 18:05 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0e826fa18e252.job
2015-10-08 14:55 - 2013-02-21 22:12 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-07 22:44 - 2014-03-03 18:27 - 00000000 ____D C:\Users\Wendy\OneDrive
2015-10-06 20:16 - 2011-10-08 22:42 - 00000000 ____D C:\ProgramData\clear.fi
2015-10-06 20:15 - 2015-01-25 17:58 - 00000000 ___RD C:\Users\Wendy\iCloudDrive
2015-10-06 10:38 - 2015-07-10 06:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-06 10:29 - 2015-08-03 17:37 - 00000000 ____D C:\Users\Wendy
2015-10-06 10:27 - 2015-07-10 08:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 __RSD C:\WINDOWS\Media
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\system32\Nui
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system\Speech
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\IME
2015-10-06 10:20 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\rescache
2015-10-06 10:20 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-10-06 10:20 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\servicing
2015-10-06 10:20 - 2013-03-06 21:38 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-10-06 10:19 - 2015-08-03 18:04 - 00000000 ____D C:\Users\Wendy\AppData\Local\Packages
2015-10-06 10:19 - 2015-08-03 17:37 - 00000000 ___RD C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-06 10:19 - 2011-10-08 22:16 - 00000000 ____D C:\Users\Wendy\AppData\Local\PowerCinema
2015-10-06 10:17 - 2015-07-10 07:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-10-06 10:17 - 2015-03-21 09:56 - 00000000 ____D C:\Users\Wendy\AppData\Local\Microsoft Help
2015-10-06 10:17 - 2014-03-03 18:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-10-06 10:17 - 2014-03-03 18:17 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-10-06 10:17 - 2013-03-06 21:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
2015-10-06 10:17 - 2013-03-06 21:38 - 00000000 ____D C:\Program Files\Microsoft Office
2015-10-06 10:17 - 2013-03-06 21:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client
2015-10-06 10:17 - 2013-02-21 22:13 - 00000000 ____D C:\Program Files\Google
2015-10-06 10:17 - 2013-02-21 22:12 - 00000000 ____D C:\Program Files (x86)\Google
2015-10-06 10:17 - 2011-05-14 10:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-10-06 10:17 - 2011-04-06 17:00 - 00000000 ____D C:\ProgramData\BackupManager
2015-10-06 10:05 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\registration
2015-10-06 10:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-10-06 10:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SystemResources
2015-10-06 09:59 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-10-06 09:58 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-10-06 09:58 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-10-06 09:57 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-10-06 09:55 - 2013-03-06 21:39 - 00000000 ____D C:\Users\Wendy\AppData\Roaming\SoftGrid Client
2015-10-06 09:34 - 2015-08-03 21:18 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-10-06 09:34 - 2015-07-10 09:14 - 00000000 ____D C:\Program Files\Windows Journal
2015-10-06 09:34 - 2015-07-10 07:04 - 00000000 ____D C:\Program Files\Windows NT
2015-10-06 09:34 - 2013-03-14 03:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-10-06 09:30 - 2015-08-03 21:18 - 00000000 ____D C:\inetpub
2015-10-06 09:30 - 2011-04-06 16:56 - 00000000 ___HD C:\OEM
2015-10-06 09:30 - 2011-04-06 16:55 - 00000000 ____D C:\Program Files (x86)\EgisTec Shredder
2015-10-06 09:30 - 2011-04-06 16:54 - 00000000 ____D C:\Program Files (x86)\EgisTec MyWinLocker
2015-10-06 09:30 - 2011-04-06 16:53 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-10-06 09:30 - 2011-04-06 16:52 - 00000000 ____D C:\Program Files (x86)\Windows Live
2015-10-06 09:30 - 2011-04-06 16:21 - 00000000 ____D C:\Program Files (x86)\Acer Games
2015-10-04 22:04 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-04 16:29 - 2015-09-05 19:15 - 00006208 _____ C:\WINDOWS\PFRO.log
2015-10-04 13:31 - 2015-08-03 17:35 - 00042366 _____ C:\WINDOWS\iis.log
2015-10-03 18:54 - 2013-03-06 21:38 - 00000000 ____D C:\Users\Wendy\AppData\Roaming\TP
2015-10-01 18:25 - 2015-07-10 08:20 - 00018136 _____ C:\WINDOWS\setupact.log
2015-09-27 15:46 - 2015-09-07 18:52 - 00000000 ____D C:\Users\Wendy\AppData\Local\Comms
2015-09-21 00:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-09-20 23:22 - 2011-10-08 22:15 - 00000000 ____D C:\Users\Wendy\AppData\Local\VirtualStore
2015-09-20 20:41 - 2015-07-10 08:20 - 00336488 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-20 20:40 - 2015-07-10 05:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-09-20 20:21 - 2013-08-15 03:01 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-20 18:46 - 2015-08-23 20:31 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-20 18:39 - 2015-08-03 18:13 - 00002378 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-09-20 18:39 - 2015-08-03 18:09 - 00001331 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan.lnk
2015-09-20 18:39 - 2015-08-03 18:07 - 00001313 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Realtek HD Audio Manager.lnk
2015-09-20 18:39 - 2015-08-03 17:46 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002425 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002289 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002287 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00001578 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00000853 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop.lnk
2015-09-20 18:39 - 2015-03-21 09:27 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-09-20 18:39 - 2014-08-18 02:33 - 00001015 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2015-09-20 18:39 - 2014-07-12 18:05 - 00001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-09-20 18:39 - 2014-03-03 18:27 - 00002162 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-09-20 18:39 - 2012-10-14 10:52 - 00001866 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fooz Kids.lnk
2015-09-20 18:39 - 2011-12-02 19:21 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-09-20 18:39 - 2011-10-08 22:16 - 00000915 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Times Reader.lnk
2015-09-20 18:39 - 2011-05-14 10:14 - 00002478 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2015-09-20 18:39 - 2011-04-06 16:52 - 00001450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-09-20 18:38 - 2015-09-07 14:00 - 00000989 _____ C:\Users\Wendy\Desktop\CBS.log - Shortcut.lnk
2015-09-20 18:38 - 2015-08-23 20:31 - 00001173 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-20 18:38 - 2015-07-18 15:05 - 00001751 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-09-20 18:38 - 2015-07-18 14:54 - 00001843 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2015-09-20 18:38 - 2015-03-21 09:27 - 00002017 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-09-20 18:38 - 2014-08-18 02:34 - 00001015 _____ C:\Users\Wendy\Desktop\Audacity.lnk
2015-09-20 18:38 - 2014-07-26 09:52 - 00001211 _____ C:\Users\Wendy\Desktop\Kaspersky Security Scan.lnk
2015-09-20 18:38 - 2014-07-12 18:59 - 00001216 _____ C:\Users\Public\Desktop\XSplit Gamecaster.lnk
2015-09-20 18:38 - 2014-07-12 18:05 - 00001297 _____ C:\Users\Wendy\Desktop\Movie Maker.lnk
2015-09-20 18:38 - 2014-07-12 17:52 - 00002691 _____ C:\Users\Public\Desktop\Skype.lnk
2015-09-20 18:38 - 2014-07-11 19:19 - 00002151 _____ C:\Users\Public\Desktop\AVerMedia RECentral.lnk
2015-09-20 18:38 - 2012-10-14 10:52 - 00001860 _____ C:\Users\Public\Desktop\Fooz Kids.lnk
2015-09-20 18:38 - 2011-10-16 14:23 - 00002229 _____ C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
2015-09-20 18:38 - 2011-10-08 22:17 - 00002603 _____ C:\Users\Public\Desktop\eBay.lnk
2015-09-20 18:38 - 2011-10-08 22:17 - 00001962 _____ C:\Users\Public\Desktop\Netflix.lnk
2015-09-20 18:38 - 2011-10-08 22:16 - 00000909 _____ C:\Users\Public\Desktop\Times Reader.lnk
2015-09-20 18:38 - 2011-05-14 10:11 - 00001206 _____ C:\Users\Public\Desktop\NOOK for PC.lnk
2015-09-20 18:38 - 2011-05-14 10:09 - 00002165 _____ C:\Users\Public\Desktop\clear.fi.lnk
2015-09-20 18:38 - 2011-04-06 16:57 - 00001984 _____ C:\Users\Public\Desktop\Norton Online Backup.lnk
2015-09-20 18:38 - 2011-04-06 16:51 - 00002727 _____ C:\Users\Public\Desktop\clear.fi Tutorial.lnk
2015-09-20 18:38 - 2011-04-06 16:20 - 00002562 _____ C:\Users\Public\Desktop\WildTangent Games App - acer.lnk
2015-09-20 14:48 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2015-09-20 11:26 - 2015-02-02 01:57 - 00000000 ____D C:\Users\Wendy\Documents\Outlook Files
2015-09-17 18:55 - 2013-02-21 22:12 - 00003982 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-13 11:37 - 2011-10-09 09:37 - 00000000 ____D C:\Users\Wendy\AppData\Local\Apple Computer
2015-09-09 05:06 - 2009-07-14 01:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
 
==================== Files in the root of some directories =======
 
2015-10-03 18:54 - 2015-10-03 18:54 - 0000000 _____ () C:\Program Files\Microsoft Security Client
2015-10-03 18:54 - 2015-10-03 18:54 - 0000000 _____ () C:\Program Files (x86)\Broadcom
2015-10-03 18:54 - 2015-10-03 18:54 - 0000000 _____ () C:\Program Files (x86)\Itibiti Soft Phone
2015-10-03 18:54 - 2015-10-03 18:54 - 0000000 _____ () C:\Program Files (x86)\System Cleaner Pro
2011-10-16 14:23 - 2011-10-16 14:56 - 0000077 _____ () C:\Users\Wendy\AppData\Roaming\Rim.Desktop.Exception.log
2011-10-16 14:23 - 2011-10-16 14:23 - 0001153 _____ () C:\Users\Wendy\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2011-10-16 14:23 - 2011-10-16 14:56 - 0000077 _____ () C:\Users\Wendy\AppData\Roaming\Rim.DesktopHelper.Exception.log
2014-08-25 02:24 - 2014-08-28 14:02 - 0000089 _____ () C:\Users\Wendy\AppData\Roaming\WB.CFG
2015-10-05 00:08 - 2015-10-05 00:08 - 0000017 _____ () C:\Users\Wendy\AppData\Local\resmon.resmoncfg
2011-05-14 10:07 - 2011-05-14 10:10 - 0015152 _____ () C:\ProgramData\ArcadeDeluxe5.log
2015-08-03 17:33 - 2015-08-03 17:33 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll
[2015-07-10 07:00] - [2015-08-22 14:52] - 0680256 ____A (Microsoft Corporation) F84D50EF068750CB192D15D4FDD7088C
 
C:\WINDOWS\SysWOW64\dnsapi.dll
[2015-07-10 07:00] - [2015-08-22 14:53] - 0534064 ____A () D41D8CD98F00B204E9800998ECF8427E
 
C:\WINDOWS\SysWOW64\dnsapi.dll => no Company Name <===== ATTENTION
 
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 

LastRegBack: 2015-10-06 10:41
 
==================== End of FRST.txt ============================

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version:08-10-2015
Ran by Wendy (2015-10-09 23:47:05)
Running from C:\Users\Wendy\Desktop
Windows 10 Home (X64) (2015-08-03 22:04:00)
Boot Mode: Normal
==========================================================
 

==================== Accounts: =============================
 
Administrator (S-1-5-21-2389695071-1928321251-2773591669-500 - Administrator - Disabled)
DefaultAccount (S-1-5-21-2389695071-1928321251-2773591669-503 - Limited - Disabled)
Guest (S-1-5-21-2389695071-1928321251-2773591669-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-2389695071-1928321251-2773591669-1002 - Limited - Enabled)
Wendy (S-1-5-21-2389695071-1928321251-2773591669-1000 - Administrator - Enabled) => C:\Users\Wendy
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Acer Backup Manager (HKLM-x32\...\InstallShield_{0B61BBD5-DA3C-409A-8730-0C3DC3B0F270}) (Version: 3.0.0.85 - NTI Corporation)
Acer Crystal Eye Webcam (HKLM-x32\...\InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}) (Version: 1.0.1510 - CyberLink Corp.)
Acer Crystal Eye Webcam (x32 Version: 1.0.1510 - CyberLink Corp.) Hidden
Acer ePower Management (HKLM-x32\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 6.00.3006 - Acer Incorporated)
Acer eRecovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3002 - Acer Incorporated)
Acer Games (HKLM-x32\...\WildTangent acer Master Uninstall) (Version: 1.0.2.4 - WildTangent)
Acer ScreenSaver (HKLM-x32\...\Acer Screensaver) (Version: 1.1.1130.2010 - Acer Incorporated)
Acer Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3005 - Acer Incorporated)
Acrobat.com (HKLM-x32\...\{287ECFA4-719A-2143-A09B-D6A12DE54E40}) (Version: 1.6.65 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.2.0.2070 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.12) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.12 - Adobe Systems Incorporated)
Agatha Christie - 4:50 from Paddington (x32 Version: 2.2.0.95 - WildTangent) Hidden
Apple Application Support (32-bit) (HKLM-x32\...\{7FE25256-B7C1-480D-B736-10A67A833AEA}) (Version: 3.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{B255D495-4734-4E9B-B4F5-96702FD4A7B9}) (Version: 3.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{5D61F006-168C-4B8B-B7FD-F113C10AE0E4}) (Version: 8.2.1.3 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)
AVerMedia C875 Live Gamer Portable 3.7.64.23 (HKLM-x32\...\AVerMedia C875 Live Gamer Portable) (Version: 3.7.64.23 - AVerMedia TECHNOLOGIES, Inc.)
AVerMedia Live Gamer HD Series 3.3.64.42 (HKLM-x32\...\AVerMedia Live Gamer HD Series) (Version: 3.3.64.42 - AVerMedia TECHNOLOGIES, Inc.)
AVerMedia RECentral (HKLM-x32\...\InstallShield_{30D6B6ED-E039-4D62-8E07-E058D17A9372}) (Version: 1.3.0.84 - AVerMedia Technologies, Inc.)
AVerMedia RECentral (x32 Version: 1.3.0.84 - AVerMedia Technologies, Inc.) Hidden
Backup Manager V3 (x32 Version: 3.0.0.85 - NTI Corporation) Hidden
Bejeweled 2 Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Belkin Setup and Router Monitor (HKLM-x32\...\Belkin Setup and Router Monitor_is1) (Version:  - )
Bing Bar (HKLM-x32\...\{1E03DB52-D5CB-4338-A338-E526DD4D4DB1}) (Version: 7.0.610.0 - Microsoft Corporation)
BlackBerry Desktop Software 6.1 (HKLM-x32\...\BlackBerry_Desktop) (Version: 6.1.0.35 - Research In Motion Ltd.)
BlackBerry Desktop Software 6.1 (x32 Version: 6.1.0.35 - Research In Motion Ltd.) Hidden
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Broadcom Card Reader Driver Installer (HKLM\...\{4710662C-8204-4334-A977-B1AC9E547819}) (Version: 14.6.1.2 - Broadcom Corporation)
Broadcom Gigabit NetLink Controller (HKLM\...\{C91DCB72-F5BB-410D-A91A-314F5D1B4284}) (Version: 14.6.1.2 - Broadcom Corporation)
Build-a-lot 2 (x32 Version: 2.2.0.95 - WildTangent) Hidden
CA Pest Patrol Realtime Protection (HKLM-x32\...\{F05A5232-CE5E-4274-AB27-44EB8105898D}) (Version: 001.001.0034 - Computer Associates Inc.)
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
clear.fi (HKLM-x32\...\InstallShield_{2637C347-9DAD-11D6-9EA2-00055D0CA761}) (Version: 1.0.1422.00 - CyberLink Corp.)
clear.fi (x32 Version: 1.0.1422.00 - CyberLink Corp.) Hidden
clear.fi (x32 Version: 9.0.7418 - CyberLink Corp.) Hidden
clear.fi Client (HKLM-x32\...\{43AAE145-83CF-4C96-9A5E-756CEFCE879F}) (Version: 1.00.3008 - Acer Incorporated)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Diner Dash 2 Restaurant Rescue (x32 Version: 2.2.0.95 - WildTangent) Hidden
Dolby Advanced Audio v2 (HKLM-x32\...\{B9E70C7A-9F85-4A39-A4A3-BFA3C3BF7613}) (Version: 7.2.7000.4 - Dolby Laboratories Inc)
Dora's World Adventure (x32 Version: 2.2.0.95 - WildTangent) Hidden
eBay Worldwide (HKLM-x32\...\{E0B19DF7-B1C7-4937-82C4-0E4B1E346965}) (Version: 2.1.0901 - OEM)
ESET Online Scanner v3 (HKLM-x32\...\ESET Online Scanner) (Version:  - )
FATE - The Traitor Soul (x32 Version: 2.2.0.95 - WildTangent) Hidden
FFCB_IEAddon (HKLM-x32\...\{F6E481AE-2288-4C26-9F16-D16BADD83BF0}) (Version: 1.0.0 - SpinBall)
Final Drive: Nitro (x32 Version: 2.2.0.95 - WildTangent) Hidden
FlashBeat (HKLM-x32\...\FlashBeat) (Version:  - ) <==== ATTENTION
Fooz Kids (HKLM-x32\...\FoozKids) (Version: 3.2.16 - FUHU, Inc.)
Fooz Kids (x32 Version: 3.2.16 - FUHU, Inc.) Hidden
Fooz Kids Platform (HKLM-x32\...\{8D68CE08-9A14-4B7B-9857-3C646A2F34C7}) (Version: 2.1 - FUHU, Inc.)
Galerie de photos (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Game Channels (HKLM-x32\...\WildTangentGameProvider-acer-main) (Version: 4.1.0.8 - WildTangent, Inc.)
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6904.2028 - Google Inc.)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (x32 Version: 1.3.28.15 - Google Inc.) Hidden
iCloud (HKLM\...\{709A2D23-C25E-47B5-9268-CB6FEE648504}) (Version: 4.1.1.53 - Apple Inc.)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3006 - Acer Incorporated)
Intel® Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1144 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2342 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.0.0.1046 - Intel Corporation)
Intel® Turbo Boost Technology Monitor 2.0 (HKLM\...\{B77EFA0B-9BD3-4122-9F9A-15A963B5EA24}) (Version: 2.0.82.0 - Intel)
iPhoneBrowser (HKLM-x32\...\{C1FCDCA1-2759-4E5E-84EE-3A665BB2F513}) (Version: 1.9.3 - Cranium Consulting and Custom Software)
Itibiti RTC (x32 Version: 0.0.1 - Itibiti Inc) Hidden
iTunes (HKLM\...\{6CF1A7E2-8001-4870-9F18-3C6CDD6FE9E3}) (Version: 12.2.1.16 - Apple Inc.)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Jewel Quest Heritage (x32 Version: 2.2.0.95 - WildTangent) Hidden
Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Kaspersky Security Scan (HKLM-x32\...\InstallWIX_{D1282694-0693-41A8-ABC1-6D1FFC1F65C4}) (Version: 12.0.1.881 - Kaspersky Lab)
Kaspersky Security Scan (x32 Version: 12.0.1.881 - Kaspersky Lab) Hidden
Launch Manager (HKLM-x32\...\LManager) (Version: 5.1.4 - Acer Inc.)
MediaEspresso (x32 Version: 1.0.1418_35759 - CyberLink Corp.) Hidden
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 15.0.4753.1003 - Microsoft Corporation)
Microsoft Office Click-to-Run 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Starter 2010 - English (HKLM-x32\...\{90140011-0066-0409-0000-0000000FF1CE}) (Version: 14.0.5131.5000 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.40728.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mystery P.I. - Stolen in San Francisco (x32 Version: 2.2.0.95 - WildTangent) Hidden
MyWinLocker (Version: 4.0.14.11 - Egis Technology Inc.) Hidden
MyWinLocker 4 (x32 Version: 4.0.14.11 - Egis Technology Inc.) Hidden
MyWinLocker Suite (HKLM-x32\...\InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}) (Version: 4.0.14.11 - Egis Technology Inc.)
MyWinLocker Suite (x32 Version: 4.0.14.11 - Egis Technology Inc.) Hidden
Namco All-Stars: PAC-MAN (x32 Version: 2.2.0.95 - WildTangent) Hidden
newsXpresso (HKLM-x32\...\InstallShield_{613C0AC5-3A67-4B94-8B13-9176AD83F5BF}) (Version: 1.0.0.40 - esobi Inc.)
newsXpresso (x32 Version: 1.0.0.40 - esobi Inc.) Hidden
NOOK for PC (HKLM-x32\...\BN_DesktopReader) (Version: 2.5.1.237 - Barnesandnoble.com)
Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
NTI Media Maker 9 (HKLM-x32\...\InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}) (Version: 9.0.2.8942 - NTI Corporation)
NTI Media Maker 9 (x32 Version: 9.0.2.8942 - NTI Corporation) Hidden
Office 15 Click-to-Run Extensibility Component (x32 Version: 15.0.4753.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Licensing Component (Version: 15.0.4753.1003 - Microsoft Corporation) Hidden
Office 15 Click-to-Run Localization Component (x32 Version: 15.0.4753.1003 - Microsoft Corporation) Hidden
Penguins! (x32 Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.95 - WildTangent) Hidden
Poker Superstars III (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.95 - WildTangent) Hidden
Polar Golfer (x32 Version: 2.2.0.95 - WildTangent) Hidden
QuickTime 7 (HKLM-x32\...\{627FFC10-CE0A-497F-BA2B-208CAC638010}) (Version: 7.77.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7535 - Realtek Semiconductor Corp.)
Setup (HKLM-x32\...\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}) (Version:  - )
Shopper-Pro (HKLM-x32\...\ShopperPro) (Version:  - ) <==== ATTENTION
Shredder (Version: 2.0.8.7 - Egis Technology Inc.) Hidden
Shredder (x32 Version: 2.0.8.7 - Egis Technology Inc.) Hidden
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.4.0.9058 - Microsoft Corporation)
Skype™ 7.0 (HKLM-x32\...\{24991BA0-F0EE-44AD-9CC8-5EC50AECF6B7}) (Version: 7.0.102 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 19.0.13.0 - Synaptics Incorporated)
System Cleaner Pro 2.01 (HKLM-x32\...\System Cleaner Pro 2.01) (Version: 2.01 - System Cleaner Pro)
Times Reader (HKLM-x32\...\com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1) (Version: 2.055 - The New York Times Company)
Times Reader (x32 Version: 2.055 - The New York Times Company) Hidden
Torchlight (x32 Version: 2.2.0.95 - WildTangent) Hidden
Update Installer for WildTangent Games App (x32 Version:  - WildTangent) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.95 - WildTangent) Hidden
Welcome Center (HKLM-x32\...\Acer Welcome Center) (Version: 1.02.3102 - Acer Incorporated)
WildTangent Games App (Acer Games) (x32 Version: 4.0.5.31 - WildTangent) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.01 (32-bit) (HKLM-x32\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
WordSurfer 1.10.0.19 (HKLM-x32\...\WordSurfer_1.10.0.19) (Version: 1.10.0.19 - WordSurfer)
XSplit Gamecaster (HKLM-x32\...\{69A0FDE5-407D-4325-81F2-D5005F847DF3}) (Version: 1.9.1407.0414 - SplitmediaLabs)
YTDownloader (HKLM-x32\...\YTDownloader) (Version:  - YTDownloader) <==== ATTENTION
Zuma's Revenge (x32 Version: 2.2.0.95 - WildTangent) Hidden
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000_Classes\CLSID\{A9B6F3D2-A55A-4061-9F31-71970E5CE3E9}\InprocServer32 -> C:\Program Files (x86)\SpinBall\FFCB_IEAddon\adxloader64.dll ()
 
==================== Restore Points =========================
 
04-10-2015 12:30:25 Removed Microsoft Office Click-to-Run 2010
05-10-2015 21:21:36 Restore Operation
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____A C:\WINDOWS\system32\Drivers\etc\hosts
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {080F17C6-3608-49AA-9C26-DA60510A89C3} - System32\Tasks\Microsoft\Windows\Media Center\OCURDiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {092967F0-C66E-43BA-9123-49BC48F6611C} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\MpCmdRun.exe
Task: {10E330AE-3E91-4F54-B7E8-0891B502A503} - System32\Tasks\DMREngine => C:\Program Files (x86)\Acer\clear.fi\MVP\.\Kernel\DMR\DMREngine.exe [2011-02-22] (CyberLink)
Task: {120DDF2E-EADA-43F3-9AFD-FEB676787D48} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW1 => C:\Windows\ehome\ehPrivJob.exe
Task: {166EEEC2-A08F-4350-9FFE-21D8BB9BCAD2} - System32\Tasks\Microsoft\Windows\Media Center\OCURActivate => C:\Windows\ehome\ehPrivJob.exe
Task: {1FE10AA4-E496-4207-BA7E-1A5F2F748DA9} - \YTDownloaderUpd -> No File <==== ATTENTION
Task: {24153C4F-1501-4D78-939E-F3887B76F5A7} - \bvxvbxvd -> No File <==== ATTENTION
Task: {29532EFE-5BB6-45D5-B494-CDA701FEE8A0} - System32\Tasks\Microsoft\Windows\Media Center\StartRecording => C:\Windows\ehome\ehrec.exe
Task: {2B35341E-58B8-495B-AF97-E8F0687A5E38} - \YTDownloader -> No File <==== ATTENTION
Task: {2E67F01C-3553-40E0-A907-8A6F176605F5} - \PaintTool SAI -> No File <==== ATTENTION
Task: {47529FDE-C74C-4DE6-9682-9200DA923BD4} - \Notify Helper -> No File <==== ATTENTION
Task: {4CDAD28F-D583-468F-B667-2FFE6356202F} - \SmartWeb Upgrade Trigger Task -> No File <==== ATTENTION
Task: {4D693E52-0515-4FA1-8AE4-E36FF19222C0} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {53F4E837-D6CA-455B-81F3-7344057C1A79} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe
Task: {55FC2B12-A712-4FAC-8760-0128CF6D2FEE} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {566C12AB-5147-4F47-A950-24F10AF60870} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscovery => C:\Windows\ehome\ehPrivJob.exe
Task: {56D716D7-79A5-4E90-8A2C-C3518FFDF2F1} - System32\Tasks\Microsoft\Windows\Media Center\ReindexSearchRoot => C:\Windows\ehome\ehPrivJob.exe
Task: {577ACAFA-6441-46FD-AA5D-BE639C1AC677} - System32\Tasks\Microsoft\Windows\Media Center\InstallPlayReady => C:\Windows\ehome\ehPrivJob.exe
Task: {5C69B07C-CC92-4368-A738-A993CB848D95} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-09-11] (Microsoft Corporation)
Task: {5D46809A-8869-4606-A198-B5FADA739E2F} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {6000EC01-A51F-4CF3-9587-5AC45C9ACF01} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {62288D2C-2758-4446-85B1-E9F187F37733} - \SPBIW_UpdateTask_Time_333939363932333431332d5a376c5a4a6c573250344141 -> No File <==== ATTENTION
Task: {64F88B8C-E57D-4AD7-B274-4AD807215EC2} - System32\Tasks\{5C2DCAC9-A1A8-4AEE-A6C6-68B5A9EE31EE} => pcalua.exe -a "C:\Users\Wendy\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K1R5SIVH\C985_application_and_driver_v1.3.0.46_20130617.exe" -d C:\Users\Wendy\Desktop
Task: {67958CCE-3DB1-4735-A3F4-2BA4557D7E65} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {67BFFA79-86B2-41CC-908A-C6A50F3BF91B} - System32\Tasks\Microsoft\Windows\Media Center\RegisterSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {68908337-05AB-4C4A-8C30-AB64B867C70A} - System32\Tasks\Microsoft\Windows\Media Center\MediaCenterRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {68C25381-E76D-4DD0-9829-39797230EC14} - System32\Tasks\Microsoft\Windows\Media Center\ActivateWindowsSearch => C:\Windows\ehome\ehPrivJob.exe
Task: {696BEDE9-AAA6-4829-80AC-2EB888CA5DFC} - System32\Tasks\Microsoft\Windows\Media Center\PBDADiscoveryW2 => C:\Windows\ehome\ehPrivJob.exe
Task: {745B77A7-4DB9-4466-9015-BAB6EC44CF5F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-07-07] (Adobe Systems Incorporated)
Task: {74E1404F-9371-4D44-9F5D-45AC16B1C07E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {7C9C84BB-49F2-42A0-8E25-392354C6C397} - \WordSurfer Auto Updater 1.10.0.19 Core -> No File <==== ATTENTION
Task: {7E5BF3F7-EDFF-4E52-A48A-A3DC317C43BA} - \WordSurfer Auto Updater 1.10.0.19 Pending Update -> No File <==== ATTENTION
Task: {803D9411-8EB3-44A3-9C21-EA5EF601FB75} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2015-08-26] (Microsoft Corporation)
Task: {830A2863-E81E-4877-AAD9-B579247EC3BA} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {88029952-6572-4631-A033-28BEA5D204A8} - System32\Tasks\GoogleUpdateTaskMachineCore1d0e826fa18e252 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-05] (Google Inc.)
Task: {89BB221D-DF91-4AF6-B785-FE601F3DE962} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {902C14BD-9365-4536-BB1A-39B79ED53A1E} - \System Cleaner Pro Auto Start -> No File <==== ATTENTION
Task: {920D5B1A-A935-43E8-B5DF-A3B21CBD8166} - System32\Tasks\Microsoft\Windows\Media Center\PeriodicScanRetry => C:\Windows\ehome\MCUpdate.exe
Task: {99B3E716-F1AA-4F2A-B33C-3AE29D29D961} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonx86\Microsoft Shared\OFFICE15\OLicenseHeartbeat.exe [2015-09-11] (Microsoft Corporation)
Task: {9C4FC0D6-AEE0-4519-95CD-6FE2BED0229F} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate => C:\Windows\ehome\mcupdate.exe
Task: {A367959F-6398-4208-8BEA-FFEA61E70294} - System32\Tasks\{6EB71239-E329-4DC7-A8F3-A64AFDC138C2} => pcalua.exe -a "C:\Program Files (x86)\DailyPcClean Support\unins000.exe"
Task: {A6BA20F8-819D-42F2-BA40-AA8E07731D11} - \Jarmeee -> No File <==== ATTENTION
Task: {A808A96E-D5B3-42CB-AD89-B351C29B7C11} - System32\Tasks\clear.fi => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe [2011-02-22] (Acer Incorporated)
Task: {AD9DB6BB-1BE5-481B-8DA2-D88CA2820DE7} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {AE9EE3EE-775E-469B-B574-89FA8611079A} - \updateTask -> No File <==== ATTENTION
Task: {B0D3CF47-F3D5-4D53-B270-CB588680A2E1} - System32\Tasks\Microsoft\Windows\Media Center\RecordingRestart => C:\Windows\ehome\ehrec.exe
Task: {B1D89B5A-D5DD-4961-A5DB-F9737392A0CA} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-07-18] (Adobe Systems Incorporated)
Task: {BC650C00-6A30-4412-B709-2D8E194AA581} - System32\Tasks\Microsoft\Windows\Media Center\ConfigureInternetTimeService => C:\Windows\ehome\ehPrivJob.exe
Task: {BC6BEFE2-E2C9-4683-9BB1-ED447830D7B9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {BC9902D7-F2B6-4982-A984-0A86AEF77929} - System32\Tasks\Microsoft\Windows\Media Center\SqlLiteRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {BDEC4C9E-2A8B-4BD1-B2ED-AD0818A09852} - System32\Tasks\Microsoft\Windows\Media Center\PvrScheduleTask => C:\Windows\ehome\mcupdate.exe
Task: {C516EFA9-F2F5-4DC2-998C-A10FAE4EB79E} - System32\Tasks\clear.fiAgent => C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe [2011-02-22] (CyberLink Corp.)
Task: {C5812387-F344-4101-AF50-F391FF880614} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {C586E004-3D6A-4FA4-BF04-1BB37CB2386D} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {C73A8AC1-5ED6-471C-94B6-68B18CDEA617} - System32\Tasks\Microsoft\Windows\Media Center\ObjectStoreRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {C8213448-346D-452D-81BA-AAA398B57DC5} - \4a752bbc-e718-4ff5-8948-5413ae8b7094 -> No File <==== ATTENTION
Task: {CC9322D8-8113-40E7-BC9C-D3CE404A3BB2} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {D01BAF9E-BB7E-44F4-BF6F-0695A078AB93} - \runTask -> No File <==== ATTENTION
Task: {D35AE52A-482C-4656-BFA0-429FDE04BD24} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {D875E597-84B7-4AAE-AE3A-7A71AB312978} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {DA781ED4-5DE4-4753-B292-F717851D6C7C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
Task: {DB335640-3E12-4EC2-910D-9E98E48A0780} - System32\Tasks\Microsoft\Windows\Media Center\ehDRMInit => C:\Windows\ehome\ehPrivJob.exe
Task: {E0A35B6F-31D6-4901-859F-B285695EA54B} - System32\Tasks\Microsoft\Windows\Media Center\PvrRecoveryTask => C:\Windows\ehome\mcupdate.exe
Task: {E1FB7C5E-7341-4C5A-812B-9ACFB6DBEE67} - System32\Tasks\Microsoft\Windows\Media Center\DispatchRecoveryTasks => C:\Windows\ehome\ehPrivJob.exe
Task: {EE680E16-2613-4220-AE25-F4D39B1747A8} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2015-09-11] (Microsoft Corporation)
Task: {F727FFEE-9EC8-4ABD-A89C-7ABCF977FBC6} - System32\Tasks\{2517B75F-59B6-40E8-83DA-494CD712841E} => pcalua.exe -a C:\ProgramData\FlashBeat\SoftConfigTest.exe
Task: {FF967F5C-F8B1-4AE8-B2F2-D24594F0704B} - System32\Tasks\Microsoft\Windows\Media Center\UpdateRecordPath => C:\Windows\ehome\ehPrivJob.exe
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0e826fa18e252.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Loaded Modules (Whitelisted) ==============
 
2015-08-03 21:24 - 2015-08-03 21:24 - 00032768 _____ () C:\WINDOWS\SYSTEM32\licensemanagerapi.dll
2015-01-20 23:35 - 2015-01-20 23:35 - 00085832 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-05-15 16:26 - 2015-05-15 16:26 - 01346344 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2015-08-20 09:37 - 2015-08-11 05:14 - 00404480 _____ () C:\WINDOWS\System32\diagtrack_wininternal.dll
2014-03-03 18:17 - 2014-05-20 09:19 - 00105640 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll
2015-09-07 21:23 - 2015-08-18 03:56 - 02498808 _____ () C:\WINDOWS\system32\CoreUIComponents.dll
2015-09-07 21:23 - 2015-08-18 03:56 - 02498808 _____ () C:\WINDOWS\System32\CoreUIComponents.dll
2015-09-24 13:05 - 2015-08-11 23:15 - 08900672 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2009-01-21 19:45 - 2009-01-21 19:45 - 01401856 _____ () C:\Program Files (x86)\EgisTec MyWinLocker\x64\LIBEAY32.dll
2015-07-10 06:59 - 2015-07-10 06:59 - 00429056 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\QuickActions.dll
2015-07-10 06:59 - 2015-07-10 06:59 - 00143360 _____ () C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\XamlTileRendering.dll
2015-06-01 21:00 - 2015-06-01 21:00 - 00102912 _____ () C:\Windows\System32\IccLibDll_x64.dll
2009-08-19 13:25 - 2009-08-19 13:25 - 01589208 _____ () C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpy.exe
2015-10-07 17:38 - 2015-10-07 17:38 - 08395776 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.10.5.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll
2015-10-07 17:38 - 2015-10-07 17:38 - 02311680 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_2015.10.5.0_x64__8wekyb3d8bbwe\MS.Entertainment.Common.Mobile.dll
2015-08-13 14:53 - 2015-08-02 21:11 - 06569472 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.dll
2015-07-10 07:00 - 2015-07-10 09:14 - 00471040 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2015-08-20 09:37 - 2015-08-11 04:58 - 01808384 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.BackgroundTask.dll
2015-08-13 14:53 - 2015-08-02 21:09 - 02274816 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\RemindersUI.dll
2015-07-10 07:00 - 2015-07-10 09:14 - 00210432 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\CortanaApi.ProxyStub.dll
2015-08-20 09:37 - 2015-08-11 05:10 - 00293376 _____ () C:\WINDOWS\SYSTEM32\textinputframework.dll
2012-09-01 16:14 - 2012-02-23 15:57 - 00022944 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinServicePS.dll
2014-06-15 23:40 - 2014-06-15 23:40 - 02124256 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\QtCore4.dll
2014-06-15 23:39 - 2014-06-15 23:39 - 07422144 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\QtGui4.dll
2014-06-15 23:39 - 2014-06-15 23:39 - 02453696 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\QtDeclarative4.dll
2014-06-15 23:39 - 2014-06-15 23:39 - 00794816 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\QtNetwork4.dll
2014-06-15 23:39 - 2014-06-15 23:39 - 01269952 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\QtScript4.dll
2014-06-15 23:39 - 2014-06-15 23:39 - 00192704 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\QtSql4.dll
2011-02-15 14:37 - 2011-02-15 14:37 - 00465640 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\sqlite3.dll
2011-02-15 14:37 - 2011-02-15 14:37 - 00125760 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\MailConverter32.dll
2011-02-15 14:36 - 2011-02-15 14:36 - 01081664 _____ () C:\Program Files (x86)\NTI\Acer Backup Manager\ACE.dll
2015-08-07 20:38 - 2015-08-07 20:38 - 00169984 _____ () C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\IsdiInterop\c481f8491232123e86ffb7cccffebdfb\IsdiInterop.ni.dll
2011-04-06 16:15 - 2010-09-13 21:28 - 00058880 _____ () C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IsdiInterop.dll
2011-02-22 13:01 - 2011-02-22 13:01 - 00206216 _____ () C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\CLNetMediaDMA.dll
2015-05-15 16:27 - 2015-05-15 16:27 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2012-09-01 16:14 - 2010-08-22 20:01 - 07187456 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtGui4.dll
2012-09-01 16:14 - 2010-08-22 20:01 - 00325632 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtXml4.dll
2012-09-01 16:14 - 2010-08-22 20:01 - 00847360 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtNetwork4.dll
2012-09-01 16:14 - 2010-08-22 20:01 - 01954304 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\QtCore4.dll
2012-09-01 16:14 - 2010-08-22 19:32 - 00119808 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\imageformats\qjpeg4.dll
2012-09-01 16:14 - 2012-02-23 15:19 - 00669696 _____ () C:\Program Files (x86)\Belkin\Router Setup and Monitor\gateways\GenericBelkinGatewayLOC.dll
2015-07-23 10:26 - 2015-07-23 10:26 - 00122024 _____ () C:\Program Files\Microsoft Office 15\root\Office15\JitV.dll
2014-11-22 14:15 - 2014-11-22 14:15 - 00316576 _____ () C:\Program Files\Microsoft Office 15\root\Office15\AppVIsvStream32.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\04bf7963418bedcfdde09dca48:Win32App
AlternateDataStreams: C:\3089b6a24ef724d145:Win32App
AlternateDataStreams: C:\318cab8197d210aa5c5e:Win32App
AlternateDataStreams: C:\419a2caadd4290847864:Win32App
AlternateDataStreams: C:\4f4fa18d4dd8f99f0ea6a6420281251a:Win32App
AlternateDataStreams: C:\65b66254bc6a4f7c7497ac9d8307:Win32App
AlternateDataStreams: C:\776e24d3f6aba141bb9c83b3fe63ae77:Win32App
AlternateDataStreams: C:\b9c13b78d128895b6e52:Win32App
AlternateDataStreams: C:\bd9118d39e1f207ee9cd6dcd0939:Win32App
AlternateDataStreams: C:\be8106b9bc95323fd268ba6235ad69:Win32App
AlternateDataStreams: C:\DOLBY PCEE4:Win32App
AlternateDataStreams: C:\Program Files\Bonjour:Win32App
AlternateDataStreams: C:\Program Files\Broadcom:Win32App
AlternateDataStreams: C:\Program Files\iTunes:Win32App
AlternateDataStreams: C:\Program Files\Microsoft Security Client:Win32App
AlternateDataStreams: C:\Program Files\Microsoft Silverlight:Win32App
AlternateDataStreams: C:\Program Files (x86)\Acer Games:Win32App
AlternateDataStreams: C:\Program Files (x86)\Apple Software Update:Win32App
AlternateDataStreams: C:\Program Files (x86)\Audacity:Win32App
AlternateDataStreams: C:\Program Files (x86)\Bonjour:Win32App
AlternateDataStreams: C:\Program Files (x86)\Broadcom:Win32App
AlternateDataStreams: C:\Program Files (x86)\EgisTec MyWinLocker:Win32App
AlternateDataStreams: C:\Program Files (x86)\EgisTec MyWinLockerSuite:Win32App
AlternateDataStreams: C:\Program Files (x86)\EgisTec Shredder:Win32App
AlternateDataStreams: C:\Program Files (x86)\Itibiti Soft Phone:Win32App
AlternateDataStreams: C:\Program Files (x86)\Launch Manager:Win32App
AlternateDataStreams: C:\Program Files (x86)\Microsoft SQL Server Compact Edition:Win32App
AlternateDataStreams: C:\Program Files (x86)\newsXpresso:Win32App
AlternateDataStreams: C:\Program Files (x86)\QuickTime:Win32App
AlternateDataStreams: C:\Program Files (x86)\System Cleaner Pro:Win32App
AlternateDataStreams: C:\Program Files (x86)\Times Reader:Win32App
AlternateDataStreams: C:\Program Files (x86)\Windows Live:Win32App
AlternateDataStreams: C:\Program Files (x86)\WinRAR:Win32App
AlternateDataStreams: C:\WINDOWS\SysWOW64:Win32App
AlternateDataStreams: C:\WINDOWS\system32\Drivers\rncmaqih.sys:changelist
AlternateDataStreams: C:\Program Files\Common Files\microsoft shared:Win32App
AlternateDataStreams: C:\ProgramData\regid.1991-06.com.microsoft:Win32App
AlternateDataStreams: C:\Users\Wendy\Desktop\REC:Win32App
AlternateDataStreams: C:\Users\Wendy\AppData\Local\Temp:Win32App
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Uiviuuj => ""="service"
 
==================== EXE Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 

==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 

==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Wendy\AppData\Local\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
(Currently there is no automatic fix for this section.)
 
HKLM\...\StartupApproved\Run: => "shopperz12082015"
HKLM\...\StartupApproved\Run: => "shopperz1208201564"
HKLM\...\StartupApproved\Run32: => "SmartWeb"
HKLM\...\StartupApproved\Run32: => "gmsd_us_005010068"
HKLM\...\StartupApproved\Run32: => "YTDownloader"
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\StartupApproved\StartupFolder: => "crossbrowse.lnk"
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\StartupApproved\StartupFolder: => "Dropbox.lnk"
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\StartupApproved\StartupFolder: => "SmartWeb.lnk"
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\StartupApproved\Run: => "GoogleChromeAutoLaunch_C2B59C6CEFF9726828003DBE1F6BF7E2"
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\StartupApproved\Run: => "YTDownloader"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [MSMQ-In-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-TCP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-In-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [MSMQ-Out-UDP] => (Allow) %systemroot%\system32\mqsvc.exe
FirewallRules: [WCF-NetTcpActivator-In-TCP-64bit] => (Allow) LPort=808
FirewallRules: [{3DB77488-D00C-4AEF-A1B6-5346B57DB9E6}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [UDP Query User{F581FA8E-90AB-414B-83CC-2D2CCAD4BC7F}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [TCP Query User{B764241D-551B-463F-96DB-5DF56FADFC33}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [UDP Query User{3251DACF-D388-4E6C-A220-B8AA88D4ACF7}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [TCP Query User{2C2F53D6-AA3E-49F5-AD08-4F88AB3BAEB6}C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre1.8.0_31\bin\javaw.exe
FirewallRules: [{A9AE3580-6D0F-4D5C-9DA4-867C776CA1C9}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{F9AC5A3F-EDD1-48C1-B69F-D620E7EDEFBC}] => (Allow) LPort=1900
FirewallRules: [{70C72209-A639-4527-AA42-7D4763163A35}] => (Allow) LPort=2869
FirewallRules: [{B7E50A7B-8687-4FC1-9CFD-8B618353F45C}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{4E55DA83-AED6-4EFD-B252-0B032CAE8896}] => (Allow) C:\Users\Wendy\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{53D69301-BF2D-4C70-9264-281F3F081404}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe
FirewallRules: [UDP Query User{5EDD340E-005F-4D94-AC4C-AA47AA88882F}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [TCP Query User{DDE6527E-4BBD-4C47-ACF1-39B2E90C131C}C:\program files (x86)\java\jre7\bin\javaw.exe] => (Block) C:\program files (x86)\java\jre7\bin\javaw.exe
FirewallRules: [{262B95DF-BA2C-43C4-947F-F099F94F80A9}] => (Allow) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
FirewallRules: [{A0A27374-FE0D-41EE-928F-9727C5476EED}] => (Allow) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
FirewallRules: [{C827F6CA-70DB-4677-B48C-A4313DE3CCCC}] => (Allow) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
FirewallRules: [{6B53BBB4-DD3D-41AF-A40B-905B9538724F}] => (Allow) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
FirewallRules: [{AA9AA1EA-8F9B-4534-94FF-EC75CEDD2442}] => (Allow) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
FirewallRules: [{508B16B2-32B0-4DC7-86FF-6A7EF77F0C56}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{89F0035A-49CD-4689-9C7F-02187E40C343}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{65C4E871-F869-44F2-BD1C-362A936973BF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{798BF025-6514-4D74-B137-B5FC656DBA8F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{18C0A254-8AE6-4923-A137-4C11EA503C32}] => (Allow) LPort=4482
FirewallRules: [{D5CF7AB0-CDA3-433D-B405-3ADF78221863}] => (Allow) LPort=4482
FirewallRules: [{72CA7657-64C0-4511-820A-5F009D1EF9A5}] => (Allow) LPort=4481
FirewallRules: [{6E0A5D7C-7FF2-4212-B67B-6984D7BFC08C}] => (Allow) LPort=4481
FirewallRules: [{55B275CA-5713-4412-807C-C06DE5D2E50A}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
FirewallRules: [{57B69D87-95F7-42AB-BE3A-5398B35B5C14}] => (Allow) C:\Program Files (x86)\Research In Motion\BlackBerry Desktop\Rim.Desktop.exe
FirewallRules: [{7E013D39-8398-4810-98DA-55A38296AF9D}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{2B419DC0-AE11-45D8-9FB3-C1CA4BCEDC9C}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovieService.exe
FirewallRules: [{CE798B7B-3CF3-4CF7-84D2-1FA194BC1FED}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovie.exe
FirewallRules: [{FD6BD230-5815-46DA-8154-DC1B853F1D98}] => (Block) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{344655B9-671D-47F9-B842-10575BA65E89}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{C0E5225C-B739-4A34-9D3B-697DA31A9AE6}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
FirewallRules: [{65C478B0-25D6-4FDF-9501-31A2158DDAE9}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\CLML\CLMLSvc.exe
FirewallRules: [{F092A236-2A7F-4E8F-A736-C2F3BF2170C8}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
FirewallRules: [{68B9BC7C-2F2C-4607-A754-DAFA26D9744A}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fi.exe
FirewallRules: [{DDD8EC91-FF64-42C6-BE3C-18A2065BFF88}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{C4E00E0C-3DF3-454E-BD03-C0E845228F66}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
FirewallRules: [{4431C433-B35C-45E4-A8DE-86FC541A6304}] => (Allow) C:\Torrentex\Torrentex.exe
FirewallRules: [{2ABAA82A-9A6B-4991-9150-EE6249CCCCB5}] => (Allow) C:\Torrentex\Torrentex.exe
FirewallRules: [{155E6D08-9385-4385-AF1E-7FBAAD1D5EA9}] => (Allow) C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
FirewallRules: [{ADF7AED6-F76B-4994-AC07-C59B8822209F}] => (Allow) C:\Program Files (x86)\Crossbrowse\Crossbrowse\Application\crossbrowse.exe
FirewallRules: [{1F48D41A-7AA7-4D70-A5A9-02C80576659B}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovie.exe
FirewallRules: [{E8F5EF16-F369-454A-982D-9FC44CC2B1EB}] => (Allow) C:\Program Files (x86)\Acer\clear.fi\Movie\TouchMovieService.exe
 
==================== Faulty Device Manager Devices =============
 

==================== Event log errors: =========================
 
Application errors:
==================
Error: (10/09/2015 11:37:07 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_3bccb1ff6bcd1849.manifest.
 
Error: (10/09/2015 10:36:15 PM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest1".Error in manifest or policy file "C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest2" on line C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest3.
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_f41f7b285750ef43.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.10240.16384_none_3bccb1ff6bcd1849.manifest.
 
Error: (10/09/2015 08:05:00 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Local Hostname Notebook.local already in use; will try Notebook-2.local instead
 
Error: (10/09/2015 08:05:00 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: ProbeCount 2; will deregister    4 Notebook.local. Addr 10.0.0.3
 
Error: (10/09/2015 08:05:00 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: mDNSCoreReceiveResponse: Received from 10.0.0.3:5353   16 Notebook.local. AAAA 2601:0085:4500:12C0:0000:0000:0000:0005
 
Error: (10/06/2015 08:30:47 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program HxMail.exe version 16.0.6224.4228 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 1764
 
Start Time: 01d10096e17c0453
 
Termination Time: 4294967295
 
Application Path: C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6224.42281.0_x64__8wekyb3d8bbwe\HxMail.exe
 
Report Id: a577d690-6c8a-11e5-9bd9-b870f483651e
 
Faulting package full name: microsoft.windowscommunicationsapps_17.6224.42281.0_x64__8wekyb3d8bbwe
 
Faulting package-relative application ID: microsoft.windowslive.mail
 
Error: (10/06/2015 08:30:44 PM) (Source: Microsoft-Windows-Immersive-Shell) (EventID: 2484) (User: Notebook)
Description: Package microsoft.windowscommunicationsapps_17.6224.42281.0_x64__8wekyb3d8bbwe+microsoft.windowslive.mail was terminated because it took too long to suspend.
 
Error: (10/06/2015 10:28:12 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Information only.
The action cannot be completed. Try the action again. If the problem continues, contact Microsoft Product Support.
 
Error: (10/06/2015 09:19:48 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: BelkinSetup.exe, version: 4.1.0.25491, time stamp: 0x4f46b479
Faulting module name: KERNELBASE.dll, version: 10.0.10240.16384, time stamp: 0x559f3b2a
Exception code: 0xc06d007e
Fault offset: 0x000b3e28
Faulting process id: 0x1ef0
Faulting application start time: 0xBelkinSetup.exe0
Faulting application path: BelkinSetup.exe1
Faulting module path: BelkinSetup.exe2
Report Id: BelkinSetup.exe3
Faulting package full name: BelkinSetup.exe4
Faulting package-relative application ID: BelkinSetup.exe5
 
Error: (10/06/2015 08:46:25 AM) (Source: CVHSVC) (EventID: 100) (User: )
Description: Information only.
The action cannot be completed. Try the action again. If the problem continues, contact Microsoft Product Support.
 

System errors:
=============
Error: (10/06/2015 08:17:31 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY)
Description: application-specificLocalActivation{D63B10C5-BB46-4990-A94F-E40B9D520160}{9CA88EE3-ACB7-47C8-AFC4-AB702511C276}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)UnavailableUnavailable
 
Error: (10/06/2015 08:17:14 PM) (Source: DCOM) (EventID: 10010) (User: Notebook)
Description: {14286318-B6CF-49A1-81FC-D74AD94902F9}
 
Error: (10/06/2015 08:16:59 PM) (Source: DCOM) (EventID: 10016) (User: Notebook)
Description: machine-defaultLocalActivation{C2F03A33-21F5-47FA-B4BB-156362A2F239}{316CDED5-E4AE-4B15-9113-7055D84DCC97}NotebookWendyS-1-5-21-2389695071-1928321251-2773591669-1000LocalHost (Using LRPC)Microsoft.WindowsStore_2015.9.9.0_x64__8wekyb3d8bbweS-1-15-2-1609473798-1231923017-684268153-4268514328-882773646-2760585773-1760938157
 
Error: (10/06/2015 08:16:24 PM) (Source: DCOM) (EventID: 10010) (User: Notebook)
Description: {14286318-B6CF-49A1-81FC-D74AD94902F9}
 
Error: (10/06/2015 10:30:33 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Intel® Management and Security Application User Notification Service service depends on the Intel® Management and Security Application Local Management Service service which failed to start because of the following error:
%%1053
 
Error: (10/06/2015 10:30:33 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Intel® Management and Security Application Local Management Service service failed to start due to the following error:
%%1053
 
Error: (10/06/2015 10:30:33 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Intel® Management and Security Application Local Management Service service to connect.
 
Error: (10/06/2015 10:30:27 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Intel® Management and Security Application Local Management Service service failed to start due to the following error:
%%1053
 
Error: (10/06/2015 10:30:27 AM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Intel® Management and Security Application Local Management Service service to connect.
 
Error: (10/06/2015 10:27:52 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The Net.Msmq Listener Adapter service failed to start due to the following error:
%%1053
 

CodeIntegrity:
===================================
  Date: 2015-10-09 22:38:12.203
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\dnsapi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-10-08 06:09:57.394
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\dnsapi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-10-08 06:09:57.369
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-10-08 06:09:57.338
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\dnsapi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-10-08 06:09:31.300
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\dnsapi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-10-08 06:09:31.281
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-10-08 06:09:31.224
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\dnsapi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-10-08 06:01:25.219
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\dnsapi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-10-08 06:00:17.077
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2015-10-08 06:00:17.042
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Windows\System32\dnsapi.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 

==================== Memory info ===========================
 
Processor: Intel® Core™ i5-2410M CPU @ 2.30GHz
Percentage of memory in use: 68%
Total physical RAM: 3947.86 MB
Available physical RAM: 1245.29 MB
Total Virtual: 7915.86 MB
Available Virtual: 4859.45 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:450.66 GB) (Free:345.5 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 526033AE)
Partition 1: (Not Active) - (Size=15 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=450.7 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

 

 


Edited by mistywjd, 10 October 2015 - 12:00 PM.

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi I will need additional runs to ensure that I get it all

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
HKLM-x32\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => No File
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => No File
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
ProxyServer: [HKLM] => 127.0.0.1:9091
ProxyServer: [HKLM-x32] => 127.0.0.1:9091
AutoConfigURL: [HKLM] => 127.0.0.1:9091
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
URLSearchHook: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 - (No Name) - {0633EE93-D776-472f-A0FF-E1416B8B2E3D} - No File
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
S4 BrsHelper; C:\PROGRA~2\YTDOWN~1\BROWSE~2.EXE [X]
S1 nqvxuyue; \??\C:\WINDOWS\system32\drivers\nqvxuyue.sys [X]
S2 sbmntr; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [X]
2015-10-06 22:00 - 2015-10-06 22:00 - 00055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rncmaqih.sys
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files (x86)\System Cleaner Pro
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files (x86)\Itibiti Soft Phone
CustomCLSID: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000_Classes\CLSID\{A9B6F3D2-A55A-4061-9F31-71970E5CE3E9}\InprocServer32 -> C:\Program Files (x86)\SpinBall\FFCB_IEAddon\adxloader64.dll ()
Task: {1FE10AA4-E496-4207-BA7E-1A5F2F748DA9} - \YTDownloaderUpd -> No File <==== ATTENTION
Task: {24153C4F-1501-4D78-939E-F3887B76F5A7} - \bvxvbxvd -> No File <==== ATTENTION
Task: {2B35341E-58B8-495B-AF97-E8F0687A5E38} - \YTDownloader -> No File <==== ATTENTION
Task: {2E67F01C-3553-40E0-A907-8A6F176605F5} - \PaintTool SAI -> No File <==== ATTENTION
Task: {47529FDE-C74C-4DE6-9682-9200DA923BD4} - \Notify Helper -> No File <==== ATTENTION
Task: {4CDAD28F-D583-468F-B667-2FFE6356202F} - \SmartWeb Upgrade Trigger Task -> No File <==== ATTENTION
Task: {4D693E52-0515-4FA1-8AE4-E36FF19222C0} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {55FC2B12-A712-4FAC-8760-0128CF6D2FEE} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {5D46809A-8869-4606-A198-B5FADA739E2F} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {62288D2C-2758-4446-85B1-E9F187F37733} - \SPBIW_UpdateTask_Time_333939363932333431332d5a376c5a4a6c573250344141 -> No File <==== ATTENTION
Task: {67958CCE-3DB1-4735-A3F4-2BA4557D7E65} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {7C9C84BB-49F2-42A0-8E25-392354C6C397} - \WordSurfer Auto Updater 1.10.0.19 Core -> No File <==== ATTENTION
Task: {7E5BF3F7-EDFF-4E52-A48A-A3DC317C43BA} - \WordSurfer Auto Updater 1.10.0.19 Pending Update -> No File <==== ATTENTION
Task: {830A2863-E81E-4877-AAD9-B579247EC3BA} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {89BB221D-DF91-4AF6-B785-FE601F3DE962} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {902C14BD-9365-4536-BB1A-39B79ED53A1E} - \System Cleaner Pro Auto Start -> No File <==== ATTENTION
Task: {A367959F-6398-4208-8BEA-FFEA61E70294} - System32\Tasks\{6EB71239-E329-4DC7-A8F3-A64AFDC138C2} => pcalua.exe -a "C:\Program Files (x86)\DailyPcClean Support\unins000.exe"
Task: {A6BA20F8-819D-42F2-BA40-AA8E07731D11} - \Jarmeee -> No File <==== ATTENTION
Task: {AD9DB6BB-1BE5-481B-8DA2-D88CA2820DE7} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {AE9EE3EE-775E-469B-B574-89FA8611079A} - \updateTask -> No File <==== ATTENTION
Task: {BC6BEFE2-E2C9-4683-9BB1-ED447830D7B9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {C5812387-F344-4101-AF50-F391FF880614} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {C8213448-346D-452D-81BA-AAA398B57DC5} - \4a752bbc-e718-4ff5-8948-5413ae8b7094 -> No File <==== ATTENTION
Task: {CC9322D8-8113-40E7-BC9C-D3CE404A3BB2} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {D01BAF9E-BB7E-44F4-BF6F-0695A078AB93} - \runTask -> No File <==== ATTENTION
Task: {D35AE52A-482C-4656-BFA0-429FDE04BD24} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {D875E597-84B7-4AAE-AE3A-7A71AB312978} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {DA781ED4-5DE4-4753-B292-F717851D6C7C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
AlternateDataStreams: C:\04bf7963418bedcfdde09dca48:Win32App
AlternateDataStreams: C:\3089b6a24ef724d145:Win32App
AlternateDataStreams: C:\318cab8197d210aa5c5e:Win32App
AlternateDataStreams: C:\419a2caadd4290847864:Win32App
AlternateDataStreams: C:\4f4fa18d4dd8f99f0ea6a6420281251a:Win32App
AlternateDataStreams: C:\65b66254bc6a4f7c7497ac9d8307:Win32App
AlternateDataStreams: C:\776e24d3f6aba141bb9c83b3fe63ae77:Win32App
AlternateDataStreams: C:\b9c13b78d128895b6e52:Win32App
AlternateDataStreams: C:\bd9118d39e1f207ee9cd6dcd0939:Win32App
AlternateDataStreams: C:\be8106b9bc95323fd268ba6235ad69:Win32App
AlternateDataStreams: C:\DOLBY PCEE4:Win32App
AlternateDataStreams: C:\Program Files\Bonjour:Win32App
AlternateDataStreams: C:\Program Files\Broadcom:Win32App
AlternateDataStreams: C:\Program Files\iTunes:Win32App
AlternateDataStreams: C:\Program Files\Microsoft Security Client:Win32App
AlternateDataStreams: C:\Program Files\Microsoft Silverlight:Win32App
AlternateDataStreams: C:\Program Files (x86)\Acer Games:Win32App
AlternateDataStreams: C:\Program Files (x86)\Apple Software Update:Win32App
AlternateDataStreams: C:\Program Files (x86)\Audacity:Win32App
AlternateDataStreams: C:\Program Files (x86)\Bonjour:Win32App
AlternateDataStreams: C:\Program Files (x86)\Broadcom:Win32App
AlternateDataStreams: C:\Program Files (x86)\EgisTec MyWinLocker:Win32App
AlternateDataStreams: C:\Program Files (x86)\EgisTec MyWinLockerSuite:Win32App
AlternateDataStreams: C:\Program Files (x86)\EgisTec Shredder:Win32App
AlternateDataStreams: C:\Program Files (x86)\Itibiti Soft Phone:Win32App
AlternateDataStreams: C:\Program Files (x86)\Launch Manager:Win32App
AlternateDataStreams: C:\Program Files (x86)\Microsoft SQL Server Compact Edition:Win32App
AlternateDataStreams: C:\Program Files (x86)\newsXpresso:Win32App
AlternateDataStreams: C:\Program Files (x86)\QuickTime:Win32App
AlternateDataStreams: C:\Program Files (x86)\System Cleaner Pro:Win32App
AlternateDataStreams: C:\Program Files (x86)\Times Reader:Win32App
AlternateDataStreams: C:\Program Files (x86)\Windows Live:Win32App
AlternateDataStreams: C:\Program Files (x86)\WinRAR:Win32App
AlternateDataStreams: C:\WINDOWS\SysWOW64:Win32App
AlternateDataStreams: C:\WINDOWS\system32\Drivers\rncmaqih.sys:changelist
AlternateDataStreams: C:\Program Files\Common Files\microsoft shared:Win32App
AlternateDataStreams: C:\ProgramData\regid.1991-06.com.microsoft:Win32App
AlternateDataStreams: C:\Users\Wendy\Desktop\REC:Win32App
AlternateDataStreams: C:\Users\Wendy\AppData\Local\Temp:Win32App
C:\Program Files (x86)\YTDownloader
C:\PROGRA~2\SearchProtect
C:\WINDOWS\system32\drivers\nqvxuyue.sys
C:\Program Files (x86)\MyPC Backup
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Uiviuuj => ""="service"
cmd: sfc /scanfile=C:\Windows\system32\dnsapi.dll
cmd: sfc /scanfile=C:\Windows\SysWOW64\dnsapi.dll
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.
FINALLY

Please run a fresh FRST scan
  • 0

#3
mistywjd

mistywjd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
Here is my fixlog. Will run AdCleaner now and post my results soon. Thank you!
 
Fix result of Farbar Recovery Scan Tool (x64) Version:10-10-2015
Ran by Wendy (2015-10-10 16:45:13) Run:1
Running from C:\Users\Wendy\Desktop
Loaded Profiles: Wendy (Available Profiles: Wendy)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
HKLM-x32\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [YTDownloader] => "C:\Program Files (x86)\YTDownloader\YTDownloader.exe" /boot
AppInit_DLLs: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll => No File
AppInit_DLLs-x32: C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll => No File
GroupPolicy: Restriction - Chrome <======= ATTENTION
CHR HKLM\SOFTWARE\Policies\Google: Restriction <======= ATTENTION
ProxyServer: [HKLM] => 127.0.0.1:9091
ProxyServer: [HKLM-x32] => 127.0.0.1:9091
AutoConfigURL: [HKLM] => 127.0.0.1:9091
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
URLSearchHook: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 - (No Name) - {0633EE93-D776-472f-A0FF-E1416B8B2E3D} - No File
BHO-x32: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
S4 BrsHelper; C:\PROGRA~2\YTDOWN~1\BROWSE~2.EXE [X]
S1 nqvxuyue; \??\C:\WINDOWS\system32\drivers\nqvxuyue.sys [X]
S2 sbmntr; \??\C:\PROGRA~2\YTDOWN~1\sbmntr.sys [X]
2015-10-06 22:00 - 2015-10-06 22:00 - 00055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rncmaqih.sys
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files (x86)\System Cleaner Pro
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files (x86)\Itibiti Soft Phone
CustomCLSID: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000_Classes\CLSID\{A9B6F3D2-A55A-4061-9F31-71970E5CE3E9}\InprocServer32 -> C:\Program Files (x86)\SpinBall\FFCB_IEAddon\adxloader64.dll ()
Task: {1FE10AA4-E496-4207-BA7E-1A5F2F748DA9} - \YTDownloaderUpd -> No File <==== ATTENTION
Task: {24153C4F-1501-4D78-939E-F3887B76F5A7} - \bvxvbxvd -> No File <==== ATTENTION
Task: {2B35341E-58B8-495B-AF97-E8F0687A5E38} - \YTDownloader -> No File <==== ATTENTION
Task: {2E67F01C-3553-40E0-A907-8A6F176605F5} - \PaintTool SAI -> No File <==== ATTENTION
Task: {47529FDE-C74C-4DE6-9682-9200DA923BD4} - \Notify Helper -> No File <==== ATTENTION
Task: {4CDAD28F-D583-468F-B667-2FFE6356202F} - \SmartWeb Upgrade Trigger Task -> No File <==== ATTENTION
Task: {4D693E52-0515-4FA1-8AE4-E36FF19222C0} - \Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd -> No File <==== ATTENTION
Task: {55FC2B12-A712-4FAC-8760-0128CF6D2FEE} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {5D46809A-8869-4606-A198-B5FADA739E2F} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {62288D2C-2758-4446-85B1-E9F187F37733} - \SPBIW_UpdateTask_Time_333939363932333431332d5a376c5a4a6c573250344141 -> No File <==== ATTENTION
Task: {67958CCE-3DB1-4735-A3F4-2BA4557D7E65} - System32\Tasks\LaunchSignup => C:\Program Files (x86)\MyPC Backup\Signup Wizard.exe <==== ATTENTION
Task: {7C9C84BB-49F2-42A0-8E25-392354C6C397} - \WordSurfer Auto Updater 1.10.0.19 Core -> No File <==== ATTENTION
Task: {7E5BF3F7-EDFF-4E52-A48A-A3DC317C43BA} - \WordSurfer Auto Updater 1.10.0.19 Pending Update -> No File <==== ATTENTION
Task: {830A2863-E81E-4877-AAD9-B579247EC3BA} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {89BB221D-DF91-4AF6-B785-FE601F3DE962} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {902C14BD-9365-4536-BB1A-39B79ED53A1E} - \System Cleaner Pro Auto Start -> No File <==== ATTENTION
Task: {A367959F-6398-4208-8BEA-FFEA61E70294} - System32\Tasks\{6EB71239-E329-4DC7-A8F3-A64AFDC138C2} => pcalua.exe -a "C:\Program Files (x86)\DailyPcClean Support\unins000.exe"
Task: {A6BA20F8-819D-42F2-BA40-AA8E07731D11} - \Jarmeee -> No File <==== ATTENTION
Task: {AD9DB6BB-1BE5-481B-8DA2-D88CA2820DE7} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {AE9EE3EE-775E-469B-B574-89FA8611079A} - \updateTask -> No File <==== ATTENTION
Task: {BC6BEFE2-E2C9-4683-9BB1-ED447830D7B9} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {C5812387-F344-4101-AF50-F391FF880614} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {C8213448-346D-452D-81BA-AAA398B57DC5} - \4a752bbc-e718-4ff5-8948-5413ae8b7094 -> No File <==== ATTENTION
Task: {CC9322D8-8113-40E7-BC9C-D3CE404A3BB2} - \Microsoft\Windows\Setup\gwx\refreshgwxcontent -> No File <==== ATTENTION
Task: {D01BAF9E-BB7E-44F4-BF6F-0695A078AB93} - \runTask -> No File <==== ATTENTION
Task: {D35AE52A-482C-4656-BFA0-429FDE04BD24} - \ShopperProJSUpd -> No File <==== ATTENTION
Task: {D875E597-84B7-4AAE-AE3A-7A71AB312978} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {DA781ED4-5DE4-4753-B292-F717851D6C7C} - \Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent -> No File <==== ATTENTION
AlternateDataStreams: C:\04bf7963418bedcfdde09dca48:Win32App
AlternateDataStreams: C:\3089b6a24ef724d145:Win32App
AlternateDataStreams: C:\318cab8197d210aa5c5e:Win32App
AlternateDataStreams: C:\419a2caadd4290847864:Win32App
AlternateDataStreams: C:\4f4fa18d4dd8f99f0ea6a6420281251a:Win32App
AlternateDataStreams: C:\65b66254bc6a4f7c7497ac9d8307:Win32App
AlternateDataStreams: C:\776e24d3f6aba141bb9c83b3fe63ae77:Win32App
AlternateDataStreams: C:\b9c13b78d128895b6e52:Win32App
AlternateDataStreams: C:\bd9118d39e1f207ee9cd6dcd0939:Win32App
AlternateDataStreams: C:\be8106b9bc95323fd268ba6235ad69:Win32App
AlternateDataStreams: C:\DOLBY PCEE4:Win32App
AlternateDataStreams: C:\Program Files\Bonjour:Win32App
AlternateDataStreams: C:\Program Files\Broadcom:Win32App
AlternateDataStreams: C:\Program Files\iTunes:Win32App
AlternateDataStreams: C:\Program Files\Microsoft Security Client:Win32App
AlternateDataStreams: C:\Program Files\Microsoft Silverlight:Win32App
AlternateDataStreams: C:\Program Files (x86)\Acer Games:Win32App
AlternateDataStreams: C:\Program Files (x86)\Apple Software Update:Win32App
AlternateDataStreams: C:\Program Files (x86)\Audacity:Win32App
AlternateDataStreams: C:\Program Files (x86)\Bonjour:Win32App
AlternateDataStreams: C:\Program Files (x86)\Broadcom:Win32App
AlternateDataStreams: C:\Program Files (x86)\EgisTec MyWinLocker:Win32App
AlternateDataStreams: C:\Program Files (x86)\EgisTec MyWinLockerSuite:Win32App
AlternateDataStreams: C:\Program Files (x86)\EgisTec Shredder:Win32App
AlternateDataStreams: C:\Program Files (x86)\Itibiti Soft Phone:Win32App
AlternateDataStreams: C:\Program Files (x86)\Launch Manager:Win32App
AlternateDataStreams: C:\Program Files (x86)\Microsoft SQL Server Compact Edition:Win32App
AlternateDataStreams: C:\Program Files (x86)\newsXpresso:Win32App
AlternateDataStreams: C:\Program Files (x86)\QuickTime:Win32App
AlternateDataStreams: C:\Program Files (x86)\System Cleaner Pro:Win32App
AlternateDataStreams: C:\Program Files (x86)\Times Reader:Win32App
AlternateDataStreams: C:\Program Files (x86)\Windows Live:Win32App
AlternateDataStreams: C:\Program Files (x86)\WinRAR:Win32App
AlternateDataStreams: C:\WINDOWS\SysWOW64:Win32App
AlternateDataStreams: C:\WINDOWS\system32\Drivers\rncmaqih.sys:changelist
AlternateDataStreams: C:\Program Files\Common Files\microsoft shared:Win32App
AlternateDataStreams: C:\ProgramData\regid.1991-06.com.microsoft:Win32App
AlternateDataStreams: C:\Users\Wendy\Desktop\REC:Win32App
AlternateDataStreams: C:\Users\Wendy\AppData\Local\Temp:Win32App
C:\Program Files (x86)\YTDownloader
C:\PROGRA~2\SearchProtect
C:\WINDOWS\system32\drivers\nqvxuyue.sys
C:\Program Files (x86)\MyPC Backup
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Uiviuuj => ""="service"
cmd: sfc /scanfile=C:\Windows\system32\dnsapi.dll
cmd: sfc /scanfile=C:\Windows\SysWOW64\dnsapi.dll
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
Reg: Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F
RemoveProxy:
CMD: netsh advfirewall reset
CMD: netsh advfirewall set allprofiles state ON
CMD: ipconfig /flushdns
CMD: netsh winsock reset catalog
CMD: netsh int ip reset c:\resetlog.txt
CMD: ipconfig /release
CMD: ipconfig /renew
CMD: netsh int ipv4 reset
CMD: netsh int ipv6 reset
EmptyTemp:
CMD: bitsadmin /reset /allusers
 
*****************
 
Restore point was successfully created.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\YTDownloader => value removed successfully
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\Microsoft\Windows\CurrentVersion\Run\\YTDownloader => value removed successfully
"C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC64Loader.dll" => Value data removed successfully.
"C:\PROGRA~2\SearchProtect\SearchProtect\bin\VC32Loader.dll" => Value data removed successfully.
C:\WINDOWS\system32\GroupPolicy\Machine => moved successfully
C:\WINDOWS\system32\GroupPolicy\GPT.ini => moved successfully
C:\WINDOWS\SysWOW64\GroupPolicy\GPT.ini => moved successfully
"HKLM\SOFTWARE\Policies\Google" => key removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer => value removed successfully
HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL => value not found.
"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{0633EE93-D776-472f-A0FF-E1416B8B2E3D} => value removed successfully
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}" => key removed successfully
HKCR\Wow6432Node\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670} => key not found.
BrsHelper => service removed successfully
nqvxuyue => service removed successfully
sbmntr => service removed successfully
C:\WINDOWS\system32\Drivers\rncmaqih.sys => moved successfully
C:\Program Files (x86)\System Cleaner Pro => moved successfully
C:\Program Files (x86)\Itibiti Soft Phone => moved successfully
"HKU\S-1-5-21-2389695071-1928321251-2773591669-1000_Classes\CLSID\{A9B6F3D2-A55A-4061-9F31-71970E5CE3E9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1FE10AA4-E496-4207-BA7E-1A5F2F748DA9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1FE10AA4-E496-4207-BA7E-1A5F2F748DA9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloaderUpd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{24153C4F-1501-4D78-939E-F3887B76F5A7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{24153C4F-1501-4D78-939E-F3887B76F5A7}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bvxvbxvd => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2B35341E-58B8-495B-AF97-E8F0687A5E38}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2B35341E-58B8-495B-AF97-E8F0687A5E38}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\YTDownloader" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2E67F01C-3553-40E0-A907-8A6F176605F5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2E67F01C-3553-40E0-A907-8A6F176605F5}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\PaintTool SAI => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{47529FDE-C74C-4DE6-9682-9200DA923BD4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{47529FDE-C74C-4DE6-9682-9200DA923BD4}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Notify Helper" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4CDAD28F-D583-468F-B667-2FFE6356202F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CDAD28F-D583-468F-B667-2FFE6356202F}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SmartWeb Upgrade Trigger Task => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{4D693E52-0515-4FA1-8AE4-E36FF19222C0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4D693E52-0515-4FA1-8AE4-E36FF19222C0}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Telemetry-4xd" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{55FC2B12-A712-4FAC-8760-0128CF6D2FEE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{55FC2B12-A712-4FAC-8760-0128CF6D2FEE}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Logon-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{5D46809A-8869-4606-A198-B5FADA739E2F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{5D46809A-8869-4606-A198-B5FADA739E2F}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\launchtrayprocess" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{62288D2C-2758-4446-85B1-E9F187F37733}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{62288D2C-2758-4446-85B1-E9F187F37733}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\SPBIW_UpdateTask_Time_333939363932333431332d5a376c5a4a6c573250344141 => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{67958CCE-3DB1-4735-A3F4-2BA4557D7E65}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{67958CCE-3DB1-4735-A3F4-2BA4557D7E65}" => key removed successfully
C:\WINDOWS\System32\Tasks\LaunchSignup => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\LaunchSignup" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7C9C84BB-49F2-42A0-8E25-392354C6C397}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7C9C84BB-49F2-42A0-8E25-392354C6C397}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WordSurfer Auto Updater 1.10.0.19 Core => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{7E5BF3F7-EDFF-4E52-A48A-A3DC317C43BA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{7E5BF3F7-EDFF-4E52-A48A-A3DC317C43BA}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\WordSurfer Auto Updater 1.10.0.19 Pending Update => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{830A2863-E81E-4877-AAD9-B579247EC3BA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{830A2863-E81E-4877-AAD9-B579247EC3BA}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{89BB221D-DF91-4AF6-B785-FE601F3DE962}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{89BB221D-DF91-4AF6-B785-FE601F3DE962}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{902C14BD-9365-4536-BB1A-39B79ED53A1E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{902C14BD-9365-4536-BB1A-39B79ED53A1E}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\System Cleaner Pro Auto Start" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A367959F-6398-4208-8BEA-FFEA61E70294} => key not found.
C:\WINDOWS\System32\Tasks\{6EB71239-E329-4DC7-A8F3-A64AFDC138C2} => not found.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{6EB71239-E329-4DC7-A8F3-A64AFDC138C2} => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{A6BA20F8-819D-42F2-BA40-AA8E07731D11}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A6BA20F8-819D-42F2-BA40-AA8E07731D11}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Jarmeee => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AD9DB6BB-1BE5-481B-8DA2-D88CA2820DE7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AD9DB6BB-1BE5-481B-8DA2-D88CA2820DE7}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\Time-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AE9EE3EE-775E-469B-B574-89FA8611079A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AE9EE3EE-775E-469B-B574-89FA8611079A}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\updateTask" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{BC6BEFE2-E2C9-4683-9BB1-ED447830D7B9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{BC6BEFE2-E2C9-4683-9BB1-ED447830D7B9}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C5812387-F344-4101-AF50-F391FF880614}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C5812387-F344-4101-AF50-F391FF880614}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfig" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C8213448-346D-452D-81BA-AAA398B57DC5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C8213448-346D-452D-81BA-AAA398B57DC5}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\4a752bbc-e718-4ff5-8948-5413ae8b7094" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CC9322D8-8113-40E7-BC9C-D3CE404A3BB2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CC9322D8-8113-40E7-BC9C-D3CE404A3BB2}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxcontent" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D01BAF9E-BB7E-44F4-BF6F-0695A078AB93}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D01BAF9E-BB7E-44F4-BF6F-0695A078AB93}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\runTask" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D35AE52A-482C-4656-BFA0-429FDE04BD24}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D35AE52A-482C-4656-BFA0-429FDE04BD24}" => key removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ShopperProJSUpd => key not found.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D875E597-84B7-4AAE-AE3A-7A71AB312978}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D875E597-84B7-4AAE-AE3A-7A71AB312978}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{DA781ED4-5DE4-4753-B292-F717851D6C7C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{DA781ED4-5DE4-4753-B292-F717851D6C7C}" => key removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent" => key removed successfully
C:\04bf7963418bedcfdde09dca48 => ":Win32App" ADS removed successfully.
C:\3089b6a24ef724d145 => ":Win32App" ADS removed successfully.
C:\318cab8197d210aa5c5e => ":Win32App" ADS removed successfully.
C:\419a2caadd4290847864 => ":Win32App" ADS removed successfully.
C:\4f4fa18d4dd8f99f0ea6a6420281251a => ":Win32App" ADS removed successfully.
C:\65b66254bc6a4f7c7497ac9d8307 => ":Win32App" ADS removed successfully.
C:\776e24d3f6aba141bb9c83b3fe63ae77 => ":Win32App" ADS removed successfully.
C:\b9c13b78d128895b6e52 => ":Win32App" ADS removed successfully.
C:\bd9118d39e1f207ee9cd6dcd0939 => ":Win32App" ADS removed successfully.
C:\be8106b9bc95323fd268ba6235ad69 => ":Win32App" ADS removed successfully.
C:\DOLBY PCEE4 => ":Win32App" ADS removed successfully.
C:\Program Files\Bonjour => ":Win32App" ADS removed successfully.
C:\Program Files\Broadcom => ":Win32App" ADS removed successfully.
C:\Program Files\iTunes => ":Win32App" ADS removed successfully.
C:\Program Files\Microsoft Security Client => ":Win32App" ADS removed successfully.
C:\Program Files\Microsoft Silverlight => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\Acer Games => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\Apple Software Update => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\Audacity => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\Bonjour => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\Broadcom => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\EgisTec MyWinLocker => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\EgisTec MyWinLockerSuite => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\EgisTec Shredder => ":Win32App" ADS removed successfully.
"C:\Program Files (x86)\Itibiti Soft Phone" => ":Win32App" ADS not found.
C:\Program Files (x86)\Launch Manager => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\Microsoft SQL Server Compact Edition => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\newsXpresso => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\QuickTime => ":Win32App" ADS removed successfully.
"C:\Program Files (x86)\System Cleaner Pro" => ":Win32App" ADS not found.
C:\Program Files (x86)\Times Reader => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\Windows Live => ":Win32App" ADS removed successfully.
C:\Program Files (x86)\WinRAR => ":Win32App" ADS removed successfully.
C:\WINDOWS\SysWOW64 => ":Win32App" ADS removed successfully.
"C:\WINDOWS\system32\Drivers\rncmaqih.sys" => ":changelist" ADS not found.
C:\Program Files\Common Files\microsoft shared => ":Win32App" ADS removed successfully.
C:\ProgramData\regid.1991-06.com.microsoft => ":Win32App" ADS removed successfully.
C:\Users\Wendy\Desktop\REC => ":Win32App" ADS removed successfully.
C:\Users\Wendy\AppData\Local\Temp => ":Win32App" ADS removed successfully.
"C:\Program Files (x86)\YTDownloader" => File/Folder not found.
"C:\PROGRA~2\SearchProtect" => File/Folder not found.
"C:\WINDOWS\system32\drivers\nqvxuyue.sys" => File/Folder not found.
"C:\Program Files (x86)\MyPC Backup" => File/Folder not found.
"HKLM\System\CurrentControlSet\Control\SafeBoot\Network\Uiviuuj" => key removed successfully
 
=========  sfc /scanfile=C:\Windows\system32\dnsapi.dll =========
 

 
 
 
 
 W i n d o w s   R e s o u r c e   P r o t e c t i o n   f o u n d   c o r r u p t   f i l e s   b u t   w a s   u n a b l e   t o   f i x   s o m e  
 
 
 o f   t h e m .   D e t a i l s   a r e   i n c l u d e d   i n   t h e   C B S . L o g   w i n d i r \ L o g s \ C B S \ C B S . l o g .   F o r  
 
 
 e x a m p l e   C : \ W i n d o w s \ L o g s \ C B S \ C B S . l o g .   N o t e   t h a t   l o g g i n g   i s   c u r r e n t l y   n o t  
 
 
 s u p p o r t e d   i n   o f f l i n e   s e r v i c i n g   s c e n a r i o s .
 
 
 
========= End of CMD: =========
 

=========  sfc /scanfile=C:\Windows\SysWOW64\dnsapi.dll =========
 

 
 
 
 
 W i n d o w s   R e s o u r c e   P r o t e c t i o n   f o u n d   c o r r u p t   f i l e s   b u t   w a s   u n a b l e   t o   f i x   s o m e  
 
 
 o f   t h e m .   D e t a i l s   a r e   i n c l u d e d   i n   t h e   C B S . L o g   w i n d i r \ L o g s \ C B S \ C B S . l o g .   F o r  
 
 
 e x a m p l e   C : \ W i n d o w s \ L o g s \ C B S \ C B S . l o g .   N o t e   t h a t   l o g g i n g   i s   c u r r e n t l y   n o t  
 
 
 s u p p o r t e d   i n   o f f l i n e   s e r v i c i n g   s c e n a r i o s .
 
 
 
========= End of CMD: =========
 

========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 

========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 

========= Reg Delete "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F =========
 
ERROR: The system was unable to find the specified registry key or value.
 

========= End of Reg: =========
 

========= Reg Add "HKLM\SOFTWARE\Microsoft\Shared Tools\MSConfig\startupreg" /F =========
 
The operation completed successfully.
 
 
 
========= End of Reg: =========
 

========= RemoveProxy: =========
 
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
 

========= End of RemoveProxy: =========
 

=========  netsh advfirewall reset =========
 
Ok.
 

========= End of CMD: =========
 

=========  netsh advfirewall set allprofiles state ON =========
 
Ok.
 

========= End of CMD: =========
 

=========  ipconfig /flushdns =========
 

Windows IP Configuration
 
Successfully flushed the DNS Resolver Cache.
 
========= End of CMD: =========
 

=========  netsh winsock reset catalog =========
 

Sucessfully reset the Winsock Catalog.
You must restart the computer in order to complete the reset.
 

========= End of CMD: =========
 

=========  netsh int ip reset c:\resetlog.txt =========
 
Resetting Interface, OK!
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting , failed.
Access is denied.
 
Resetting , OK!
Restart the computer to complete this action.
 

========= End of CMD: =========
 

=========  ipconfig /release =========
 

Windows IP Configuration
 
No operation can be performed on Local Area Connection while it has its media disconnected.
 
Ethernet adapter Local Area Connection:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
 
Wireless LAN adapter Wireless Network Connection:
 
   Connection-specific DNS Suffix  . :
   IPv6 Address. . . . . . . . . . . : 2601:85:4500:12c0::5
   IPv6 Address. . . . . . . . . . . : 2601:85:4500:12c0:642a:f912:24f1:c827
   Temporary IPv6 Address. . . . . . : 2601:85:4500:12c0:50e4:7c70:d5e1:7eda
   Link-local IPv6 Address . . . . . : fe80::642a:f912:24f1:c827%4
   Default Gateway . . . . . . . . . : fe80::e288:5dff:fe38:4056%4
 
========= End of CMD: =========
 

=========  ipconfig /renew =========
 

Windows IP Configuration
 
No operation can be performed on Local Area Connection while it has its media disconnected.
 
Ethernet adapter Local Area Connection:
 
   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
 
Wireless LAN adapter Wireless Network Connection:
 
   Connection-specific DNS Suffix  . :
   IPv6 Address. . . . . . . . . . . : 2601:85:4500:12c0::5
   IPv6 Address. . . . . . . . . . . : 2601:85:4500:12c0:642a:f912:24f1:c827
   Temporary IPv6 Address. . . . . . : 2601:85:4500:12c0:50e4:7c70:d5e1:7eda
   Link-local IPv6 Address . . . . . : fe80::642a:f912:24f1:c827%4
   IPv4 Address. . . . . . . . . . . : 10.0.0.3
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . : fe80::e288:5dff:fe38:4056%4
                                       10.0.0.1
 
========= End of CMD: =========
 

=========  netsh int ipv4 reset =========
 
Resetting Interface, OK!
Resetting , failed.
Access is denied.
 
Restart the computer to complete this action.
 

========= End of CMD: =========
 

=========  netsh int ipv6 reset =========
 
Resetting Neighbor, OK!
Resetting Path, OK!
Resetting , failed.
Access is denied.
 
Resetting , OK!
Resetting , OK!
Restart the computer to complete this action.
 

========= End of CMD: =========
 

=========  bitsadmin /reset /allusers =========
 

BITSADMIN version 3.0 [ 7.8.10240 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
Unable to cancel {2B43653C-7876-4832-A1F8-25A1A3749AA1}.
Unable to cancel {47C853B3-743C-4833-ABFF-46F61BC57715}.
Unable to cancel {1225C430-96F2-43BD-B967-BFAC765A3AD0}.
Unable to cancel {6E204D35-3B10-4EF8-A078-6C2D5CC49937}.
Unable to cancel {4F844797-328C-457B-9E0A-9F501EB488C6}.
Unable to cancel {4D5BE532-21A4-4DCA-84D7-D0A28A032EC4}.
Unable to cancel {FFFEA128-821D-417C-8B25-EEB0E71B641B}.
Unable to cancel {C1B930B1-7DC5-4CC5-897E-B88F32A3C6CD}.
{32C7FAF3-9B61-4FDE-B3F8-CB4DAEC7C658} canceled.
{02AF828D-A0D6-42C7-9CC5-13C6853D61BD} canceled.
{4527E915-F220-40C1-AAC3-FEACF0F45D78} canceled.
{B1B1FB31-9102-4A4B-9834-651088807391} canceled.
{39E10693-4ED3-429F-B71A-84181597F1FD} canceled.
{6BA90659-8182-4D97-B3DA-05FF8DAA9395} canceled.
{05C24628-48E3-4C1A-816A-002732AC3D01} canceled.
{EC00873D-2980-497B-850C-2FDD9B3F31BF} canceled.
{0F63D4DF-0865-45E3-B08D-7E6489A91111} canceled.
{A6A9F702-0FAF-4CF0-93F4-44C1552FB1A0} canceled.
10 out of 18 jobs canceled.
 
========= End of CMD: =========
 
EmptyTemp: => 422.8 MB temporary data Removed.
 

The system needed a reboot.
 
==== End of Fixlog 16:48:39 ====


  • 0

#4
mistywjd

mistywjd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

Here is the AdWare log and Fresh FRST Scan. Also, Windows defender keeps turning on and trying to quarantine dnsapi.dll.  Do you recommend keeping windows defender off for now? Thank you again for helping!

 

 

Adware Log

 

# AdwCleaner v5.013 - Logfile created 10/10/2015 at 17:18:20
# Updated 09/10/2015 by Xplode
# Database : 2015-10-04.3 [Local]
# Operating system : Windows 10 Home  (x64)
# Username : Wendy - NOTEBOOK
# Running from : C:\Users\Wendy\Desktop\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum
 
***** [ Services ] *****
 

***** [ Folders ] *****
 
[-] Folder Deleted : C:\Program Files (x86)\comcasttb
[-] Folder Deleted : C:\Program Files (x86)\xfin_portal
[-] Folder Deleted : C:\ProgramData\28341ff220e0446c9fff27c4493d622e
[-] Folder Deleted : C:\Users\Wendy\AppData\LocalLow\comcasttb
 
***** [ Files ] *****
 
[-] File Deleted : C:\Users\Public\Desktop\eBay.lnk
 
***** [ DLLs ] *****
 
[!] File Not Disinfected : C:\WINDOWS\SysNative\dnsapi.dll
 
***** [ Shortcuts ] *****
 
[-] Shortcut Disinfected : C:\Users\Wendy\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\W?rld?f??nks.lnk
 
***** [ Scheduled tasks ] *****
 

***** [ Registry ] *****
 
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\CptUrlPassthru.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\dca-bho.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho
[-] Key Deleted : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\YTDownloader.exe
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{0014298C-A9BA-440D-AAA8-AD12C7010EE5}
[-] Key Deleted : HKLM\SYSTEM\CurrentControlSet\Control\Class\{181A06EA-B82C-47DE-B851-E20FD0E1CC7D}
[-] Value Deleted : HKLM\SOFTWARE\Classes\.xht\OpenWithProgIDs [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\Classes\.webp\OpenWithProgIDs [CRSBRWSHTML]
[-] Value Deleted : HKLM\SOFTWARE\Classes\.shtml\OpenWithProgIDs [CRSBRWSHTML]
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Key Deleted : HKLM\SOFTWARE\Classes\Crossbrowse
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{A57F7191-1E7F-4852-BAAF-F80A43E2687A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{DD7C44CC-0F60-4FD9-A38F-5CF30D698AC2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{425F4ABF-B8E4-402D-9E49-06E494EB8DBF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{0214A12B-C5A3-437F-A6F3-068ABCD8C85E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{058F0E48-61CA-4964-9FBA-1978A1BB060D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{08635077-8829-49E2-B338-C968817EB460}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{18F33C35-8EF2-40D7-8BA4-932B0121B472}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{20A3F109-F7C1-47B4-8098-8E654B264B1D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3278F5CF-48F3-4253-A6BB-004CE84AF492}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3B5702BA-7F4C-4D1A-B026-1E9A01D43978}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{577975B8-C40E-43E6-B0DE-4C6B44088B52}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{69F256DF-BA98-45E9-86EA-FC3CFECF9D30}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6E87FC94-9866-49B9-8E93-5736D6DE3DD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E49F793-B3CD-4BF7-8419-B34B8BD30E61}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{834469E3-CA2B-4F21-A5CA-4F6F4DBCDE87}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8529FAA3-5BFD-43C1-AB35-B53C4B96C6E5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{8C7478AB-3155-463E-936F-55F91F0F10D0}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ADBC39BE-3D20-4333-8D99-E91EB1B62474}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E06CA7F5-BA34-4FF6-8D24-B1BDC594D91F}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F6421EE5-A5BE-4D31-81D5-C16B7BF48E4C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD8E81D0-F5FE-4CB1-9AEA-1E163D2BAB78}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7D8DAE88-BC05-4578-8C29-E541FFBA5757}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6EDBF8C0-C94C-4A13-956F-E393BCA5BA4B}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{61AB12E1-A5FF-11D1-B2E9-444553540000}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{82351441-9094-11D1-A24B-00A0C932C7DF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2A563926-CF4B-4363-A760-F71E46205B7E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{357D32FC-F0AE-4B37-B36F-D44AA31496F5}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{80B3B43F-7508-4627-BE66-00FB9AE5EE72}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A8F7D0A5-7074-40B8-9BDC-1174BDD0A132}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D14D64BC-A0E4-42E3-BB72-FB41EA43C198}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{DD1F043F-ABC8-4643-8B95-D2C5B22BB019}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E3F3E8F9-F747-4DD6-BA6B-82A6CE1E0860}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{ED0B64D4-BF27-4521-AD27-190F49BF5EA7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{023E9EC8-B147-40EB-B0B3-DF90618FB371}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0522D9A4-4D57-437D-978D-E5B3B6C9005D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{07F41522-AF7D-4F26-B394-094F059FDB8A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0C40F472-7407-4467-8914-1DEA7C326972}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{212E6D43-6062-492A-B8CC-144669FF11ED}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{224FE662-1E6D-4BC0-AEBB-9E2FB4057BE9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3A807417-B46D-4D37-8C9A-19AC6DE204F9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3CC60715-D6C5-429D-830E-43FA3F86C61D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4517D94C-19BA-46FA-BE66-2A30CEAC4A85}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{555D7146-94A8-4C94-AE76-C39CDC7F7705}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{59D188FA-757A-424E-8C93-F58FFD896BD7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{8120D9D6-785C-4413-9C0C-DF2028C56FAD}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{823AE2EB-E62C-4847-B192-C99B91B92416}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B4F7CFE-987D-410E-A8E4-20182E0B3C24}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9B9A45F4-18FC-484A-BACA-076D78273D8E}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A6D54287-7939-466A-8579-92546D946C8C}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A78EDAFB-926F-4D93-AB13-8232D7378EB1}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{68DE31F7-43FF-4EE2-B88B-10665016970D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{82351433-9094-11D1-A24B-00A0C932C7DF}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{5A83D7C9-4A14-4000-BC05-389268238753}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{4B9BCCE8-A70B-402A-A7E1-DB96831EE26F}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{5645E0E7-FC12-43BF-A6E4-F9751942B298}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{C7BF8F4B-7BC7-4F42-B944-3D28A3A86D8A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Ext\CLSID [{3593C8B9-8E18-4B4B-B7D3-CB8BEB1AA42C}]
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{5E89ACE9-E16B-499A-87B4-0DBF742404C1}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{96DD9437-5D20-4EFB-BF52-A4A605A4E0AA}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{357D32FC-F0AE-4B37-B36F-D44AA31496F5}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{80B3B43F-7508-4627-BE66-00FB9AE5EE72}
[-] Key Deleted : [x64] HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2E00D31D-D171-423D-836D-1A4D7EA7F1A9}
[-] Key Deleted : HKU\.DEFAULT\Software\PennyBee
[-] Key Deleted : HKU\.DEFAULT\Software\Yahoo\Companion
[-] Key Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\Compete
[-] Key Deleted : HKCU\Software\GlobalUpdate
[-] Key Deleted : HKCU\Software\IM
[-] Key Deleted : HKCU\Software\InstalledBrowserExtensions
[-] Key Deleted : HKCU\Software\pc optimizer pro
[-] Key Deleted : HKCU\Software\SoftwareUpdater
[-] Key Deleted : HKCU\Software\Tutorials
[-] Key Deleted : HKCU\Software\YTDownloader
[-] Key Deleted : HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
[-] Key Deleted : HKCU\Software\DAILYPCCLEAN
[-] Key Deleted : HKCU\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\xfin_portal
[-] Key Deleted : HKCU\Software\AppDataLow\Software\SmartWeb
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\AppDataLow\SOFTWARE\_CrossriderRegNamePlaceHolder_
[-] Key Deleted : HKLM\SOFTWARE\GlobalUpdate
[-] Key Deleted : HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : HKLM\SOFTWARE\V9Software
[-] Key Deleted : HKLM\SOFTWARE\YTDownloader
[-] Key Deleted : HKLM\SOFTWARE\BoostSoftware
[-] Key Deleted : HKLM\SOFTWARE\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ShopperPro
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\YTDownloader
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\FlashBeat
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{7ADF667E-E14D-4D2C-827C-B0108F0D93BC}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SU
[!] Key Not Deleted : [x64] HKCU\Software\GlobalUpdate
[!] Key Not Deleted : [x64] HKCU\Software\IM
[!] Key Not Deleted : [x64] HKCU\Software\InstalledBrowserExtensions
[!] Key Not Deleted : [x64] HKCU\Software\pc optimizer pro
[!] Key Not Deleted : [x64] HKCU\Software\SoftwareUpdater
[!] Key Not Deleted : [x64] HKCU\Software\Tutorials
[!] Key Not Deleted : [x64] HKCU\Software\YTDownloader
[!] Key Not Deleted : [x64] HKCU\Software\{3BDFD1D7-7A9B-4D29-80B3-D00E66E62885}
[!] Key Not Deleted : [x64] HKCU\Software\DAILYPCCLEAN
[!] Key Not Deleted : [x64] HKCU\Software\Yahoo\Companion
[!] Key Not Deleted : [x64] HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : [x64] HKLM\SOFTWARE\InstalledBrowserExtensions
[-] Key Deleted : [x64] HKLM\SOFTWARE\ShopperPro
[!] Key Not Deleted : HKU\.DEFAULT\Software\AppDataLow\Software\Compete
[!] Key Not Deleted : HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\AppDataLow\Software\xfin_portal
[!] Key Not Deleted : HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\AppDataLow\Software\SmartWeb
[!] Key Not Deleted : HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\AppDataLow\Software\Yahoo\Companion
[!] Key Not Deleted : HKU\S-1-5-18\Software\AppDataLow\Software\Compete
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [CustomizeSearch]
[-] Data Restored : HKLM\SOFTWARE\Microsoft\Internet Explorer\Search [SearchAssistant]
 
***** [ Web browsers ] *****
 

*************************
 
:: Winsock settings cleared
 
########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [12184 bytes] ##########
 
Fresh FRST Scan
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:10-10-2015
Ran by Wendy (administrator) on NOTEBOOK (10-10-2015 17:30:19)
Running from C:\Users\Wendy\Desktop
Loaded Profiles: Wendy (Available Profiles: Wendy)
Platform: Windows 10 Home (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(AVerMedia TECHNOLOGIES, Inc.) C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Microsoft Corporation) C:\Windows\System32\wuapihost.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdge.exe
(Microsoft Corporation) C:\Windows\System32\browser_broker.exe
(Microsoft Corporation) C:\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe
 

==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-23] (Acer Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3935912 2015-08-03] (Synaptics Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340336 2010-09-27] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-09-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-09-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-02-18] (CyberLink Corp.)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [79192 2011-02-18] (Research In Motion Limited)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [InstaLAN] => C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe [1885088 2012-02-23] (Affinegy, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [ComcastAntispyClient] => "C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" /hide
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [KSS] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202080 2014-06-15] (Kaspersky Lab ZAO)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\RunOnce: [Uninstall C:\Users\Wendy\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Wendy\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64"
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [805888 2015-07-10] (Microsoft Corporation)
Startup: C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2012-08-02]
ShortcutTarget: Dropbox.lnk -> C:\Users\Wendy\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2014-04-05]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{5b4fc3c7-a4fe-466a-ad1a-8982deeffde7}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{ec165e47-7983-45dc-b201-36594d8a9bc9}: [DhcpNameServer] 192.168.2.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237268288&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237273679&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237285619&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 -> {D62E54FD-024A-4A46-BB39-0AEECC058C51} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-08-04] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-24] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-11] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-25] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-25] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-24] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-03-03] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2011-05-26] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\7\NP_wtapp.dll [2013-12-27] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
 
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AffinegyService; C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe [563104 2012-02-23] (Affinegy, Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 AVerRECentral; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe [373248 2014-01-16] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2774104 2015-09-11] (Microsoft Corporation)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2013-12-16] (WildTangent)
S3 ITMRTSVC; C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe [283912 2007-09-26] (CA, Inc.)
S2 KSS; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202080 2014-06-15] (Kaspersky Lab ZAO)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-03] (Microsoft Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2015-08-03] (Synaptics Incorporated)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-03] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-03] (Microsoft Corporation)
S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S4 AntiSpywareService; C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-20] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-03] (Microsoft Corporation)
R3 RimVSerPort; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2015-08-03] (Synaptics Incorporated)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S1 rncmaqih; \??\C:\WINDOWS\system32\drivers\rncmaqih.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 

==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-10-10 17:22 - 2015-10-10 17:22 - 00016148 _____ C:\WINDOWS\system32\NOTEBOOK_Wendy_HistoryPrediction.bin
2015-10-10 17:13 - 2015-10-10 17:18 - 00000000 ____D C:\AdwCleaner
2015-10-10 17:04 - 2015-10-10 17:04 - 01682432 _____ C:\Users\Wendy\Desktop\AdwCleaner.exe
2015-10-10 16:44 - 2015-10-10 16:44 - 00000000 ____D C:\Users\Wendy\Desktop\FRST-OlderVersion
2015-10-10 16:27 - 2015-10-10 16:27 - 00003216 _____ C:\WINDOWS\System32\Tasks\4a752bbc-e718-4ff5-8948-5413ae8b7094
2015-10-10 13:25 - 2015-10-10 13:25 - 00002901 _____ C:\Users\Wendy\Downloads\wendy's list.txt
2015-10-09 22:37 - 2015-10-09 22:37 - 00000000 ____D C:\Users\Wendy\Downloads\FRST-OlderVersion
2015-10-08 06:09 - 2015-10-08 06:09 - 00159298 _____ C:\Users\Wendy\Desktop\Shortcut.txt
2015-10-08 06:07 - 2015-10-09 23:48 - 00054433 _____ C:\Users\Wendy\Desktop\Addition.txt
2015-10-08 06:02 - 2015-10-10 17:30 - 00021178 _____ C:\Users\Wendy\Desktop\FRST.txt
2015-10-08 06:01 - 2015-10-08 06:01 - 02870984 _____ (ESET) C:\Users\Wendy\Desktop\esetsmartinstaller_enu.exe
2015-10-08 05:59 - 2015-10-10 17:30 - 00000000 ____D C:\FRST
2015-10-08 05:59 - 2015-10-10 16:44 - 02195456 _____ (Farbar) C:\Users\Wendy\Desktop\FRST64.exe
2015-10-05 00:08 - 2015-10-05 00:08 - 00000017 _____ C:\Users\Wendy\AppData\Local\resmon.resmoncfg
2015-10-04 13:49 - 2015-10-04 14:03 - 2421989376 _____ C:\Users\Wendy\Downloads\O365HomePremRetail.img
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v4.5 Classic
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v4.5
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v2.0
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Local\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Local\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Local\Adobe
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v4.5\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v4.5 Classic\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v2.0\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 __RSD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 __RSD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\Classic .NET AppPool
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0 Classic
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Macromedia
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Intel Corporation
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\InstallShield
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Windows Live
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Downloaded Installations
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Macromedia
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Intel Corporation
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\InstallShield
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Local\Windows Live
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Local\Adobe
2015-10-04 13:30 - 2011-04-06 16:20 - 00057560 _____ C:\Users\Classic .NET AppPool\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:30 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v2.0 Classic\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:29 - 2015-10-04 13:29 - 00000000 ____D C:\Program Files\Windows Identity Foundation
2015-10-04 12:31 - 2015-10-04 12:31 - 00000000 ____D C:\Users\Wendy\AppData\Local\Google
2015-10-04 11:36 - 2015-10-04 11:36 - 00997927 _____ C:\Users\Wendy\Downloads\O15CTRRemove.diagcab
2015-10-03 22:22 - 2015-10-03 22:22 - 00000000 ____D C:\Program Files\DisplayLink Graphics
2015-10-03 22:20 - 2015-10-05 22:10 - 00000000 ____D C:\Program Files\DisplayLink Core Software
2015-10-03 22:20 - 2015-10-03 22:21 - 00002930 _____ C:\WINDOWS\system32\MsiExec.log
2015-10-03 21:02 - 2015-10-03 21:02 - 00000000 ____D C:\$SysReset
2015-10-03 19:20 - 2015-10-03 19:20 - 00038563 _____ C:\Users\Wendy\Downloads\cssemerg69697.diagcab
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files\Microsoft Security Client
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files (x86)\Broadcom
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\be8106b9bc95323fd268ba6235ad69
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\bd9118d39e1f207ee9cd6dcd0939
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\b9c13b78d128895b6e52
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\776e24d3f6aba141bb9c83b3fe63ae77
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\65b66254bc6a4f7c7497ac9d8307
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\4f4fa18d4dd8f99f0ea6a6420281251a
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\419a2caadd4290847864
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\318cab8197d210aa5c5e
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\3089b6a24ef724d145
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\04bf7963418bedcfdde09dca48
2015-09-20 18:39 - 2015-09-20 18:39 - 00001040 _____ C:\Users\Wendy\Desktop\9-20-15.txt
2015-09-17 18:55 - 2015-09-17 18:55 - 00003780 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0e826fa18e252
2015-09-13 15:51 - 2015-09-01 21:20 - 00077400 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-09-13 15:51 - 2015-09-01 20:25 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-09-13 15:51 - 2015-09-01 20:25 - 01382912 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-09-13 15:51 - 2015-08-27 02:36 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-13 15:51 - 2015-08-27 02:32 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-13 15:51 - 2015-08-27 02:04 - 21874688 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-09-13 15:51 - 2015-08-27 01:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-13 15:51 - 2015-08-27 01:55 - 24594944 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-09-13 15:51 - 2015-08-27 01:54 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-13 15:51 - 2015-08-27 01:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-13 15:51 - 2015-08-27 01:51 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-13 15:51 - 2015-08-27 01:51 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-13 15:51 - 2015-08-27 01:49 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-13 15:51 - 2015-08-27 01:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-13 15:51 - 2015-08-27 01:43 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-13 15:51 - 2015-08-27 01:43 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00578560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-09-13 15:51 - 2015-08-27 01:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-13 15:51 - 2015-08-27 01:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-13 15:51 - 2015-08-27 01:23 - 19324416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-09-13 15:51 - 2015-08-27 01:23 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-13 15:51 - 2015-08-27 01:16 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-09-13 15:51 - 2015-08-27 01:16 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-13 15:51 - 2015-08-27 01:16 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-13 15:51 - 2015-08-27 01:12 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-13 15:51 - 2015-08-27 01:12 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-13 15:51 - 2015-08-27 01:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-13 15:51 - 2015-08-27 01:11 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-13 15:51 - 2015-08-27 01:09 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-13 15:51 - 2015-08-27 01:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-10-10 17:29 - 2012-06-17 10:30 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-10 17:24 - 2011-10-08 22:42 - 00000000 ____D C:\ProgramData\clear.fi
2015-10-10 17:23 - 2015-09-05 18:05 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0e826fa18e252.job
2015-10-10 17:23 - 2015-01-25 17:58 - 00000000 ___RD C:\Users\Wendy\iCloudDrive
2015-10-10 17:23 - 2013-02-21 22:12 - 00000894 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-10 17:21 - 2015-07-10 08:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-10 17:20 - 2015-07-10 08:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-10 17:20 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-10 17:20 - 2015-07-10 05:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-10-10 17:02 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-10 17:01 - 2013-02-21 22:12 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-10 16:51 - 2015-09-05 19:15 - 00007334 _____ C:\WINDOWS\PFRO.log
2015-10-10 16:51 - 2014-08-18 12:55 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-10-10 16:50 - 2014-03-03 18:27 - 00000000 ____D C:\Users\Wendy\OneDrive
2015-10-10 16:46 - 2013-12-31 22:12 - 00000000 ____D C:\Users\Wendy\AppData\LocalLow\Temp
2015-10-10 16:45 - 2015-08-20 14:37 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2015-10-10 16:45 - 2009-07-13 23:20 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2015-10-10 16:36 - 2013-02-21 22:12 - 00003468 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-10-10 16:33 - 2011-05-14 10:09 - 00003410 _____ C:\WINDOWS\System32\Tasks\clear.fiAgent
2015-10-10 14:58 - 2011-12-25 20:30 - 00004154 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896}
2015-10-09 20:09 - 2015-08-03 17:35 - 01006528 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-06 10:38 - 2015-07-10 06:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-06 10:29 - 2015-08-03 17:37 - 00000000 ____D C:\Users\Wendy
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 __RSD C:\WINDOWS\Media
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\system32\Nui
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system\Speech
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\IME
2015-10-06 10:20 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\rescache
2015-10-06 10:20 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-10-06 10:20 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\servicing
2015-10-06 10:20 - 2013-03-06 21:38 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-10-06 10:19 - 2015-08-03 18:04 - 00000000 ____D C:\Users\Wendy\AppData\Local\Packages
2015-10-06 10:19 - 2015-08-03 17:37 - 00000000 ___RD C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-06 10:19 - 2011-10-08 22:16 - 00000000 ____D C:\Users\Wendy\AppData\Local\PowerCinema
2015-10-06 10:17 - 2015-07-10 07:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-10-06 10:17 - 2015-03-21 09:56 - 00000000 ____D C:\Users\Wendy\AppData\Local\Microsoft Help
2015-10-06 10:17 - 2014-03-03 18:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-10-06 10:17 - 2014-03-03 18:17 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-10-06 10:17 - 2013-03-06 21:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
2015-10-06 10:17 - 2013-03-06 21:38 - 00000000 ____D C:\Program Files\Microsoft Office
2015-10-06 10:17 - 2013-03-06 21:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client
2015-10-06 10:17 - 2013-02-21 22:13 - 00000000 ____D C:\Program Files\Google
2015-10-06 10:17 - 2013-02-21 22:12 - 00000000 ____D C:\Program Files (x86)\Google
2015-10-06 10:17 - 2011-05-14 10:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-10-06 10:17 - 2011-04-06 17:00 - 00000000 ____D C:\ProgramData\BackupManager
2015-10-06 10:05 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\registration
2015-10-06 10:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-10-06 10:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SystemResources
2015-10-06 09:59 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-10-06 09:58 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-10-06 09:58 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-10-06 09:57 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-10-06 09:55 - 2013-03-06 21:39 - 00000000 ____D C:\Users\Wendy\AppData\Roaming\SoftGrid Client
2015-10-06 09:34 - 2015-08-03 21:18 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-10-06 09:34 - 2015-07-10 09:14 - 00000000 ____D C:\Program Files\Windows Journal
2015-10-06 09:34 - 2015-07-10 07:04 - 00000000 ____D C:\Program Files\Windows NT
2015-10-06 09:34 - 2013-03-14 03:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-10-06 09:30 - 2015-08-03 21:18 - 00000000 ____D C:\inetpub
2015-10-06 09:30 - 2011-04-06 16:56 - 00000000 ___HD C:\OEM
2015-10-06 09:30 - 2011-04-06 16:55 - 00000000 ____D C:\Program Files (x86)\EgisTec Shredder
2015-10-06 09:30 - 2011-04-06 16:54 - 00000000 ____D C:\Program Files (x86)\EgisTec MyWinLocker
2015-10-06 09:30 - 2011-04-06 16:53 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-10-06 09:30 - 2011-04-06 16:52 - 00000000 ____D C:\Program Files (x86)\Windows Live
2015-10-06 09:30 - 2011-04-06 16:21 - 00000000 ____D C:\Program Files (x86)\Acer Games
2015-10-04 22:04 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-04 13:31 - 2015-08-03 17:35 - 00042366 _____ C:\WINDOWS\iis.log
2015-10-03 18:54 - 2013-03-06 21:38 - 00000000 ____D C:\Users\Wendy\AppData\Roaming\TP
2015-10-01 18:25 - 2015-07-10 08:20 - 00018136 _____ C:\WINDOWS\setupact.log
2015-09-27 15:46 - 2015-09-07 18:52 - 00000000 ____D C:\Users\Wendy\AppData\Local\Comms
2015-09-21 00:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-09-20 23:22 - 2011-10-08 22:15 - 00000000 ____D C:\Users\Wendy\AppData\Local\VirtualStore
2015-09-20 20:41 - 2015-07-10 08:20 - 00336488 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-20 20:21 - 2013-08-15 03:01 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-20 18:46 - 2015-08-23 20:31 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-20 18:39 - 2015-08-03 18:13 - 00002378 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-09-20 18:39 - 2015-08-03 18:09 - 00001331 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan.lnk
2015-09-20 18:39 - 2015-08-03 18:07 - 00001313 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Realtek HD Audio Manager.lnk
2015-09-20 18:39 - 2015-08-03 17:46 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002425 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002289 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002287 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00001578 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00000853 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop.lnk
2015-09-20 18:39 - 2015-03-21 09:27 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-09-20 18:39 - 2014-08-18 02:33 - 00001015 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2015-09-20 18:39 - 2014-07-12 18:05 - 00001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-09-20 18:39 - 2014-03-03 18:27 - 00002162 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-09-20 18:39 - 2012-10-14 10:52 - 00001866 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fooz Kids.lnk
2015-09-20 18:39 - 2011-12-02 19:21 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-09-20 18:39 - 2011-10-08 22:16 - 00000915 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Times Reader.lnk
2015-09-20 18:39 - 2011-05-14 10:14 - 00002478 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2015-09-20 18:39 - 2011-04-06 16:52 - 00001450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-09-20 18:38 - 2015-09-07 14:00 - 00000989 _____ C:\Users\Wendy\Desktop\CBS.log - Shortcut.lnk
2015-09-20 18:38 - 2015-08-23 20:31 - 00001173 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-20 18:38 - 2015-07-18 15:05 - 00001751 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-09-20 18:38 - 2015-07-18 14:54 - 00001843 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2015-09-20 18:38 - 2015-03-21 09:27 - 00002017 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-09-20 18:38 - 2014-08-18 02:34 - 00001015 _____ C:\Users\Wendy\Desktop\Audacity.lnk
2015-09-20 18:38 - 2014-07-26 09:52 - 00001211 _____ C:\Users\Wendy\Desktop\Kaspersky Security Scan.lnk
2015-09-20 18:38 - 2014-07-12 18:59 - 00001216 _____ C:\Users\Public\Desktop\XSplit Gamecaster.lnk
2015-09-20 18:38 - 2014-07-12 18:05 - 00001297 _____ C:\Users\Wendy\Desktop\Movie Maker.lnk
2015-09-20 18:38 - 2014-07-12 17:52 - 00002691 _____ C:\Users\Public\Desktop\Skype.lnk
2015-09-20 18:38 - 2014-07-11 19:19 - 00002151 _____ C:\Users\Public\Desktop\AVerMedia RECentral.lnk
2015-09-20 18:38 - 2012-10-14 10:52 - 00001860 _____ C:\Users\Public\Desktop\Fooz Kids.lnk
2015-09-20 18:38 - 2011-10-16 14:23 - 00002229 _____ C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
2015-09-20 18:38 - 2011-10-08 22:17 - 00001962 _____ C:\Users\Public\Desktop\Netflix.lnk
2015-09-20 18:38 - 2011-10-08 22:16 - 00000909 _____ C:\Users\Public\Desktop\Times Reader.lnk
2015-09-20 18:38 - 2011-05-14 10:11 - 00001206 _____ C:\Users\Public\Desktop\NOOK for PC.lnk
2015-09-20 18:38 - 2011-05-14 10:09 - 00002165 _____ C:\Users\Public\Desktop\clear.fi.lnk
2015-09-20 18:38 - 2011-04-06 16:57 - 00001984 _____ C:\Users\Public\Desktop\Norton Online Backup.lnk
2015-09-20 18:38 - 2011-04-06 16:51 - 00002727 _____ C:\Users\Public\Desktop\clear.fi Tutorial.lnk
2015-09-20 18:38 - 2011-04-06 16:20 - 00002562 _____ C:\Users\Public\Desktop\WildTangent Games App - acer.lnk
2015-09-20 14:48 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2015-09-20 11:26 - 2015-02-02 01:57 - 00000000 ____D C:\Users\Wendy\Documents\Outlook Files
2015-09-17 18:55 - 2013-02-21 22:12 - 00003982 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-13 11:37 - 2011-10-09 09:37 - 00000000 ____D C:\Users\Wendy\AppData\Local\Apple Computer
 
==================== Files in the root of some directories =======
 
2015-10-03 18:54 - 2015-10-03 18:54 - 0000000 _____ () C:\Program Files\Microsoft Security Client
2015-10-03 18:54 - 2015-10-03 18:54 - 0000000 _____ () C:\Program Files (x86)\Broadcom
2011-10-16 14:23 - 2011-10-16 14:56 - 0000077 _____ () C:\Users\Wendy\AppData\Roaming\Rim.Desktop.Exception.log
2011-10-16 14:23 - 2011-10-16 14:23 - 0001153 _____ () C:\Users\Wendy\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2011-10-16 14:23 - 2011-10-16 14:56 - 0000077 _____ () C:\Users\Wendy\AppData\Roaming\Rim.DesktopHelper.Exception.log
2014-08-25 02:24 - 2014-08-28 14:02 - 0000089 _____ () C:\Users\Wendy\AppData\Roaming\WB.CFG
2015-10-05 00:08 - 2015-10-05 00:08 - 0000017 _____ () C:\Users\Wendy\AppData\Local\resmon.resmoncfg
2011-05-14 10:07 - 2011-05-14 10:10 - 0015152 _____ () C:\ProgramData\ArcadeDeluxe5.log
2015-08-03 17:33 - 2015-08-03 17:33 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
C:\Users\Wendy\AppData\Local\Temp\sqlite3.dll
 

==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll
[2015-07-10 07:00] - [2015-08-22 14:52] - 0680256 ____A (Microsoft Corporation) F84D50EF068750CB192D15D4FDD7088C
 
C:\WINDOWS\SysWOW64\dnsapi.dll
[2015-07-10 07:00] - [2015-08-22 14:53] - 0534064 ____A () D41D8CD98F00B204E9800998ECF8427E
 
C:\WINDOWS\SysWOW64\dnsapi.dll => no Company Name <===== ATTENTION
 
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 

LastRegBack: 2015-10-06 10:41
 
==================== End of FRST.txt ============================


  • 0

#5
mistywjd

mistywjd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

do i have to do something else when i reply? Or do i just need to be patient?


  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK the malware has destroyed the backup copies of dnsapi.... so we will need to replace them

By the way I am on GMT :)

Copy the following two files to your desktop by right clicking the links and selecting Save target as (IE) :

https://dl.dropboxus...5776/dnsapi.dll
https://dl.dropboxus.../dnsapi (2).dll

It is important that they are saved to your desktop and nowhere else as I will be using FRST to replace the infected files with clean copies

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
Replace: C:\Users\Wendy\Desktop\dnsapi.dll C:\WINDOWS\system32\dnsapi.dll
Replace: C:\Users\Wendy\Desktop\dnsapi(2).dll C:\WINDOWS\SysWOW64\dnsapi.dll
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
Then run a fresh FRST scan please
  • 0

#7
mistywjd

mistywjd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

First, Im sorry, I just needed some patience, lol.

so I just ran the fix and when my computer rebooted, everything stopped working... my firewall is off, windows defender, ect. I have no internet connectivity at all. Initially only my internet explorer wasn't working but now Edge wont go online either. im using my other laptop to type this. Is this normal or should I do a system restore?


  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Run a system restore and then run a fresh FRST scan please
  • 0

#9
mistywjd

mistywjd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

Okay, i did a restore and ran a fresh FRST scan. here is the results of the scan:

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:10-10-2015
Ran by Wendy (administrator) on NOTEBOOK (11-10-2015 09:38:23)
Running from C:\Users\Wendy\Desktop
Loaded Profiles: Wendy (Available Profiles: Wendy)
Platform: Windows 10 Home (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(AVerMedia TECHNOLOGIES, Inc.) C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Microsoft Corporation) C:\Windows\System32\wbengine.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreamsDownloader.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
(Microsoft Corporation) C:\Windows\System32\wuapihost.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.6306.42251.0_x64__8wekyb3d8bbwe\HxTsr.exe
 

==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-23] (Acer Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3935912 2015-08-03] (Synaptics Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340336 2010-09-27] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-09-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-09-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-02-18] (CyberLink Corp.)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [79192 2011-02-18] (Research In Motion Limited)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [InstaLAN] => C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe [1885088 2012-02-23] (Affinegy, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [ComcastAntispyClient] => "C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" /hide
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [KSS] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202080 2014-06-15] (Kaspersky Lab ZAO)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\RunOnce: [Uninstall C:\Users\Wendy\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Wendy\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64"
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [805888 2015-07-10] (Microsoft Corporation)
Startup: C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2012-08-02]
ShortcutTarget: Dropbox.lnk -> C:\Users\Wendy\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2014-04-05]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{5b4fc3c7-a4fe-466a-ad1a-8982deeffde7}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{ec165e47-7983-45dc-b201-36594d8a9bc9}: [DhcpNameServer] 192.168.2.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237268288&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237273679&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237285619&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 -> {D62E54FD-024A-4A46-BB39-0AEECC058C51} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-08-04] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-24] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-11] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-25] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-25] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-24] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-03-03] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2011-05-26] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\7\NP_wtapp.dll [2013-12-27] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
 
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AffinegyService; C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe [563104 2012-02-23] (Affinegy, Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 AVerRECentral; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe [373248 2014-01-16] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2774104 2015-09-11] (Microsoft Corporation)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2013-12-16] (WildTangent)
S3 ITMRTSVC; C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe [283912 2007-09-26] (CA, Inc.)
R2 KSS; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202080 2014-06-15] (Kaspersky Lab ZAO)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-03] (Microsoft Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2015-08-03] (Synaptics Incorporated)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-03] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-03] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S4 AntiSpywareService; C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-20] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-03] (Microsoft Corporation)
R3 RimVSerPort; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2015-08-03] (Synaptics Incorporated)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S1 rncmaqih; \??\C:\WINDOWS\system32\drivers\rncmaqih.sys [X]
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 

==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-10-11 09:36 - 2015-10-11 09:36 - 00000000 ___HD C:\OneDriveTemp
2015-10-11 09:34 - 2015-10-11 09:34 - 00016148 _____ C:\WINDOWS\system32\NOTEBOOK_Wendy_HistoryPrediction.bin
2015-10-11 08:56 - 2015-10-11 08:56 - 00534064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2015-10-11 08:19 - 2015-10-11 08:19 - 00678160 ____T (Microsoft Corporation) C:\Users\Wendy\Desktop\dnsapi (2).dll
2015-10-11 08:18 - 2015-10-11 08:17 - 00530904 _____ (Microsoft Corporation) C:\Users\Wendy\Desktop\dnsapi.dll
2015-10-10 18:23 - 2015-09-14 23:31 - 00812008 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-10 18:23 - 2015-09-14 23:31 - 00178152 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-10 18:01 - 2015-10-10 18:01 - 00469192 _____ (Broadcom Corporation) C:\WINDOWS\system32\Drivers\k57nd60a.sys
2015-10-10 17:13 - 2015-10-10 17:18 - 00000000 ____D C:\AdwCleaner
2015-10-10 17:04 - 2015-10-10 17:04 - 01682432 _____ C:\Users\Wendy\Desktop\AdwCleaner.exe
2015-10-10 16:44 - 2015-10-10 16:44 - 00000000 ____D C:\Users\Wendy\Desktop\FRST-OlderVersion
2015-10-10 16:27 - 2015-10-10 16:27 - 00003216 _____ C:\WINDOWS\System32\Tasks\4a752bbc-e718-4ff5-8948-5413ae8b7094
2015-10-10 13:25 - 2015-10-10 13:25 - 00002901 _____ C:\Users\Wendy\Downloads\wendy's list.txt
2015-10-09 22:37 - 2015-10-09 22:37 - 00000000 ____D C:\Users\Wendy\Downloads\FRST-OlderVersion
2015-10-08 06:09 - 2015-10-08 06:09 - 00159298 _____ C:\Users\Wendy\Desktop\Shortcut.txt
2015-10-08 06:07 - 2015-10-09 23:48 - 00054433 _____ C:\Users\Wendy\Desktop\Addition.txt
2015-10-08 06:02 - 2015-10-11 09:38 - 00021885 _____ C:\Users\Wendy\Desktop\FRST.txt
2015-10-08 06:01 - 2015-10-08 06:01 - 02870984 _____ (ESET) C:\Users\Wendy\Desktop\esetsmartinstaller_enu.exe
2015-10-08 05:59 - 2015-10-11 09:38 - 00000000 ____D C:\FRST
2015-10-08 05:59 - 2015-10-10 16:44 - 02195456 _____ (Farbar) C:\Users\Wendy\Desktop\FRST64.exe
2015-10-06 11:53 - 2015-09-24 19:34 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-06 11:53 - 2015-09-24 19:34 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-06 11:53 - 2015-09-24 18:43 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-06 11:53 - 2015-09-24 18:43 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-06 11:53 - 2015-09-24 18:25 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-06 11:53 - 2015-09-24 18:25 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-06 11:53 - 2015-09-24 18:25 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-06 11:53 - 2015-09-24 18:25 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-06 11:53 - 2015-09-24 18:25 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-06 11:53 - 2015-09-24 18:24 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-06 11:53 - 2015-09-24 18:19 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-10-06 11:53 - 2015-09-17 02:28 - 05120056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-10-06 11:53 - 2015-09-17 02:28 - 02154808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-10-06 11:53 - 2015-09-17 02:28 - 01357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-10-06 11:53 - 2015-09-17 02:28 - 00441168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2015-10-06 11:53 - 2015-09-17 02:28 - 00407608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-10-06 11:53 - 2015-09-17 02:28 - 00074880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-10-06 11:53 - 2015-09-17 02:27 - 01766952 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-10-06 11:53 - 2015-09-17 02:27 - 00454512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 02446648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 01895568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 00646672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 00508248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 00434376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 00428128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-10-06 11:53 - 2015-09-17 02:25 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-06 11:53 - 2015-09-17 02:21 - 00658528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2015-10-06 11:53 - 2015-09-17 02:20 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-10-06 11:53 - 2015-09-17 01:51 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-06 11:53 - 2015-09-17 01:51 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2015-10-06 11:53 - 2015-09-17 01:49 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2015-10-06 11:53 - 2015-09-17 01:47 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-10-06 11:53 - 2015-09-17 01:45 - 19325440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-06 11:53 - 2015-09-17 01:45 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2015-10-06 11:53 - 2015-09-17 01:43 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-10-06 11:53 - 2015-09-17 01:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-06 11:53 - 2015-09-17 01:41 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-10-06 11:53 - 2015-09-17 01:40 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-10-06 11:53 - 2015-09-17 01:40 - 01918464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-06 11:53 - 2015-09-17 01:40 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-10-06 11:53 - 2015-09-17 01:39 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-10-06 11:53 - 2015-09-17 01:39 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-06 11:53 - 2015-09-17 01:38 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2015-10-06 11:53 - 2015-09-17 01:37 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-06 11:53 - 2015-09-17 01:37 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-10-06 11:53 - 2015-09-17 01:36 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2015-10-06 11:53 - 2015-09-17 01:35 - 05079552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-10-06 11:53 - 2015-09-17 01:35 - 02207232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-10-06 11:53 - 2015-09-17 01:35 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-10-06 11:53 - 2015-09-17 01:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-10-06 11:53 - 2015-09-17 01:34 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-10-06 11:53 - 2015-09-17 01:33 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-06 11:53 - 2015-09-17 01:32 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-06 11:53 - 2015-09-17 01:32 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-10-06 11:53 - 2015-09-17 01:32 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-10-06 11:53 - 2015-09-17 01:32 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-10-06 11:53 - 2015-09-17 01:31 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-06 11:53 - 2015-09-17 01:31 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2015-10-06 11:53 - 2015-09-17 01:30 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-10-06 11:53 - 2015-09-17 01:29 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-10-06 11:53 - 2015-09-17 01:29 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-10-06 11:53 - 2015-09-17 01:29 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-10-06 11:53 - 2015-09-17 01:29 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-06 11:53 - 2015-09-17 01:28 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-10-06 11:53 - 2015-09-17 01:26 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-10-06 11:53 - 2015-09-17 01:16 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-10-06 11:53 - 2015-09-12 21:41 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-06 11:50 - 2015-09-24 20:35 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-06 11:50 - 2015-09-24 20:34 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-06 11:50 - 2015-09-24 20:13 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-06 11:50 - 2015-09-24 19:23 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-06 11:50 - 2015-09-24 19:08 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-06 11:50 - 2015-09-24 19:07 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-06 11:50 - 2015-09-24 19:06 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-06 11:50 - 2015-09-24 19:05 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-06 11:50 - 2015-09-24 19:01 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-06 11:50 - 2015-09-24 19:01 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-06 11:50 - 2015-09-24 19:00 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-06 11:50 - 2015-09-24 19:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-06 11:50 - 2015-09-24 19:00 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-06 11:50 - 2015-09-24 19:00 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-06 11:50 - 2015-09-17 02:50 - 01563392 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-10-06 11:50 - 2015-09-17 02:49 - 01563472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-10-06 11:50 - 2015-09-17 02:49 - 00894256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys
2015-10-06 11:50 - 2015-09-17 02:49 - 00553808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2015-10-06 11:50 - 2015-09-17 02:48 - 02432336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-10-06 11:50 - 2015-09-17 02:48 - 02156400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2015-10-06 11:50 - 2015-09-17 02:48 - 00537080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-10-06 11:50 - 2015-09-17 02:48 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-10-06 11:50 - 2015-09-17 02:48 - 00406864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-10-06 11:50 - 2015-09-17 02:48 - 00278352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-10-06 11:50 - 2015-09-17 02:47 - 01397088 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-06 11:50 - 2015-09-17 02:43 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-10-06 11:50 - 2015-09-17 02:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-10-06 11:50 - 2015-09-17 02:08 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll
2015-10-06 11:50 - 2015-09-17 02:05 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-10-06 11:50 - 2015-09-17 02:04 - 00910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-10-06 11:50 - 2015-09-17 01:58 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-10-06 11:50 - 2015-09-17 01:57 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-10-06 11:50 - 2015-09-17 01:57 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-10-06 11:50 - 2015-09-17 01:57 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-10-06 11:50 - 2015-09-17 01:55 - 02236416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-10-06 11:50 - 2015-09-17 01:55 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-10-06 11:50 - 2015-09-17 01:55 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2015-10-06 11:50 - 2015-09-17 01:55 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-10-06 11:50 - 2015-09-17 01:55 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-10-06 11:50 - 2015-09-17 01:54 - 00780288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-10-06 11:50 - 2015-09-17 01:54 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 01181696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-10-06 11:50 - 2015-09-17 01:51 - 02660864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-10-06 11:50 - 2015-09-17 01:50 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2015-10-06 11:50 - 2015-09-17 01:49 - 01290240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-10-06 11:50 - 2015-09-17 01:48 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-10-06 11:50 - 2015-09-17 01:45 - 01331200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-10-06 11:50 - 2015-09-17 01:45 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-06 11:50 - 2015-09-17 01:43 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-10-06 11:49 - 2015-09-24 19:24 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-06 11:49 - 2015-09-24 19:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-06 11:49 - 2015-09-24 19:17 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-06 11:49 - 2015-09-24 18:53 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-06 11:49 - 2015-09-24 18:42 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-06 11:49 - 2015-09-19 01:14 - 00102304 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2015-10-06 11:49 - 2015-09-17 02:50 - 02464216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-10-06 11:49 - 2015-09-17 02:50 - 00099664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2015-10-06 11:49 - 2015-09-17 02:50 - 00088384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-10-06 11:49 - 2015-09-17 02:49 - 08020816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-06 11:49 - 2015-09-17 02:49 - 06487248 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-10-06 11:49 - 2015-09-17 02:49 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 02824248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 02494712 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 01983824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-10-06 11:49 - 2015-09-17 02:48 - 00809352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 00784136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 00584656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 00555768 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-10-06 11:49 - 2015-09-17 02:48 - 00476760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 00395088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-10-06 11:49 - 2015-09-17 02:48 - 00332624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2015-10-06 11:49 - 2015-09-17 02:48 - 00243760 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-10-06 11:49 - 2015-09-17 02:44 - 00781976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2015-10-06 11:49 - 2015-09-17 02:39 - 00081488 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-06 11:49 - 2015-09-17 02:37 - 01295712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2015-10-06 11:49 - 2015-09-17 02:37 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-10-06 11:49 - 2015-09-17 02:12 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-06 11:49 - 2015-09-17 02:11 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-10-06 11:49 - 2015-09-17 02:10 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2015-10-06 11:49 - 2015-09-17 02:09 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-10-06 11:49 - 2015-09-17 02:09 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-10-06 11:49 - 2015-09-17 02:08 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-10-06 11:49 - 2015-09-17 02:07 - 21875712 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-06 11:49 - 2015-09-17 02:06 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-10-06 11:49 - 2015-09-17 02:06 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-10-06 11:49 - 2015-09-17 02:06 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-10-06 11:49 - 2015-09-17 02:05 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-10-06 11:49 - 2015-09-17 02:04 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-10-06 11:49 - 2015-09-17 02:04 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2015-10-06 11:49 - 2015-09-17 02:03 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2015-10-06 11:49 - 2015-09-17 02:03 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-10-06 11:49 - 2015-09-17 02:03 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-10-06 11:49 - 2015-09-17 02:03 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2015-10-06 11:49 - 2015-09-17 02:03 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2015-10-06 11:49 - 2015-09-17 02:02 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-10-06 11:49 - 2015-09-17 02:02 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2015-10-06 11:49 - 2015-09-17 02:00 - 24595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-06 11:49 - 2015-09-17 02:00 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-06 11:49 - 2015-09-17 02:00 - 02417664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-06 11:49 - 2015-09-17 02:00 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-10-06 11:49 - 2015-09-17 02:00 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeywordDetectorMsftSidAdapter.dll
2015-10-06 11:49 - 2015-09-17 01:57 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-10-06 11:49 - 2015-09-17 01:56 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-10-06 11:49 - 2015-09-17 01:56 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-10-06 11:49 - 2015-09-17 01:56 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-10-06 11:49 - 2015-09-17 01:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2015-10-06 11:49 - 2015-09-17 01:55 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2015-10-06 11:49 - 2015-09-17 01:55 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2015-10-06 11:49 - 2015-09-17 01:55 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-10-06 11:49 - 2015-09-17 01:54 - 03781120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-10-06 11:49 - 2015-09-17 01:53 - 07055872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-10-06 11:49 - 2015-09-17 01:52 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2015-10-06 11:49 - 2015-09-17 01:52 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-10-06 11:49 - 2015-09-17 01:52 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-10-06 11:49 - 2015-09-17 01:51 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-10-06 11:49 - 2015-09-17 01:51 - 01203712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-10-06 11:49 - 2015-09-17 01:51 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-06 11:49 - 2015-09-17 01:51 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-10-06 11:49 - 2015-09-17 01:50 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-10-06 11:49 - 2015-09-17 01:50 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-10-06 11:49 - 2015-09-17 01:50 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeWiFi.dll
2015-10-06 11:49 - 2015-09-17 01:50 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeCell.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWebproxy.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationCrowdsource.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeIP.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWiFiAdapter.dll
2015-10-06 11:49 - 2015-09-17 01:48 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-10-06 11:49 - 2015-09-17 01:48 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-10-06 11:49 - 2015-09-17 01:48 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-10-06 11:49 - 2015-09-17 01:48 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2015-10-06 11:49 - 2015-09-17 01:48 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-10-06 11:49 - 2015-09-17 01:47 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-06 11:49 - 2015-09-17 01:47 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2015-10-06 11:49 - 2015-09-17 01:47 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2015-10-06 11:49 - 2015-09-17 01:46 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncmlhook.dll
2015-10-06 11:49 - 2015-09-17 01:45 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-06 11:49 - 2015-09-17 01:45 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-10-06 11:49 - 2015-09-17 01:45 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-10-06 11:49 - 2015-09-17 01:44 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2015-10-06 11:49 - 2015-09-17 01:44 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-10-06 11:49 - 2015-09-17 01:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2015-10-06 11:49 - 2015-09-17 01:44 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-10-06 11:49 - 2015-09-17 01:43 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-10-06 11:49 - 2015-09-17 01:43 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-10-06 11:49 - 2015-09-12 22:05 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-06 11:48 - 2015-09-17 01:50 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\buttonconverter.sys
2015-10-05 00:08 - 2015-10-05 00:08 - 00000017 _____ C:\Users\Wendy\AppData\Local\resmon.resmoncfg
2015-10-04 13:49 - 2015-10-04 14:03 - 2421989376 _____ C:\Users\Wendy\Downloads\O365HomePremRetail.img
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v4.5 Classic
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v4.5
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v2.0
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Local\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Local\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Local\Adobe
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v4.5\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v4.5 Classic\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v2.0\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 __RSD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 __RSD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\Classic .NET AppPool
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0 Classic
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Macromedia
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Intel Corporation
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\InstallShield
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Windows Live
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Downloaded Installations
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Macromedia
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Intel Corporation
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\InstallShield
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Local\Windows Live
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Local\Adobe
2015-10-04 13:30 - 2011-04-06 16:20 - 00057560 _____ C:\Users\Classic .NET AppPool\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:30 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v2.0 Classic\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:29 - 2015-10-04 13:29 - 00000000 ____D C:\Program Files\Windows Identity Foundation
2015-10-04 12:31 - 2015-10-04 12:31 - 00000000 ____D C:\Users\Wendy\AppData\Local\Google
2015-10-04 11:36 - 2015-10-04 11:36 - 00997927 _____ C:\Users\Wendy\Downloads\O15CTRRemove.diagcab
2015-10-03 22:22 - 2015-10-03 22:22 - 00000000 ____D C:\Program Files\DisplayLink Graphics
2015-10-03 22:20 - 2015-10-05 22:10 - 00000000 ____D C:\Program Files\DisplayLink Core Software
2015-10-03 22:20 - 2015-10-03 22:21 - 00002930 _____ C:\WINDOWS\system32\MsiExec.log
2015-10-03 21:02 - 2015-10-03 21:02 - 00000000 ____D C:\$SysReset
2015-10-03 19:20 - 2015-10-03 19:20 - 00038563 _____ C:\Users\Wendy\Downloads\cssemerg69697.diagcab
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files\Microsoft Security Client
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files (x86)\Broadcom
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\be8106b9bc95323fd268ba6235ad69
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\bd9118d39e1f207ee9cd6dcd0939
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\b9c13b78d128895b6e52
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\776e24d3f6aba141bb9c83b3fe63ae77
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\65b66254bc6a4f7c7497ac9d8307
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\4f4fa18d4dd8f99f0ea6a6420281251a
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\419a2caadd4290847864
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\318cab8197d210aa5c5e
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\3089b6a24ef724d145
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\04bf7963418bedcfdde09dca48
2015-09-20 18:39 - 2015-09-20 18:39 - 00001040 _____ C:\Users\Wendy\Desktop\9-20-15.txt
2015-09-17 18:55 - 2015-09-17 18:55 - 00003780 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0e826fa18e252
2015-09-13 15:51 - 2015-08-27 02:36 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-13 15:51 - 2015-08-27 02:32 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-13 15:51 - 2015-08-27 01:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-13 15:51 - 2015-08-27 01:54 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-13 15:51 - 2015-08-27 01:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-13 15:51 - 2015-08-27 01:51 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-13 15:51 - 2015-08-27 01:51 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-13 15:51 - 2015-08-27 01:49 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-13 15:51 - 2015-08-27 01:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-13 15:51 - 2015-08-27 01:43 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-13 15:51 - 2015-08-27 01:43 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-13 15:51 - 2015-08-27 01:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-13 15:51 - 2015-08-27 01:23 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-13 15:51 - 2015-08-27 01:16 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-13 15:51 - 2015-08-27 01:16 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-13 15:51 - 2015-08-27 01:12 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-13 15:51 - 2015-08-27 01:12 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-13 15:51 - 2015-08-27 01:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-13 15:51 - 2015-08-27 01:11 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-13 15:51 - 2015-08-27 01:09 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-13 15:51 - 2015-08-27 01:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-10-11 09:37 - 2011-10-08 22:42 - 00000000 ____D C:\ProgramData\clear.fi
2015-10-11 09:36 - 2015-09-05 18:05 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0e826fa18e252.job
2015-10-11 09:36 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-11 09:36 - 2015-01-25 17:58 - 00000000 ___RD C:\Users\Wendy\iCloudDrive
2015-10-11 09:36 - 2014-03-03 18:27 - 00000000 ____D C:\Users\Wendy\OneDrive
2015-10-11 09:36 - 2013-02-21 22:12 - 00000894 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-11 09:34 - 2015-08-03 17:37 - 00000000 ____D C:\Users\Wendy
2015-10-11 09:34 - 2015-07-10 08:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-11 09:34 - 2015-07-10 08:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-11 09:33 - 2011-10-08 22:16 - 00000000 ____D C:\Users\Wendy\AppData\Local\PowerCinema
2015-10-11 09:32 - 2014-11-23 13:23 - 00000000 ____D C:\Program Files (x86)\ESET
2015-10-11 09:32 - 2013-03-06 21:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client
2015-10-11 09:27 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\registration
2015-10-11 08:58 - 2015-09-05 19:15 - 00008006 _____ C:\WINDOWS\PFRO.log
2015-10-11 08:29 - 2012-06-17 10:30 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-11 08:01 - 2013-02-21 22:12 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-11 03:34 - 2011-12-25 20:30 - 00004154 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896}
2015-10-10 21:14 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\rescache
2015-10-10 20:13 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-10 18:41 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-10 18:27 - 2015-08-03 17:35 - 01006528 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-10 18:20 - 2015-07-10 05:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-10 18:18 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-10 18:18 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-10 18:18 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-10 18:06 - 2015-07-10 06:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-10 16:51 - 2014-08-18 12:55 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-10-10 16:46 - 2013-12-31 22:12 - 00000000 ____D C:\Users\Wendy\AppData\LocalLow\Temp
2015-10-10 16:45 - 2015-08-20 14:37 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2015-10-10 16:45 - 2009-07-13 23:20 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2015-10-10 16:36 - 2013-02-21 22:12 - 00003468 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-10-10 16:33 - 2011-05-14 10:09 - 00003410 _____ C:\WINDOWS\System32\Tasks\clear.fiAgent
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 __RSD C:\WINDOWS\Media
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\system32\Nui
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system\Speech
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\IME
2015-10-06 10:20 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-10-06 10:20 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\servicing
2015-10-06 10:20 - 2013-03-06 21:38 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-10-06 10:19 - 2015-08-03 18:04 - 00000000 ____D C:\Users\Wendy\AppData\Local\Packages
2015-10-06 10:19 - 2015-08-03 17:37 - 00000000 ___RD C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-06 10:17 - 2015-07-10 07:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-10-06 10:17 - 2015-03-21 09:56 - 00000000 ____D C:\Users\Wendy\AppData\Local\Microsoft Help
2015-10-06 10:17 - 2014-03-03 18:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-10-06 10:17 - 2014-03-03 18:17 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-10-06 10:17 - 2013-03-06 21:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
2015-10-06 10:17 - 2013-03-06 21:38 - 00000000 ____D C:\Program Files\Microsoft Office
2015-10-06 10:17 - 2013-02-21 22:13 - 00000000 ____D C:\Program Files\Google
2015-10-06 10:17 - 2013-02-21 22:12 - 00000000 ____D C:\Program Files (x86)\Google
2015-10-06 10:17 - 2011-05-14 10:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-10-06 10:17 - 2011-04-06 17:00 - 00000000 ____D C:\ProgramData\BackupManager
2015-10-06 10:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-10-06 10:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SystemResources
2015-10-06 09:59 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-10-06 09:58 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-10-06 09:58 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-10-06 09:57 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-10-06 09:55 - 2013-03-06 21:39 - 00000000 ____D C:\Users\Wendy\AppData\Roaming\SoftGrid Client
2015-10-06 09:34 - 2015-08-03 21:18 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-10-06 09:34 - 2015-07-10 09:14 - 00000000 ____D C:\Program Files\Windows Journal
2015-10-06 09:34 - 2015-07-10 07:04 - 00000000 ____D C:\Program Files\Windows NT
2015-10-06 09:34 - 2013-03-14 03:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-10-06 09:30 - 2015-08-03 21:18 - 00000000 ____D C:\inetpub
2015-10-06 09:30 - 2011-04-06 16:56 - 00000000 ___HD C:\OEM
2015-10-06 09:30 - 2011-04-06 16:55 - 00000000 ____D C:\Program Files (x86)\EgisTec Shredder
2015-10-06 09:30 - 2011-04-06 16:54 - 00000000 ____D C:\Program Files (x86)\EgisTec MyWinLocker
2015-10-06 09:30 - 2011-04-06 16:53 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-10-06 09:30 - 2011-04-06 16:52 - 00000000 ____D C:\Program Files (x86)\Windows Live
2015-10-06 09:30 - 2011-04-06 16:21 - 00000000 ____D C:\Program Files (x86)\Acer Games
2015-10-04 13:31 - 2015-08-03 17:35 - 00042366 _____ C:\WINDOWS\iis.log
2015-10-03 18:54 - 2013-03-06 21:38 - 00000000 ____D C:\Users\Wendy\AppData\Roaming\TP
2015-10-01 18:25 - 2015-07-10 08:20 - 00018136 _____ C:\WINDOWS\setupact.log
2015-09-27 15:46 - 2015-09-07 18:52 - 00000000 ____D C:\Users\Wendy\AppData\Local\Comms
2015-09-21 00:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-09-20 23:22 - 2011-10-08 22:15 - 00000000 ____D C:\Users\Wendy\AppData\Local\VirtualStore
2015-09-20 20:41 - 2015-07-10 08:20 - 00336488 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-20 20:21 - 2013-08-15 03:01 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-20 18:46 - 2015-08-23 20:31 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-20 18:39 - 2015-08-03 18:13 - 00002378 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-09-20 18:39 - 2015-08-03 18:09 - 00001331 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan.lnk
2015-09-20 18:39 - 2015-08-03 18:07 - 00001313 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Realtek HD Audio Manager.lnk
2015-09-20 18:39 - 2015-08-03 17:46 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002425 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002289 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002287 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00001578 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00000853 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop.lnk
2015-09-20 18:39 - 2015-03-21 09:27 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-09-20 18:39 - 2014-08-18 02:33 - 00001015 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2015-09-20 18:39 - 2014-07-12 18:05 - 00001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-09-20 18:39 - 2014-03-03 18:27 - 00002162 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-09-20 18:39 - 2012-10-14 10:52 - 00001866 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fooz Kids.lnk
2015-09-20 18:39 - 2011-12-02 19:21 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-09-20 18:39 - 2011-10-08 22:16 - 00000915 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Times Reader.lnk
2015-09-20 18:39 - 2011-05-14 10:14 - 00002478 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2015-09-20 18:39 - 2011-04-06 16:52 - 00001450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-09-20 18:38 - 2015-09-07 14:00 - 00000989 _____ C:\Users\Wendy\Desktop\CBS.log - Shortcut.lnk
2015-09-20 18:38 - 2015-08-23 20:31 - 00001173 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-20 18:38 - 2015-07-18 15:05 - 00001751 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-09-20 18:38 - 2015-07-18 14:54 - 00001843 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2015-09-20 18:38 - 2015-03-21 09:27 - 00002017 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-09-20 18:38 - 2014-08-18 02:34 - 00001015 _____ C:\Users\Wendy\Desktop\Audacity.lnk
2015-09-20 18:38 - 2014-07-26 09:52 - 00001211 _____ C:\Users\Wendy\Desktop\Kaspersky Security Scan.lnk
2015-09-20 18:38 - 2014-07-12 18:59 - 00001216 _____ C:\Users\Public\Desktop\XSplit Gamecaster.lnk
2015-09-20 18:38 - 2014-07-12 18:05 - 00001297 _____ C:\Users\Wendy\Desktop\Movie Maker.lnk
2015-09-20 18:38 - 2014-07-12 17:52 - 00002691 _____ C:\Users\Public\Desktop\Skype.lnk
2015-09-20 18:38 - 2014-07-11 19:19 - 00002151 _____ C:\Users\Public\Desktop\AVerMedia RECentral.lnk
2015-09-20 18:38 - 2012-10-14 10:52 - 00001860 _____ C:\Users\Public\Desktop\Fooz Kids.lnk
2015-09-20 18:38 - 2011-10-16 14:23 - 00002229 _____ C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
2015-09-20 18:38 - 2011-10-08 22:17 - 00001962 _____ C:\Users\Public\Desktop\Netflix.lnk
2015-09-20 18:38 - 2011-10-08 22:16 - 00000909 _____ C:\Users\Public\Desktop\Times Reader.lnk
2015-09-20 18:38 - 2011-05-14 10:11 - 00001206 _____ C:\Users\Public\Desktop\NOOK for PC.lnk
2015-09-20 18:38 - 2011-05-14 10:09 - 00002165 _____ C:\Users\Public\Desktop\clear.fi.lnk
2015-09-20 18:38 - 2011-04-06 16:57 - 00001984 _____ C:\Users\Public\Desktop\Norton Online Backup.lnk
2015-09-20 18:38 - 2011-04-06 16:51 - 00002727 _____ C:\Users\Public\Desktop\clear.fi Tutorial.lnk
2015-09-20 18:38 - 2011-04-06 16:20 - 00002562 _____ C:\Users\Public\Desktop\WildTangent Games App - acer.lnk
2015-09-20 14:48 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2015-09-20 11:26 - 2015-02-02 01:57 - 00000000 ____D C:\Users\Wendy\Documents\Outlook Files
2015-09-17 18:55 - 2013-02-21 22:12 - 00003982 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-13 11:37 - 2011-10-09 09:37 - 00000000 ____D C:\Users\Wendy\AppData\Local\Apple Computer
 
==================== Files in the root of some directories =======
 
2015-10-03 18:54 - 2015-10-03 18:54 - 0000000 _____ () C:\Program Files\Microsoft Security Client
2015-10-03 18:54 - 2015-10-03 18:54 - 0000000 _____ () C:\Program Files (x86)\Broadcom
2011-10-16 14:23 - 2011-10-16 14:56 - 0000077 _____ () C:\Users\Wendy\AppData\Roaming\Rim.Desktop.Exception.log
2011-10-16 14:23 - 2011-10-16 14:23 - 0001153 _____ () C:\Users\Wendy\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2011-10-16 14:23 - 2011-10-16 14:56 - 0000077 _____ () C:\Users\Wendy\AppData\Roaming\Rim.DesktopHelper.Exception.log
2014-08-25 02:24 - 2014-08-28 14:02 - 0000089 _____ () C:\Users\Wendy\AppData\Roaming\WB.CFG
2015-10-05 00:08 - 2015-10-05 00:08 - 0000017 _____ () C:\Users\Wendy\AppData\Local\resmon.resmoncfg
2011-05-14 10:07 - 2011-05-14 10:10 - 0015152 _____ () C:\ProgramData\ArcadeDeluxe5.log
2015-08-03 17:33 - 2015-08-03 17:33 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
Some files in TEMP:
====================
C:\Users\Wendy\AppData\Local\Temp\sqlite3.dll
 

==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll
[2015-07-10 07:00] - [2015-08-22 14:52] - 0680256 ____A (Microsoft Corporation) F84D50EF068750CB192D15D4FDD7088C
 
C:\WINDOWS\SysWOW64\dnsapi.dll
[2015-10-11 08:56] - [2015-10-11 08:56] - 0534064 ____A (Microsoft Corporation) 9E3E09B58BD454CC882A2DF6D7D35CED
 
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 

LastRegBack: 2015-10-06 10:41
 
==================== End of FRST.txt ============================
 
 
 


  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

OK we need to find a different way of restoring those files

First we will remove the service that restore returned that we do not want :)


CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 

CreateRestorePoint:
S1 rncmaqih; \??\C:\WINDOWS\system32\drivers\rncmaqih.sys [X]
2015-10-10 16:27 - 2015-10-10 16:27 - 00003216 _____ C:\WINDOWS\System32\Tasks\4a752bbc-e718-4ff5-8948-5413ae8b7094
C:\WINDOWS\system32\drivers\rncmaqih.sys
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers


Save this as fixlist.txt, in the same location as FRST.exe
FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that

THEN

Press the windows + x key together
A menu will open select command prompt (admin)
In the black box that opens copy/paste the following command and press enter

DISM /Online /Cleanup-Image /RestoreHealth

 

 

Once done reboot and run a fresh FRST yet again

 


  • 0

Advertisements


#11
mistywjd

mistywjd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
I did the new fixlist and will post that. Now I will do the dsim command. Just wanted to update you, since ive done the system restore my computer seems to be acting much better than it has since my daughter accidedntly downloaded the malware. my internet explorer is working again. My Microsoft office is working again. Also, Windows defender is no longer scanning dnsapi.dll as a Trojan and trying to quarantine it! its not even listed in the quarantined folder. So does that mean things are looking better?
 
Here is the next fixlog:
 
Fix result of Farbar Recovery Scan Tool (x64) Version:10-10-2015
Ran by Wendy (2015-10-11 12:04:21) Run:3
Running from C:\Users\Wendy\Desktop
Loaded Profiles: Wendy (Available Profiles: Wendy)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
 S1 rncmaqih; \??\C:\WINDOWS\system32\drivers\rncmaqih.sys [X]
 2015-10-10 16:27 - 2015-10-10 16:27 - 00003216 _____ C:\WINDOWS\System32\Tasks\4a752bbc-e718-4ff5-8948-5413ae8b7094
 C:\WINDOWS\system32\drivers\rncmaqih.sys
 RemoveProxy:
 EmptyTemp:
 CMD: bitsadmin /reset /allusers
*****************
 
Restore point was successfully created.
rncmaqih => service removed successfully
C:\WINDOWS\System32\Tasks\4a752bbc-e718-4ff5-8948-5413ae8b7094 => moved successfully
"C:\WINDOWS\system32\drivers\rncmaqih.sys" => File/Folder not found.
 
========= RemoveProxy: =========
 
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
 

========= End of RemoveProxy: =========
 

=========  bitsadmin /reset /allusers =========
 

BITSADMIN version 3.0 [ 7.8.10240 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.
 
BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.
 
0 out of 0 jobs canceled.
 
========= End of CMD: =========
 
EmptyTemp: => 89.1 MB temporary data Removed.
 

The system needed a reboot.
 
==== End of Fixlog 12:05:53 ====


  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts

Yes much better, dism should replace these next and then mayhap you will be good :)
 


C:\WINDOWS\system32\dnsapi.dll
[2015-07-10 07:00] - [2015-08-22 14:52] - 0680256 ____A (Microsoft Corporation) F84D50EF068750CB192D15D4FDD7088C
C:\WINDOWS\SysWOW64\dnsapi.dll
[2015-10-11 08:56] - [2015-10-11 08:56] - 0534064 ____A (Microsoft Corporation) 9E3E09B58BD454CC882A2DF6D7D35CED

 

 


  • 0

#13
mistywjd

mistywjd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts
I did the DISM command, rebooted and just finished the fresh FRST scan. I will paste the results, and I am also including the DISM results that I got.
 
DISM Command:
 
Microsoft Windows [Version 10.0.10240]
© 2015 Microsoft Corporation. All rights reserved.
 
C:\WINDOWS\system32>DISM /Online /Cleanup-Image /RestoreHealth
 
Deployment Image Servicing and Management tool
Version: 10.0.10240.16384
 
Image Version: 10.0.10240.16384
 
[===========                20.0%                          ]
Error: 1726
 
The remote procedure call failed.
 
The DISM log file can be found at C:\WINDOWS\Logs\DISM\dism.log
 
C:\WINDOWS\system32>
 
 
FRST Scan:
 
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:10-10-2015
Ran by Wendy (administrator) on NOTEBOOK (11-10-2015 12:57:05)
Running from C:\Users\Wendy\Desktop
Loaded Profiles: Wendy (Available Profiles: Wendy)
Platform: Windows 10 Home (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
(Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
(AVerMedia TECHNOLOGIES, Inc.) C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe
(Microsoft Corporation) C:\Windows\System32\mqsvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMutilps32.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\MVP\clear.fiAgent.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(CyberLink) C:\Program Files (x86)\Acer\clear.fi\MVP\Kernel\DMR\DMREngine.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe
(Intel Corporation) C:\Windows\System32\igfxext.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
(NTI Corporation) C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LManager.exe
(CyberLink Corp.) C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe
(Research In Motion Limited) C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\MMDx64Fx.exe
(Dritek System Inc.) C:\Program Files (x86)\Launch Manager\LMworker.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
(Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
(Affinegy, Inc.) C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinSetup.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\System32\wbem\WMIADAP.exe
 

==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13885696 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1402624 2015-06-24] (Realtek Semiconductor)
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1796200 2011-02-23] (Acer Incorporated)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [170280 2015-07-11] (Apple Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3935912 2015-08-03] (Synaptics Incorporated)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [SuiteTray] => C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [340336 2010-09-27] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisTecPMMUpdate] => C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [407920 2010-09-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [EgisUpdate] => C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201584 2010-09-17] (Egis Technology Inc.)
HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-02-15] (NTI Corporation)
HKLM-x32\...\Run: [LManager] => C:\Program Files (x86)\Launch Manager\LManager.exe [1081424 2011-03-14] (Dritek System Inc.)
HKLM-x32\...\Run: [Dolby Advanced Audio v2] => C:\Dolby PCEE4\pcee4.exe [506712 2011-02-03] (Dolby Laboratories Inc.)
HKLM-x32\...\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-02-18] (CyberLink Corp.)
HKLM-x32\...\Run: [RIMBBLaunchAgent.exe] => C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe [79192 2011-02-18] (Research In Motion Limited)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2015-05-15] (Apple Inc.)
HKLM-x32\...\Run: [InstaLAN] => C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe [1885088 2012-02-23] (Affinegy, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-06-17] (Apple Inc.)
Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [ComcastAntispyClient] => "C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntispy.exe" /hide
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [ApplePhotoStreams] => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [KSS] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202080 2014-06-15] (Kaspersky Lab ZAO)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\Run: [iCloudDrive] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudDrive.exe [43816 2015-04-26] (Apple Inc.)
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\...\RunOnce: [Uninstall C:\Users\Wendy\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Wendy\AppData\Local\Microsoft\OneDrive\17.3.5907.0716_1\amd64"
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [805888 2015-07-10] (Microsoft Corporation)
Startup: C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk [2012-08-02]
ShortcutTarget: Dropbox.lnk -> C:\Users\Wendy\AppData\Roaming\Dropbox\bin\Dropbox.exe (No File)
Startup: C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Send to OneNote.lnk [2014-04-05]
ShortcutTarget: Send to OneNote.lnk -> C:\Program Files\Microsoft Office 15\root\office15\onenotem.exe (Microsoft Corporation)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{5b4fc3c7-a4fe-466a-ad1a-8982deeffde7}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{ec165e47-7983-45dc-b201-36594d8a9bc9}: [DhcpNameServer] 192.168.2.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237268288&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237273679&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/
HKU\S-1-5-21-2389695071-1928321251-2773591669-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617910&ResetID=130847823237285619&GUID=25D787AA-CA5F-48BB-BB3C-3640A04FCC3E
SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AARTDF&pc=MAAR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSE1
SearchScopes: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL =
SearchScopes: HKU\S-1-5-21-2389695071-1928321251-2773591669-1000 -> {D62E54FD-024A-4A46-BB39-0AEECC058C51} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2015-08-04] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-24] (Google Inc.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2015-09-11] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll [2015-01-25] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll [2015-01-25] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-09-24] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-09-24] (Google Inc.)
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} hxxp://download.eset.com/special/eos/OnlineScanner.cab
Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2015-02-03] (Microsoft Corporation)
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-05-01] (Microsoft Corporation)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-05-01] (Microsoft Corporation)
 
FireFox:
========
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll [2015-01-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll [2015-01-25] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2014-03-03] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @RIM.com/WebSLLauncher,version=1.0 -> C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll [2011-05-26] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.15\npGoogleUpdate3.dll [2015-09-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\7\NP_wtapp.dll [2013-12-27] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-06-29] (Adobe Systems Inc.)
 
Chrome:
=======
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
 
==================== Services (Whitelisted) ========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AffinegyService; C:\Program Files (x86)\Belkin\Router Setup and Monitor\BelkinService.exe [563104 2012-02-23] (Affinegy, Inc.)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [77128 2015-05-29] (Apple Inc.)
R2 AVerRECentral; C:\Program Files (x86)\Common Files\AVerMedia\Service\AVerRECentral.exe [373248 2014-01-16] (AVerMedia TECHNOLOGIES, Inc.) [File not signed]
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1394816 2015-05-01] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1772672 2015-05-01] (Microsoft Corporation)
R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2774104 2015-09-11] (Microsoft Corporation)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2013-12-16] (WildTangent)
S3 ITMRTSVC; C:\Program Files (x86)\CA\PPRT\bin\ITMRTSVC.exe [283912 2007-09-26] (CA, Inc.)
R2 KSS; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan 2.0\kss.exe [202080 2014-06-15] (Kaspersky Lab ZAO)
R2 MSMQ; C:\Windows\system32\mqsvc.exe [26112 2015-08-03] (Microsoft Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [257344 2011-02-15] (NTI Corporation)
R2 SynTPEnhService; C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe [237736 2015-08-03] (Synaptics Incorporated)
S3 w3logsvc; C:\Windows\system32\inetsrv\w3logsvc.dll [84480 2015-08-03] (Microsoft Corporation)
R2 W3SVC; C:\Windows\system32\inetsrv\iisw3adm.dll [578560 2015-08-03] (Microsoft Corporation)
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [362928 2015-07-10] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [24864 2015-07-10] (Microsoft Corporation)
S4 AntiSpywareService; C:\Program Files (x86)\comcasttb\ComcastSpywareScan\ComcastAntiSpyService.exe [X]
 
===================== Drivers (Whitelisted) ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 MBAMSwissArmy; C:\WINDOWS\system32\drivers\MBAMSwissArmy.sys [113880 2015-09-20] (Malwarebytes Corporation)
R3 MQAC; C:\Windows\System32\drivers\mqac.sys [175104 2015-08-03] (Microsoft Corporation)
R3 RimVSerPort; C:\Windows\system32\DRIVERS\RimSerial_AMD64.sys [31744 2009-01-09] (Research in Motion Ltd)
R3 SmbDrvI; C:\Windows\system32\DRIVERS\Smb_driver_Intel.sys [33960 2015-08-03] (Synaptics Incorporated)
S3 UdeCx; C:\Windows\System32\drivers\udecx.sys [44032 2015-07-10] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [44568 2015-07-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [291680 2015-07-10] (Microsoft Corporation)
R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [119648 2015-07-10] (Microsoft Corporation)
U3 idsvc; no ImagePath
S3 wfpcapture; \SystemRoot\System32\drivers\wfpcapture.sys [X]
U3 wpcsvc; no ImagePath
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 

==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-10-11 12:54 - 2015-10-11 12:54 - 00000000 ___HD C:\OneDriveTemp
2015-10-11 12:53 - 2015-10-11 12:53 - 00016148 _____ C:\WINDOWS\system32\NOTEBOOK_Wendy_HistoryPrediction.bin
2015-10-11 12:50 - 2015-10-11 12:50 - 00000525 _____ C:\Users\Wendy\Desktop\dsmi.txt
2015-10-11 08:56 - 2015-10-11 08:56 - 00534064 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dnsapi.dll
2015-10-11 08:19 - 2015-10-11 08:19 - 00678160 ____T (Microsoft Corporation) C:\Users\Wendy\Desktop\dnsapi (2).dll
2015-10-11 08:18 - 2015-10-11 08:17 - 00530904 _____ (Microsoft Corporation) C:\Users\Wendy\Desktop\dnsapi.dll
2015-10-10 18:23 - 2015-09-14 23:31 - 00812008 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2015-10-10 18:23 - 2015-09-14 23:31 - 00178152 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2015-10-10 18:01 - 2015-10-10 18:01 - 00469192 _____ (Broadcom Corporation) C:\WINDOWS\system32\Drivers\k57nd60a.sys
2015-10-10 17:13 - 2015-10-10 17:18 - 00000000 ____D C:\AdwCleaner
2015-10-10 17:04 - 2015-10-10 17:04 - 01682432 _____ C:\Users\Wendy\Desktop\AdwCleaner.exe
2015-10-10 16:44 - 2015-10-10 16:44 - 00000000 ____D C:\Users\Wendy\Desktop\FRST-OlderVersion
2015-10-10 13:25 - 2015-10-10 13:25 - 00002901 _____ C:\Users\Wendy\Downloads\wendy's list.txt
2015-10-09 22:37 - 2015-10-09 22:37 - 00000000 ____D C:\Users\Wendy\Downloads\FRST-OlderVersion
2015-10-08 06:09 - 2015-10-08 06:09 - 00159298 _____ C:\Users\Wendy\Desktop\Shortcut.txt
2015-10-08 06:07 - 2015-10-11 09:40 - 00040482 _____ C:\Users\Wendy\Desktop\Addition.txt
2015-10-08 06:02 - 2015-10-11 12:58 - 00021393 _____ C:\Users\Wendy\Desktop\FRST.txt
2015-10-08 06:01 - 2015-10-08 06:01 - 02870984 _____ (ESET) C:\Users\Wendy\Desktop\esetsmartinstaller_enu.exe
2015-10-08 05:59 - 2015-10-11 12:57 - 00000000 ____D C:\FRST
2015-10-08 05:59 - 2015-10-10 16:44 - 02195456 _____ (Farbar) C:\Users\Wendy\Desktop\FRST64.exe
2015-10-06 11:53 - 2015-09-24 19:34 - 00195584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataAccountApis.dll
2015-10-06 11:53 - 2015-09-24 19:34 - 00172032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhoneCallHistoryApis.dll
2015-10-06 11:53 - 2015-09-24 18:43 - 00613376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2015-10-06 11:53 - 2015-09-24 18:43 - 00480256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Web.Core.dll
2015-10-06 11:53 - 2015-09-24 18:25 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2015-10-06 11:53 - 2015-09-24 18:25 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ContactApis.dll
2015-10-06 11:53 - 2015-09-24 18:25 - 00579584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppointmentApis.dll
2015-10-06 11:53 - 2015-09-24 18:25 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ChatApis.dll
2015-10-06 11:53 - 2015-09-24 18:25 - 00525312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\EmailApis.dll
2015-10-06 11:53 - 2015-09-24 18:24 - 00131072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CallHistoryClient.dll
2015-10-06 11:53 - 2015-09-24 18:19 - 00466432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2015-10-06 11:53 - 2015-09-17 02:28 - 05120056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2015-10-06 11:53 - 2015-09-17 02:28 - 02154808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2015-10-06 11:53 - 2015-09-17 02:28 - 01357888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2015-10-06 11:53 - 2015-09-17 02:28 - 00441168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2015-10-06 11:53 - 2015-09-17 02:28 - 00407608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2015-10-06 11:53 - 2015-09-17 02:28 - 00074880 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\remoteaudioendpoint.dll
2015-10-06 11:53 - 2015-09-17 02:27 - 01766952 _____ C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2015-10-06 11:53 - 2015-09-17 02:27 - 00454512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\directmanipulation.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 02446648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msmpeg2vdec.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 01895568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\hevcdecoder.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 00646672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 00508248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mf.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 00434376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2015-10-06 11:53 - 2015-09-17 02:26 - 00428128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWanAPI.dll
2015-10-06 11:53 - 2015-09-17 02:25 - 00962400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2015-10-06 11:53 - 2015-09-17 02:21 - 00658528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfds.dll
2015-10-06 11:53 - 2015-09-17 02:20 - 00764416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2015-10-06 11:53 - 2015-09-17 01:51 - 13027840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2015-10-06 11:53 - 2015-09-17 01:51 - 00145920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mdmregistration.dll
2015-10-06 11:53 - 2015-09-17 01:49 - 00041472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Speech.Pal.dll
2015-10-06 11:53 - 2015-09-17 01:47 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2015-10-06 11:53 - 2015-09-17 01:45 - 19325440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2015-10-06 11:53 - 2015-09-17 01:45 - 00193024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2015-10-06 11:53 - 2015-09-17 01:43 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapConfiguration.dll
2015-10-06 11:53 - 2015-09-17 01:42 - 02646528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2015-10-06 11:53 - 2015-09-17 01:41 - 00217088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2015-10-06 11:53 - 2015-09-17 01:40 - 06101504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2015-10-06 11:53 - 2015-09-17 01:40 - 01918464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2015-10-06 11:53 - 2015-09-17 01:40 - 01162240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Speech.dll
2015-10-06 11:53 - 2015-09-17 01:39 - 00587264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2015-10-06 11:53 - 2015-09-17 01:39 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-06 11:53 - 2015-09-17 01:38 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\usoapi.dll
2015-10-06 11:53 - 2015-09-17 01:37 - 18806272 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2015-10-06 11:53 - 2015-09-17 01:37 - 00454656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2015-10-06 11:53 - 2015-09-17 01:36 - 01171456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\netcenter.dll
2015-10-06 11:53 - 2015-09-17 01:35 - 05079552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2015-10-06 11:53 - 2015-09-17 01:35 - 02207232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2015-10-06 11:53 - 2015-09-17 01:35 - 01820160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Logon.dll
2015-10-06 11:53 - 2015-09-17 01:35 - 00828928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2015-10-06 11:53 - 2015-09-17 01:34 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2015-10-06 11:53 - 2015-09-17 01:33 - 00574464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakradiag.dll
2015-10-06 11:53 - 2015-09-17 01:32 - 03579904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2015-10-06 11:53 - 2015-09-17 01:32 - 00336384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CredProvDataModel.dll
2015-10-06 11:53 - 2015-09-17 01:32 - 00313856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LockAppBroker.dll
2015-10-06 11:53 - 2015-09-17 01:32 - 00195072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.LockScreen.dll
2015-10-06 11:53 - 2015-09-17 01:31 - 05454848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2015-10-06 11:53 - 2015-09-17 01:31 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ncryptprov.dll
2015-10-06 11:53 - 2015-09-17 01:30 - 00311808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2015-10-06 11:53 - 2015-09-17 01:29 - 01104384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2015-10-06 11:53 - 2015-09-17 01:29 - 00701952 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\JpMapControl.dll
2015-10-06 11:53 - 2015-09-17 01:29 - 00677888 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapControlCore.dll
2015-10-06 11:53 - 2015-09-17 01:29 - 00464896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2015-10-06 11:53 - 2015-09-17 01:28 - 00473088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2015-10-06 11:53 - 2015-09-17 01:26 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RemoteNaturalLanguage.dll
2015-10-06 11:53 - 2015-09-17 01:16 - 00512000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2015-10-06 11:53 - 2015-09-12 21:41 - 02639872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\esent.dll
2015-10-06 11:50 - 2015-09-24 20:35 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataAccountApis.dll
2015-10-06 11:50 - 2015-09-24 20:34 - 00223232 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhoneCallHistoryApis.dll
2015-10-06 11:50 - 2015-09-24 20:13 - 01276416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wifinetworkmanager.dll
2015-10-06 11:50 - 2015-09-24 19:23 - 00579072 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2015-10-06 11:50 - 2015-09-24 19:08 - 03586560 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2015-10-06 11:50 - 2015-09-24 19:07 - 01382400 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2015-10-06 11:50 - 2015-09-24 19:06 - 01423872 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataService.dll
2015-10-06 11:50 - 2015-09-24 19:05 - 00288256 _____ (Microsoft Corporation) C:\WINDOWS\system32\PimIndexMaintenance.dll
2015-10-06 11:50 - 2015-09-24 19:01 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\ContactApis.dll
2015-10-06 11:50 - 2015-09-24 19:01 - 00685568 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppointmentApis.dll
2015-10-06 11:50 - 2015-09-24 19:00 - 01205248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2015-10-06 11:50 - 2015-09-24 19:00 - 00752640 _____ (Microsoft Corporation) C:\WINDOWS\system32\ChatApis.dll
2015-10-06 11:50 - 2015-09-24 19:00 - 00720896 _____ (Microsoft Corporation) C:\WINDOWS\system32\EmailApis.dll
2015-10-06 11:50 - 2015-09-24 19:00 - 00163840 _____ (Microsoft Corporation) C:\WINDOWS\system32\CallHistoryClient.dll
2015-10-06 11:50 - 2015-09-17 02:50 - 01563392 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2015-10-06 11:50 - 2015-09-17 02:49 - 01563472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2015-10-06 11:50 - 2015-09-17 02:49 - 00894256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\Wdf01000.sys
2015-10-06 11:50 - 2015-09-17 02:49 - 00553808 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2015-10-06 11:50 - 2015-09-17 02:48 - 02432336 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2015-10-06 11:50 - 2015-09-17 02:48 - 02156400 _____ (Microsoft Corporation) C:\WINDOWS\system32\hevcdecoder.dll
2015-10-06 11:50 - 2015-09-17 02:48 - 00537080 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWanAPI.dll
2015-10-06 11:50 - 2015-09-17 02:48 - 00516448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2015-10-06 11:50 - 2015-09-17 02:48 - 00406864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\FWPKCLNT.SYS
2015-10-06 11:50 - 2015-09-17 02:48 - 00278352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2015-10-06 11:50 - 2015-09-17 02:47 - 01397088 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2015-10-06 11:50 - 2015-09-17 02:43 - 00966416 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2015-10-06 11:50 - 2015-09-17 02:08 - 00494592 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2015-10-06 11:50 - 2015-09-17 02:08 - 00053760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Speech.Pal.dll
2015-10-06 11:50 - 2015-09-17 02:05 - 00483328 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2015-10-06 11:50 - 2015-09-17 02:04 - 00910848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2015-10-06 11:50 - 2015-09-17 01:58 - 00503808 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2015-10-06 11:50 - 2015-09-17 01:57 - 02228736 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlansvc.dll
2015-10-06 11:50 - 2015-09-17 01:57 - 00281600 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEEventDispatcher.dll
2015-10-06 11:50 - 2015-09-17 01:57 - 00137728 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2015-10-06 11:50 - 2015-09-17 01:55 - 02236416 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2015-10-06 11:50 - 2015-09-17 01:55 - 01601536 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Speech.dll
2015-10-06 11:50 - 2015-09-17 01:55 - 00671232 _____ (Microsoft Corporation) C:\WINDOWS\system32\WUDFx02000.dll
2015-10-06 11:50 - 2015-09-17 01:55 - 00366592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2015-10-06 11:50 - 2015-09-17 01:55 - 00073728 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwancfg.dll
2015-10-06 11:50 - 2015-09-17 01:54 - 00780288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2015-10-06 11:50 - 2015-09-17 01:54 - 00324096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 06572032 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanmm.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 01181696 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 00856576 _____ (Microsoft Corporation) C:\WINDOWS\system32\MPSSVC.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 00591360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 00465920 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanconn.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2015-10-06 11:50 - 2015-09-17 01:52 - 00162304 _____ (Microsoft Corporation) C:\WINDOWS\system32\SubscriptionMgr.dll
2015-10-06 11:50 - 2015-09-17 01:51 - 02660864 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2015-10-06 11:50 - 2015-09-17 01:50 - 00320000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\portcls.sys
2015-10-06 11:50 - 2015-09-17 01:49 - 01290240 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Shell.dll
2015-10-06 11:50 - 2015-09-17 01:48 - 02093056 _____ (Microsoft Corporation) C:\WINDOWS\system32\wlidsvc.dll
2015-10-06 11:50 - 2015-09-17 01:45 - 01331200 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2015-10-06 11:50 - 2015-09-17 01:45 - 00627712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2015-10-06 11:50 - 2015-09-17 01:43 - 00378368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemEventsBrokerServer.dll
2015-10-06 11:49 - 2015-09-24 19:24 - 00796160 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2015-10-06 11:49 - 2015-09-24 19:24 - 00689152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Web.Core.dll
2015-10-06 11:49 - 2015-09-24 19:17 - 02178560 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2015-10-06 11:49 - 2015-09-24 18:53 - 00590336 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2015-10-06 11:49 - 2015-09-24 18:42 - 01795072 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.dll
2015-10-06 11:49 - 2015-09-19 01:14 - 00102304 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmapi.dll
2015-10-06 11:49 - 2015-09-17 02:50 - 02464216 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2015-10-06 11:49 - 2015-09-17 02:50 - 00099664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2015-10-06 11:49 - 2015-09-17 02:50 - 00088384 _____ (Microsoft Corporation) C:\WINDOWS\system32\remoteaudioendpoint.dll
2015-10-06 11:49 - 2015-09-17 02:49 - 08020816 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2015-10-06 11:49 - 2015-09-17 02:49 - 06487248 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2015-10-06 11:49 - 2015-09-17 02:49 - 00501008 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 02824248 _____ (Microsoft Corporation) C:\WINDOWS\system32\msmpeg2vdec.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 02494712 _____ C:\WINDOWS\system32\CoreUIComponents.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 01983824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2015-10-06 11:49 - 2015-09-17 02:48 - 00809352 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 00784136 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 00584656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mf.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 00555768 _____ (Microsoft Corporation) C:\WINDOWS\system32\directmanipulation.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 00505696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2015-10-06 11:49 - 2015-09-17 02:48 - 00476760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2015-10-06 11:49 - 2015-09-17 02:48 - 00395088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2015-10-06 11:49 - 2015-09-17 02:48 - 00332624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2015-10-06 11:49 - 2015-09-17 02:48 - 00243760 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2015-10-06 11:49 - 2015-09-17 02:44 - 00781976 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfds.dll
2015-10-06 11:49 - 2015-09-17 02:39 - 00081488 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2015-10-06 11:49 - 2015-09-17 02:37 - 01295712 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2015-10-06 11:49 - 2015-09-17 02:37 - 01168736 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2015-10-06 11:49 - 2015-09-17 02:12 - 16708608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2015-10-06 11:49 - 2015-09-17 02:11 - 00160256 _____ (Microsoft Corporation) C:\WINDOWS\system32\enrollmentapi.dll
2015-10-06 11:49 - 2015-09-17 02:10 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmregistration.dll
2015-10-06 11:49 - 2015-09-17 02:09 - 00269312 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2015-10-06 11:49 - 2015-09-17 02:09 - 00143360 _____ (Microsoft Corporation) C:\WINDOWS\system32\provops.dll
2015-10-06 11:49 - 2015-09-17 02:08 - 00026624 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManagerShellext.exe
2015-10-06 11:49 - 2015-09-17 02:07 - 21875712 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2015-10-06 11:49 - 2015-09-17 02:06 - 00690688 _____ (Microsoft Corporation) C:\WINDOWS\system32\CellularAPI.dll
2015-10-06 11:49 - 2015-09-17 02:06 - 00467968 _____ (Microsoft Corporation) C:\WINDOWS\system32\MBMediaManager.dll
2015-10-06 11:49 - 2015-09-17 02:06 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\tetheringservice.dll
2015-10-06 11:49 - 2015-09-17 02:05 - 02226688 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2015-10-06 11:49 - 2015-09-17 02:04 - 07569408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2015-10-06 11:49 - 2015-09-17 02:04 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\system32\DataSenseHandlers.dll
2015-10-06 11:49 - 2015-09-17 02:03 - 00267776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2015-10-06 11:49 - 2015-09-17 02:03 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\provisioningcsp.dll
2015-10-06 11:49 - 2015-09-17 02:03 - 00154624 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcertinst.exe
2015-10-06 11:49 - 2015-09-17 02:03 - 00088064 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngckeyenum.dll
2015-10-06 11:49 - 2015-09-17 02:03 - 00083968 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceEnroller.exe
2015-10-06 11:49 - 2015-09-17 02:02 - 00168960 _____ (Microsoft Corporation) C:\WINDOWS\system32\mdmmigrator.dll
2015-10-06 11:49 - 2015-09-17 02:02 - 00068096 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseDesktopAppMgmtCSP.dll
2015-10-06 11:49 - 2015-09-17 02:00 - 24595456 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2015-10-06 11:49 - 2015-09-17 02:00 - 03248640 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2015-10-06 11:49 - 2015-09-17 02:00 - 02417664 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2015-10-06 11:49 - 2015-09-17 02:00 - 00446976 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapConfiguration.dll
2015-10-06 11:49 - 2015-09-17 02:00 - 00106496 _____ (Microsoft Corporation) C:\WINDOWS\system32\KeywordDetectorMsftSidAdapter.dll
2015-10-06 11:49 - 2015-09-17 01:57 - 00403456 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmenrollengine.dll
2015-10-06 11:49 - 2015-09-17 01:56 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2015-10-06 11:49 - 2015-09-17 01:56 - 00521728 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2015-10-06 11:49 - 2015-09-17 01:56 - 00317440 _____ (Microsoft Corporation) C:\WINDOWS\system32\configmanager2.dll
2015-10-06 11:49 - 2015-09-17 01:55 - 00346112 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngccredprov.dll
2015-10-06 11:49 - 2015-09-17 01:55 - 00202240 _____ (Microsoft Corporation) C:\WINDOWS\system32\accountaccessor.dll
2015-10-06 11:49 - 2015-09-17 01:55 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcsps.dll
2015-10-06 11:49 - 2015-09-17 01:55 - 00120832 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2015-10-06 11:49 - 2015-09-17 01:54 - 03781120 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2015-10-06 11:49 - 2015-09-17 01:53 - 07055872 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2015-10-06 11:49 - 2015-09-17 01:52 - 01216512 _____ (Microsoft Corporation) C:\WINDOWS\system32\netcenter.dll
2015-10-06 11:49 - 2015-09-17 01:52 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2015-10-06 11:49 - 2015-09-17 01:52 - 00371712 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll
2015-10-06 11:49 - 2015-09-17 01:51 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\pnidui.dll
2015-10-06 11:49 - 2015-09-17 01:51 - 01203712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2015-10-06 11:49 - 2015-09-17 01:51 - 01067520 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2015-10-06 11:49 - 2015-09-17 01:51 - 00359936 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll
2015-10-06 11:49 - 2015-09-17 01:50 - 00421888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2015-10-06 11:49 - 2015-09-17 01:50 - 00312832 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2015-10-06 11:49 - 2015-09-17 01:50 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeWiFi.dll
2015-10-06 11:49 - 2015-09-17 01:50 - 00204288 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeCell.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 02740224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 01010176 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00771072 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00439296 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWebproxy.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationGeofences.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00268800 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationFramework.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00215552 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationCrowdsource.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00176640 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationPeIP.dll
2015-10-06 11:49 - 2015-09-17 01:49 - 00095744 _____ (Microsoft Corporation) C:\WINDOWS\system32\LocationWiFiAdapter.dll
2015-10-06 11:49 - 2015-09-17 01:48 - 00517632 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2015-10-06 11:49 - 2015-09-17 01:48 - 00408064 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredProvDataModel.dll
2015-10-06 11:49 - 2015-09-17 01:48 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2015-10-06 11:49 - 2015-09-17 01:48 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncryptprov.dll
2015-10-06 11:49 - 2015-09-17 01:48 - 00273920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.LockScreen.dll
2015-10-06 11:49 - 2015-09-17 01:47 - 07523328 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2015-10-06 11:49 - 2015-09-17 01:47 - 00513536 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2015-10-06 11:49 - 2015-09-17 01:47 - 00186880 _____ (Microsoft Corporation) C:\WINDOWS\system32\cloudAP.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00928256 _____ (Microsoft Corporation) C:\WINDOWS\system32\JpMapControl.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCore.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00118272 _____ (Microsoft Corporation) C:\WINDOWS\system32\KnobsCsp.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00084480 _____ (Microsoft Corporation) C:\WINDOWS\system32\MDMAppInstaller.exe
2015-10-06 11:49 - 2015-09-17 01:46 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\system32\HttpsDataSource.dll
2015-10-06 11:49 - 2015-09-17 01:46 - 00030208 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncmlhook.dll
2015-10-06 11:49 - 2015-09-17 01:45 - 04791296 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2015-10-06 11:49 - 2015-09-17 01:45 - 00869376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapControlCore.dll
2015-10-06 11:49 - 2015-09-17 01:45 - 00832512 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2015-10-06 11:49 - 2015-09-17 01:44 - 01844736 _____ (Microsoft Corporation) C:\WINDOWS\system32\workfolderssvc.dll
2015-10-06 11:49 - 2015-09-17 01:44 - 00599552 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2015-10-06 11:49 - 2015-09-17 01:44 - 00526336 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2015-10-06 11:49 - 2015-09-17 01:44 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\syncutil.dll
2015-10-06 11:49 - 2015-09-17 01:43 - 01213440 _____ (Microsoft Corporation) C:\WINDOWS\system32\RemoteNaturalLanguage.dll
2015-10-06 11:49 - 2015-09-17 01:43 - 00185344 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2015-10-06 11:49 - 2015-09-12 22:05 - 02987520 _____ (Microsoft Corporation) C:\WINDOWS\system32\esent.dll
2015-10-06 11:48 - 2015-09-17 01:50 - 00036352 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\buttonconverter.sys
2015-10-05 00:08 - 2015-10-05 00:08 - 00000017 _____ C:\Users\Wendy\AppData\Local\resmon.resmoncfg
2015-10-04 13:49 - 2015-10-04 14:03 - 2421989376 _____ C:\Users\Wendy\Downloads\O365HomePremRetail.img
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v4.5 Classic
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v4.5
2015-10-04 13:31 - 2015-10-05 22:16 - 00000000 ____D C:\Users\.NET v2.0
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5\AppData\Local\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v4.5 Classic\AppData\Local\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Macromedia
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Intel Corporation
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\InstallShield
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Roaming\Adobe
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Local\Windows Live
2015-10-04 13:31 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0\AppData\Local\Adobe
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v4.5\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v4.5 Classic\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:31 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v2.0\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 __RSD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 __RSD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows PowerShell
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tools
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ___RD C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\Classic .NET AppPool
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-10-04 13:30 - 2015-10-05 22:10 - 00000000 ____D C:\Users\.NET v2.0 Classic
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Macromedia
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Intel Corporation
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\InstallShield
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Roaming\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Windows Live
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Downloaded Installations
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\Classic .NET AppPool\AppData\Local\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Macromedia
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Intel Corporation
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\InstallShield
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Roaming\Adobe
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Local\Windows Live
2015-10-04 13:30 - 2015-08-03 17:46 - 00000000 ____D C:\Users\.NET v2.0 Classic\AppData\Local\Adobe
2015-10-04 13:30 - 2011-04-06 16:20 - 00057560 _____ C:\Users\Classic .NET AppPool\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:30 - 2011-04-06 16:20 - 00057560 _____ C:\Users\.NET v2.0 Classic\AppData\Local\GDIPFONTCACHEV1.DAT
2015-10-04 13:29 - 2015-10-04 13:29 - 00000000 ____D C:\Program Files\Windows Identity Foundation
2015-10-04 12:31 - 2015-10-04 12:31 - 00000000 ____D C:\Users\Wendy\AppData\Local\Google
2015-10-04 11:36 - 2015-10-04 11:36 - 00997927 _____ C:\Users\Wendy\Downloads\O15CTRRemove.diagcab
2015-10-03 22:22 - 2015-10-03 22:22 - 00000000 ____D C:\Program Files\DisplayLink Graphics
2015-10-03 22:20 - 2015-10-05 22:10 - 00000000 ____D C:\Program Files\DisplayLink Core Software
2015-10-03 22:20 - 2015-10-03 22:21 - 00002930 _____ C:\WINDOWS\system32\MsiExec.log
2015-10-03 21:02 - 2015-10-03 21:02 - 00000000 ____D C:\$SysReset
2015-10-03 19:20 - 2015-10-03 19:20 - 00038563 _____ C:\Users\Wendy\Downloads\cssemerg69697.diagcab
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files\Microsoft Security Client
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\Program Files (x86)\Broadcom
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\be8106b9bc95323fd268ba6235ad69
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\bd9118d39e1f207ee9cd6dcd0939
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\b9c13b78d128895b6e52
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\776e24d3f6aba141bb9c83b3fe63ae77
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\65b66254bc6a4f7c7497ac9d8307
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\4f4fa18d4dd8f99f0ea6a6420281251a
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\419a2caadd4290847864
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\318cab8197d210aa5c5e
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\3089b6a24ef724d145
2015-10-03 18:54 - 2015-10-03 18:54 - 00000000 _____ C:\04bf7963418bedcfdde09dca48
2015-09-20 18:39 - 2015-09-20 18:39 - 00001040 _____ C:\Users\Wendy\Desktop\9-20-15.txt
2015-09-17 18:55 - 2015-09-17 18:55 - 00003780 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0e826fa18e252
2015-09-13 15:51 - 2015-08-27 02:36 - 03620736 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2015-09-13 15:51 - 2015-08-27 02:32 - 00608936 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2015-09-13 15:51 - 2015-08-27 01:59 - 02880032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2015-09-13 15:51 - 2015-08-27 01:54 - 00541248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2015-09-13 15:51 - 2015-08-27 01:54 - 00365568 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2015-09-13 15:51 - 2015-08-27 01:51 - 02350592 _____ (Microsoft Corporation) C:\WINDOWS\system32\authui.dll
2015-09-13 15:51 - 2015-08-27 01:51 - 01774592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2015-09-13 15:51 - 2015-08-27 01:49 - 01008640 _____ (Microsoft Corporation) C:\WINDOWS\system32\schedsvc.dll
2015-09-13 15:51 - 2015-08-27 01:47 - 12503552 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2015-09-13 15:51 - 2015-08-27 01:43 - 00826880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript.dll
2015-09-13 15:51 - 2015-08-27 01:43 - 00576000 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00596480 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSync.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00187904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.PicturePassword.dll
2015-09-13 15:51 - 2015-08-27 01:42 - 00184320 _____ (Microsoft Corporation) C:\WINDOWS\system32\shacct.dll
2015-09-13 15:51 - 2015-08-27 01:39 - 00045568 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2015-09-13 15:51 - 2015-08-27 01:23 - 00303104 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2015-09-13 15:51 - 2015-08-27 01:16 - 02153472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\authui.dll
2015-09-13 15:51 - 2015-08-27 01:16 - 01612288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2015-09-13 15:51 - 2015-08-27 01:12 - 00650752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript.dll
2015-09-13 15:51 - 2015-08-27 01:12 - 00504320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2015-09-13 15:51 - 2015-08-27 01:11 - 00484352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSync.dll
2015-09-13 15:51 - 2015-08-27 01:11 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shacct.dll
2015-09-13 15:51 - 2015-08-27 01:09 - 11262464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2015-09-13 15:51 - 2015-08-27 01:08 - 00037376 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2015-10-11 12:54 - 2015-01-25 17:58 - 00000000 ___RD C:\Users\Wendy\iCloudDrive
2015-10-11 12:54 - 2014-03-03 18:27 - 00000000 ____D C:\Users\Wendy\OneDrive
2015-10-11 12:54 - 2011-10-08 22:42 - 00000000 ____D C:\ProgramData\clear.fi
2015-10-11 12:53 - 2015-09-05 18:05 - 00000920 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d0e826fa18e252.job
2015-10-11 12:53 - 2013-02-21 22:12 - 00000894 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job
2015-10-11 12:52 - 2015-07-10 08:22 - 00000275 _____ C:\WINDOWS\WindowsUpdate.log
2015-10-11 12:52 - 2015-07-10 08:21 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2015-10-11 12:51 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\sru
2015-10-11 12:51 - 2015-07-10 05:05 - 00262144 ___SH C:\WINDOWS\system32\config\BBI
2015-10-11 12:33 - 2015-07-10 06:55 - 00000000 ____D C:\WINDOWS\CbsTemp
2015-10-11 12:29 - 2012-06-17 10:30 - 00000830 _____ C:\WINDOWS\Tasks\Adobe Flash Player Updater.job
2015-10-11 12:12 - 2015-08-03 17:35 - 01006528 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2015-10-11 12:07 - 2015-09-05 19:15 - 00008678 _____ C:\WINDOWS\PFRO.log
2015-10-11 12:00 - 2013-02-21 22:12 - 00000924 _____ C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job
2015-10-11 10:16 - 2011-12-25 20:30 - 00004154 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896}
2015-10-11 09:34 - 2015-08-03 17:37 - 00000000 ____D C:\Users\Wendy
2015-10-11 09:33 - 2011-10-08 22:16 - 00000000 ____D C:\Users\Wendy\AppData\Local\PowerCinema
2015-10-11 09:32 - 2014-11-23 13:23 - 00000000 ____D C:\Program Files (x86)\ESET
2015-10-11 09:32 - 2013-03-06 21:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Application Virtualization Client
2015-10-11 09:27 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\registration
2015-10-10 21:14 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\rescache
2015-10-10 20:13 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\AppReadiness
2015-10-10 18:41 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\NDF
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\system32\F12
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessibility
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\SystemResetPlatform
2015-10-10 18:19 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\appraiser
2015-10-10 18:18 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PurchaseDialog
2015-10-10 18:18 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\Provisioning
2015-10-10 18:18 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\L2Schemas
2015-10-10 16:51 - 2014-08-18 12:55 - 00000008 __RSH C:\ProgramData\ntuser.pol
2015-10-10 16:46 - 2013-12-31 22:12 - 00000000 ____D C:\Users\Wendy\AppData\LocalLow\Temp
2015-10-10 16:45 - 2015-08-20 14:37 - 00000000 ____D C:\WINDOWS\SysWOW64\GroupPolicy
2015-10-10 16:45 - 2009-07-13 23:20 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2015-10-10 16:36 - 2013-02-21 22:12 - 00003468 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2015-10-10 16:33 - 2011-05-14 10:09 - 00003410 _____ C:\WINDOWS\System32\Tasks\clear.fiAgent
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 __RSD C:\WINDOWS\Media
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___SD C:\WINDOWS\system32\Nui
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\oobe
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\MailContactsCalendarSync
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system\Speech
2015-10-06 10:21 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\IME
2015-10-06 10:20 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2015-10-06 10:20 - 2015-07-10 05:05 - 00000000 ____D C:\WINDOWS\servicing
2015-10-06 10:20 - 2013-03-06 21:38 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2015-10-06 10:19 - 2015-08-03 18:04 - 00000000 ____D C:\Users\Wendy\AppData\Local\Packages
2015-10-06 10:19 - 2015-08-03 17:37 - 00000000 ___RD C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-10-06 10:17 - 2015-07-10 07:04 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2015-10-06 10:17 - 2015-03-21 09:56 - 00000000 ____D C:\Users\Wendy\AppData\Local\Microsoft Help
2015-10-06 10:17 - 2014-03-03 18:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013
2015-10-06 10:17 - 2014-03-03 18:17 - 00000000 ____D C:\Program Files\Microsoft Office 15
2015-10-06 10:17 - 2013-03-06 21:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
2015-10-06 10:17 - 2013-03-06 21:38 - 00000000 ____D C:\Program Files\Microsoft Office
2015-10-06 10:17 - 2013-02-21 22:13 - 00000000 ____D C:\Program Files\Google
2015-10-06 10:17 - 2013-02-21 22:12 - 00000000 ____D C:\Program Files (x86)\Google
2015-10-06 10:17 - 2011-05-14 10:01 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
2015-10-06 10:17 - 2011-04-06 17:00 - 00000000 ____D C:\ProgramData\BackupManager
2015-10-06 10:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2015-10-06 10:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\SystemResources
2015-10-06 09:59 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2015-10-06 09:58 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\PrintDialog
2015-10-06 09:58 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2015-10-06 09:57 - 2015-07-10 07:04 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2015-10-06 09:55 - 2013-03-06 21:39 - 00000000 ____D C:\Users\Wendy\AppData\Roaming\SoftGrid Client
2015-10-06 09:34 - 2015-08-03 21:18 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-10-06 09:34 - 2015-07-10 09:14 - 00000000 ____D C:\Program Files\Windows Journal
2015-10-06 09:34 - 2015-07-10 07:04 - 00000000 ____D C:\Program Files\Windows NT
2015-10-06 09:34 - 2013-03-14 03:01 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2015-10-06 09:30 - 2015-08-03 21:18 - 00000000 ____D C:\inetpub
2015-10-06 09:30 - 2011-04-06 16:56 - 00000000 ___HD C:\OEM
2015-10-06 09:30 - 2011-04-06 16:55 - 00000000 ____D C:\Program Files (x86)\EgisTec Shredder
2015-10-06 09:30 - 2011-04-06 16:54 - 00000000 ____D C:\Program Files (x86)\EgisTec MyWinLocker
2015-10-06 09:30 - 2011-04-06 16:53 - 00000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2015-10-06 09:30 - 2011-04-06 16:52 - 00000000 ____D C:\Program Files (x86)\Windows Live
2015-10-06 09:30 - 2011-04-06 16:21 - 00000000 ____D C:\Program Files (x86)\Acer Games
2015-10-04 13:31 - 2015-08-03 17:35 - 00042366 _____ C:\WINDOWS\iis.log
2015-10-03 18:54 - 2013-03-06 21:38 - 00000000 ____D C:\Users\Wendy\AppData\Roaming\TP
2015-10-01 18:25 - 2015-07-10 08:20 - 00018136 _____ C:\WINDOWS\setupact.log
2015-09-27 15:46 - 2015-09-07 18:52 - 00000000 ____D C:\Users\Wendy\AppData\Local\Comms
2015-09-21 00:00 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2015-09-20 23:22 - 2011-10-08 22:15 - 00000000 ____D C:\Users\Wendy\AppData\Local\VirtualStore
2015-09-20 20:41 - 2015-07-10 08:20 - 00336488 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2015-09-20 20:21 - 2013-08-15 03:01 - 00000000 ____D C:\WINDOWS\system32\MRT
2015-09-20 18:46 - 2015-08-23 20:31 - 00113880 _____ (Malwarebytes Corporation) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2015-09-20 18:39 - 2015-08-03 18:13 - 00002378 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2015-09-20 18:39 - 2015-08-03 18:09 - 00001331 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan.lnk
2015-09-20 18:39 - 2015-08-03 18:07 - 00001313 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Realtek HD Audio Manager.lnk
2015-09-20 18:39 - 2015-08-03 17:46 - 00001540 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002425 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Immersive Control Panel.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002289 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PrintDialog.lnk
2015-09-20 18:39 - 2015-07-10 07:01 - 00002287 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Devices Flow.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00002313 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MiracastView.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00001578 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Search.lnk
2015-09-20 18:39 - 2015-07-10 07:00 - 00000853 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Desktop.lnk
2015-09-20 18:39 - 2015-03-21 09:27 - 00002429 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2015-09-20 18:39 - 2014-08-18 02:33 - 00001015 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
2015-09-20 18:39 - 2014-07-12 18:05 - 00001366 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Photo Gallery.lnk
2015-09-20 18:39 - 2014-03-03 18:27 - 00002162 _____ C:\Users\Wendy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2015-09-20 18:39 - 2012-10-14 10:52 - 00001866 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fooz Kids.lnk
2015-09-20 18:39 - 2011-12-02 19:21 - 00002507 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Apple Software Update.lnk
2015-09-20 18:39 - 2011-10-08 22:16 - 00000915 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Times Reader.lnk
2015-09-20 18:39 - 2011-05-14 10:14 - 00002478 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Messenger.lnk
2015-09-20 18:39 - 2011-04-06 16:52 - 00001450 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk
2015-09-20 18:38 - 2015-09-07 14:00 - 00000989 _____ C:\Users\Wendy\Desktop\CBS.log - Shortcut.lnk
2015-09-20 18:38 - 2015-08-23 20:31 - 00001173 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2015-09-20 18:38 - 2015-07-18 15:05 - 00001751 _____ C:\Users\Public\Desktop\iTunes.lnk
2015-09-20 18:38 - 2015-07-18 14:54 - 00001843 _____ C:\Users\Public\Desktop\QuickTime Player.lnk
2015-09-20 18:38 - 2015-03-21 09:27 - 00002017 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2015-09-20 18:38 - 2014-08-18 02:34 - 00001015 _____ C:\Users\Wendy\Desktop\Audacity.lnk
2015-09-20 18:38 - 2014-07-26 09:52 - 00001211 _____ C:\Users\Wendy\Desktop\Kaspersky Security Scan.lnk
2015-09-20 18:38 - 2014-07-12 18:59 - 00001216 _____ C:\Users\Public\Desktop\XSplit Gamecaster.lnk
2015-09-20 18:38 - 2014-07-12 18:05 - 00001297 _____ C:\Users\Wendy\Desktop\Movie Maker.lnk
2015-09-20 18:38 - 2014-07-12 17:52 - 00002691 _____ C:\Users\Public\Desktop\Skype.lnk
2015-09-20 18:38 - 2014-07-11 19:19 - 00002151 _____ C:\Users\Public\Desktop\AVerMedia RECentral.lnk
2015-09-20 18:38 - 2012-10-14 10:52 - 00001860 _____ C:\Users\Public\Desktop\Fooz Kids.lnk
2015-09-20 18:38 - 2011-10-16 14:23 - 00002229 _____ C:\Users\Public\Desktop\BlackBerry Desktop Software.lnk
2015-09-20 18:38 - 2011-10-08 22:17 - 00001962 _____ C:\Users\Public\Desktop\Netflix.lnk
2015-09-20 18:38 - 2011-10-08 22:16 - 00000909 _____ C:\Users\Public\Desktop\Times Reader.lnk
2015-09-20 18:38 - 2011-05-14 10:11 - 00001206 _____ C:\Users\Public\Desktop\NOOK for PC.lnk
2015-09-20 18:38 - 2011-05-14 10:09 - 00002165 _____ C:\Users\Public\Desktop\clear.fi.lnk
2015-09-20 18:38 - 2011-04-06 16:57 - 00001984 _____ C:\Users\Public\Desktop\Norton Online Backup.lnk
2015-09-20 18:38 - 2011-04-06 16:51 - 00002727 _____ C:\Users\Public\Desktop\clear.fi Tutorial.lnk
2015-09-20 18:38 - 2011-04-06 16:20 - 00002562 _____ C:\Users\Public\Desktop\WildTangent Games App - acer.lnk
2015-09-20 14:48 - 2015-07-10 07:04 - 00000000 ____D C:\WINDOWS\system32\AppLocker
2015-09-20 11:26 - 2015-02-02 01:57 - 00000000 ____D C:\Users\Wendy\Documents\Outlook Files
2015-09-17 18:55 - 2013-02-21 22:12 - 00003982 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA
2015-09-13 11:37 - 2011-10-09 09:37 - 00000000 ____D C:\Users\Wendy\AppData\Local\Apple Computer
 
==================== Files in the root of some directories =======
 
2015-10-03 18:54 - 2015-10-03 18:54 - 0000000 _____ () C:\Program Files\Microsoft Security Client
2015-10-03 18:54 - 2015-10-03 18:54 - 0000000 _____ () C:\Program Files (x86)\Broadcom
2011-10-16 14:23 - 2011-10-16 14:56 - 0000077 _____ () C:\Users\Wendy\AppData\Roaming\Rim.Desktop.Exception.log
2011-10-16 14:23 - 2011-10-16 14:23 - 0001153 _____ () C:\Users\Wendy\AppData\Roaming\Rim.Desktop.HttpServerSetup.log
2011-10-16 14:23 - 2011-10-16 14:56 - 0000077 _____ () C:\Users\Wendy\AppData\Roaming\Rim.DesktopHelper.Exception.log
2014-08-25 02:24 - 2014-08-28 14:02 - 0000089 _____ () C:\Users\Wendy\AppData\Roaming\WB.CFG
2015-10-05 00:08 - 2015-10-05 00:08 - 0000017 _____ () C:\Users\Wendy\AppData\Local\resmon.resmoncfg
2011-05-14 10:07 - 2011-05-14 10:10 - 0015152 _____ () C:\ProgramData\ArcadeDeluxe5.log
2015-08-03 17:33 - 2015-08-03 17:33 - 0000000 ____H () C:\ProgramData\DP45977C.lfl
 
==================== Bamital & volsnap =================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll
[2015-07-10 07:00] - [2015-08-22 14:52] - 0680256 ____A (Microsoft Corporation) F84D50EF068750CB192D15D4FDD7088C
 
C:\WINDOWS\SysWOW64\dnsapi.dll
[2015-10-11 08:56] - [2015-10-11 08:56] - 0534064 ____A (Microsoft Corporation) 9E3E09B58BD454CC882A2DF6D7D35CED
 
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 

LastRegBack: 2015-10-06 10:41
 
==================== End of FRST.txt ============================
 
 

  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK could you press windows + x key then select command prompt (admin)

Copy and paste the following into the black box one at a time and press enter after each :

sfc /scanfile=C:\Windows\system32\dnsapi.dll

sfc /scanfile=C:\Windows\SysWOW64\dnsapi.dll


Let me know what windows reports on completion... There may need to be a reboot each time
  • 0

#15
mistywjd

mistywjd

    Member

  • Topic Starter
  • Member
  • PipPip
  • 12 posts

Heres what I got. I also copied part of the CBS log. Don't know if that info will help you or not.

 

Microsoft Windows [Version 10.0.10240]
© 2015 Microsoft Corporation. All rights reserved.
 
C:\WINDOWS\system32>sfc /scanfile=C:\Windows\system32\dnsapi.dll
 

Windows Resource Protection found corrupt files but was unable to fix some
of them. Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For
example C:\Windows\Logs\CBS\CBS.log. Note that logging is currently not
supported in offline servicing scenarios.
 
C:\WINDOWS\system32>sfc /scanfile=C:\Windows\SysWOW64\dnsapi.dll
 

Windows Resource Protection found corrupt files but was unable to fix some
of them. Details are included in the CBS.Log windir\Logs\CBS\CBS.log. For
example C:\Windows\Logs\CBS\CBS.log. Note that logging is currently not
supported in offline servicing scenarios.
 
C:\WINDOWS\system32>

 

 

CBS Log:

 

2015-10-11 13:38:08, Info                  CBS    TiWorker: Client requests SFP repair object.
2015-10-11 13:38:08, Info                  CSI    0000002c [SR] Verifying 1 components
2015-10-11 13:38:08, Info                  CSI    0000002d [SR] Beginning Verify and Repair transaction
2015-10-11 13:38:08, Info                  CSI    0000002e [SR] Cannot repair member file [l:20{10}]"dnsapi.dll" of Microsoft-Windows-DNS-Client-MinWin, Version = 10.0.10240.16384, pA Host= amd64 Guest= x86, nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35} in the store, file is missing
2015-10-11 13:38:08, Error                 CSI    0000002f (F) Failed on regenerating file [l:20{10}]"dnsapi.dll"[gle=0x80004005]
2015-10-11 13:38:08, Info                  CSI    00000030 [SR] Unable to repair \SystemRoot\WinSxS\wow64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.10240.16384_none_a7e0cfc0f233a685\\[l:20{10}]"dnsapi.dll"
2015-10-11 13:38:08, Info                  CSI    00000031 [SR] Repaired file \SystemRoot\WinSxS\wow64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.10240.16384_none_a7e0cfc0f233a685\\[l:20{10}]"dnsapi.dll" by copying from backup
2015-10-11 13:38:08, Info                  CSI    [email protected]/10/11:17:38:08.237 Primitive installers committed for repair
2015-10-11 13:38:08, Info                  CSI    00000033 [SR] Cannot repair member file [l:20{10}]"dnsapi.dll" of Microsoft-Windows-DNS-Client-MinWin, Version = 10.0.10240.16384, pA Host= amd64 Guest= x86, nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35} in the store, file is missing
2015-10-11 13:38:08, Info                  CSI    00000034 [SR] This component was referenced by [l:244{122}]"Microsoft-OneCore-CoreSystem-WOW64-minio-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.14e1b652c6ec0cb59aef90962374aa68"
2015-10-11 13:38:08, Info                  CSI    00000035 [SR] This component was referenced by [l:362{181}]"Microsoft-Windows-Client-Features-WOW64-Package-AutoMerged-minio~31bf3856ad364e35~amd64~~10.0.10240.16384.Microsoft-Windows-Client-Features-WOW64-Package-AutoMerged-minio-Deployment"
2015-10-11 13:38:08, Info                  CSI    00000036 Hashes for file member \??\C:\WINDOWS\SysWOW64\dnsapi.dll do not match actual file [l:20{10}]"dnsapi.dll" :
  Found: {l:32 b:pr+WNONWQG1FrXKzIFGrNHWXDbeMSJDc2Zm0HJNhP8k=} Expected: {l:32 b:+b4VwQ0vg1w9k9sMCTjvkVMTIPgp4HEXUMZnCIGtWYg=}
2015-10-11 13:38:08, Info                  CSI    00000037 [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\WINDOWS\SysWOW64"\[l:20{10}]"dnsapi.dll"; source file in store is also corrupted
2015-10-11 13:38:08, Info                  CSI    [email protected]/10/11:17:38:08.284 Primitive installers committed for repair
2015-10-11 13:38:08, Info                  CSI    00000039 [SR] Verify complete
2015-10-11 13:38:08, Info                  CSI    0000003a [SR] Repairing 1 components
2015-10-11 13:38:08, Info                  CSI    0000003b [SR] Beginning Verify and Repair transaction
2015-10-11 13:38:08, Info                  CSI    0000003c [SR] Cannot repair member file [l:20{10}]"dnsapi.dll" of Microsoft-Windows-DNS-Client-MinWin, Version = 10.0.10240.16384, pA Host= amd64 Guest= x86, nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35} in the store, file is missing
2015-10-11 13:38:08, Error                 CSI    0000003d (F) Failed on regenerating file [l:20{10}]"dnsapi.dll"[gle=0x80004005]
2015-10-11 13:38:08, Info                  CSI    0000003e [SR] Unable to repair \SystemRoot\WinSxS\wow64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.10240.16384_none_a7e0cfc0f233a685\\[l:20{10}]"dnsapi.dll"
2015-10-11 13:38:08, Info                  CSI    0000003f [SR] Repaired file \SystemRoot\WinSxS\wow64_microsoft-windows-dns-client-minwin_31bf3856ad364e35_10.0.10240.16384_none_a7e0cfc0f233a685\\[l:20{10}]"dnsapi.dll" by copying from backup
2015-10-11 13:38:08, Info                  CSI    [email protected]/10/11:17:38:08.315 Primitive installers committed for repair
2015-10-11 13:38:08, Info                  CSI    00000041 [SR] Cannot repair member file [l:20{10}]"dnsapi.dll" of Microsoft-Windows-DNS-Client-MinWin, Version = 10.0.10240.16384, pA Host= amd64 Guest= x86, nonSxS, PublicKeyToken = {l:8 b:31bf3856ad364e35} in the store, file is missing
2015-10-11 13:38:08, Info                  CSI    00000042 [SR] This component was referenced by [l:244{122}]"Microsoft-OneCore-CoreSystem-WOW64-minio-Package~31bf3856ad364e35~amd64~~10.0.10240.16384.14e1b652c6ec0cb59aef90962374aa68"
2015-10-11 13:38:08, Info                  CSI    00000043 [SR] This component was referenced by [l:362{181}]"Microsoft-Windows-Client-Features-WOW64-Package-AutoMerged-minio~31bf3856ad364e35~amd64~~10.0.10240.16384.Microsoft-Windows-Client-Features-WOW64-Package-AutoMerged-minio-Deployment"
2015-10-11 13:38:08, Info                  CSI    00000044 Hashes for file member \??\C:\WINDOWS\SysWOW64\dnsapi.dll do not match actual file [l:20{10}]"dnsapi.dll" :
  Found: {l:32 b:pr+WNONWQG1FrXKzIFGrNHWXDbeMSJDc2Zm0HJNhP8k=} Expected: {l:32 b:+b4VwQ0vg1w9k9sMCTjvkVMTIPgp4HEXUMZnCIGtWYg=}
2015-10-11 13:38:08, Info                  CSI    00000045 [SR] Could not reproject corrupted file [ml:48{24},l:46{23}]"\??\C:\WINDOWS\SysWOW64"\[l:20{10}]"dnsapi.dll"; source file in store is also corrupted
2015-10-11 13:38:08, Info                  CSI    [email protected]/10/11:17:38:08.331 Primitive installers committed for repair
2015-10-11 13:38:08, Info                  CSI    00000047 [SR] Repair complete
2015-10-11 13:38:08, Info                  CSI    00000048 [SR] Committing transaction
2015-10-11 13:38:08, Info                  CSI    00000049 Creating NT transaction (seq 3), objectname [6]"(null)"
2015-10-11 13:38:08, Info                  CSI    0000004a Created NT transaction (seq 3) result 0x00000000, handle @0x390
2015-10-11 13:38:08, Info                  CSI    [email protected]/10/11:17:38:08.409 Beginning NT transaction commit...
2015-10-11 13:38:08, Info                  CSI    [email protected]/10/11:17:38:08.440 CSI perf trace:
CSIPERF:TXCOMMIT;50940​


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP