Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Norton disappeared, and Windows Not Genuine. [Solved]


  • This topic is locked This topic is locked

#1
chanseygirl

chanseygirl

    Member

  • Member
  • PipPip
  • 13 posts

My Norton firewall and virus protector disappeared, and the file is empty. I tried to re-download it, but am unsuccessful. Also getting popup saying that Windows is not genuine, computer is extremely slow, website pages keep becoming unresponsive, and can not utilize Windows Updates.

 

I ran the FRST scan and is pasted below:

 

FRST - Notepad

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:14-12-2015
Ran by home (administrator) on MAIN (14-12-2015 20:28:06)
Running from C:\Users\home\Desktop
Loaded Profiles: home (Available Profiles: home)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 10 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\Lexmark Z2300 Series\lxdpmon.exe
(Lexmark International Inc.) C:\Program Files (x86)\Lexmark Z2300 Series\ezprint.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(TomTom) C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(IOI) C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\concentr.exe
() C:\Program Files (x86)\AVG Secure Search\vprot.exe
(Citrix Systems, Inc.) C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe
(Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
(Acer Incorporated) C:\Program Files (x86)\Gateway\Registration\GREGsvc.exe
( ) C:\Windows\System32\lxdpcoms.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe
() C:\Program Files\MySQL\MySQL Server 5.5\bin\mysqld.exe
(Symantec Corporation) C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\n360.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Acer Group) C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.1.0\ToolbarUpdater.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
() C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.1.0\loggingserver.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Microsoft Corp.) C:\Program Files (x86)\Microsoft HealthVault\Connection Center\ConnectionCenter.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [IAAnotif] => C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-04] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7981088 2009-07-20] (Realtek Semiconductor)
HKLM\...\Run: [lxdpmon.exe] => C:\Program Files (x86)\Lexmark Z2300 Series\lxdpmon.exe [672424 2010-02-04] ()
HKLM\...\Run: [EzPrint] => C:\Program Files (x86)\Lexmark Z2300 Series\ezprint.exe [107176 2010-02-04] (Lexmark International Inc.)
HKLM-x32\...\Run: [Gateway Photo Frame] => C:\Program Files (x86)\Gateway Photo Frame\ButtonMonitor.exe [124416 2009-07-20] (IOI)
HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [103768 2009-09-12] (Citrix Systems, Inc.)
HKLM-x32\...\Run: [vProt] => C:\Program Files (x86)\AVG Secure Search\vprot.exe [2573712 2015-12-11] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [453736 2013-02-19] (CANON INC.)
HKLM-x32\...\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1064144 2015-03-06] (Carbonite, Inc.)
HKLM-x32\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4377256 2015-09-04] (Fitbit, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\...\Run: [MyTomTomSA.exe] => C:\Program Files (x86)\MyTomTom 3\MyTomTomSA.exe [455608 2013-05-23] (TomTom)
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4377256 2015-09-04] (Fitbit, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files (x86)\Norton 360\Engine64\21.7.0.11\buShell.dll [2015-03-06] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files (x86)\Norton 360\Engine64\21.7.0.11\buShell.dll [2015-03-06] (Symantec Corporation)
ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files (x86)\Norton 360\Engine64\21.7.0.11\buShell.dll [2015-03-06] (Symantec Corporation)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll [2015-03-06] (Carbonite, Inc.)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2007-10-10]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk [2007-10-10]
ShortcutTarget: Best Buy pc app.lnk -> C:\ProgramData\Best Buy pc app\ClickOnceSetup.exe (Microsoft)
Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MedApps Device Monitor.lnk [2012-08-14]
ShortcutTarget: MedApps Device Monitor.lnk -> C:\Users\home\AppData\Roaming\Microsoft\Installer\{057FC282-826A-41E4-B6D9-9E6BCFD8B8E3}\_11C58EEF5D7511CC7409FC.exe ()
Startup: C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Microsoft HealthVault Connection Center.lnk [2012-08-14]
ShortcutTarget: Microsoft HealthVault Connection Center.lnk -> C:\Program Files (x86)\Microsoft HealthVault\Connection Center\ConnectionCenter.exe (Microsoft Corp.)

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{0240F8FF-32BB-42EF-8D34-35CC0129BE58}: [DhcpNameServer] 192.168.1.1

Internet Explorer:
==================
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=N360&pvid=21.6.0.32
HKU\S-1-5-19\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=N360&pvid=21.6.0.32
HKU\S-1-5-20\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=N360&pvid=21.6.0.32
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=N360&pvid=21.6.0.32
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
URLSearchHook: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> Default = {810a18c2-8c07-be74-21b6-b8261b1487fd}
URLSearchHook: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 - FCToolbarURLSearchHook Class - {810a18c2-8c07-be74-21b6-b8261b1487fd} - C:\Program Files (x86)\BucksBee Loyalty Plugin - OpenInstall\Helper.dll ()
SearchScopes: HKLM-x32 -> DefaultScope {608093E8-E04B-40D6-85F6-7764FE0723D4} URL =
SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACGW
SearchScopes: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> {608093E8-E04B-40D6-85F6-7764FE0723D4} URL =
SearchScopes: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACGW_enUS419
SearchScopes: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=US&ver=6
BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine64\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\IPS\IPSBHO.DLL [2015-03-04] (Symantec Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll [2013-12-18] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21] (Microsoft Corp.)
BHO-x32: AVG Security Toolbar -> {95B7759C-8C7F-4BF1-B163-73684A933233} -> C:\Program Files (x86)\AVG Secure Search\19.1.0.285\AVG Secure Search_toolbar.dll [2015-12-11] (AVG Secure Search)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll [2013-12-18] (Oracle Corporation)
Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine64\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
Toolbar: HKLM-x32 - AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\19.1.0.285\AVG Secure Search_toolbar.dll [2015-12-11] (AVG Secure Search)
Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation)
Toolbar: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Toolbar: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
DPF: HKLM-x32 {4871A87A-BFDD-4106-8153-FFDE2BAC2967} hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.7.cab
DPF: HKLM-x32 {895D1291-D5BD-4982-BA84-AD11D29C1D6A} hxxp://community.weightwatchers.com/Scripts/ImageUploader6.cab
Handler-x32: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\19.1.0\ViProtocol.dll [2015-12-11] (AVG Secure Search)

FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin -> C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\19.1.0\\npsitesafety.dll [No File]
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll [2013-12-18] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll [2013-12-18] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.40728.0\npctrl.dll [2015-07-28] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2012-03-16] (VideoLAN)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2015-09-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-839081694-1943692923-2272886626-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Program Files (x86)\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10171.dll [2012-07-24] (Amazon.com, Inc.)
FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn
FF Extension: No Name - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2015-07-09] [not signed]
FF HKLM-x32\...\Firefox\Extensions: [avg@toolbar] - C:\ProgramData\AVG Secure Search\FireFoxExt\17.3.0.49 => not found

Chrome:
=======
CHR Profile: C:\Users\home\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Docs) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-05-08]
CHR Extension: (Google Drive) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-05-08]
CHR Extension: (YouTube) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-05-08]
CHR Extension: (Google Search) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-05-08]
CHR Extension: (No Name) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\gmlllbghnfkpflemihljekbapjopfjik [2015-07-12]
CHR Extension: (Norton Identity Safe) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\iikflkcanblccfahdhdonehdalibjnif [2014-09-10]
CHR Extension: (Chrome Hotword Shared Module) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-12]
CHR Extension: (Norton Security Toolbar) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk [2015-07-12]
CHR Extension: (Google Wallet) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-07-12]
CHR Extension: (Gmail) - C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-05-08]
CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\Exts\Chrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - <no Path/update_url>
CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\Exts\Chrome.crx <not found>
CHR HKLM-x32\...\Chrome\Extension: [ndibdjnfmopecpmkdieinmbadjfpblof] - C:\ProgramData\AVG Secure Search\ChromeExt\17.3.0.49\avg.crx <not found>

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 AeLookupSvc; C:\Windows\System32\aelupsvc.dll [72192 2009-07-13] (Microsoft Corporation) [File not signed]
S3 ALG; C:\Windows\System32\alg.exe [79360 2009-07-13] (Microsoft Corporation) [File not signed]
S3 AppIDSvc; C:\Windows\System32\appidsvc.dll [32256 2009-07-13] (Microsoft Corporation) [File not signed]
S3 Appinfo; C:\Windows\System32\appinfo.dll [70144 2013-02-26] (Microsoft Corporation) [File not signed]
R2 AudioEndpointBuilder; C:\Windows\System32\Audiosrv.dll [679424 2010-11-20] (Microsoft Corporation) [File not signed]
R2 AudioSrv; C:\Windows\System32\Audiosrv.dll [679424 2010-11-20] (Microsoft Corporation) [File not signed]
S3 AxInstSV; C:\Windows\System32\AxInstSV.dll [114688 2010-11-20] (Microsoft Corporation) [File not signed]
S3 BDESVC; C:\Windows\System32\bdesvc.dll [100864 2009-07-13] (Microsoft Corporation) [File not signed]
R2 BFE; C:\Windows\System32\bfe.dll [705024 2010-11-20] (Microsoft Corporation) [File not signed]
R2 BITS; C:\Windows\system32\qmgr.dll [849920 2010-11-20] (Microsoft Corporation) [File not signed]
R2 Browser; C:\Windows\System32\browser.dll [136704 2012-07-04] (Microsoft Corporation) [File not signed]
S3 bthserv; C:\Windows\system32\bthserv.dll [83968 2009-07-13] (Microsoft Corporation) [File not signed]
S3 CertPropSvc; C:\Windows\System32\certprop.dll [80384 2010-11-20] (Microsoft Corporation) [File not signed]
R2 CryptSvc; C:\Windows\system32\cryptsvc.dll [184320 2013-07-08] (Microsoft Corporation) [File not signed]
R2 CryptSvc; C:\Windows\SysWOW64\cryptsvc.dll [140288 2013-07-08] (Microsoft Corporation) [File not signed]
R2 DcomLaunch; C:\Windows\system32\rpcss.dll [512000 2010-11-20] (Microsoft Corporation) [File not signed]
S3 defragsvc; C:\Windows\System32\defragsvc.dll [291328 2009-07-13] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\Windows\system32\dhcpcore.dll [317952 2010-11-20] (Microsoft Corporation) [File not signed]
R2 Dhcp; C:\Windows\SysWOW64\dhcpcore.dll [254464 2010-11-20] (Microsoft Corporation) [File not signed]
R2 Dnscache; C:\Windows\System32\dnsrslvr.dll [183296 2011-03-03] (Microsoft Corporation) [File not signed]
S3 dot3svc; C:\Windows\System32\dot3svc.dll [252416 2010-11-20] (Microsoft Corporation) [File not signed]
R2 DPS; C:\Windows\system32\dps.dll [162816 2010-11-20] (Microsoft Corporation) [File not signed]
S3 EapHost; C:\Windows\System32\eapsvc.dll [111104 2009-07-13] (Microsoft Corporation) [File not signed]
R2 EFS; C:\Windows\System32\lsass.exe [30720 2013-09-24] (Microsoft Corporation) [File not signed]
S3 ehRecvr; C:\Windows\ehome\ehRecvr.exe [696832 2010-11-20] (Microsoft Corporation) [File not signed]
S3 ehSched; C:\Windows\ehome\ehsched.exe [127488 2009-07-13] (Microsoft Corporation) [File not signed]
R2 eventlog; C:\Windows\System32\wevtsvc.dll [1646080 2010-11-20] (Microsoft Corporation) [File not signed]
R2 EventSystem; C:\Windows\system32\es.dll [402944 2009-07-13] (Microsoft Corporation) [File not signed]
R2 EventSystem; C:\Windows\SysWOW64\es.dll [271360 2009-07-13] (Microsoft Corporation) [File not signed]
S3 Fax; C:\Windows\system32\fxssvc.exe [689152 2010-11-20] (Microsoft Corporation) [File not signed]
R3 fdPHost; C:\Windows\system32\fdPHost.dll [16384 2009-07-13] (Microsoft Corporation) [File not signed]
R2 FDResPub; C:\Windows\system32\fdrespub.dll [34816 2009-07-13] (Microsoft Corporation) [File not signed]
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [5750440 2015-09-04] (Fitbit, Inc.)
R2 FontCache; C:\Windows\system32\FntCache.dll [1175552 2013-06-05] (Microsoft Corporation) [File not signed]
R2 gpsvc; C:\Windows\System32\gpsvc.dll [777728 2010-11-20] (Microsoft Corporation) [File not signed]
R3 hidserv; C:\Windows\System32\hidserv.dll [38912 2009-07-13] (Microsoft Corporation) [File not signed]
R3 hidserv; C:\Windows\SysWOW64\hidserv.dll [49152 2009-07-13] (Microsoft Corporation) [File not signed]
S3 hkmsvc; C:\Windows\system32\kmsvc.dll [90624 2010-11-20] (Microsoft Corporation) [File not signed]
R3 HomeGroupListener; C:\Windows\system32\ListSvc.dll [232448 2010-11-20] (Microsoft Corporation) [File not signed]
R3 HomeGroupProvider; C:\Windows\system32\provsvc.dll [187904 2010-11-20] (Microsoft Corporation) [File not signed]
R3 HomeGroupProvider; C:\Windows\SysWOW64\provsvc.dll [165376 2010-11-20] (Microsoft Corporation) [File not signed]
R2 IKEEXT; C:\Windows\System32\ikeext.dll [859648 2013-10-11] (Microsoft Corporation) [File not signed]
S3 IPBusEnum; C:\Windows\system32\ipbusenum.dll [101888 2009-07-13] (Microsoft Corporation) [File not signed]
R3 KeyIso; C:\Windows\system32\lsass.exe [30720 2013-09-24] (Microsoft Corporation) [File not signed]
S3 KtmRm; C:\Windows\system32\msdtckrm.dll [368640 2009-07-13] (Microsoft Corporation) [File not signed]
R2 LanmanServer; C:\Windows\System32\srvsvc.dll [236032 2010-11-20] (Microsoft Corporation) [File not signed]
R2 LanmanWorkstation; C:\Windows\System32\wkssvc.dll [118784 2010-11-20] (Microsoft Corporation) [File not signed]
S3 lltdsvc; C:\Windows\System32\lltdsvc.dll [300032 2009-07-13] (Microsoft Corporation) [File not signed]
R2 lmhosts; C:\Windows\System32\lmhsvc.dll [23552 2009-07-13] (Microsoft Corporation) [File not signed]
R2 lxdp_device; C:\Windows\system32\lxdpcoms.exe [1039872 2007-11-19] ( ) [File not signed]
R2 lxdp_device; C:\Windows\SysWOW64\lxdpcoms.exe [589824 2007-11-19] ( ) [File not signed]
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [1871160 2015-04-14] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [1080120 2015-04-14] (Malwarebytes Corporation)
S4 Mcx2Svc; C:\Windows\system32\Mcx2Svc.dll [84992 2010-11-20] (Microsoft Corporation) [File not signed]
R2 MMCSS; C:\Windows\system32\mmcss.dll [67584 2009-07-13] (Microsoft Corporation) [File not signed]
R2 MpsSvc; C:\Windows\system32\mpssvc.dll [828416 2010-11-20] (Microsoft Corporation) [File not signed]
S3 MSDTC; C:\Windows\System32\msdtc.exe [141824 2009-07-13] (Microsoft Corporation) [File not signed]
S3 MSiSCSI; C:\Windows\system32\iscsiexe.dll [156672 2009-07-13] (Microsoft Corporation) [File not signed]
S3 msiserver; C:\Windows\System32\msiexec.exe [128000 2010-11-20] (Microsoft Corporation) [File not signed]
S3 msiserver; C:\Windows\SysWOW64\msiexec.exe [73216 2010-11-20] (Microsoft Corporation) [File not signed]
R2 MSSQLSERVER; c:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\sqlservr.exe [62111072 2011-06-17] (Microsoft Corporation)
R2 MySQL; C:\Program Files\MySQL\MySQL Server 5.5\my.ini [8918 2011-02-15] () [File not signed]
R2 N360; C:\Program Files (x86)\Norton 360\Engine\21.7.0.11\N360.exe [265000 2015-03-07] (Symantec Corporation)
S3 napagent; C:\Windows\system32\qagentRT.dll [476160 2010-11-20] (Microsoft Corporation) [File not signed]
S3 Netlogon; C:\Windows\system32\lsass.exe [30720 2013-09-24] (Microsoft Corporation) [File not signed]
R3 Netman; C:\Windows\System32\netman.dll [360448 2009-07-13] (Microsoft Corporation) [File not signed]
R3 netprofm; C:\Windows\System32\netprofm.dll [459776 2009-07-13] (Microsoft Corporation) [File not signed]
R3 netprofm; C:\Windows\SysWOW64\netprofm.dll [360448 2009-07-13] (Microsoft Corporation) [File not signed]
R2 NlaSvc; C:\Windows\System32\nlasvc.dll [303104 2012-10-03] (Microsoft Corporation) [File not signed]
R2 nsi; C:\Windows\system32\nsisvc.dll [25600 2009-07-13] (Microsoft Corporation) [File not signed]
R3 p2pimsvc; C:\Windows\system32\pnrpsvc.dll [327168 2009-07-13] (Microsoft Corporation) [File not signed]
R3 p2psvc; C:\Windows\system32\p2psvc.dll [438784 2009-07-13] (Microsoft Corporation) [File not signed]
R2 PcaSvc; C:\Windows\System32\pcasvc.dll [186368 2009-07-13] (Microsoft Corporation) [File not signed]
S3 PerfHost; C:\Windows\SysWow64\perfhost.exe [20992 2009-07-13] (Microsoft Corporation) [File not signed]
S3 pla; C:\Windows\system32\pla.dll [1389056 2010-11-20] (Microsoft Corporation) [File not signed]
S3 pla; C:\Windows\SysWOW64\pla.dll [1508864 2010-11-20] (Microsoft Corporation) [File not signed]
R2 PlugPlay; C:\Windows\system32\umpnpmgr.dll [404480 2011-05-24] (Microsoft Corporation) [File not signed]
S3 PNRPAutoReg; C:\Windows\system32\pnrpauto.dll [25088 2009-07-13] (Microsoft Corporation) [File not signed]
R3 PNRPsvc; C:\Windows\system32\pnrpsvc.dll [327168 2009-07-13] (Microsoft Corporation) [File not signed]
R2 PolicyAgent; C:\Windows\System32\ipsecsvc.dll [501248 2010-11-20] (Microsoft Corporation) [File not signed]
R2 Power; C:\Windows\system32\umpo.dll [163840 2009-07-13] (Microsoft Corporation) [File not signed]
R2 ProfSvc; C:\Windows\system32\profsvc.dll [209920 2012-04-30] (Microsoft Corporation) [File not signed]
S3 ProtectedStorage; C:\Windows\system32\lsass.exe [30720 2013-09-24] (Microsoft Corporation) [File not signed]
S3 QWAVE; C:\Windows\system32\qwave.dll [242688 2009-07-13] (Microsoft Corporation) [File not signed]
S3 QWAVE; C:\Windows\SysWOW64\qwave.dll [210944 2009-07-13] (Microsoft Corporation) [File not signed]
S3 RasAuto; C:\Windows\System32\rasauto.dll [99328 2009-07-13] (Microsoft Corporation) [File not signed]
R3 RasMan; C:\Windows\System32\rasmans.dll [344064 2010-11-20] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\Windows\System32\mprdim.dll [97792 2009-07-13] (Microsoft Corporation) [File not signed]
S4 RemoteAccess; C:\Windows\SysWOW64\mprdim.dll [75264 2009-07-13] (Microsoft Corporation) [File not signed]
S3 RemoteRegistry; C:\Windows\system32\regsvc.dll [159232 2009-07-13] (Microsoft Corporation) [File not signed]
R2 RpcEptMapper; C:\Windows\System32\RpcEpMap.dll [67072 2009-07-13] (Microsoft Corporation) [File not signed]
S3 RpcLocator; C:\Windows\system32\locator.exe [10240 2009-07-13] (Microsoft Corporation) [File not signed]
R2 RpcSs; C:\Windows\System32\rpcss.dll [512000 2010-11-20] (Microsoft Corporation) [File not signed]
R2 SamSs; C:\Windows\system32\lsass.exe [30720 2013-09-24] (Microsoft Corporation) [File not signed]
S3 SCardSvr; C:\Windows\System32\SCardSvr.dll [190976 2009-07-13] (Microsoft Corporation) [File not signed]
R2 Schedule; C:\Windows\system32\schedsvc.dll [1110016 2010-11-20] (Microsoft Corporation) [File not signed]
S3 SCPolicySvc; C:\Windows\System32\certprop.dll [80384 2010-11-20] (Microsoft Corporation) [File not signed]
S3 SDRSVC; C:\Windows\System32\SDRSVC.dll [170496 2010-11-20] (Microsoft Corporation) [File not signed]
R2 seclogon; C:\Windows\system32\seclogon.dll [30720 2010-11-20] (Microsoft Corporation) [File not signed]
R2 SENS; C:\Windows\system32\sens.dll [64512 2009-07-13] (Microsoft Corporation) [File not signed]
R2 SENS; C:\Windows\SysWOW64\sens.dll [49664 2009-07-13] (Microsoft Corporation) [File not signed]
S3 SensrSvc; C:\Windows\system32\sensrsvc.dll [29184 2009-07-13] (Microsoft Corporation) [File not signed]
S3 SessionEnv; C:\Windows\system32\sessenv.dll [121856 2010-11-20] (Microsoft Corporation) [File not signed]
S3 SessionEnv; C:\Windows\SysWOW64\sessenv.dll [113664 2010-11-20] (Microsoft Corporation) [File not signed]
S2 SharedAccess; C:\Windows\System32\ipnathlp.dll [359424 2009-07-13] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\Windows\System32\shsvcs.dll [370688 2010-11-20] (Microsoft Corporation) [File not signed]
R2 ShellHWDetection; C:\Windows\SysWOW64\shsvcs.dll [328192 2010-11-20] (Microsoft Corporation) [File not signed]
S3 SNMPTRAP; C:\Windows\System32\snmptrap.exe [14336 2009-07-13] (Microsoft Corporation) [File not signed]
R2 Spooler; C:\Windows\System32\spoolsv.exe [559104 2012-02-11] (Microsoft Corporation) [File not signed]
S2 sppsvc; C:\Windows\system32\sppsvc.exe [3524608 2010-11-20] (Microsoft Corporation) [File not signed]
S3 sppuinotify; C:\Windows\system32\sppuinotify.dll [65536 2009-07-13] (Microsoft Corporation) [File not signed]
S4 SQLSERVERAGENT; c:\Program Files\Microsoft SQL Server\MSSQL10_50.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE [431456 2011-06-17] (Microsoft Corporation)
R3 SSDPSRV; C:\Windows\System32\ssdpsrv.dll [193024 2009-07-13] (Microsoft Corporation) [File not signed]
R3 SstpSvc; C:\Windows\system32\sstpsvc.dll [75264 2009-07-13] (Microsoft Corporation) [File not signed]
R2 stisvc; C:\Windows\System32\wiaservc.dll [580096 2010-11-20] (Microsoft Corporation) [File not signed]
S3 swprv; C:\Windows\System32\swprv.dll [524288 2009-07-13] (Microsoft Corporation) [File not signed]
R2 SysMain; C:\Windows\system32\sysmain.dll [1743360 2010-11-20] (Microsoft Corporation) [File not signed]
S3 TabletInputService; C:\Windows\System32\TabSvc.dll [92672 2010-11-20] (Microsoft Corporation) [File not signed]
R3 TapiSrv; C:\Windows\System32\tapisrv.dll [316928 2010-11-20] (Microsoft Corporation) [File not signed]
R3 TapiSrv; C:\Windows\SysWOW64\tapisrv.dll [242176 2010-11-20] (Microsoft Corporation) [File not signed]
S3 TBS; C:\Windows\System32\tbssvc.dll [65536 2009-07-13] (Microsoft Corporation) [File not signed]
S3 TermService; C:\Windows\System32\termsrv.dll [680960 2010-11-20] (Microsoft Corporation) [File not signed]
R2 Themes; C:\Windows\system32\themeservice.dll [44544 2009-07-13] (Microsoft Corporation) [File not signed]
S3 THREADORDER; C:\Windows\system32\mmcss.dll [67584 2009-07-13] (Microsoft Corporation) [File not signed]
R2 TrkWks; C:\Windows\System32\trkwks.dll [119808 2009-07-13] (Microsoft Corporation) [File not signed]
S3 TrustedInstaller; C:\Windows\servicing\TrustedInstaller.exe [194048 2010-11-20] (Microsoft Corporation) [File not signed]
S3 UI0Detect; C:\Windows\system32\UI0Detect.exe [40960 2009-07-13] (Microsoft Corporation) [File not signed]
R3 upnphost; C:\Windows\System32\upnphost.dll [353792 2009-07-13] (Microsoft Corporation) [File not signed]
R3 upnphost; C:\Windows\SysWOW64\upnphost.dll [266752 2009-07-13] (Microsoft Corporation) [File not signed]
R2 UxSms; C:\Windows\System32\uxsms.dll [38912 2009-07-13] (Microsoft Corporation) [File not signed]
S3 VaultSvc; C:\Windows\system32\lsass.exe [30720 2013-09-24] (Microsoft Corporation) [File not signed]
S3 vds; C:\Windows\System32\vds.exe [533504 2010-11-20] (Microsoft Corporation) [File not signed]
S3 VSS; C:\Windows\system32\vssvc.exe [1600512 2010-11-20] (Microsoft Corporation) [File not signed]
R2 vToolbarUpdater19.1.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\19.1.0\ToolbarUpdater.exe [1864592 2015-12-11] (AVG Secure Search)
S3 W32Time; C:\Windows\system32\w32time.dll [381952 2009-07-13] (Microsoft Corporation) [File not signed]
S3 wbengine; C:\Windows\system32\wbengine.exe [1504256 2010-11-20] (Microsoft Corporation) [File not signed]
S3 WbioSrvc; C:\Windows\System32\wbiosrvc.dll [202240 2009-07-13] (Microsoft Corporation) [File not signed]
R3 wcncsvc; C:\Windows\System32\wcncsvc.dll [367104 2010-11-20] (Microsoft Corporation) [File not signed]
R3 wcncsvc; C:\Windows\SysWOW64\wcncsvc.dll [276992 2010-11-20] (Microsoft Corporation) [File not signed]
S3 WcsPlugInService; C:\Windows\System32\WcsPlugInService.dll [40960 2009-07-13] (Microsoft Corporation) [File not signed]
S3 WcsPlugInService; C:\Windows\SysWOW64\WcsPlugInService.dll [32768 2009-07-13] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\Windows\system32\wdi.dll [90624 2009-07-13] (Microsoft Corporation) [File not signed]
R3 WdiServiceHost; C:\Windows\SysWOW64\wdi.dll [76288 2009-07-13] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\system32\wdi.dll [90624 2009-07-13] (Microsoft Corporation) [File not signed]
R3 WdiSystemHost; C:\Windows\SysWOW64\wdi.dll [76288 2009-07-13] (Microsoft Corporation) [File not signed]
S3 WebClient; C:\Windows\System32\webclnt.dll [259584 2013-07-04] (Microsoft Corporation) [File not signed]
S3 WebClient; C:\Windows\SysWOW64\webclnt.dll [205824 2013-07-04] (Microsoft Corporation) [File not signed]
S3 Wecsvc; C:\Windows\system32\wecsvc.dll [237568 2009-07-13] (Microsoft Corporation) [File not signed]
S3 wercplsupport; C:\Windows\System32\wercplsupport.dll [84480 2009-07-13] (Microsoft Corporation) [File not signed]
R3 WerSvc; C:\Windows\System32\WerSvc.dll [76800 2009-07-13] (Microsoft Corporation) [File not signed]
S3 WinHttpAutoProxySvc; C:\Windows\system32\winhttp.dll [444416 2010-11-20] (Microsoft Corporation) [File not signed]
S3 WinHttpAutoProxySvc; C:\Windows\SysWOW64\winhttp.dll [351232 2010-11-20] (Microsoft Corporation) [File not signed]
R2 Winmgmt; C:\Windows\system32\wbem\WMIsvc.dll [242688 2009-07-13] (Microsoft Corporation) [File not signed]
S3 WinRM; C:\Windows\system32\WsmSvc.dll [2018304 2010-11-20] (Microsoft Corporation) [File not signed]
S3 WinRM; C:\Windows\SysWOW64\WsmSvc.dll [1175040 2010-11-20] (Microsoft Corporation) [File not signed]
S3 Wlansvc; C:\Windows\System32\wlansvc.dll [886784 2009-07-13] (Microsoft Corporation) [File not signed]
S3 wmiApSrv; C:\Windows\system32\wbem\WmiApSrv.exe [203264 2009-07-13] (Microsoft Corporation) [File not signed]
R2 WMPNetworkSvc; C:\Program Files\Windows Media Player\wmpnetwk.exe [1525248 2010-11-20] (Microsoft Corporation) [File not signed]
S3 WPCSvc; C:\Windows\System32\wpcsvc.dll [12288 2009-07-13] (Microsoft Corporation) [File not signed]
S3 WPCSvc; C:\Windows\SysWOW64\wpcsvc.dll [10752 2009-07-13] (Microsoft Corporation) [File not signed]
R3 WPDBusEnum; C:\Windows\system32\wpdbusenum.dll [117248 2010-11-20] (Microsoft Corporation) [File not signed]
R2 wscsvc; C:\Windows\system32\wscsvc.dll [97280 2009-07-13] (Microsoft Corporation) [File not signed]
R2 WSearch; C:\Windows\system32\SearchIndexer.exe [591872 2011-05-03] (Microsoft Corporation) [File not signed]
R2 WSearch; C:\Windows\SysWOW64\SearchIndexer.exe [427520 2011-05-03] (Microsoft Corporation) [File not signed]
R3 wudfsvc; C:\Windows\System32\WUDFSvc.dll [84992 2012-07-25] (Microsoft Corporation) [File not signed]
S3 WwanSvc; C:\Windows\System32\wwansvc.dll [230400 2013-03-18] (Microsoft Corporation) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R3 1394ohci; C:\Windows\system32\drivers\1394ohci.sys [229888 2010-11-20] (Microsoft Corporation) [File not signed]
S3 AcpiPmi; C:\Windows\system32\drivers\acpipmi.sys [12800 2010-11-20] (Microsoft Corporation) [File not signed]
R1 AFD; C:\Windows\system32\drivers\afd.sys [497152 2013-09-27] (Microsoft Corporation) [File not signed]
S3 AmdK8; C:\Windows\system32\DRIVERS\amdk8.sys [64512 2009-07-13] (Microsoft Corporation) [File not signed]
S3 AmdPPM; C:\Windows\system32\DRIVERS\amdppm.sys [60928 2009-07-13] (Microsoft Corporation) [File not signed]
S3 AppID; C:\Windows\system32\drivers\appid.sys [61440 2010-11-20] (Microsoft Corporation) [File not signed]
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-13] (Microsoft Corporation) [File not signed]
S3 AsyncMac; C:\Windows\System32\DRIVERS\asyncmac.sys [23040 2009-07-13] (Microsoft Corporation) [File not signed]
S3 b06bdrv; C:\Windows\system32\DRIVERS\bxvbda.sys [468480 2009-06-10] (Broadcom Corporation) [File not signed]
S3 b57nd60a; C:\Windows\System32\DRIVERS\b57nd60a.sys [270848 2009-06-10] (Broadcom Corporation) [File not signed]
S1 BHDrvx64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150601.001\BHDrvx64.sys [1640152 2015-05-21] (Symantec Corporation)
R1 blbdrive; C:\Windows\system32\DRIVERS\blbdrive.sys [45056 2009-07-13] (Microsoft Corporation) [File not signed]
R3 bowser; C:\Windows\System32\DRIVERS\bowser.sys [90624 2011-02-22] (Microsoft Corporation) [File not signed]
S3 BrFiltLo; C:\Windows\system32\DRIVERS\BrFiltLo.sys [18432 2009-06-10] (Brother Industries, Ltd.) [File not signed]
S3 BrFiltUp; C:\Windows\system32\DRIVERS\BrFiltUp.sys [8704 2009-06-10] (Brother Industries, Ltd.) [File not signed]
S3 Brserid; C:\Windows\System32\Drivers\Brserid.sys [286720 2009-07-13] (Brother Industries Ltd.) [File not signed]
S3 BrSerWdm; C:\Windows\System32\Drivers\BrSerWdm.sys [47104 2009-06-10] (Brother Industries Ltd.) [File not signed]
S3 BrUsbMdm; C:\Windows\System32\Drivers\BrUsbMdm.sys [14976 2009-06-10] (Brother Industries Ltd.) [File not signed]
S3 BrUsbSer; C:\Windows\System32\Drivers\BrUsbSer.sys [14720 2009-06-10] (Brother Industries Ltd.) [File not signed]
S3 BTHMODEM; C:\Windows\system32\DRIVERS\bthmodem.sys [72192 2009-07-13] (Microsoft Corporation) [File not signed]
R1 ccSet_N360; C:\Windows\system32\drivers\N360x64\1507000.00B\ccSetx64.sys [162392 2013-09-25] (Symantec Corporation)
S4 cdfs; C:\Windows\System32\DRIVERS\cdfs.sys [92160 2009-07-13] (Microsoft Corporation) [File not signed]
R1 cdrom; C:\Windows\system32\drivers\cdrom.sys [147456 2010-11-20] (Microsoft Corporation) [File not signed]
S3 circlass; C:\Windows\system32\DRIVERS\circlass.sys [45568 2009-07-13] (Microsoft Corporation) [File not signed]
S3 CmBatt; C:\Windows\system32\DRIVERS\CmBatt.sys [17664 2009-07-13] (Microsoft Corporation) [File not signed]
R3 CompositeBus; C:\Windows\system32\drivers\CompositeBus.sys [38912 2010-11-20] (Microsoft Corporation) [File not signed]
R1 DfsC; C:\Windows\System32\Drivers\dfsc.sys [102400 2010-11-20] (Microsoft Corporation) [File not signed]
R1 discache; C:\Windows\System32\drivers\discache.sys [40448 2009-07-13] (Microsoft Corporation) [File not signed]
S3 drmkaud; C:\Windows\system32\drivers\drmkaud.sys [5632 2009-07-13] (Microsoft Corporation) [File not signed]
R3 e1yexpress; C:\Windows\System32\DRIVERS\e1y60x64.sys [281088 2009-06-10] (Intel Corporation) [File not signed]
S3 ebdrv; C:\Windows\system32\DRIVERS\evbda.sys [3286016 2009-06-10] (Broadcom Corporation) [File not signed]
R1 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [489776 2015-05-27] (Symantec Corporation)
R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [31432 2012-04-17] (EldoS Corporation)
S3 ErrDev; C:\Windows\system32\drivers\errdev.sys [9728 2009-07-13] (Microsoft Corporation) [File not signed]
S3 exfat; C:\Windows\System32\Drivers\exfat.sys [195072 2009-07-13] (Microsoft Corporation) [File not signed]
S3 fastfat; C:\Windows\System32\Drivers\fastfat.sys [204800 2009-07-13] (Microsoft Corporation) [File not signed]
S3 fdc; C:\Windows\system32\DRIVERS\fdc.sys [29696 2009-07-13] (Microsoft Corporation) [File not signed]
S3 Filetrace; C:\Windows\System32\drivers\filetrace.sys [34304 2009-07-13] (Microsoft Corporation) [File not signed]
S3 flpydisk; C:\Windows\system32\DRIVERS\flpydisk.sys [24576 2009-07-13] (Microsoft Corporation) [File not signed]
S3 hcw85cir; C:\Windows\system32\drivers\hcw85cir.sys [31232 2009-06-10] (Hauppauge Computer Works, Inc.) [File not signed]
S3 HdAudAddService; C:\Windows\system32\drivers\HdAudio.sys [350208 2010-11-20] (Microsoft Corporation) [File not signed]
R3 HDAudBus; C:\Windows\system32\drivers\HDAudBus.sys [122368 2010-11-20] (Microsoft Corporation) [File not signed]
S3 HidBatt; C:\Windows\system32\DRIVERS\HidBatt.sys [26624 2009-07-13] (Microsoft Corporation) [File not signed]
S3 HidBth; C:\Windows\system32\DRIVERS\hidbth.sys [100864 2009-07-13] (Microsoft Corporation) [File not signed]
S3 HidIr; C:\Windows\system32\DRIVERS\hidir.sys [46592 2009-07-13] (Microsoft Corporation) [File not signed]
R3 HidUsb; C:\Windows\System32\DRIVERS\hidusb.sys [30208 2010-11-20] (Microsoft Corporation) [File not signed]
R3 HTTP; C:\Windows\System32\drivers\HTTP.sys [753664 2010-11-20] (Microsoft Corporation) [File not signed]
R3 i8042prt; C:\Windows\system32\drivers\i8042prt.sys [105472 2009-07-13] (Microsoft Corporation) [File not signed]
R1 IDSVia64; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150608.001\IDSvia64.sys [684248 2015-05-28] (Symantec Corporation)
R3 igfx; C:\Windows\System32\DRIVERS\igdkmd64.sys [10628640 2011-02-11] (Intel Corporation) [File not signed]
R3 IntcHdmiAddService; C:\Windows\System32\drivers\IntcHdmi.sys [138752 2009-05-25] (Intel® Corporation) [File not signed]
R3 intelppm; C:\Windows\System32\DRIVERS\intelppm.sys [62464 2009-07-13] (Microsoft Corporation) [File not signed]
S3 IpFilterDriver; C:\Windows\System32\DRIVERS\ipfltdrv.sys [82944 2010-11-20] (Microsoft Corporation) [File not signed]
S3 IPMIDRV; C:\Windows\system32\drivers\IPMIDrv.sys [78848 2010-11-20] (Microsoft Corporation) [File not signed]
S3 IPNAT; C:\Windows\System32\drivers\ipnat.sys [116224 2009-07-13] (Microsoft Corporation) [File not signed]
S3 IRENUM; C:\Windows\System32\drivers\irenum.sys [17920 2009-07-13] (Microsoft Corporation) [File not signed]
S3 kbdhid; C:\Windows\System32\DRIVERS\kbdhid.sys [33280 2010-11-20] (Microsoft Corporation) [File not signed]
R3 ksthunk; C:\Windows\system32\drivers\ksthunk.sys [20992 2009-07-13] (Microsoft Corporation) [File not signed]
R2 lltdio; C:\Windows\System32\DRIVERS\lltdio.sys [60928 2009-07-13] (Microsoft Corporation) [File not signed]
R2 luafv; C:\Windows\system32\drivers\luafv.sys [113152 2009-07-13] (Microsoft Corporation) [File not signed]
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2015-04-14] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [136408 2015-07-12] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2015-04-14] (Malwarebytes Corporation)
R0 MFX; C:\Windows\System32\Drivers\MFX.sys [0 ] () <==== ATTENTION (zero byte File/Folder)
S3 Modem; C:\Windows\System32\drivers\modem.sys [40448 2009-07-13] (Microsoft Corporation) [File not signed]
R3 monitor; C:\Windows\System32\DRIVERS\monitor.sys [30208 2009-07-13] (Microsoft Corporation) [File not signed]
R3 mouhid; C:\Windows\System32\DRIVERS\mouhid.sys [31232 2009-07-13] (Microsoft Corporation) [File not signed]
R3 mpsdrv; C:\Windows\System32\drivers\mpsdrv.sys [77312 2009-07-13] (Microsoft Corporation) [File not signed]
S3 MRxDAV; C:\Windows\system32\drivers\mrxdav.sys [140800 2013-07-04] (Microsoft Corporation) [File not signed]
R3 mrxsmb; C:\Windows\System32\DRIVERS\mrxsmb.sys [158208 2011-04-26] (Microsoft Corporation) [File not signed]
R3 mrxsmb10; C:\Windows\System32\DRIVERS\mrxsmb10.sys [288768 2011-07-08] (Microsoft Corporation) [File not signed]
R3 mrxsmb20; C:\Windows\System32\DRIVERS\mrxsmb20.sys [128000 2011-04-26] (Microsoft Corporation) [File not signed]
S3 mshidkmdf; C:\Windows\System32\drivers\mshidkmdf.sys [8192 2009-07-13] (Microsoft Corporation) [File not signed]
S3 MSKSSRV; C:\Windows\System32\drivers\MSKSSRV.sys [11136 2009-07-13] (Microsoft Corporation) [File not signed]
S3 MSPCLOCK; C:\Windows\System32\drivers\MSPCLOCK.sys [7168 2009-07-13] (Microsoft Corporation) [File not signed]
S3 MSPQM; C:\Windows\System32\drivers\MSPQM.sys [6784 2009-07-13] (Microsoft Corporation) [File not signed]
S3 MSTEE; C:\Windows\System32\drivers\MSTEE.sys [8064 2009-07-13] (Microsoft Corporation) [File not signed]
S3 MTConfig; C:\Windows\system32\DRIVERS\MTConfig.sys [15360 2009-07-13] (Microsoft Corporation) [File not signed]
S3 NativeWifiP; C:\Windows\System32\DRIVERS\nwifi.sys [318976 2009-07-13] (Microsoft Corporation) [File not signed]
S3 NAVENG; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150608.016\ENG64.SYS [129752 2015-04-29] (Symantec Corporation)
S3 NAVEX15; C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150608.016\EX64.SYS [2137304 2015-04-29] (Symantec Corporation)
S3 NdisCap; C:\Windows\System32\DRIVERS\ndiscap.sys [35328 2009-07-13] (Microsoft Corporation) [File not signed]
R3 NdisTapi; C:\Windows\System32\DRIVERS\ndistapi.sys [24064 2009-07-13] (Microsoft Corporation) [File not signed]
S3 Ndisuio; C:\Windows\System32\DRIVERS\ndisuio.sys [56832 2010-11-20] (Microsoft Corporation) [File not signed]
R3 NdisWan; C:\Windows\System32\DRIVERS\ndiswan.sys [164352 2010-11-20] (Microsoft Corporation) [File not signed]
R1 NetBIOS; C:\Windows\System32\DRIVERS\netbios.sys [44544 2009-07-13] (Microsoft Corporation) [File not signed]
R1 NetBT; C:\Windows\System32\DRIVERS\netbt.sys [261632 2010-11-20] (Microsoft Corporation) [File not signed]
R1 nsiproxy; C:\Windows\System32\drivers\nsiproxy.sys [24576 2009-07-13] (Microsoft Corporation) [File not signed]
R1 Null; C:\Windows\System32\Drivers\Null.sys [6144 2009-07-13] (Microsoft Corporation) [File not signed]
S3 ohci1394; C:\Windows\system32\drivers\ohci1394.sys [72832 2009-07-13] (Microsoft Corporation) [File not signed]
S3 Parport; C:\Windows\system32\DRIVERS\parport.sys [97280 2009-07-13] (Microsoft Corporation) [File not signed]
R2 PEAUTH; C:\Windows\System32\drivers\peauth.sys [651264 2009-07-13] (Microsoft Corporation) [File not signed]
R3 PptpMiniport; C:\Windows\System32\DRIVERS\raspptp.sys [111104 2010-11-20] (Microsoft Corporation) [File not signed]
S3 Processor; C:\Windows\system32\DRIVERS\processr.sys [60416 2009-07-13] (Microsoft Corporation) [File not signed]
R1 Psched; C:\Windows\System32\DRIVERS\pacer.sys [131584 2010-11-20] (Microsoft Corporation) [File not signed]
S3 QWAVEdrv; C:\Windows\system32\drivers\qwavedrv.sys [46592 2009-07-13] (Microsoft Corporation) [File not signed]
S3 RasAcd; C:\Windows\System32\DRIVERS\rasacd.sys [14848 2009-07-13] (Microsoft Corporation) [File not signed]
R3 RasAgileVpn; C:\Windows\System32\DRIVERS\AgileVpn.sys [60416 2009-07-13] (Microsoft Corporation) [File not signed]
R3 Rasl2tp; C:\Windows\System32\DRIVERS\rasl2tp.sys [129536 2010-11-20] (Microsoft Corporation) [File not signed]
R3 RasPppoe; C:\Windows\System32\DRIVERS\raspppoe.sys [92672 2009-07-13] (Microsoft Corporation) [File not signed]
R3 RasSstp; C:\Windows\System32\DRIVERS\rassstp.sys [83968 2009-07-13] (Microsoft Corporation) [File not signed]
R1 rdbss; C:\Windows\System32\DRIVERS\rdbss.sys [309248 2010-11-20] (Microsoft Corporation) [File not signed]
S3 rdpbus; C:\Windows\system32\DRIVERS\rdpbus.sys [24064 2009-07-13] (Microsoft Corporation) [File not signed]
R1 RDPCDD; C:\Windows\System32\DRIVERS\RDPCDD.sys [7680 2009-07-13] (Microsoft Corporation) [File not signed]
R1 RDPENCDD; C:\Windows\System32\drivers\rdpencdd.sys [7680 2009-07-13] (Microsoft Corporation) [File not signed]
R1 RDPREFMP; C:\Windows\System32\drivers\rdprefmp.sys [8192 2009-07-13] (Microsoft Corporation) [File not signed]
S3 RdpVideoMiniport; C:\Windows\System32\drivers\rdpvideominiport.sys [19456 2012-08-23] (Microsoft Corporation) [File not signed]
S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) [File not signed]
R2 rspndr; C:\Windows\System32\DRIVERS\rspndr.sys [76800 2009-07-13] (Microsoft Corporation) [File not signed]
S3 scfilter; C:\Windows\System32\DRIVERS\scfilter.sys [29696 2010-11-20] (Microsoft Corporation) [File not signed]
S3 Serenum; C:\Windows\system32\DRIVERS\serenum.sys [23552 2009-07-13] (Microsoft Corporation) [File not signed]
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-13] (Microsoft Corporation) [File not signed]
S3 sermouse; C:\Windows\system32\DRIVERS\sermouse.sys [26624 2009-07-13] (Microsoft Corporation) [File not signed]
S3 sffdisk; C:\Windows\system32\drivers\sffdisk.sys [14336 2009-07-13] (Microsoft Corporation) [File not signed]
S3 sffp_mmc; C:\Windows\system32\drivers\sffp_mmc.sys [13824 2009-07-13] (Microsoft Corporation) [File not signed]
S3 sffp_sd; C:\Windows\system32\drivers\sffp_sd.sys [14336 2010-11-20] (Microsoft Corporation) [File not signed]
S3 sfloppy; C:\Windows\system32\DRIVERS\sfloppy.sys [16896 2009-07-13] (Microsoft Corporation) [File not signed]
S3 Smb; C:\Windows\System32\DRIVERS\smb.sys [93184 2009-07-13] (Microsoft Corporation) [File not signed]
S1 SRTSP; C:\Windows\System32\Drivers\N360x64\1507000.00B\SRTSP64.SYS [876248 2014-08-25] (Symantec Corporation)
R1 SRTSPX; C:\Windows\system32\drivers\N360x64\1507000.00B\SRTSPX64.SYS [37592 2014-08-25] (Symantec Corporation)
R3 srv; C:\Windows\System32\DRIVERS\srv.sys [467456 2011-04-28] (Microsoft Corporation) [File not signed]
R3 srv2; C:\Windows\System32\DRIVERS\srv2.sys [410112 2011-04-28] (Microsoft Corporation) [File not signed]
R3 srvnet; C:\Windows\System32\DRIVERS\srvnet.sys [168448 2011-04-28] (Microsoft Corporation) [File not signed]
R0 SymDS; C:\Windows\System32\drivers\N360x64\1507000.00B\SYMDS64.SYS [493656 2013-09-09] (Symantec Corporation)
R0 SymEFA; C:\Windows\System32\drivers\N360x64\1507000.00B\SYMEFA64.SYS [1148120 2014-03-03] (Symantec Corporation)
R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2013-12-15] (Symantec Corporation)
S1 SymIRON; C:\Windows\system32\drivers\N360x64\1507000.00B\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation)
S1 SymNetS; C:\Windows\System32\Drivers\N360x64\1507000.00B\SYMNETS.SYS [593112 2014-02-17] (Symantec Corporation)
R2 tcpipreg; C:\Windows\System32\drivers\tcpipreg.sys [45568 2012-10-03] (Microsoft Corporation) [File not signed]
S3 TDPIPE; C:\Windows\System32\drivers\tdpipe.sys [15872 2009-07-13] (Microsoft Corporation) [File not signed]
S3 TDTCP; C:\Windows\System32\drivers\tdtcp.sys [23552 2012-02-16] (Microsoft Corporation) [File not signed]
R1 tdx; C:\Windows\System32\DRIVERS\tdx.sys [119296 2010-11-20] (Microsoft Corporation) [File not signed]
S3 tssecsrv; C:\Windows\System32\DRIVERS\tssecsrv.sys [39424 2010-11-20] (Microsoft Corporation) [File not signed]
S3 TsUsbFlt; C:\Windows\System32\drivers\tsusbflt.sys [57856 2012-08-23] (Microsoft Corporation) [File not signed]
R3 tunnel; C:\Windows\System32\DRIVERS\tunnel.sys [125440 2010-11-20] (Microsoft Corporation) [File not signed]
S4 udfs; C:\Windows\System32\DRIVERS\udfs.sys [328192 2010-11-20] (Microsoft Corporation) [File not signed]
R3 umbus; C:\Windows\system32\drivers\umbus.sys [48640 2010-11-20] (Microsoft Corporation) [File not signed]
S3 UmPass; C:\Windows\system32\DRIVERS\umpass.sys [9728 2009-07-13] (Microsoft Corporation) [File not signed]
S3 usbaudio; C:\Windows\system32\drivers\usbaudio.sys [109824 2013-07-12] (Microsoft Corporation) [File not signed]
R3 usbccgp; C:\Windows\System32\DRIVERS\usbccgp.sys [99840 2013-11-26] (Microsoft Corporation) [File not signed]
S3 usbcir; C:\Windows\system32\drivers\usbcir.sys [100864 2013-07-12] (Microsoft Corporation) [File not signed]
R3 usbehci; C:\Windows\System32\DRIVERS\usbehci.sys [53248 2013-11-26] (Microsoft Corporation) [File not signed]
R3 usbhub; C:\Windows\System32\DRIVERS\usbhub.sys [343040 2013-11-26] (Microsoft Corporation) [File not signed]
S3 usbohci; C:\Windows\system32\drivers\usbohci.sys [25600 2013-11-26] (Microsoft Corporation) [File not signed]
S3 usbprint; C:\Windows\System32\DRIVERS\usbprint.sys [25088 2009-07-13] (Microsoft Corporation) [File not signed]
R3 USBSTOR; C:\Windows\System32\DRIVERS\USBSTOR.SYS [91648 2011-03-10] (Microsoft Corporation) [File not signed]
R3 usbuhci; C:\Windows\System32\DRIVERS\usbuhci.sys [30720 2013-11-26] (Microsoft Corporation) [File not signed]
S3 usb_rndisx; C:\Windows\system32\drivers\usb8023x.sys [19968 2013-02-11] (Microsoft Corporation) [File not signed]
S3 vga; C:\Windows\System32\DRIVERS\vgapnp.sys [29184 2009-07-13] (Microsoft Corporation) [File not signed]
R1 VgaSave; C:\Windows\System32\drivers\vga.sys [29184 2009-07-13] (Microsoft Corporation) [File not signed]
S3 vwifibus; C:\Windows\System32\drivers\vwifibus.sys [24576 2009-07-13] (Microsoft Corporation) [File not signed]
S3 WacomPen; C:\Windows\system32\DRIVERS\wacompen.sys [27776 2009-07-13] (Microsoft Corporation) [File not signed]
S3 WANARP; C:\Windows\System32\DRIVERS\wanarp.sys [88576 2010-11-20] (Microsoft Corporation) [File not signed]
R1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [88576 2010-11-20] (Microsoft Corporation) [File not signed]
R1 WfpLwf; C:\Windows\System32\DRIVERS\wfplwf.sys [12800 2009-07-13] (Microsoft Corporation) [File not signed]
S3 WinUsb; C:\Windows\System32\DRIVERS\WinUsb.sys [41984 2010-11-20] (Microsoft Corporation) [File not signed]
R3 WmiAcpi; C:\Windows\system32\drivers\wmiacpi.sys [14336 2009-07-13] (Microsoft Corporation) [File not signed]
S4 ws2ifsl; C:\Windows\system32\drivers\ws2ifsl.sys [21504 2009-07-13] (Microsoft Corporation) [File not signed]
R3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [87040 2012-07-25] (Microsoft Corporation) [File not signed]
R3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [198656 2012-07-25] (Microsoft Corporation) [File not signed]

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-14 20:28 - 2015-12-14 20:28 - 00057324 _____ C:\Users\home\Desktop\FRST.txt
2015-12-14 20:26 - 2015-12-14 20:28 - 00000000 ____D C:\FRST
2015-12-14 20:26 - 2015-12-14 20:26 - 02369536 _____ (Farbar) C:\Users\home\Desktop\FRST64.exe
2015-12-06 15:44 - 2015-12-06 16:43 - 00041767 ____H C:\Users\home\Documents\~WRL2814.tmp
2015-11-22 18:24 - 2015-11-22 18:33 - 00013541 ____H C:\Users\home\Documents\~WRL0647.tmp
2015-11-19 08:44 - 2015-11-19 08:47 - 00000000 ____D C:\Users\home\Documents\Jack - Scanned For Work
2015-11-16 16:26 - 2015-11-16 16:29 - 00013313 ____H C:\Users\home\Documents\~WRL2131.tmp
2015-11-14 11:14 - 2015-11-16 20:04 - 00000000 ___RD C:\Users\home\Documents\Scanned Documents
2015-11-14 11:14 - 2015-11-14 11:14 - 00000000 ____D C:\Users\home\Documents\Fax

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2015-12-14 20:27 - 2009-07-13 22:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-12-14 20:27 - 2009-07-13 22:45 - 00009920 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-12-14 20:26 - 2007-07-11 19:48 - 00000000 ___HD C:\Windows
2015-12-14 20:13 - 2012-04-02 20:44 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-12-14 20:10 - 2013-05-31 12:24 - 00000350 _____ C:\Windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2015-12-14 20:10 - 2009-07-13 23:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-12-14 20:09 - 2015-07-12 21:15 - 00237912 ____H C:\Windows\ntbtlog.txt
2015-12-11 06:02 - 2012-07-17 20:12 - 00000000 ____D C:\Program Files (x86)\AVG Secure Search
2015-12-10 18:45 - 2011-12-15 08:04 - 01793024 ___SH C:\Users\home\Documents\Thumbs.db
2015-12-07 07:05 - 2011-02-14 19:34 - 00000000 ____D C:\Users\home\AppData\Roaming\SoftGrid Client
2015-11-25 17:36 - 2015-08-09 14:09 - 00002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2015-11-16 20:08 - 2011-11-08 21:17 - 00000000 ____D C:\Users\home\Documents\2007 Tax Returns
2015-11-14 12:48 - 2011-05-14 12:30 - 00000000 ____D C:\Users\home\AppData\Local\ApplicationHistory
2015-11-14 11:29 - 2011-05-14 12:28 - 00000000 ____D C:\Program Files (x86)\WrapCandy70

==================== Files in the root of some directories =======

2012-05-04 14:11 - 2014-04-29 14:39 - 0007605 _____ () C:\Users\home\AppData\Local\resmon.resmoncfg
2011-02-14 20:02 - 2012-05-04 18:28 - 0000504 _____ () C:\ProgramData\FastPics.log
2011-12-04 00:35 - 2011-12-04 00:35 - 0000089 _____ () C:\ProgramData\lxdp.log
2012-04-18 23:27 - 2012-04-18 23:41 - 0000248 _____ () C:\ProgramData\lxdpDiagnostics.log
2013-03-01 14:54 - 2013-03-01 14:54 - 0823396 _____ () C:\ProgramData\SPL3CC4.tmp
2011-06-21 08:29 - 2011-06-21 08:29 - 6920974 _____ () C:\ProgramData\SPL9690.tmp
2014-01-10 10:45 - 2014-01-10 10:45 - 1270289 _____ () C:\ProgramData\SPLF75C.tmp
2012-04-18 23:27 - 2012-04-18 23:27 - 0000000 _____ () C:\ProgramData\UpdaterLog.txt

Files to move or delete:
====================
C:\Users\home\lametritonus_en.dll
C:\Users\home\lame_enc_en.dll

Some files in TEMP:
====================
C:\Users\home\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\home\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
C:\Users\home\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\home\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\home\AppData\Local\Temp\jre-8u40-windows-au.exe
C:\Users\home\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\home\AppData\Local\Temp\jre-8u51-windows-au.exe
C:\Users\home\AppData\Local\Temp\jre-8u65-windows-au.exe
C:\Users\home\AppData\Local\Temp\jre-8u66-windows-au.exe
C:\Users\home\AppData\Local\Temp\miunst_.exe
C:\Users\home\AppData\Local\Temp\MSETUP4.EXE
C:\Users\home\AppData\Local\Temp\uninstall.exe

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\dnsapi.dll => MD5 is legit
C:\Windows\SysWOW64\dnsapi.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2015-12-10 15:55

==================== End of FRST.txt ============================

 

 


  • 0

Advertisements


#2
chanseygirl

chanseygirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts

I keep getting and error when I try to past the Addition Notepad


  • 0

#3
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

Hello chanseygirl,

Welcome to Geekstogo.

See if you can download and run Mr Fix It for Microsoft Windows Update Troubleshooter see link below:

http://windows.micro...s#1TC=windows-7

Come back and tell me if the popup saying that Windows is not genuine is still there.


  • 0

#4
chanseygirl

chanseygirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts

I ran the Mr Fix It, but still have the not genuine windows popup.


  • 0

#5
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

Hello chanseygirl,

 

Download the attached fixlist.txt file and save it on the flashdrive as fixlist.txt

NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

Please enter System Recovery Options, as we've done previously.
Run FRST64 and press the Fix button just once and wait.
The tool will make a log on the flashdrive (Fixlog.txt) please post it to your reply.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 

Attached Files


  • 0

#6
chanseygirl

chanseygirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts

Fix result of Farbar Recovery Scan Tool (x64) Version:16-12-2015 03
Ran by home (2015-12-16 14:47:24) Run:1
Running from G:\
Loaded Profiles: home (Available Profiles: home)
Boot Mode: Normal
==============================================

fixlist content:
*****************
HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
SearchScopes: HKLM-x32 -> DefaultScope {608093E8-E04B-40D6-85F6-7764FE0723D4} URL =
URLSearchHook: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 - FCToolbarURLSearchHook Class - {810a18c2-8c07-be74-21b6-b8261b1487fd} - C:\Program Files (x86)\BucksBee Loyalty Plugin - OpenInstall\Helper.dll ()
C:\Program Files (x86)\BucksBee Loyalty Plugin - OpenInstall
SearchScopes: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> {608093E8-E04B-40D6-85F6-7764FE0723D4} URL =
SearchScopes: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> {AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} URL = hxxp://www.ask.com/web?q={SEARCHTERMS}&o=15527&l=dis&prt=360&chn=retail&geo=US&ver=6
Toolbar: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Toolbar: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} -  No File
Toolbar: HKU\S-1-5-21-839081694-1943692923-2272886626-1001 -> No Name - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} -  No File
CHR HKLM-x32\...\Chrome\Extension: [jfmjfhklogoienhpfnppmbcbjfjnkonk] - <no Path/update_url>
2015-12-06 15:44 - 2015-12-06 16:43 - 00041767 ____H C:\Users\home\Documents\~WRL2814.tmp
2015-11-22 18:24 - 2015-11-22 18:33 - 00013541 ____H C:\Users\home\Documents\~WRL0647.tmp
2015-11-16 16:26 - 2015-11-16 16:29 - 00013313 ____H C:\Users\home\Documents\~WRL2131.tmp
2013-03-01 14:54 - 2013-03-01 14:54 - 0823396 _____ () C:\ProgramData\SPL3CC4.tmp
2011-06-21 08:29 - 2011-06-21 08:29 - 6920974 _____ () C:\ProgramData\SPL9690.tmp
2014-01-10 10:45 - 2014-01-10 10:45 - 1270289 _____ () C:\ProgramData\SPLF75C.tmp
C:\Users\home\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
C:\Users\home\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
C:\Users\home\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe
C:\Users\home\AppData\Local\Temp\jre-8u31-windows-au.exe
C:\Users\home\AppData\Local\Temp\jre-8u40-windows-au.exe
C:\Users\home\AppData\Local\Temp\jre-8u45-windows-au.exe
C:\Users\home\AppData\Local\Temp\jre-8u51-windows-au.exe
C:\Users\home\AppData\Local\Temp\jre-8u65-windows-au.exe
C:\Users\home\AppData\Local\Temp\jre-8u66-windows-au.exe
C:\Users\home\AppData\Local\Temp\miunst_.exe
C:\Users\home\AppData\Local\Temp\MSETUP4.EXE
C:\Users\home\AppData\Local\Temp\uninstall.exe
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
CMD: bitsadmin /reset /allusers
CMD: ipconfig /flushdns
EmptyTemp:

*****************

"HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
"HKU\S-1-5-21-839081694-1943692923-2272886626-1001\SOFTWARE\Policies\Microsoft\Internet Explorer" => key removed successfully
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\Software\Microsoft\Internet Explorer\URLSearchHooks\\{810a18c2-8c07-be74-21b6-b8261b1487fd} => value removed successfully
"HKCR\Wow6432Node\CLSID\{810a18c2-8c07-be74-21b6-b8261b1487fd}" => key removed successfully
C:\Program Files (x86)\BucksBee Loyalty Plugin - OpenInstall => moved successfully
"HKU\S-1-5-21-839081694-1943692923-2272886626-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{608093E8-E04B-40D6-85F6-7764FE0723D4}" => key removed successfully
HKCR\CLSID\{608093E8-E04B-40D6-85F6-7764FE0723D4} => key not found.
"HKU\S-1-5-21-839081694-1943692923-2272886626-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}" => key removed successfully
HKCR\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4} => key not found.
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => value removed successfully
HKCR\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F} => key not found.
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => value removed successfully
HKCR\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} => key not found.
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} => value removed successfully
HKCR\CLSID\{759D9886-0C6F-4498-BAB6-4A5F47C6C72F} => key not found.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk" => key removed successfully
C:\Users\home\Documents\~WRL2814.tmp => moved successfully
C:\Users\home\Documents\~WRL0647.tmp => moved successfully
C:\Users\home\Documents\~WRL2131.tmp => moved successfully
C:\ProgramData\SPL3CC4.tmp => moved successfully
C:\ProgramData\SPL9690.tmp => moved successfully
C:\ProgramData\SPLF75C.tmp => moved successfully
C:\Users\home\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe => moved successfully
C:\Users\home\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe => moved successfully
C:\Users\home\AppData\Local\Temp\jre-7u71-windows-i586-iftw.exe => moved successfully
C:\Users\home\AppData\Local\Temp\jre-8u31-windows-au.exe => moved successfully
C:\Users\home\AppData\Local\Temp\jre-8u40-windows-au.exe => moved successfully
C:\Users\home\AppData\Local\Temp\jre-8u45-windows-au.exe => moved successfully
C:\Users\home\AppData\Local\Temp\jre-8u51-windows-au.exe => moved successfully
C:\Users\home\AppData\Local\Temp\jre-8u65-windows-au.exe => moved successfully
C:\Users\home\AppData\Local\Temp\jre-8u66-windows-au.exe => moved successfully
C:\Users\home\AppData\Local\Temp\miunst_.exe => moved successfully
C:\Users\home\AppData\Local\Temp\MSETUP4.EXE => moved successfully
C:\Users\home\AppData\Local\Temp\uninstall.exe => moved successfully

========= reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========

The operation completed successfully.

 

========= End of Reg: =========

========= reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f =========

The operation completed successfully.

 

========= End of Reg: =========

========= RemoveProxy: =========

HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings => value removed successfully
HKU\S-1-5-21-839081694-1943692923-2272886626-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings => value removed successfully

========= End of RemoveProxy: =========

=========  bitsadmin /reset /allusers =========

BITSADMIN version 3.0 [ 7.5.7601 ]
BITS administration utility.
© Copyright 2000-2006 Microsoft Corp.

BITSAdmin is deprecated and is not guaranteed to be available in future versions of Windows.
Administrative tools for the BITS service are now provided by BITS PowerShell cmdlets.

{090DC0A4-86B1-4C5B-8604-C31DAF32BCE3} canceled.
{3471DA57-FAF2-4FC0-8B94-3D12A68E07BE} canceled.
{6DA765AA-9121-4102-B975-C17988BC9535} canceled.
{37699B1B-6AFE-453C-9CEA-01E073BE41AA} canceled.
{966151B2-2CA9-4BCD-B0E6-32238ED945A2} canceled.
{61A77324-C344-4DAA-BB24-FA437087B139} canceled.
{8A5029A1-55D0-4350-A8D2-0F5975EFA27D} canceled.
{1E4A8B5D-6ED4-48E6-84DD-E716A3884DB7} canceled.
{1D0466E9-D268-40E9-8CA6-C54A2574C2F8} canceled.
{195F46E9-A981-40EF-BB27-8A7249DF9438} canceled.
{11C64A3D-A065-4784-819A-5D4F47736608} canceled.
{5B2A99CD-BCD4-45DE-9272-53405E78CFAA} canceled.
{9D504D09-0762-4F42-8BF7-00EF922B2CE4} canceled.
{B28DD53B-BA5B-4A64-B3AD-0D39A703F60E} canceled.
{1481E94A-2374-46FF-8396-B21A4919222F} canceled.
{50A7DB97-495F-4348-8A82-D3BC358078D3} canceled.
{4A65739C-03F7-49E7-A463-E727331BFCB4} canceled.
{859F8D35-3471-4B38-AD9F-E439331F2ADD} canceled.
{36A942A2-D1EC-4B86-AFBB-9A5435C23A65} canceled.
{D69816DD-B985-4C7F-B356-1D4E8C029442} canceled.
{424B9A18-89E6-473C-9702-DF915D97B15D} canceled.
{295BB00C-EB6D-47FC-8325-B146965FEBB0} canceled.
{746A9972-3A36-4021-A5E9-6FB5CD8B6BC6} canceled.
{6C11F5C8-6856-470A-AA35-79739E846145} canceled.
{643256FC-79B4-4944-880E-BB090D4542C2} canceled.
{D2F7DC00-623E-4EFC-BC41-32343F2E768E} canceled.
{BBB3F84A-F5CC-4E93-B81D-B7F60D788309} canceled.
{B11AA61F-1240-43EC-B11D-D77B6CEBF1AE} canceled.
{3DD2B1F9-86DA-4BA8-87FC-3C92C5656C89} canceled.
{5343C090-D88C-47E2-96B9-845626E5AFF5} canceled.
{B9617410-E413-426C-8117-E19D44962549} canceled.
{5056907D-397F-4B4D-A367-1B5F2EEE7899} canceled.
{ABC0F3E4-1610-4652-835C-FE21F03CBF8E} canceled.
{A4C2F36D-CC04-4D55-A8F4-9EE3BFB67D83} canceled.
{583E6C1C-1968-4F1E-AE17-79192C3D3C1D} canceled.
{95A3EAC0-A899-4FD9-BA57-0BE8CD5826AB} canceled.
{17E203A8-2FEC-422D-97FE-2B215B0EB898} canceled.
{0303B9C2-90AB-4307-AFFA-1AD17DD26768} canceled.
{CA2A1CFF-94E5-4387-9EAA-ADAFAA675019} canceled.
{0CD38348-7CB3-4693-BC5B-DDB1B5FAB24D} canceled.
{46C3AB88-9674-49E6-B19B-B91B0FA441E5} canceled.
{AA34E88E-9631-4055-9179-6C962420FFD0} canceled.
{6E0CE46B-2554-4E49-893D-D1C933AAD309} canceled.
{3E186E2A-4F2E-482A-BD49-A88E5DE00A11} canceled.
{008EFA86-EBB6-45FD-8430-1305D12BA96E} canceled.
{402DC53A-FFDC-4FCC-93E2-6E086064E5E6} canceled.
{A9C130F0-1DDF-4E17-B4B2-501F09D96E1B} canceled.
{F2ECCBD8-0A29-4E1D-A510-A66B53BD4C01} canceled.
{C7C77D6E-F4F6-453C-82F9-2FF77B78A8F5} canceled.
{74130FEC-249B-48DD-89D9-BE037AAD027A} canceled.
{2D7560B7-0B07-429D-B9AF-F8EC01610466} canceled.
{CDC02CB3-CEF9-4DB0-9AF0-ECB89ED1ECB2} canceled.
{7279F238-75A1-4F08-B40E-84F76B40954B} canceled.
{C5A128E7-DC0E-45ED-8965-D61A97C343B6} canceled.
{75E5D614-F52B-4CDB-BBE5-A70F44EF9D94} canceled.
{897DAC43-5078-426A-A616-1DB14724622B} canceled.
{309AFF71-91C9-494D-A497-A096A5FF8D64} canceled.
{943272F5-8427-4B70-A196-62C517A3A9DB} canceled.
{733A7A18-33D1-4C7D-957A-6DEF9BBF6E53} canceled.
{B6BC0475-AE17-4EC8-ADC9-E7E49613297B} canceled.
{105EFAC9-5608-4E19-8062-D6C2D2280B68} canceled.
{9BB803CB-0721-4503-9958-A66F392A45BA} canceled.
{621C8EDE-D3C2-4E43-97CC-6E98D91DC8DA} canceled.
{A7360122-EEE6-4C0D-9A39-AEDEF6CB0265} canceled.
{89512CAF-6D7F-4BFC-B0C3-BF62A50D59DD} canceled.
{C9C8683E-7FDC-4A0B-AA8A-A11C234A33CE} canceled.
{25A4103C-16B4-4BDB-A3E2-4DCFF9981C7C} canceled.
{25EA093B-0D12-4D74-8463-B03393F94820} canceled.
{37AE4484-2AEB-43CB-83A2-16CA8DB3F4E6} canceled.
{033A6B79-EEAE-4C1D-B4A4-AB6AA3044023} canceled.
{173ABBC7-9354-4D5B-A067-6E69EAC9E40B} canceled.
{856D1E6E-FC23-4D0C-A18F-84B5A43DC7BA} canceled.
{5A875D56-366E-49C0-B96E-022E3331A203} canceled.
{12993E22-0828-4E9A-9E09-4A55B857580B} canceled.
{7D97E245-252F-4EC2-8773-B3476E3E2E20} canceled.
{62612E6C-C002-4D06-8579-98BA9EB7819A} canceled.
{1AB648FD-D24D-405A-8219-B24F64B6DA38} canceled.
{F64511F3-0305-4B6B-B63E-7626E84A5C19} canceled.
{A369E3DF-121B-4D89-8847-3337D4501832} canceled.
{601D2418-42F3-4102-8ECD-9C25FAEEEA98} canceled.
{8A75BDFB-C801-40F7-9A40-8FB47A700C8F} canceled.
{EB0F2CD9-79C0-48DB-A94C-CD0BAB418749} canceled.
{A78E23D6-119C-4C10-84A5-FCFF85F47025} canceled.
{DF423C51-19DF-4CF5-B684-7DCF0B04D8E6} canceled.
{D5F73157-DA9B-457E-925F-E48FCDAB96B8} canceled.
{E5EC7D37-539D-4321-B4BD-A73FC31DFD35} canceled.
{0236075E-8C6B-4821-8F3C-2A08EBE67720} canceled.
{A5E06A99-58AD-4227-9985-AFDE90C34D8B} canceled.
{16091ED6-53BF-42A4-9ED5-064804C7FDB7} canceled.
{64F61101-B56C-4E95-A9B1-66F2D6B1DD00} canceled.
{D16DA7D6-2DC8-4EAE-B6C1-C2DD65090BCB} canceled.
{ECE6B661-54FB-4615-AAFC-6397D71FB7E1} canceled.
{69B03132-C730-4271-B2B2-4C54F0929974} canceled.
{65350FE5-3AAB-4F53-8E72-6201ED305525} canceled.
{5FE46BB8-B935-46EB-9DF4-6BA26806CA11} canceled.
{1C4CC832-DAC8-4961-B3A9-B7B534B515CF} canceled.
{4328FFA9-CA1F-4FF3-8E2B-04D0D56581F1} canceled.
{9B3053C4-BCFD-4640-987F-EBC9FBD661EB} canceled.
{8BC8CF2E-DF1E-4BD5-AE19-A212A75341E8} canceled.
{07437AE7-0B84-42A7-8F99-2B0ADFA7634F} canceled.
{0D0CE45E-6B14-4C1F-A711-B5EEDCC42994} canceled.
{3B3CA9A8-9560-4C58-90D4-5088FF6F01B4} canceled.
{F5686DF3-AC87-4ACF-A6BC-20A2E6E7596A} canceled.
{C5DC1B98-6FF5-421D-8776-A5DBC7F73539} canceled.
{AFD84533-D72A-4703-83AA-108F999AAC0D} canceled.
{25F5F47A-39A5-47F3-83FE-70B62108B7BD} canceled.
{560F03F0-C666-40E6-A93C-8B8C4F60BDD7} canceled.
{D468DF6B-2207-4C7E-8A4E-75A32E1C810D} canceled.
{05F7A665-08E8-4821-8505-C7F56F0EF618} canceled.
{59AC7354-0E7E-4F8A-B1D8-F075F7AE96FF} canceled.
{71B8C60E-3FCB-4079-B7B4-CE50788D3F84} canceled.
{AD8386F9-55FE-4A49-B819-F96F87C7050C} canceled.
{37D2FF1C-545E-4366-A9CF-A705C86D6BAE} canceled.
{3807D96C-11B9-4B69-AE7A-BA1E460ED206} canceled.
{995E8ACA-C136-4447-AA28-99A68BEB2280} canceled.
{D253BC31-F97C-4AE0-B928-801C90350F11} canceled.
{F3AEC271-5672-4714-AA73-7F83F5786F28} canceled.
{77FBF245-9C35-4520-8DB0-F714C57F6FD5} canceled.
{9EE6DE7F-8FD1-4272-A77F-8102E04ADA1A} canceled.
{80209976-DFD3-489A-9990-90FFF6CB3B47} canceled.
{3C956079-8127-41EE-817E-4F04CDDF8111} canceled.
{87ACD4A1-1F6D-4253-8CAA-ED08A7E0E665} canceled.
{F9C91550-E915-4EC8-BBAA-EA02D0562D1B} canceled.
{3FFA163D-1BF1-454E-864A-A1A938099120} canceled.
{5F34003A-7923-4743-A2C3-6976178FF215} canceled.
{83F790B1-2F65-4397-BB21-5F33AD390772} canceled.
{76ABB908-66A5-4930-9DB0-871487C1C24D} canceled.
{4EEAD80D-2FB6-4461-BDB3-66E203D5204F} canceled.
{BE5398B8-8AE5-46AC-B1EE-CBBD233D1C8F} canceled.
{20AFA43C-3E9D-4393-A5F9-6FA92FA26401} canceled.
{C2EB5E38-5494-440E-B91F-620D4C1E3036} canceled.
{462EF6A7-3C08-48E0-AF26-7F3DBE8CE6DC} canceled.
{C4229B7D-8F6B-4180-8DDB-EFB2417B15A3} canceled.
{0CE449DB-FFAD-4DF4-8D79-2C1F0C4E3779} canceled.
{0ACD0B3B-A258-43B5-A24A-B9A7068134E3} canceled.
{91472AAE-28DD-4081-9312-A4BA140D058C} canceled.
{E922C11D-0588-4C1F-82A3-E746FB5DADA2} canceled.
{95378AF5-4E47-4EF4-9163-835B71D2F3D0} canceled.
{F5CD6D1C-2801-49CB-83CC-A29E4C6916A3} canceled.
{D201D9CE-9DD1-44DE-81C1-57901A243204} canceled.
{EF2B71D2-5FC1-4B68-BA6E-17C9A44E832F} canceled.
{DC4E56A6-D1A4-4B45-9DB0-8BF24F7F77ED} canceled.
{FB938C5D-14CC-4105-AA9D-45E6F4A0642E} canceled.
{B93C674E-6B27-4817-BFF6-DE580E2AF9C5} canceled.
{9707F28C-4C8F-43F5-B79C-C6A5FAF8D757} canceled.
{44F911D2-E3B7-4B8C-A2D3-19F611A745E5} canceled.
{4AD49A16-8CB2-4F20-ADB7-048D5E207F6F} canceled.
{C7D5309A-B864-45E7-8E50-2E436F9BCAA9} canceled.
{17AD1A02-2D5F-4924-8207-3CC6482A5207} canceled.
{F31C9BD8-DAA9-462B-9D70-90722CEAA921} canceled.
{571A0F56-B89E-4340-A716-0577A4810199} canceled.
{2F12CAE7-A083-4AEC-B932-AA799EF720C9} canceled.
{77365C9B-C936-40DB-A9CA-203453B0051A} canceled.
{E60AB001-59CF-4AB8-B001-50E8CFE4AF02} canceled.
{5A8B835D-2A65-4558-9DFE-6A17A33C9B43} canceled.
{91F47505-B73B-464F-8D57-A949329FC503} canceled.
{447F9E9C-44A9-45EE-8D7A-95A4868E2FE7} canceled.
{B02E95D9-7DC0-4FA7-8A85-7A95434167D4} canceled.
{C210D487-0149-4E3E-95AC-B8419EF7FAF9} canceled.
{6FABF80D-D516-4718-8723-EAFA1635428B} canceled.
{3A662F0E-AE5D-4DF3-98D9-23812832B5D9} canceled.
{AB4DA023-5331-4B24-B356-19F0655B0A55} canceled.
{4183FF68-38BA-43E4-8D9E-68EC2501BC0F} canceled.
{50609255-EBC9-4A3C-BA3E-4BB4EA40DA71} canceled.
{E9315708-D4DC-4C3B-97B0-104B7DEB633F} canceled.
{3258F70C-21CA-49AC-A668-941B4CA07577} canceled.
{AA9FF77F-97A0-49D6-B64B-017D3A941F88} canceled.
{E77126E2-F204-4794-9E73-21D88E9AD80A} canceled.
{58FE80BA-D17B-4B60-B70C-2D0A129ED157} canceled.
{DF6D3789-395E-4406-A34F-80B3FB38F0EC} canceled.
{E3F1BB3D-30B4-44A7-A967-DD24577F80B5} canceled.
{DEA3B1E1-322A-4BCA-9113-86C42947E6C8} canceled.
{E45C306B-2E6F-4EBC-8BE9-0B605D07D0F4} canceled.
{FE9F024C-748D-40C2-AF1D-E91388775474} canceled.
{E9419F37-504B-45B0-A735-807A2CC5F6BC} canceled.
{50D75385-E473-438D-831F-3F25A2CDD3FC} canceled.
{AE7B9A04-843D-45F5-B986-A3B72CF3D6A8} canceled.
{2FA30BEF-EFF1-48F2-81F9-CFED262671EC} canceled.
{A95814F6-DC2B-4001-89EF-EB2A1FBB90DC} canceled.
{E6FC96FB-4038-42B5-9A2D-D0E7DF66E37E} canceled.
{1E96E966-7BFE-4336-BAA2-36C65ACB1D8C} canceled.
{1DE3EFFD-E164-4E28-A7B9-C9881E2983AF} canceled.
{5310EA6C-F543-444A-9884-F159ED747853} canceled.
{BBA3E94B-D091-4852-BE9F-30116B87623F} canceled.
{CA2FCC4C-5C5B-4B9B-B58A-595BD1F6A7B6} canceled.
{134EA0CA-B515-49D8-B216-79BE555E38CE} canceled.
{D0E6DA90-46AC-4479-89A6-46FFBEB360D5} canceled.
{C6B4CAE9-4498-4DB0-93A4-09344DB54BB7} canceled.
{E85B28C6-DE2D-45F4-AC3E-3C3999DC8E73} canceled.
{0F545A90-5D19-4F48-AA72-578E4FD1F192} canceled.
{6D5D8A35-47C5-4DA0-B806-1FA661E62795} canceled.
{20107A3A-F087-4F3C-BFEE-758CD231C3DD} canceled.
{FF05CAAE-6DF3-498C-A9F2-6B34D94EDB37} canceled.
{D5998FFD-A5C3-4A3E-B571-8D55F4FEB8F2} canceled.
{E94E6F91-1D59-490C-98EA-59D331E23C47} canceled.
{0969FDA8-5903-4193-9BEB-006ED3B8966C} canceled.
{94C43216-A629-4745-8AFB-B2B53093C915} canceled.
{3AE83779-EA1C-4DCB-A92B-47728FAB2180} canceled.
{98265833-20BA-44D6-8FEC-EBB105620322} canceled.
{9C8EDA7A-DB7D-427E-8338-369D1907607F} canceled.
{50E676DE-705B-436C-8978-355599AF5C80} canceled.
{FAF866FA-E17C-4AAC-AF54-787512F16459} canceled.
{7467BA0C-1F64-4D24-98BB-23765C9D5C74} canceled.
{16BCD106-9C50-4528-9981-F39F970CC46F} canceled.
{18D1D377-D199-41DC-879D-1E7FCB51B11C} canceled.
{BC4E9D5E-93C7-402A-BD01-8B7E8A44FEFB} canceled.
{EE6588C7-89F6-4A67-9A53-1BF3412D7C51} canceled.
{4C49C44C-9CB6-46DF-8B6C-94D3C68732D7} canceled.
{6A283A54-39E2-444F-A5D3-8D2A77B01E6C} canceled.
{D3FCCCCE-1911-41C9-8CF5-91BEE4149862} canceled.
{38E26EB2-0B6D-4147-B83B-181258937EDE} canceled.
{D83AF25A-FD98-408F-A216-46D43A68C2EE} canceled.
{2624AFEB-EB6C-4777-A7C5-94884EE4B8BD} canceled.
{1871073F-19BB-4BE7-B85D-AF086EFE6F71} canceled.
{4E222672-6629-41F2-AB77-256CB7D9A88D} canceled.
{D7B74D26-400C-49D2-B6F7-F3678252CE86} canceled.
{9C3F045C-D037-4299-808E-F55F6F7FC006} canceled.
{977F253C-8864-47A7-8ED0-617FD5127BFA} canceled.
{F9580A11-6B14-42AF-B421-18393BF3A215} canceled.
{273249B8-452B-4634-BA93-8A2E1AB4A347} canceled.
{77958051-1DB9-4127-9B65-8D63A2A6FDDC} canceled.
{2555FD24-2E44-4181-881A-B20828B35FCF} canceled.
{00F71B24-7A01-4262-A3EA-9EE227D97FF0} canceled.
{01D44119-935D-4D1C-AE5B-8A7399C12529} canceled.
{086632BD-A625-4655-A35D-1505C8E248BD} canceled.
{01800FD8-A9FE-4080-88BD-6B4321381A10} canceled.
{F77A7FBF-A31D-4589-8B4A-1CDE72773DC7} canceled.
{4D5BC8D3-5F7D-4CA6-816B-8C95099A7AF3} canceled.
{92DB5F2B-6CA3-44DE-B273-A51330DBD643} canceled.
{51561DF5-C881-4D86-8D3A-22F1F482B241} canceled.
{7AE7B569-7134-4A98-B39B-BB79B47B6462} canceled.
{C6315D62-F3DE-4688-AE3C-67D090627938} canceled.
{E6B99665-1D04-4F03-8FFE-C658FB04DF88} canceled.
{0376475D-50FF-43C8-BA66-58015371C3B8} canceled.
{77B25381-7133-42D9-A135-71BB74EC4A68} canceled.
{C972EE86-A72F-4A32-B5B2-73B46AA81C88} canceled.
{D2FE7891-BF01-424D-8C77-267C01C37F17} canceled.
{FBBF6D3A-903D-43C9-B3EA-238B1D1FAB88} canceled.
{6D074975-889D-4AA1-B8B2-B0E59863384A} canceled.
{E940C54C-9012-4EB1-ACB3-F1DDF66247F2} canceled.
{7C6A9532-67ED-4033-9D56-6114714A378C} canceled.
{70AEAE66-CABC-49B6-B655-FBDE81E65AA6} canceled.
{50D505E3-0872-45D1-9277-EAF532B0F283} canceled.
{003CD014-DBB8-4FA3-BE77-28ED491F503F} canceled.
{2C50A813-BB5B-422F-A6AF-29D3FE355E63} canceled.
{F48F51E4-7D89-4484-BC9A-6890EE0796B8} canceled.
{9F52C0CB-0D76-4FCF-887C-F132FB7F5C84} canceled.
{F5C76C71-52EE-4B24-A4A8-663B57847453} canceled.
{DF01D4D8-E6A4-46C7-B0D1-43724D95DAC5} canceled.
{DAB0D989-50A4-47A1-8775-62A89B09B818} canceled.
{68E43EDE-C36B-40C5-9FD0-FED3F1A2DA55} canceled.
{362039E0-EE86-4FA7-B56F-7872D0163FA0} canceled.
{239EBAA3-3438-4CC9-8325-CC8CA1BC982C} canceled.
{A0AC0400-CF51-4514-B316-8618C5D76EAC} canceled.
{C99C149C-DEFB-4DA4-A240-23804C97735C} canceled.
{40111477-0F17-4749-893E-ACDC54A3AD75} canceled.
{16A62402-0845-4774-BCC3-8B160ADC04CC} canceled.
{D60C0DCA-0E01-41EB-A5A1-6B6E559159EC} canceled.
{ED7D38DD-4877-4181-969C-BB2BB3D3974B} canceled.
{7268A0D4-C4D1-49AC-BF69-1B1CA656C86B} canceled.
{362B5C5C-12FF-435F-85C4-2FC56929CFB3} canceled.
{DCBB3844-6CC2-4168-A016-4773E8B0C905} canceled.
{BFE11AD0-41F5-4910-89ED-1041B81A24E2} canceled.
{16E04BA3-23D5-4858-80A9-95E215DC0C6C} canceled.
{FEDD2BA6-71FA-4D50-9A1F-E46F3F9D261B} canceled.
{F2E1FD6D-6DBE-4F52-82FB-F8029D17B157} canceled.
{F7214D50-7D41-4468-848E-C84E80552E80} canceled.
{8DC90130-02DF-49A3-BB4C-D4BD34EA09B5} canceled.
{00E4912B-40A3-48C9-BC71-04D559297FD4} canceled.
{C1679B70-8F51-44A1-9A95-F64F1B5F976F} canceled.
{438D3276-CD23-4BC3-9AF2-EFC9E374E15E} canceled.
{629745A6-3A37-4402-9819-BD42DADC5D9E} canceled.
{00BB0553-78BB-4FAB-94AD-D1E1A98D6698} canceled.
{732632BD-CD61-4DFB-A57D-E5E124243D75} canceled.
{F817BF59-1E7B-45D0-ACCB-5637E4D70E8B} canceled.
{B87669DE-B228-4EC4-AD7D-CC863F05CADC} canceled.
{FA8B5DBA-826F-4096-8907-F291B95A4326} canceled.
{67E52778-1118-410C-8010-885316A0FAD0} canceled.
{D55452EF-AD1D-407B-B8AE-4CA5994811D3} canceled.
{B6AA1E73-E78B-4116-B506-CAD62CC7F2D2} canceled.
{7CB24540-5E7E-4703-AFC6-2B3517B6647F} canceled.
{EB2F6AE5-9981-4F4D-9373-917EA7240238} canceled.
{12AB051D-E5D1-4C47-8889-49BCB81DED55} canceled.
{E8D53447-87CA-4CA7-A8F3-FEEC533164A4} canceled.
{011ABEF3-78AD-46D2-B908-3B232E0FEE19} canceled.
{ADD56C91-90B3-4453-A633-0311A2641151} canceled.
{E0090F70-B4E1-45CB-A5CC-F073B62FEC51} canceled.
{2E18A17B-56B0-4319-80B1-F080B0D92848} canceled.
{697CAC9A-F6F6-4669-A256-70177B82DB1B} canceled.
{1214FF6C-726D-46E5-AF8C-8E137DC1D760} canceled.
{AE960EDB-AF31-4A67-8650-3F724CB66F3B} canceled.
{DC349F7B-1A3C-48B1-BF1F-2B68B1DFFE4B} canceled.
{EF62061A-D601-4D74-AAAA-DDC490513E84} canceled.
{38D1489A-1A03-44C2-A486-75E7F930F1ED} canceled.
{ACD9EC19-1301-4010-BE8F-37579EE9A291} canceled.
{EBCA61DE-C2B9-4519-9F23-64B28FB5A71C} canceled.
{97266BC3-7672-4508-9B7C-ACCD586F7682} canceled.
{8969237A-8635-4243-9BDA-57C52D413ED2} canceled.
{C1C2DC92-47DD-453B-8A4A-ED080D04F8AF} canceled.
{0061A4BB-F2E1-4212-851A-59C8B64D85B1} canceled.
{C7B19A91-15F0-4315-B758-85FE53E97BE8} canceled.
{61888C2F-D04F-4B29-A06F-1A82A05E2172} canceled.
{A6FBA221-F5B8-437C-82D3-F00C6BC26467} canceled.
{49324308-582B-4A02-B11B-7A211DD616BA} canceled.
{3904DB3C-59F5-4518-8A8D-93CBD0854705} canceled.
{CF89D80F-61E4-4FCA-B4B7-13C2308B714A} canceled.
{211CC667-5BE7-4045-B3CF-D48646A6E4A1} canceled.
{D5D5A0E0-86DA-4795-A85D-BCB71110B08D} canceled.
{B6B2526C-2F46-43F2-8232-96607BB5EF7F} canceled.
{F4E531EC-8270-4BAD-B360-526ADF9E8D84} canceled.
{63BB6EEA-EE1F-49F1-9432-1CE836DDAE86} canceled.
{E17B39AA-B696-4315-AA00-98251B66EAFC} canceled.
{268D820F-BE82-4986-9025-18F8098FAC38} canceled.
{81780814-B40F-4D31-B9AE-BCE1C9488EC8} canceled.
{557178CC-5D9B-43E3-A5B9-EEC7B2C0BCC2} canceled.
{23CCC72C-9770-46E6-828D-0E863FD38734} canceled.
{CEAD35A4-08F7-4696-853C-345CF25845F2} canceled.
{E96D5936-1A44-4BD9-9EEE-8848C48C440E} canceled.
{9D7B7A35-AF7C-4E16-A3D2-03BD6E8B1C28} canceled.
{1192842A-73F5-40DF-B387-20B927239631} canceled.
{56044BCA-F08E-4A64-A6DC-15A090EAF799} canceled.
{A5227914-B3D7-40DA-9760-E0D3EFC9A8C4} canceled.
{161F8A54-AF72-42A0-9433-F5CAF37C7C60} canceled.
{6BAD94F2-39A6-4233-A633-C6DFDA974D78} canceled.
{BEB6B331-3353-4627-BE3C-96685F4CEF9C} canceled.
{A8188AF1-6C89-4BF3-8647-EDF724945C06} canceled.
{F710501F-1A83-4662-800D-E62B96F6B065} canceled.
{71F63898-6B57-4771-9E3F-9B987E87F4B0} canceled.
{29123731-1B2B-4C03-BAC5-D27A45880F2B} canceled.
{8F3779D4-A50C-4303-B87E-AF07891697E4} canceled.
{3E2709CE-5979-448F-AC12-9BDA8567D628} canceled.
{78B5B2C8-E6FF-4E64-8EAE-45E4F496D0AF} canceled.
{37FC8717-9FE1-4311-AF81-5035BB83B021} canceled.
{AE81AB4C-C66E-489B-9AEC-8DBB36D98C75} canceled.
{1F945FA3-2D09-422B-9378-709C7B6E14BB} canceled.
{CBE786D4-2506-49D8-9070-82DF1884AA63} canceled.
{4C3B91A6-6B25-4825-AC86-2CB35F84E79E} canceled.
{CA0D5C58-AEA4-4180-901E-FCD84F9C30A6} canceled.
{14250A82-0CCB-4516-9050-CC41AF138A24} canceled.
{B1913466-E77E-416A-B290-5DCB3E37D2C5} canceled.
{312561AA-13DD-4D0D-AF42-A03F9735D2DF} canceled.
{696175E3-BA34-481B-9052-37D1F397158D} canceled.
{15802DF8-C6B0-4DEA-B89B-128BAE599DA6} canceled.
{0253EFE9-A26F-44C7-8E8E-8E9D73F6D7A1} canceled.
{D96FE14D-1C94-4FE7-8767-4CCABF7A792F} canceled.
{6409DE31-32A2-4469-8595-4305DECF33A1} canceled.
{622E7F7B-F40B-43F6-9C7F-81ED7D2BF329} canceled.
{7F75D766-76C5-4856-9307-3B3C2641B758} canceled.
{5791BA50-F985-4A6A-99B5-772EA1C0959B} canceled.
{CD4AE013-CD92-44DB-A474-3E191C87BD1D} canceled.
{0300FD64-ED8C-443B-AC8B-1A9EC8345F8D} canceled.
{DBB154B7-84CD-40E6-92D6-9B036F6A41EE} canceled.
{2D893E65-1035-4F29-80F3-EE57F3ACACB4} canceled.
{443AB71C-0BCC-4D19-8A0C-5AF2E7F2AFF7} canceled.
{6F89B003-D8E4-4EDF-81DE-1353F57163A0} canceled.
{16CF2E95-F9AD-46D3-BFF2-E7A7CF33AC25} canceled.
{20D8F5C4-7F81-47B1-94D2-FC81C94C107C} canceled.
{D2E9DDA9-87C5-460B-84C2-254544569386} canceled.
{39F68355-2EC3-459F-AA29-7D7572FE848B} canceled.
{8543EC07-C8B7-475B-9BAD-A1BE3C7E3C97} canceled.
{75A8E370-CAF0-4A25-AA92-702C6EB118E0} canceled.
{BD7F0EDF-DF7A-4B07-A724-C5E1E9F60A61} canceled.
362 out of 362 jobs canceled.

========= End of CMD: =========

=========  ipconfig /flushdns =========

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========= End of CMD: =========

EmptyTemp: => 4 GB temporary data Removed.

The system needed a reboot.

==== End of Fixlog 14:51:28 ====


  • 0

#7
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

Hello chanseygirl,

 

Note: When downloading the next two tools choose the @Bleepingcompter green button you see. If you are unable to run JRT.txt just move on to AdwCleaner.

 

Please download Junkware Removal Tool to your desktop.

  • Shut down your protection software to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right click JRT.exe and "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.

Next
 

Please download : ADWCleaner to your desktop  (use the Download Now @ BleepingComputer button)..

NOTE: If using Internet Explorer and get an alert that stops the program downloading, click on the warning and allow the download to complete.

Close all programs and click on the AdwCleaner icon. AdwCleaner will update itself and then open.

AdwCleaner.jpg

Click on Scan  and follow the prompts. It may appear not to be doing anything, please be patient and let it run unhindered. When the "Please uncheck elements you don't want to remove" appears just go ahead and click on the Clean button, and follow the prompts. Allow the system to reboot. You will then be presented with the report. Copy and paste back here. If a report doesn't appear, press the report button and Copy & Paste the contents on your next reply.

A copy of the report is also saved in the C:\AdwCleaner folder.

 

Lastly in this post

 

Download CKScanner from here

Important : Save it to your desktop.

  • Doubleclick (Vista and above - right click and run as Administrator) CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A message box will verify that the file is saved.
  • Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.

 

When you return please post

JRT.txt

AdwCleaner log

CKFiles.txt


  • 0

#8
chanseygirl

chanseygirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Malwarebytes
Version: 8.0.1 (11.24.2015)
Operating System: Windows 7 Home Premium x64
Ran by home (Administrator) on Wed 12/16/2015 at 17:43:08.93
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

File System: 120

Failed to delete: C:\Windows\wininit.ini (File)
Successfully deleted: C:\end (File)
Successfully deleted: C:\ProgramData\best buy pc app (Folder)
Successfully deleted: C:\ProgramData\partner (Folder)
Successfully deleted: C:\Users\home\AppData\Local\{01DB8B1D-5F0D-4A14-9FC4-BBE4E73E8C52} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{05EFEB5F-AF9B-41E5-9A55-842DDBFEBDCC} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{07C4DB80-33EE-43A1-8DB9-81AE93CB0357} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{0A84DE8A-F86A-4A3E-BC0E-B59C8DE0C6B0} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{0B27A3C3-AED7-468A-8655-5E6BC4E55CD0} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{0CB72EA0-7761-47F8-86E0-294FBB68B905} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{0F7BD91D-F6FA-4DAB-B470-6D0A854E067D} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{13D7196C-DB5B-4EAA-9601-392B3A6088D5} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{19DA975A-A1FD-4E8C-9DBC-1FDBB3A642E9} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{1C4CEB0C-549A-4E77-96F3-14C1C9720A0D} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{1EA18D31-D7DF-4407-B97F-C30E1748087A} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{29217F6F-87F8-4E6A-B9F8-180DE7C82212} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{2E494818-E916-459B-B5B8-E86DA7C3678D} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{329B90B8-2477-4D71-B35F-60120806F3B2} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{35405FEF-E531-4E95-87F9-F672496CBE25} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{37FF0A34-FB3B-47D4-9CBF-E79B36F7F3D2} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{3B567434-9610-41C8-9AE4-74BF6418A9D0} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{4591BB98-CF8C-4CFE-B58B-1E94D2094788} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{477BC517-4A5B-4E4E-9401-B5CB79948F3C} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{4780AD5E-7988-4410-8F95-18B4A387199C} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{504BE676-F62C-4611-A005-3C1D3E9C9FC7} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{56D05734-B6ED-4E6D-B357-8B2596E0C16B} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{5BFBD43A-849C-4100-911D-0EDA16FD542A} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{5D8D50E6-7675-4E4E-8BD4-5D41A145D29C} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{6334F63F-72CC-4278-A0EE-9CFC440247E8} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{647111C1-2924-4BD9-8F91-8047202FD9DE} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{656839C9-EC58-4FBD-AA40-D942F8F8621D} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{661A63E2-E97D-4F79-AE21-71D031C76C80} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{6F2E99CF-F0CB-4DA0-BE23-F6A773FC2FB8} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{7069C886-C40D-4110-AC0A-0184089E9B95} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{72FCAD66-14D6-4D92-BBF8-305A645395D8} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{7676A869-87A2-451C-AFA6-9D8F20F41651} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{797DAA8B-39E0-4054-9DE9-2D67DBE22FAC} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{79B8E6D9-240B-4E36-A72A-48481BF7A427} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{7B6808ED-6298-492F-8952-DA565FB4AA85} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{8030569C-7A22-4B81-9205-6894928FAD58} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{87FDE11B-453D-4C1F-B3BC-5C1D0DB341C8} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{88D8555A-13AD-49BB-AAFA-FA30F1102D02} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{8CB99266-47DE-4B26-9435-EC99DCDBCDA4} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{96D85398-231F-44D2-B154-196AB21E87E9} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{9753F46E-70FD-484B-B381-0A1F44EE4DF8} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{9D07ED03-3CFE-48B6-B35F-DD6D2E813A3F} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{9D445D9B-6ACD-4F1C-BB13-871C64BF9AE9} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{A6100084-C0FA-4FE0-8A1A-4917842F5405} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{A853E73E-0092-4ABF-BBFB-9752E2EFFFFA} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{AA3EF4A3-AAD4-4D3D-A62A-A03044012E29} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{B03DA089-658A-4CCF-9315-B6FD839376BE} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{B7D524E9-79F4-41B9-870F-337AC816DDDF} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{B8F446D5-E68A-4FDC-B2C2-9FEBDC01434F} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{BA7A067C-97B9-4C6C-92E7-6837E0F18B0D} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{BAD8A0E6-D765-41A2-B2EA-4F0150CDC16F} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{C0085FFD-01DF-426C-99C5-78EEA06806AF} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{C80E5569-AB62-494C-9B9F-11F6658EFC1F} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{C964094D-A565-4231-B4C6-581F254ABCA0} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{CA69E4F6-454E-41D7-9C22-60FF04AE9F8D} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{CF25D28A-34AA-4A9B-8D2D-18D9EBD58054} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{CF69EB4A-5CE5-49B5-B7D1-2C9090651A72} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{CFCD8C56-2905-44D0-894E-8C3963650851} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{D0C11FAF-39B2-4680-8476-3DF5190D24BC} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{D7277716-46BD-4254-94C1-2169D8DEE7F4} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{DB6B97B5-3905-4439-8823-F45036F7A85C} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{E8479522-BDA7-494F-A749-CAAAE2021D31} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{EF5BF205-A1BE-4765-BAAD-6611A4AEA9CF} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\{FB6841CA-2E36-4432-B0AE-77E34A852B0B} (Empty Folder)
Successfully deleted: C:\Users\home\AppData\Local\best buy pc app (Folder)
Successfully deleted: C:\Users\home\AppData\Local\conduit (Folder)
Successfully deleted: C:\Users\home\AppData\Local\cre (Folder)
Successfully deleted: C:\Users\home\Appdata\LocalLow\conduit (Folder)
Successfully deleted: C:\Users\home\Appdata\LocalLow\FCTB000100493 (Folder)
Successfully deleted: C:\Users\home\AppData\Roaming\download manager (Folder)
Successfully deleted: C:\Users\home\AppData\Roaming\performersoft (Folder)
Successfully deleted: C:\Windows\system32\Tasks\? (Task)
Successfully deleted: C:\Program Files (x86)\avg security toolbar (Folder)
Successfully deleted: C:\Program Files (x86)\conduit (Folder)
Successfully deleted: C:\Program Files\003 (Folder)
Successfully deleted: C:\Windows\prefetch\TOOLBARUPDATER.EXE-41C2386E.pf (File)
Successfully deleted: C:\Windows\SysWOW64\sho10B8.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho17F0.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho1A27.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho2179.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho2796.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho2DC.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho43C5.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho45E5.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho4715.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho622F.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho69AA.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho6AF6.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho6D20.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho6E3.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho6F79.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho7505.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho7525.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho7A0D.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho7A1E.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho7A31.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho7CEC.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho7F57.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho81B1.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho8258.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho838B.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho8499.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\sho964A.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoA158.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoA5D5.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoB154.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoC097.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoC2A.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoCD5A.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoCFA5.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoD3D8.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoE33B.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoE704.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoE843.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoEF1E.tmp (File)
Successfully deleted: C:\Windows\SysWOW64\shoF46D.tmp (File)

 

Registry: 6

Successfully deleted: HKLM\Software\Google\Chrome\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof (Registry Key)
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\vToolbarUpdater19.1.0 (Registry Key)
Successfully deleted: HKLM\SYSTEM\CurrentControlSet\services\YahooAUService (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Key)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Search\\SearchAssistant (Registry Value)
Successfully deleted: HKLM\Software\Microsoft\Internet Explorer\Toolbar\\{95B7759C-8C7F-4BF1-B163-73684A933233} (Registry Value)

 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Wed 12/16/2015 at 17:47:45.20
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

 

# AdwCleaner v5.025 - Logfile created 16/12/2015 at 17:57:44
# Updated 13/12/2015 by Xplode
# Database : 2015-12-13.2 [Server]
# Operating system : Windows 7 Home Premium Service Pack 1 (x64)
# Username : home - MAIN
# Running from : C:\Users\home\Desktop\AdwCleaner.exe
# Option : Cleaning
# Support : http://toolslib.net/forum

***** [ Services ] *****

[-] Service Deleted : YahooAUService

***** [ Folders ] *****

[-] Folder Deleted : C:\Program Files (x86)\AVG Secure Search
[-] Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
[-] Folder Deleted : C:\ProgramData\AVG Secure Search
[-] Folder Deleted : C:\ProgramData\Avg_Update_0814tb
[-] Folder Deleted : C:\Users\home\AppData\Local\AVG Secure Search
[-] Folder Deleted : C:\Users\home\AppData\LocalLow\AVG Secure Search
[-] Folder Deleted : C:\Users\home\AppData\LocalLow\Yahoo!\Companion
[-] Folder Deleted : C:\Users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\bucksbee loyalty plugin - openinstall

***** [ Files ] *****

***** [ DLLs ] *****

***** [ Shortcuts ] *****

***** [ Scheduled tasks ] *****

[-] Task Deleted : AVG-Secure-Search-Update_JUNE2013_TB_rmv
[-] Task Deleted : AVG-Secure-Search-Update_JUNE2013_TB_rmv

***** [ Registry ] *****

[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL
[-] Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI
[-] Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj
[-] Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\FreeCauseURLSearchHook.FCToolbarURLSearchHook
[-] Key Deleted : HKLM\SOFTWARE\Classes\FreeCauseURLSearchHook.FCToolbarURLSearchHook.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\protocols\handler\viprotocol
[-] Key Deleted : HKLM\SOFTWARE\Classes\S
[-] Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi
[-] Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE
[-] Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run [vProt]
[-] Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin
[-] Key Deleted : HKLM\SOFTWARE\Google\Chrome\NativeMessagingHosts\avgsh
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1
[-] Key Deleted : HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_BROWSER_EMULATION [BackgroundHost.exe]
[-] Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\MAIN\FeatureControl\FEATURE_WEBOC_MOVESIZECHILD [BackgroundHost.exe]
[-] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT3279411
[-] Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar]
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2}
[-] Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB}
[-] Key Deleted : HKCU\Software\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{408CFAD9-8F13-4747-8EC7-770A339C7237}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{933B95E2-E7B7-4AD9-B952-7AC336682AE3}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{94496571-6AC5-4836-82D5-D46260C44B17}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AF175732-0D59-716D-F757-9F1492D808D9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{BC9FD17D-30F6-4464-9E53-596A90AFF023}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CA3A5461-96B5-46DD-9341-5350D3C94615}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
[-] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{07CAC314-E962-4F78-89AB-DD002F2490EE}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{13ABD093-D46F-40DF-A608-47E162EC799D}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
[-] Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{810A18C2-8C07-BE74-21B6-B8261B1487FD}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
[-] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{045F91B3-695F-423A-98C7-8DE3C47AA020}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1348BD1B-C32A-41A7-9BD4-5377AA1AB925}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{395AFE6E-8308-48DB-89BE-ED5F4AA3D3EC}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{43969E3F-3E7C-4911-A8F1-79C6CA6AC731}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{43B390F0-6BA2-45CA-ABF2-5DB0CEE9B49D}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{94CADA2E-1D3F-419F-8A3D-06C58EDF53C8}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E52EB8B-8DD9-4605-AD36-D352BCD482F2}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{A1440EC3-F0FA-407A-B811-DE6668C06D29}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{B9A84AD0-5777-46FD-8B8F-1EBD06750FBC}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C1995F88-1C7F-40D7-B0FA-6F107F6308B8}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C815E3DA-0823-49B0-9270-D1771D58B317}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E4A994B0-5550-4680-A4C6-B9470B888069}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{EE95078D-518C-4FD2-8093-FD1D4E33D3CA}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{F9EB11AB-9384-4736-9B33-993940F88895}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F25AF245-4A81-40DC-92F9-E9021F207706}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B2BC04DF-EFBD-409A-95CA-36874E5AB92A}
[-] Key Deleted : HKCU\Software\AVG Secure Search
[-] Key Deleted : HKCU\Software\IGearSettings
[-] Key Deleted : HKCU\Software\YahooPartnerToolbar
[-] Key Deleted : HKCU\Software\Yahoo\Companion
[-] Key Deleted : HKCU\Software\Yahoo\YFriendsBar
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Freecause
[-] Key Deleted : HKCU\Software\AppDataLow\Software\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\AVG Secure Search
[-] Key Deleted : HKLM\SOFTWARE\AVG Security Toolbar
[-] Key Deleted : HKLM\SOFTWARE\Conduit
[-] Key Deleted : HKLM\SOFTWARE\Yahoo\Companion
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AVG Secure Search
[-] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{EE171732-BEB4-4576-887D-CB62727F01CA}
[-] Key Deleted : [x64] HKLM\SOFTWARE\Tarma Installer
[-] Key Deleted : HKU\.DEFAULT\Software\AVG Secure Search

***** [ Web browsers ] *****

[-] [C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : aol.com
[-] [C:\Users\home\AppData\Local\Google\Chrome\User Data\Default\Web Data] [Search Provider] Deleted : ask.com

*************************

:: "Tracing" keys removed
:: Winsock settings cleared

########## EOF - C:\AdwCleaner\AdwCleaner[C1].txt - [10117 bytes] ##########

 

 

CKScanner 2.5 - Additional Security Risks - These are not necessarily bad
c:\users\home\appdata\roaming\ts3client\hotkeys.ini
c:\users\home\music\mom's stuff\all music folders\complete cds\b artists\blues traveler\blues traveler - suzie cracks the whip (released 2012)\thumbs.db
scanner sequence 3.LB.11.GONAUZ
 ----- EOF -----
 


  • 0

#9
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

Hello chanseygirl,

Please download ComboFix from this location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools.
 

  • Double click on ComboFix.exe & follow the prompts.
  • If you have an older Operating System you may be asked whether you want to install the Recovery Console. Click yes and follow any prompts.
  • Your desktop may go blank. This is normal.
  • ComboFix may appear to be doing nothing for quite long periods, this is normal, just leave it to do it's job.
  • ComboFix may reboot your machine. This is normal too.

**Note: Do not mouseclick combo-fix's window while it's running. That may cause it to stall**

When finished, it will produce a log for you.  Please include the C:\ComboFix.txt in your next reply.

 


  • 0

#10
chanseygirl

chanseygirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts

I tried to run the ComboFix, but it stopped saying that my Norton Internet Security is preventing from running. I saw where you said to disable my AntiVirus and AntiSpyware applications, but I can't find it. When I click on Norton 360 nothing happens as if nothing is there. What should I do next?


  • 0

Advertisements


#11
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

 

I tried to run the ComboFix, but it stopped saying that my Norton Internet Security is preventing from running.

 

Often it will say something along those lines but you can just continue. If that is the case then just continue. :)

 

If you cannot continue tell me the exact message.


  • 0

#12
chanseygirl

chanseygirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts

ComboFix 15-12-16.01 - home 12/16/2015  19:23:40.3.2 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.1.1033.18.6109.1795 [GMT -6:00]
Running from: c:\users\home\Desktop\ComboFix.exe
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\home\Documents\~WRL0001.tmp
c:\users\home\Documents\~WRL0002.tmp
c:\users\home\Documents\~WRL0003.tmp
c:\users\home\Documents\~WRL0004.tmp
c:\users\home\Documents\~WRL0005.tmp
c:\users\home\Documents\~WRL0112.tmp
c:\users\home\Documents\~WRL0166.tmp
c:\users\home\Documents\~WRL0221.tmp
c:\users\home\Documents\~WRL0524.tmp
c:\users\home\Documents\~WRL0646.tmp
c:\users\home\Documents\~WRL0910.tmp
c:\users\home\Documents\~WRL0989.tmp
c:\users\home\Documents\~WRL1270.tmp
c:\users\home\Documents\~WRL1357.tmp
c:\users\home\Documents\~WRL1406.tmp
c:\users\home\Documents\~WRL1714.tmp
c:\users\home\Documents\~WRL2063.tmp
c:\users\home\Documents\~WRL2194.tmp
c:\users\home\Documents\~WRL2210.tmp
c:\users\home\Documents\~WRL2681.tmp
c:\users\home\Documents\~WRL2730.tmp
c:\users\home\Documents\~WRL2837.tmp
c:\users\home\Documents\~WRL3102.tmp
c:\users\home\Documents\~WRL3214.tmp
c:\users\home\Documents\~WRL3224.tmp
c:\users\home\Documents\~WRL3434.tmp
c:\users\home\Documents\~WRL3513.tmp
c:\users\home\Documents\~WRL3542.tmp
c:\users\home\Documents\~WRL3548.tmp
c:\users\home\Documents\~WRL3586.tmp
c:\users\home\Documents\~WRL3666.tmp
c:\users\home\lame_enc_en.dll
c:\users\home\lametritonus_en.dll
c:\windows\PFRO.log
c:\windows\SysWow64\DEBUG.log
c:\windows\wininit.ini
.
.
(((((((((((((((((((((((((   Files Created from 2015-11-17 to 2015-12-17  )))))))))))))))))))))))))))))))
.
.
2015-12-17 01:36 . 2015-12-17 01:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2015-12-17 01:36 . 2015-12-17 01:36 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2015-12-16 23:56 . 2015-12-16 23:57 -------- d-----w- C:\AdwCleaner
2015-12-15 02:26 . 2015-12-16 20:53 -------- d-----w- C:\FRST
.
.
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
.
------- Sigcheck -------
Note: Unsigned files aren't necessarily malware.
.
[-] 2010-11-20 . DDAD5A7AB24D8B65F8D724F5C20FD806 . 119296 . . [6.1.7601.17514] .. c:\windows\system32\drivers\tdx.sys
.
[-] 2012-07-04 . 05F5A0D14A2EE1D8255C2AA0E9E8E694 . 136704 . . [6.1.7600.16385] .. c:\windows\system32\browser.dll
.
[-] 2013-09-25 . 4D71227301DD8D09097B9E4CC6527E5A . 30720 . . [6.1.7601.18270] .. c:\windows\system32\lsass.exe
.
[-] 2012-02-11 . 85DAA09A98C9286D4EA2BA8D0E644377 . 559104 . . [6.1.7600.16385] .. c:\windows\system32\spoolsv.exe
.
[-] 2013-07-04 . 9028D1621C43DF8DFBD1C76860412A11 . 633856 . . [5.82] .. c:\windows\system32\comctl32.dll
.
[-] 2013-07-09 . 6B400F211BEE880A37A1ED0368776BF4 . 184320 . . [6.1.7600.16385] .. c:\windows\system32\cryptsvc.dll
.
[-] 2012-11-22 . DBF99FD9CAF75CA66D042BD8D050FF71 . 800768 . . [1.0626.7601.18009] .. c:\windows\system32\usp10.dll
.
[-] 2012-11-30 . 65C113214F7B05820F6D8A65B1485196 . 1161216 . . [6.1.7601.18015] .. c:\windows\system32\kernel32.dll
.
[-] 2013-06-06 . 796B47A4B82EF1C39F13435B88834C48 . 41472 . . [6.1.7601.18177] .. c:\windows\system32\lpk.dll
.
[-] 2013-10-25 . F164B9D9EB6AA4FED10AC2DA8CB4A89A . 19271168 . . [10.00.9200.16521] .. c:\windows\system32\mshtml.dll
.
[-] 2011-12-16 . C391FC68282A000CDF953F8B6B55D2EF . 634880 . . [7.0.7601.17744] .. c:\windows\system32\msvcrt.dll
.
[-] 2013-09-08 . 9A9F9F1A77D6A80EE28B57664F00013E . 327168 . . [6.1.7600.16385] .. c:\windows\system32\mswsock.dll
.
[-] 2013-10-25 . E7099336BF7531B6FCC920DCB5101259 . 2241536 . . [10.00.9200.16521] .. c:\windows\system32\wininet.dll
.
[-] 2009-07-14 . E424B3EF666B184CEE0B6871AAA8C9F6 . 8192 . . [6.1.7600.16385] .. c:\windows\winsxs\amd64_microsoft-windows-gdi-painting_31bf3856ad364e35_6.1.7600.16385_none_d360c9c235bd1868\msimg32.dll
[-] 2009-07-14 . E424B3EF666B184CEE0B6871AAA8C9F6 . 8192 . . [6.1.7600.16385] .. c:\windows\system32\msimg32.dll
.
[-] 2013-07-04 . 700BD5A6AA5381D1D8ADC4045149DBF6 . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.1.7601.22376_none_3bee2a494f8638cf\comctl32.dll
[-] 2013-07-04 . 700BD5A6AA5381D1D8ADC4045149DBF6 . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.22376_none_ee67d2d082b9f619\comctl32.dll
[-] 2013-07-04 . 75F5E1FE8D55CF8E577E0EC5F2290D3F . 530432 . . [5.82] .. c:\windows\SysWOW64\comctl32.dll
[-] 2013-07-04 . 75F5E1FE8D55CF8E577E0EC5F2290D3F . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.1.7601.18201_none_3bab3b80363456bb\comctl32.dll
[-] 2013-07-04 . 75F5E1FE8D55CF8E577E0EC5F2290D3F . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18201_none_ec80f00e8593ece5\comctl32.dll
[-] 2010-11-20 . BDAC1AA64495D0F7E1FF810EBBF1F018 . 530432 . . [5.82] .. c:\windows\ERDNT\cache86\comctl32.dll
[-] 2010-11-20 . BDAC1AA64495D0F7E1FF810EBBF1F018 . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft-windows-shell-comctl32-v5_31bf3856ad364e35_6.1.7601.17514_none_3ba388ec36399c85\comctl32.dll
[-] 2010-11-20 . BDAC1AA64495D0F7E1FF810EBBF1F018 . 530432 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.17514_none_ec83dffa859149af\comctl32.dll
[-] 2010-11-20 . 352B3DC62A0D259A82A052238425C872 . 1680896 . . [5.82] .. c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
.
[-] 2013-10-05 . F2D9242C3BBD1C36467FCAE1AE01733F . 142848 . . [6.1.7601.22473] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22473_none_784ea5b51260b460\cryptsvc.dll
[-] 2013-07-09 . 6DB499DEFCC827317C5371164A7CDB27 . 142848 . . [6.1.7601.22380] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22380_none_7840d305126b8725\cryptsvc.dll
[-] 2013-07-09 . 7CA1BECEA5DE2643ADDAD32670E7A4C9 . 140288 . . [6.1.7600.16385] .. c:\windows\SysWOW64\cryptsvc.dll
[-] 2013-07-09 . 7CA1BECEA5DE2643ADDAD32670E7A4C9 . 140288 . . [6.1.7601.18205] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18205_none_7812b70bf9088686\cryptsvc.dll
[-] 2013-05-13 . 3897DFF247D9ED0006190349DE264E14 . 140288 . . [6.1.7601.18151] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18151_none_77d8a461f934afb8\cryptsvc.dll
[-] 2013-05-11 . AC04D05309BB2C418D0D80B9FB014642 . 142848 . . [6.1.7601.22322] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22322_none_7883b3211239122d\cryptsvc.dll
[-] 2013-05-10 . E122AA1C9A3CC46FF9DDDE46E5EB0C58 . 142848 . . [6.1.7601.22321] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22321_none_7882b2d71239f8d6\cryptsvc.dll
[-] 2013-05-10 . 33ADF6E0853AB39EA1723BE82842C1D3 . 140288 . . [6.1.7601.18150] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.18150_none_77d7a417f9359661\cryptsvc.dll
[-] 2012-06-02 . 063DD65889D21035311463337BD268E7 . 142336 . . [6.1.7601.22010] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.22010_none_788c7cc71232cc19\cryptsvc.dll
[-] 2012-06-02 . 96C0E38905CFD788313BE8E11DAE3F2F . 140288 . . [6.1.7601.17856] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17856_none_77ddc9e5f93000db\cryptsvc.dll
[-] 2010-11-20 . A585BEBF7D054BD9618EDA0922D5484A . 136192 . . [6.1.7601.17514] .. c:\windows\ERDNT\cache86\cryptsvc.dll
[-] 2010-11-20 . A585BEBF7D054BD9618EDA0922D5484A . 136192 . . [6.1.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.1.7601.17514_none_7807034ff91166f4\cryptsvc.dll
.
[-] 2013-08-29 . EE751CBD5D0C332FDF3DF7187B612416 . 1114112 . . [6.1.7601.22436] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22436_none_fcae77f5ba77fe97\kernel32.dll
[-] 2013-08-02 . 61579F821AB5FF7FA2966D64D1070BA8 . 1114112 . . [6.1.7601.22411] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22411_none_fcbf165bba6c4802\kernel32.dll
[-] 2013-08-02 . 365A5034093AD9E04F433046C4CDF6AB . 1114112 . . [6.1.7601.18229] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18229_none_fc32aa0ea14f91ba\kernel32.dll
[-] 2013-01-04 . 7E55988F5CB3BA67E2732370E8D71BBB . 1114112 . . [6.1.7601.22209] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22209_none_fcd1e4cbba5cfc7b\kernel32.dll
[-] 2012-11-30 . 9CC2571E3646B9A24296AD7ADCC71682 . 1114112 . . [6.1.7601.22177] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22177_none_fc8432ddba97903d\kernel32.dll
[-] 2012-11-30 . AC0B6F41882FC6ED186962D770EBF1D2 . 1114112 . . [6.1.7601.18015] .. c:\windows\SysWOW64\kernel32.dll
[-] 2012-11-30 . AC0B6F41882FC6ED186962D770EBF1D2 . 1114112 . . [6.1.7601.18015] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.18015_none_fc397506a14b161f\kernel32.dll
[-] 2012-10-04 . D4F3176082566CEFA633B4945802D4C4 . 1114112 . . [6.1.7601.17965] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17965_none_fc038d48a1736e92\kernel32.dll
[-] 2012-10-04 . 5FA395364EE727E4BEE6B1406C207F98 . 1114112 . . [6.1.7601.22125] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.22125_none_fcb841e5ba70d1da\kernel32.dll
[-] 2011-07-16 . D3CB12854171DF61D117D7C2BF22C675 . 1114112 . . [6.1.7601.21772] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.21772_none_fc7f5397ba9be6d3\kernel32.dll
[-] 2011-07-16 . 99C3F8E9CC59D95666EB8D8A8B4C2BEB . 1114112 . . [6.1.7601.17651] .. c:\windows\ERDNT\cache86\kernel32.dll
[-] 2011-07-16 . 99C3F8E9CC59D95666EB8D8A8B4C2BEB . 1114112 . . [6.1.7601.17651] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17651_none_fc0a565aa16ef5d0\kernel32.dll
[-] 2011-05-14 . CC5CBC069944E7EA70D8674478A70A37 . 837632 . . [6.1.7601.21728] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.21728_none_fcbb64efba6df328\kernel32.dll
[-] 2011-05-14 . 166116134C58DC36400DE59ACD64FB39 . 837632 . . [6.1.7601.17617] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17617_none_fc3b97c6a1491e16\kernel32.dll
[-] 2010-11-20 . E80758CF485DB142FCA1EE03A34EAD05 . 837632 . . [6.1.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-kernel32_31bf3856ad364e35_6.1.7601.17514_none_fc389502a14bd4ea\kernel32.dll
.
[-] 2013-06-06 . 84CA3579EEB69D8E1EE67E4F721BF71C . 25600 . . [6.1.7601.22350] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22350_none_12a807b2bec875e6\lpk.dll
[-] 2013-06-06 . CC23295DA8F7B5C53F93804D2F5D30EB . 25600 . . [6.1.7601.18177] .. c:\windows\SysWOW64\lpk.dll
[-] 2013-06-06 . CC23295DA8F7B5C53F93804D2F5D30EB . 25600 . . [6.1.7601.18177] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18177_none_120fcb2fa5b4c238\lpk.dll
[-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\ERDNT\cache86\lpk.dll
[-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17514_none_124dc839a586a988\lpk.dll
[-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17537_none_123b293fa5942d6f\lpk.dll
[-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.17563_none_1216b853a5b01be6\lpk.dll
[-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.18032_none_12360787a598d69a\lpk.dll
[-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.21636_none_12c3c5c0beb2b3e2\lpk.dll
[-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.21664_none_12a15568beccd507\lpk.dll
[-] 2009-07-14 . 384721EF4024890092625E20CADFAF85 . 25600 . . [6.1.7600.16385] .. c:\windows\winsxs\wow64_microsoft-windows-gdi_31bf3856ad364e35_6.1.7601.22195_none_1281c5a8bee46a0f\lpk.dll
.
[-] 2013-10-25 . B8FAAC62ED026D87B3E743B339C92786 . 14356992 . . [10.00.9200.16521] .. c:\windows\SysWOW64\mshtml.dll
[-] 2013-10-25 . B8FAAC62ED026D87B3E743B339C92786 . 14356992 . . [10.00.9200.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16750_none_9b5ece50c70b4520\mshtml.dll
[-] 2013-10-25 . 0720197691DE3FDBBBB115587DC39E1C . 14381056 . . [10.00.9200.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20861_none_8487414ae0b9f3be\mshtml.dll
[-] 2013-08-10 . A0FAB45701EFAA4EDA60B7614ED431BE . 14362624 . . [10.00.9200.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20794_none_8494cdbce0af70b5\mshtml.dll
[-] 2013-08-10 . 5D2D7E7850CE963C2F401D4DEE7BB32A . 14332928 . . [10.00.9200.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16686_none_9b6c166ac7010efa\mshtml.dll
[-] 2013-06-12 . E6CC3F7EAA761794E13E0F99393EEB97 . 14358528 . . [10.00.9200.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20742_none_848ff9dae0b3bec0\mshtml.dll
[-] 2013-06-11 . AF31E7D2C385F647ADFD5F5736B3BA64 . 14329856 . . [10.00.9200.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16635_none_9b672bc0c70576a6\mshtml.dll
[-] 2013-06-08 . 2C01EA6CBF9E7C6A96535BEA1AB35580 . 14355456 . . [10.00.9200.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20723_none_848de27ee0b5a5b3\mshtml.dll
[-] 2013-06-08 . 05920BD009621D06722A1CD339DA6481 . 14327808 . . [10.00.9200.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16618_none_9b64e6d4c70790db\mshtml.dll
[-] 2013-06-06 . 7A468BC721C1D34E60389D3F2F87BBEA . 14323712 . . [10.00.9200.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16576_none_9b75e60cc6f9d9b2\mshtml.dll
[-] 2013-05-17 . D77D1A53C38DF6CE26749D77BED6A527 . 14355968 . . [10.00.9200.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.20719_none_848c5984e0b72622\mshtml.dll
[-] 2013-05-17 . 69A03AB053CAD761E51BAE1B01F95F55 . 14327808 . . [10.00.9200.16521] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_10.2.9200.16614_none_9b6541f4c7072a57\mshtml.dll
[-] 2013-05-05 . 1152DE9D7FE16EC92A12165D1CBE8406 . 12325888 . . [9.00.8112.20594] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20594_none_9276e9654281af28\mshtml.dll
[-] 2013-05-05 . 26F30066B9FA78C97A0E92803D496211 . 12324864 . . [9.00.8112.16484] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16484_none_91f81c86295bf36d\mshtml.dll
[-] 2013-04-04 . 79B0D843B26BEA808EA89BA2D8A026F2 . 12324864 . . [9.00.8112.16483] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16483_none_91f71c3c295cda16\mshtml.dll
[-] 2013-04-04 . 4EBF337D1F52EA9202072348BA41CA95 . 12325376 . . [9.00.8112.20593] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.20593_none_9275e91b428295d1\mshtml.dll
[-] 2013-02-03 . 07F649CD36F266BBE33B814FA678AA43 . 12320256 . . [9.00.8112.16457] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_9.4.8112.16457_none_921b8d282940eb9f\mshtml.dll
[-] 2011-11-05 . 61C09B5AD2932538659D133C875DBB0F . 5997056 . . [8.00.7601.17720] .. c:\windows\ERDNT\cache86\mshtml.dll
[-] 2011-11-05 . 61C09B5AD2932538659D133C875DBB0F . 5997056 . . [8.00.7601.17720] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.17720_none_96693c4ce43770b8\mshtml.dll
[-] 2011-11-05 . 3E218028099F62CA630E2AFE936F1F0D . 5997568 . . [8.00.7601.21855] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.21855_none_96d76ac5fd68e308\mshtml.dll
[-] 2011-10-01 . E16F0A71B984E06FE0A90A2E2E227B23 . 5991936 . . [8.00.7601.21830] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.21830_none_96e8092bfd5d2c73\mshtml.dll
[-] 2011-10-01 . 009751094A5A9041723D635AF249DC6F . 5990400 . . [8.00.7601.17699] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.17699_none_96268d8ce4681b37\mshtml.dll
[-] 2011-07-22 . CF3C3365DC28AB97636BF11E9BB67927 . 5988864 . . [8.00.7601.21776] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.21776_none_96c2c951fd78371a\mshtml.dll
[-] 2011-07-22 . DD64818174A695E8EC766E50297AB854 . 5988864 . . [8.00.7601.17655] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.17655_none_964dcc14e44b4617\mshtml.dll
[-] 2011-05-28 . 0C32D9FF0FC163239C4B052FE6EFA8E7 . 5984768 . . [8.00.7601.21735] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.21735_none_96ed08b7fd58adff\mshtml.dll
[-] 2011-05-28 . F5B7C30075207A165FF2EED1FF89AB8D . 5984768 . . [8.00.7601.17622] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.17622_none_966b3afae435a63f\mshtml.dll
[-] 2011-03-07 . 3D2F69861D7B24A3C5B0473583FE3D9D . 5981696 . . [8.00.7601.17573] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.17573_none_963629c2e45d4e24\mshtml.dll
[-] 2011-03-07 . 5E87C06B924495F6FA381391FDE0C9D4 . 5981696 . . [8.00.7601.21676] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.21676_none_96c2c76bfd7839f3\mshtml.dll
[-] 2011-01-07 . 1C6045D48179D15A843486D12BEC0EAF . 5980672 . . [8.00.7601.17537] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.17537_none_96656a9ae43943bc\mshtml.dll
[-] 2011-01-07 . 1011333570E1CECAE8FAC34C8D9461BC . 5980672 . . [8.00.7601.21636] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.21636_none_96ee071bfd57ca2f\mshtml.dll
[-] 2010-11-20 . C50799F0D47DFB9774F721521B6C41D5 . 5977600 . . [8.00.7601.17514] .. c:\windows\winsxs\wow64_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.7601.17514_none_96780994e42bbfd5\mshtml.dll
.
[-] 2011-12-16 . 2F740C4B458331357E825E94AFB0953A . 690688 . . [7.0.7601.21878] .. c:\windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.1.7601.21878_none_d3a962431672ddd2\msvcrt.dll
[-] 2011-12-16 . 9DC80A8AAAAAC397BDAB3C67165A824E . 690688 . . [7.0.7601.17744] .. c:\windows\SysWOW64\msvcrt.dll
[-] 2011-12-16 . 9DC80A8AAAAAC397BDAB3C67165A824E . 690688 . . [7.0.7601.17744] .. c:\windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.1.7601.17744_none_d33c3413fd4084d9\msvcrt.dll
[-] 2009-07-14 . E46D48A7FE961401F1CBF85531CDF05D . 690688 . . [7.0.7600.16385] .. c:\windows\ERDNT\cache86\msvcrt.dll
[-] 2009-07-14 . E46D48A7FE961401F1CBF85531CDF05D . 690688 . . [7.0.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.1.7600.16385_none_d12b8c440039b31e\msvcrt.dll
.
[-] 2013-09-08 . E94C583CDE2348950155F2AF2876F34D . 231424 . . [6.1.7600.16385] .. c:\windows\SysWOW64\mswsock.dll
[-] 2013-09-08 . E94C583CDE2348950155F2AF2876F34D . 231424 . . [6.1.7601.18254] .. c:\windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.18254_none_ba2f64c78bae6989\mswsock.dll
[-] 2013-09-07 . 6547D445C4B69DC0083B619AC642DF04 . 231424 . . [6.1.7601.22444] .. c:\windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.22444_none_bac3d364a4c3ea89\mswsock.dll
[-] 2010-11-20 . 8999B8631C7FD9F7F9EC3CAFD953BA24 . 232448 . . [6.1.7601.17514] .. c:\windows\ERDNT\cache86\mswsock.dll
[-] 2010-11-20 . 8999B8631C7FD9F7F9EC3CAFD953BA24 . 232448 . . [6.1.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.1.7601.17514_none_ba5ac0f18b8dd799\mswsock.dll
.
[-] 2013-10-25 . 3AA6FD9B534F17CBD5D311DDC077973C . 1767936 . . [10.00.9200.16521] .. c:\windows\SysWOW64\wininet.dll
[-] 2013-10-25 . 3AA6FD9B534F17CBD5D311DDC077973C . 1767936 . . [10.00.9200.16750] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16750_none_2391695c59f6a8b9\wininet.dll
[-] 2013-10-25 . 46E150A0356D73F99A9F9EC2A9D279F4 . 1777664 . . [10.00.9200.20861] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20861_none_0cb9dc5673a55757\wininet.dll
[-] 2013-08-10 . 26BD13BB9196C2D8F8155C3C6169BC22 . 1777664 . . [10.00.9200.20794] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20794_none_0cc768c8739ad44e\wininet.dll
[-] 2013-08-10 . 535F6263035F2530A62D5D64EF6E73D3 . 1767936 . . [10.00.9200.16686] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16686_none_239eb17659ec7293\wininet.dll
[-] 2013-06-12 . 24AE444B165D11835EF3D38CF3CC7FA4 . 1777664 . . [10.00.9200.20742] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20742_none_0cc294e6739f2259\wininet.dll
[-] 2013-06-11 . 9BF7C7654EFD098EE3A27B49492A382A . 1767936 . . [10.00.9200.16635] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16635_none_2399c6cc59f0da3f\wininet.dll
[-] 2013-06-06 . 5ABB3F36AF17007F33FA275E96A2C95E . 1767424 . . [10.00.9200.16576] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16576_none_23a8811859e53d4b\wininet.dll
[-] 2013-05-17 . 425A20F1C6855222944BFD4FA9BE61A5 . 1777664 . . [10.00.9200.20716] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.20719_none_0cbef49073a289bb\wininet.dll
[-] 2013-05-17 . 2473CA6595A2659D7039A4A89FECA269 . 1767936 . . [10.00.9200.16611] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_10.2.9200.16614_none_2397dd0059f28df0\wininet.dll
[-] 2013-04-04 . 2C96B3921B4CDE10DBAED5AAD760DB67 . 1129472 . . [9.00.8112.16483] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16483_none_1a29b747bc483daf\wininet.dll
[-] 2013-04-04 . 28B2DD8DBAEE306290A74ED03DB3768F . 1129984 . . [9.00.8112.20593] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.20593_none_1aa88426d56df96a\wininet.dll
[-] 2013-02-03 . 7FA3A810F383588D46220967DE8B64FF . 1129472 . . [9.00.8112.16457] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_9.4.8112.16457_none_1a4e2833bc2c4f38\wininet.dll
[-] 2011-11-05 . 19714FA7D7204D9BEE1EE12791DA9010 . 981504 . . [8.00.7601.17720] .. c:\windows\ERDNT\cache86\wininet.dll
[-] 2011-11-05 . 19714FA7D7204D9BEE1EE12791DA9010 . 981504 . . [8.00.7601.17720] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.17720_none_1e9bd7587722d451\wininet.dll
[-] 2011-11-05 . 1903228FE0C7D402B26A217F8D7713FD . 982016 . . [8.00.7601.21855] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.21855_none_1f0a05d1905446a1\wininet.dll
[-] 2011-08-20 . 7570FA3FC82E08FB637E32D2D95DB41D . 981504 . . [8.00.7601.21795] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.21795_none_1edec43b9074b93e\wininet.dll
[-] 2011-08-20 . DBF24E87CB605A4F6E7424DD86F7A62C . 981504 . . [8.00.7601.17671] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.17671_none_1e66c620774a7c36\wininet.dll
[-] 2011-06-21 . D1E7C4FA045B34C32D12BFBB415EBE1B . 981504 . . [8.00.7601.21754] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.21754_none_1f0903a190553023\wininet.dll
[-] 2011-06-21 . 748FD4CAB1AFFD90A9556EB7D5AA1FEB . 981504 . . [8.00.7601.17638] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.17638_none_1e9907d67723bdd3\wininet.dll
[-] 2011-04-22 . 7A11DB452989040AD8570A3DCE2E9DE2 . 981504 . . [8.00.7601.21710] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.21710_none_1f30422990385b03\wininet.dll
[-] 2011-04-22 . 2CA020EACDC6DDB2BEA89FEA02C90945 . 981504 . . [8.00.7601.17601] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.17601_none_1eb275947711b89f\wininet.dll
[-] 2011-03-07 . A5B19B240901CAB0C8E7767D2873613E . 981504 . . [8.00.7601.17573] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.17573_none_1e68c4ce7748b1bd\wininet.dll
[-] 2011-03-07 . EDEB2904636B657782F824D8FF97D0B8 . 981504 . . [8.00.7601.21676] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.21676_none_1ef5627790639d8c\wininet.dll
[-] 2010-11-20 . 44214C94911C7CFB1D52CB64D5E8368D . 980992 . . [8.00.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.7601.17514_none_1eaaa4a07717236e\wininet.dll
.
[-] 2012-11-22 . CA68408922B02E8D955A2967C7CBF8CE . 626688 . . [1.0626.7601.22171] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.22171_none_af477f18d00f9c82\usp10.dll
[-] 2012-11-22 . B7230010D97787AF3D25E4C82F2B06B9 . 626688 . . [1.0626.7601.18009] .. c:\windows\SysWOW64\usp10.dll
[-] 2012-11-22 . B7230010D97787AF3D25E4C82F2B06B9 . 626688 . . [1.0626.7601.18009] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.18009_none_af119411b6b203d9\usp10.dll
[-] 2010-11-20 . 804AAAFEBB3AD5F49334DD906BCB1DE5 . 626176 . . [1.0626.7601.17514] .. c:\windows\ERDNT\cache86\usp10.dll
[-] 2010-11-20 . 804AAAFEBB3AD5F49334DD906BCB1DE5 . 626176 . . [1.0626.7601.17514] .. c:\windows\winsxs\x86_microsoft-windows-usp_31bf3856ad364e35_6.1.7601.17514_none_af01e2f9b6be7939\usp10.dll
.
[-] 2009-07-14 . 18AB2E5A40064ED5F7791AC5946A90F3 . 4608 . . [6.1.7600.16385] .. c:\windows\SysWOW64\msimg32.dll
[-] 2009-07-14 . 18AB2E5A40064ED5F7791AC5946A90F3 . 4608 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-gdi-painting_31bf3856ad364e35_6.1.7600.16385_none_77422e3e7d5fa732\msimg32.dll
.
[-] 2009-07-14 . EE5C8E27C37B79CB54A2FCEEED2DC262 . 9216 . . [6.1.7600.16385] .. c:\windows\SysWOW64\WSHTCPIP.DLL
[-] 2009-07-14 . EE5C8E27C37B79CB54A2FCEEED2DC262 . 9216 . . [6.1.7600.16385] .. c:\windows\winsxs\x86_microsoft-windows-winsock-helper-tcpip_31bf3856ad364e35_6.1.7600.16385_none_cb895be592db1acb\WSHTCPIP.DLL
.
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2015-03-07 01:56 1030352 ----a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2015-03-07 01:56 1030352 ----a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2015-03-07 01:56 1030352 ----a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2015-03-07 01:56 1030352 ----a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2015-03-07 01:56 1030352 ----a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2015-03-07 01:56 1030352 ----a-r- c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MyTomTomSA.exe"="c:\program files (x86)\MyTomTom 3\MyTomTomSA.exe" [2013-05-23 455608]
"Fitbit Connect"="c:\program files (x86)\Fitbit Connect\Fitbit Connect.exe" [2015-09-04 4377256]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"Gateway Photo Frame"="c:\program files (x86)\Gateway Photo Frame\ButtonMonitor.exe" [2009-07-20 124416]
"ConnectionCenter"="c:\program files (x86)\Citrix\ICA Client\concentr.exe" [2009-09-13 103768]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"IJNetworkScannerSelectorEX"="c:\program files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe" [2013-02-19 453736]
"Carbonite Backup"="c:\program files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe" [2015-03-07 1064144]
"Fitbit Connect"="c:\program files (x86)\Fitbit Connect\Fitbit Connect.exe" [2015-09-04 4377256]
.
c:\users\home\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
MedApps Device Monitor.lnk - c:\users\home\AppData\Roaming\Microsoft\Installer\{057FC282-826A-41E4-B6D9-9E6BCFD8B8E3}\_11C58EEF5D7511CC7409FC.exe [2012-8-14 10134]
Microsoft HealthVault Connection Center.lnk - c:\program files (x86)\Microsoft HealthVault\Connection Center\ConnectionCenter.exe /hide [2012-7-1 1153648]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
.
R1 BHDrvx64;BHDrvx64;c:\program files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150601.001\BHDrvx64.sys;c:\program files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150601.001\BHDrvx64.sys [x]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360x64\1507000.00B\Ironx64.SYS;c:\windows\SYSNATIVE\drivers\N360x64\1507000.00B\Ironx64.SYS [x]
R1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\N360x64\1507000.00B\SYMNETS.SYS;c:\windows\SYSNATIVE\Drivers\N360x64\1507000.00B\SYMNETS.SYS [x]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamservice.exe [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\MBAMSwissArmy.sys;c:\windows\SYSNATIVE\drivers\MBAMSwissArmy.sys [x]
R3 MBAMWebAccessControl;MBAMWebAccessControl;c:\windows\system32\drivers\mwac.sys;c:\windows\SYSNATIVE\drivers\mwac.sys [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [x]
R4 RsFx0151;RsFx0151 Driver;c:\windows\system32\DRIVERS\RsFx0151.sys;c:\windows\SYSNATIVE\DRIVERS\RsFx0151.sys [x]
S0 MFX;MFX; [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360x64\1507000.00B\SYMDS64.SYS;c:\windows\SYSNATIVE\drivers\N360x64\1507000.00B\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360x64\1507000.00B\SYMEFA64.SYS;c:\windows\SYSNATIVE\drivers\N360x64\1507000.00B\SYMEFA64.SYS [x]
S1 ccSet_N360;N360 Settings Manager;c:\windows\system32\drivers\N360x64\1507000.00B\ccSetx64.sys;c:\windows\SYSNATIVE\drivers\N360x64\1507000.00B\ccSetx64.sys [x]
S1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\DRIVERS\ctxusbm.sys;c:\windows\SYSNATIVE\DRIVERS\ctxusbm.sys [x]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\ElRawDsk.sys;c:\windows\SYSNATIVE\drivers\ElRawDsk.sys [x]
S1 IDSVia64;IDSVia64;c:\program files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150608.001\IDSvia64.sys;c:\program files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150608.001\IDSvia64.sys [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 Fitbit Connect;Fitbit Connect Service;c:\program files (x86)\Fitbit Connect\FitbitConnectService.exe;c:\program files (x86)\Fitbit Connect\FitbitConnectService.exe [x]
S2 GREGService;GREGService;c:\program files (x86)\Gateway\Registration\GREGsvc.exe;c:\program files (x86)\Gateway\Registration\GREGsvc.exe [x]
S2 lxdp_device;lxdp_device;c:\windows\system32\lxdpcoms.exe;c:\windows\SYSNATIVE\lxdpcoms.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes Anti-Malware\mbamscheduler.exe [x]
S2 N360;Norton 360;c:\program files (x86)\Norton 360\Engine\21.7.0.11\N360.exe;c:\program files (x86)\Norton 360\Engine\21.7.0.11\N360.exe [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 Updater Service;Updater Service;c:\program files\Gateway\Gateway Updater\UpdaterService.exe;c:\program files\Gateway\Gateway Updater\UpdaterService.exe [x]
S3 e1yexpress;Intel® Gigabit Network Connections Driver;c:\windows\system32\DRIVERS\e1y60x64.sys;c:\windows\SYSNATIVE\DRIVERS\e1y60x64.sys [x]
S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys;c:\windows\SYSNATIVE\DRIVERS\vrtaucbl.sys [x]
S3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\system32\drivers\IntcHdmi.sys;c:\windows\SYSNATIVE\drivers\IntcHdmi.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
.
.
--- Other Services/Drivers In Memory ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{A6EADE66-0000-0000-484E-7E8A45000000}]
2015-11-18 16:22 286904 ----a-w- c:\program files (x86)\Adobe\Acrobat Reader DC\Esl\AiodLite.dll
.
Contents of the 'Scheduled Tasks' folder
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2015-03-07 01:46 1303760 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2015-03-07 01:46 1303760 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2015-03-07 01:46 1303760 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2015-03-07 01:46 1303760 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2015-03-07 01:46 1303760 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2015-03-07 01:46 1303760 ----a-r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IAAnotif"="c:\program files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2009-06-05 186904]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-07-20 7981088]
"lxdpmon.exe"="c:\program files (x86)\Lexmark Z2300 Series\lxdpmon.exe" [2010-02-04 672424]
"EzPrint"="c:\program files (x86)\Lexmark Z2300 Series\ezprint.exe" [2010-02-04 107176]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-12 162328]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-08-26 386584]
"Persistence"="c:\windows\system32\igfxpers.exe" [2010-08-26 415256]
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.symantec.com/redirects/security_response/fix_homepage/index.jsp?lg=en&pid=N360&pvid=21.6.0.32
uLocal Page = c:\windows\system32\blank.htm
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_6CE5017F567343CA.dll/cmsidewiki.html
Trusted Zone: oma11pwww05
Trusted Zone: prod.westworlds.com
Trusted Zone: rhapsody.com\rhap-app-4-0
Trusted Zone: rhapsody.com\rhapreg
Trusted Zone: west.com
Trusted Zone: westathome.com
Trusted Zone: westathome.net
Trusted Zone: workathomeagent.net
TCP: DhcpNameServer = 192.168.1.1
DPF: {895D1291-D5BD-4982-BA84-AD11D29C1D6A} - hxxp://community.weightwatchers.com/Scripts/ImageUploader6.cab
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Best Buy pc app.lnk - c:\programdata\Best Buy pc app\ClickOnceSetup.exe "c:\programdata\Best Buy pc app\Best Buy pc app.application"
SafeBoot-MBAMSwissArmy
AddRemove-BucksBee Loyalty Plugin - OpenInstall - c:\program files (x86)\BucksBee Loyalty Plugin - OpenInstall\Uninst.exe
AddRemove-48e4cff94f039634 - c:\programdata\Best Buy pc app\ClickOnceUninstaller.exe
.
.
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\N360]
"ImagePath"="\"c:\program files (x86)\Norton 360\Engine\21.7.0.11\N360.exe\" /s \"N360\" /m \"c:\program files (x86)\Norton 360\Engine\21.7.0.11\diMaster.dll\" /prefetch:1"
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MySQL]
"ImagePath"="\"c:\program files\MySQL\MySQL Server 5.5\bin\mysqld\" --defaults-file=\"c:\program files\MySQL\MySQL Server 5.5\my.ini\" MySQL"
"ImagePath"="\SystemRoot\System32\Drivers\N360x64\1507000.00B\SYMNETS.SYS"
"TrustedImagePaths"="c:\program files (x86)\Norton 360\Engine\21.7.0.11;c:\program files (x86)\Norton 360\Engine64\21.7.0.11"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\S-1-5-21-839081694-1943692923-2272886626-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.Email.1"
.
[HKEY_USERS\S-1-5-21-839081694-1943692923-2272886626-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]
@Denied: (2) (LocalSystem)
"Progid"="WindowsLiveMail.VCard.1"
.
[HKEY_USERS\S-1-5-21-839081694-1943692923-2272886626-1001\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\{1B248715-1C97-BDF7-5631-6AE5FC0D2D15}*]
"japogjifacnniffjdcob"=hex:6a,61,70,64,66,6f,6e,6b,67,66,64,65,6c,69,6c,64,6e,
   68,6c,6e,00,00
"iafpejfnlkgdajnllh"=hex:6a,61,70,64,66,6f,6e,6b,67,66,64,65,6c,69,6c,64,6e,68,
   6c,6e,00,fe
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_12_0_0_77_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.12"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_12_0_0_77.ocx, 1"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\software\Wow6432Node\Nico Mak Computing\WinZip]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
   00,5c,00,4d,00,41,00,43,00,48,00,49,00,4e,00,45,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files (x86)\Citrix\ICA Client\wfcrun32.exe
c:\program files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\program files (x86)\Microsoft HealthVault\Connection Center\ConnectionCenter.exe
c:\program files (x86)\Common Files\Java\Java Update\jucheck.exe
.
**************************************************************************
.
Completion time: 2015-12-16  19:59:40 - machine was rebooted
ComboFix-quarantined-files.txt  2015-12-17 01:59
.
Pre-Run: 777,751,195,648 bytes free
Post-Run: 777,283,715,072 bytes free
.
- - End Of File - - 6393885339990ECD79FEAA2F6DEA9D91
 


  • 0

#13
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

Hello chanseygirl,

 

Use the System File Checker tool (SFC.exe) to check your system and replace files where necessary.

To do this, follow these steps:

  • To do this, click Start, click All Programs, click Accessories, right-click Command Prompt, and then click Run as administrator.
  • If you are prompted for an administrator password or for a confirmation, type the password, or click Allow.
  • Type the following command, and then press ENTER:
    sfc /scannow         Please note that there is a single space between sfc and /scannow.

The sfc /scannow command scans all protected system files and replaces incorrect versions with correct Microsoft versions.

You should see the following on-screen messages:

Beginning the system scan. This process will take some time.

Beginning verification phase of system scan.

Verification % complete.

Once the scan has completed you will receive an onscreen message resembling one of the following:

…found no integrity violations

…found corruption but repaired it

…found corruption that it could not repair


Please reply with the completion message that you received.


  • 0

#14
chanseygirl

chanseygirl

    Member

  • Topic Starter
  • Member
  • PipPip
  • 13 posts

I am sorry, but I didn't see or  I missed the corruption message. The computer did reboot itself, but no message came up after the computer was back up. Should I try running the File Checker again?


  • 0

#15
emeraldnzl

emeraldnzl

    GeekU Instructor

  • GeekU Moderator
  • 20,051 posts

No, do this instead.

 

Download SFCFix.exe by niemiro and click on it to run.
A black panel will open.
Follow the prompts pressing the requisite keys to continue
Wait completion, the tool will take a little time (runtime is approximately 15 minutes)
When finished, follow the prompt to create a summary of results you will see notification of the result. If there are no corruptions please tell me. If there are some problems please copy and paste back here the complete logfile which will open on completion.
Simply copy (Ctrl-A, Ctrl-C) and paste (Ctrl-V) the entire logfile.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP