Hello! I'm helping my neighbor who is experiencing computer issues. Several times he thought he was using google chrome, only to find out it was a different search program. Sometimes double pop up screens would open while he was using the computer.
The tower no longer shuts down correctly, the power buttons flash non stop but the monitor slows down. He also states the machine doesn't work as quickly as it did.
Pinned icons also disappear.
Any help would be appreciated - Joanne
Here is the FRST log:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by Tony (administrator) on TONY-PC (29-06-2018 17:07:26)
Running from C:\Users\Tony\Desktop
Loaded Profiles: Tony (Available Profiles: Tony)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(© 2015 Microsoft Corporation) C:\Users\Tony\AppData\Local\Microsoft\BingSvc\BingSvc.exe
(Acer Incorporated) C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe
(Acer Incorporated) C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe
(Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe
() C:\Windows\SysWOW64\spdsvc.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Yahoo! Inc.) C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11580520 2010-11-10] (Realtek Semiconductor)
HKLM\...\Run: [ALU] => C:\Program Files\eMachines\eMachines Updater\ALU.exe [2379056 2017-04-21] (Acer Incorporated)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1353680 2016-11-14] (Microsoft Corporation)
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [10290608 2018-02-07] (Piriform Ltd)
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\Run: [EEDSpeedLauncher] => rundll32.exe C:\Windows\system32\eed_ec.dll,SpeedLauncher
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\Run: [BingSvc] => C:\Users\Tony\AppData\Local\Microsoft\BingSvc\BingSvc.exe [144008 2017-12-26] (© 2015 Microsoft Corporation)
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\Policies\Explorer: [NoInternetOpenWith] 1
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\scrnsave.scr [11264 2009-07-13] (Microsoft Corporation)
CHR HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
Tcpip\..\Interfaces\{1414AF8B-1600-4411-BA4E-9DC0DEB26D74}: [DhcpNameServer] 192.168.254.254
Tcpip\..\Interfaces\{ED8D445D-0FF9-4114-AD17-8AAC465245EC}: [DhcpNameServer] 75.75.75.75 75.75.76.76
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=hp-avast&type=agc511
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxps://www.quafind.com/
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AEMTDF&pc=MAEM&src=IE-SearchBox
SearchScopes: HKLM -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL =
SearchScopes: HKLM-x32 -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=AEMTDF&pc=MAEM&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKLM-x32 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> DefaultScope {DD73391C-88AA-4758-A44B-0332D32FB5B4} URL = hxxp://search.hquickmapsanddirections.com/s?uc=20180619&i_id=maps_spt__1.30&ap=appfocus1&uid=5832f5a9-61b8-4eae-81dd-fc6f1239daaa&source=d-ccc6-lp0-bb8&query={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?FORM=U453DF&PC=U453&q={searchTerms}&src=IE-SearchBox
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {34D82E9A-0675-4E5B-AC8A-0B6FE895141F} URL = hxxps://delicious.com/search?p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {4B63626E-741B-4776-972F-A77742705792} URL = hxxps://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=chr-yie11
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {632F07F3-19A1-4d16-A23F-E6CE9486BAB5} URL = hxxp://www.bing.com/search?q={searchTerms}&FORM=AVASDF&PC=AV01
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {7A8B4688-548A-4996-88E4-B6111E121D2A} URL = hxxps://search.yahoo.com/search?ei=utf-8&fr=befds&p={searchTerms}&type=ieds-4.7-1706
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {8899C699-593C-4A8D-AE8A-DF99C9282907} URL = hxxps://www.flickr.com/search/?q={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxps://search.yahoo.com/yhs/search?type=agc511&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {A1032D92-6A87-46FF-A15C-AC0E56FE4B14} URL = hxxp://isearch.shopathome.com?user_id={6F914F5F-E315-4177-9E84-FC4B089A2094}&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {DC91FAFB-6CEA-49E5-BB74-9CEE75D09B77} URL = hxxps://search.yahoo.com/yhs/search?type=iedef&hspart=avast&hsimp=yhs-001&p={searchTerms}
SearchScopes: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> {DD73391C-88AA-4758-A44B-0332D32FB5B4} URL = hxxp://search.hquickmapsanddirections.com/s?uc=20180619&i_id=maps_spt__1.30&ap=appfocus1&uid=5832f5a9-61b8-4eae-81dd-fc6f1239daaa&source=d-ccc6-lp0-bb8&query={searchTerms}
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File
Toolbar: HKU\S-1-5-21-1688004940-62920522-2967697596-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} hxxps://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab
FireFox:
========
FF DefaultProfile: 5zgxxirw.default
FF ProfilePath: C:\Users\Tony\AppData\Roaming\TomTom\HOME\Profiles\tk8eoaie.default [2018-05-27]
FF Extension: (No Name) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\
[email protected] [not found]
FF ProfilePath: C:\Users\Tony\AppData\Roaming\Mozilla\Firefox\Profiles\5zgxxirw.default [2018-06-29]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_30_0_0_113.dll [2018-06-07] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_30_0_0_113.dll [2018-06-07] ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1229199.dll [2017-03-31] (Adobe Systems, Inc.)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2010-11-10] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-19] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2014-11-14] ()
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-05-10] (Adobe Systems Inc.)
Chrome:
=======
CHR HomePage: Default -> msn.com
CHR NewTab: Default -> Not-active:"chrome-extension://docbdkefdologaagieallljeedjpdlfk/newtab/slim_newtabpage.html", Not-active:"chrome-extension://aggobjdbghchcnapfoplmgekgjipjlke/newtabproduct.html"
CHR DefaultSearchURL: Default -> hxxp://www.bing.com/search?FORM=__PARAM__DF&PC=__PARAM__&q={searchTerms}
CHR DefaultSearchKeyword: Default -> bing.com
CHR DefaultSuggestURL: Default -> hxxp://www.bing.com/osjson.aspx?FORM=__PARAM__DF&PC=__PARAM__&query={searchTerms}
CHR Profile: C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default [2018-06-29]
CHR Extension: (Slides) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-05-27]
CHR Extension: (OnlineRouteFinder) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aggobjdbghchcnapfoplmgekgjipjlke [2018-05-27]
CHR Extension: (Docs) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-05-27]
CHR Extension: (Google Drive) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-17]
CHR Extension: (YouTube) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-17]
CHR Extension: (Easy File Converter) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\docbdkefdologaagieallljeedjpdlfk [2018-06-23]
CHR Extension: (Bing) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\fcfenmboojpjinhpgggodefccipikbpd [2018-05-27]
CHR Extension: (Sheets) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-05-27]
CHR Extension: (Google Docs Offline) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-05-27]
CHR Extension: (Scanguard Safe Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkljlnkimgcfmiklhilenokeckdiiepf [2018-05-27]
CHR Extension: (Ask Web Search) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\lgfehfbnofiffladdncogfobimealokp [2018-05-27]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-05-27]
CHR Extension: (Gmail) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-03-17]
CHR Extension: (Chrome Media Router) - C:\Users\Tony\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-09]
CHR HKLM\...\Chrome\Extension: [kkljlnkimgcfmiklhilenokeckdiiepf] - hxxps://clients2.google.com/service/update2/crx
CHR HKU\S-1-5-21-1688004940-62920522-2967697596-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [fcfenmboojpjinhpgggodefccipikbpd] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [kkljlnkimgcfmiklhilenokeckdiiepf] - hxxps://clients2.google.com/service/update2/crx
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 GREGService; C:\Program Files (x86)\eMachines\Registration\GREGsvc.exe [36456 2011-05-29] (Acer Incorporated)
R2 Live Updater Service; C:\Program Files\eMachines\eMachines Updater\UpdaterService.exe [257440 2016-06-08] (Acer Incorporated)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [119864 2016-11-14] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [361816 2016-11-14] (Microsoft Corporation)
R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation)
R2 Samsung Printer Dianostics Service; C:\Windows\SysWOW64\\spdsvc.exe [498488 2016-04-01] ()
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 ElRawDisk; C:\Windows\system32\drivers\rsdrvx64.sys [26024 2009-02-12] (EldoS Corporation)
R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [295000 2016-08-25] (Microsoft Corporation)
R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [135928 2016-08-25] (Microsoft Corporation)
S3 ssmirrdr; C:\Windows\System32\DRIVERS\ssmirrdr.sys [10112 2014-01-09] (support.com, Inc)
S3 SWDUMon; C:\Windows\System32\DRIVERS\SWDUMon.sys [13920 2017-08-31] ()
R3 WNDA3100v3; C:\Windows\System32\DRIVERS\WNDA3100v3.sys [2225808 2014-12-08] (MediaTek Inc.)
S3 cpuz134; \??\C:\Users\Tony\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] <==== ATTENTION
S1 ESProtectionDriver; \??\C:\Windows\system32\drivers\mbae64.sys [X]
S2 VBoxAswDrv; \??\C:\Program Files\AVAST Software\Avast\ng\vbox\VBoxAswDrv.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-29 17:07 - 2018-06-29 17:07 - 000015918 _____ C:\Users\Tony\Desktop\FRST.txt
2018-06-29 17:06 - 2018-06-29 17:07 - 000000000 ____D C:\FRST
2018-06-29 16:57 - 2018-06-29 16:58 - 002412544 _____ (Farbar) C:\Users\Tony\Desktop\FRST64.exe
2018-06-25 11:21 - 2018-06-25 11:22 - 029720784 _____ (Microsoft Corporation) C:\Users\Tony\Downloads\IE11-Windows6.1-x86-en-us.exe
2018-06-23 08:41 - 2018-06-23 08:42 - 055915216 _____ (Microsoft Corporation) C:\Users\Tony\Downloads\IE11-Windows6.1-x64-en-us.exe
2018-06-20 11:07 - 2018-06-20 11:07 - 000858702 _____ C:\Users\Tony\Downloads\finance - Google Search.html
2018-06-19 18:39 - 2018-06-19 18:39 - 000000000 ____D C:\Users\Tony\AppData\Roaming\{28e56cfb-e30e-4f66-85d8-339885b726b8}
2018-06-13 16:28 - 2018-05-29 16:36 - 000396960 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-06-13 16:28 - 2018-05-29 15:40 - 000348824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-06-13 16:28 - 2018-05-28 22:43 - 000631640 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-06-13 16:28 - 2018-05-28 22:41 - 005577408 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-06-13 16:28 - 2018-05-28 22:41 - 000708288 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-06-13 16:28 - 2018-05-28 22:41 - 000262336 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-06-13 16:28 - 2018-05-28 22:41 - 000154816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-06-13 16:28 - 2018-05-28 22:41 - 000095424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-06-13 16:28 - 2018-05-28 22:35 - 001665336 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 004050624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-06-13 16:28 - 2018-05-28 22:32 - 003962048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-06-13 16:28 - 2018-05-28 22:32 - 001461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 001211904 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000094208 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000007168 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:32 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:25 - 001314064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000070144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:22 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 22:03 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-06-13 16:28 - 2018-05-28 22:03 - 000064512 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-06-13 16:28 - 2018-05-28 22:03 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-06-13 16:28 - 2018-05-28 22:03 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-06-13 16:28 - 2018-05-28 22:03 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-06-13 16:28 - 2018-05-28 21:59 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-06-13 16:28 - 2018-05-28 21:59 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-06-13 16:28 - 2018-05-28 21:59 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\videoprt.sys
2018-06-13 16:28 - 2018-05-28 21:59 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-06-13 16:28 - 2018-05-28 21:59 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-06-13 16:28 - 2018-05-28 21:59 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-06-13 16:28 - 2018-05-28 21:59 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-06-13 16:28 - 2018-05-28 21:58 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-06-13 16:28 - 2018-05-28 21:58 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 21:58 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 21:58 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 21:58 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-06-13 16:28 - 2018-05-28 21:56 - 000160256 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-06-13 16:28 - 2018-05-28 21:55 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-06-13 16:28 - 2018-05-28 21:55 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-06-13 16:28 - 2018-05-28 21:54 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-06-13 16:28 - 2018-05-28 21:54 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-06-13 16:28 - 2018-05-28 20:04 - 000634272 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2018-06-13 16:28 - 2018-05-25 01:10 - 025742848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-06-13 16:28 - 2018-05-25 00:59 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-06-13 16:28 - 2018-05-25 00:59 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-06-13 16:28 - 2018-05-25 00:46 - 002902016 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-06-13 16:28 - 2018-05-25 00:45 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-06-13 16:28 - 2018-05-25 00:44 - 000578048 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-06-13 16:28 - 2018-05-25 00:44 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-06-13 16:28 - 2018-05-25 00:44 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-06-13 16:28 - 2018-05-25 00:43 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-06-13 16:28 - 2018-05-25 00:38 - 005779968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-06-13 16:28 - 2018-05-25 00:37 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-06-13 16:28 - 2018-05-25 00:36 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-06-13 16:28 - 2018-05-25 00:34 - 020286976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-06-13 16:28 - 2018-05-25 00:33 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-06-13 16:28 - 2018-05-25 00:32 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-06-13 16:28 - 2018-05-25 00:32 - 000794624 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-06-13 16:28 - 2018-05-25 00:32 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-06-13 16:28 - 2018-05-25 00:32 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-06-13 16:28 - 2018-05-25 00:28 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-06-13 16:28 - 2018-05-25 00:24 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-06-13 16:28 - 2018-05-25 00:21 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-06-13 16:28 - 2018-05-25 00:16 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-06-13 16:28 - 2018-05-25 00:16 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-06-13 16:28 - 2018-05-25 00:15 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-06-13 16:28 - 2018-05-25 00:15 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-06-13 16:28 - 2018-05-25 00:14 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-06-13 16:28 - 2018-05-25 00:14 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-06-13 16:28 - 2018-05-25 00:14 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-06-13 16:28 - 2018-05-25 00:13 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-06-13 16:28 - 2018-05-25 00:12 - 002295296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-06-13 16:28 - 2018-05-25 00:10 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-06-13 16:28 - 2018-05-25 00:10 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-06-13 16:28 - 2018-05-25 00:09 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-06-13 16:28 - 2018-05-25 00:08 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-06-13 16:28 - 2018-05-25 00:08 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-06-13 16:28 - 2018-05-25 00:07 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-06-13 16:28 - 2018-05-25 00:06 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-06-13 16:28 - 2018-05-25 00:06 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-06-13 16:28 - 2018-05-25 00:05 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-06-13 16:28 - 2018-05-25 00:05 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-06-13 16:28 - 2018-05-24 23:57 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-06-13 16:28 - 2018-05-24 23:57 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-06-13 16:28 - 2018-05-24 23:55 - 000809472 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-06-13 16:28 - 2018-05-24 23:55 - 000728064 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-06-13 16:28 - 2018-05-24 23:53 - 015283200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-06-13 16:28 - 2018-05-24 23:53 - 002135552 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-06-13 16:28 - 2018-05-24 23:53 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-06-13 16:28 - 2018-05-24 23:52 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-06-13 16:28 - 2018-05-24 23:52 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-06-13 16:28 - 2018-05-24 23:51 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-06-13 16:28 - 2018-05-24 23:49 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-06-13 16:28 - 2018-05-24 23:48 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-06-13 16:28 - 2018-05-24 23:47 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-06-13 16:28 - 2018-05-24 23:45 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-06-13 16:28 - 2018-05-24 23:42 - 004496896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-06-13 16:28 - 2018-05-24 23:40 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-06-13 16:28 - 2018-05-24 23:39 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-06-13 16:28 - 2018-05-24 23:39 - 000696320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-06-13 16:28 - 2018-05-24 23:38 - 013679616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-06-13 16:28 - 2018-05-24 23:38 - 002060288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-06-13 16:28 - 2018-05-24 23:37 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-06-13 16:28 - 2018-05-24 23:29 - 001546240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-06-13 16:28 - 2018-05-24 23:19 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-06-13 16:28 - 2018-05-24 23:17 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-06-13 16:28 - 2018-05-24 23:15 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-06-13 16:28 - 2018-05-24 23:14 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-06-13 16:28 - 2018-05-15 00:16 - 001681088 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2018-06-13 16:28 - 2018-05-14 23:44 - 004120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2018-06-13 16:28 - 2018-05-14 23:44 - 001159680 _____ (Microsoft Corporation) C:\Windows\system32\webservices.dll
2018-06-13 16:28 - 2018-05-14 23:44 - 000206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2018-06-13 16:28 - 2018-05-14 23:44 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2018-06-13 16:28 - 2018-05-14 23:24 - 000055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2018-06-13 16:28 - 2018-05-14 23:23 - 000024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2018-06-13 16:28 - 2018-05-14 23:13 - 003207168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2018-06-13 16:28 - 2018-05-14 23:13 - 000782848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webservices.dll
2018-06-13 16:28 - 2018-05-14 23:13 - 000103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2018-06-13 16:28 - 2018-05-14 23:13 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2018-06-13 16:28 - 2018-05-14 23:01 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2018-06-13 16:28 - 2018-05-14 23:01 - 000023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2018-06-13 16:28 - 2018-05-14 21:20 - 000467856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys
2018-06-13 16:28 - 2018-05-14 21:20 - 000459632 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2018-06-13 16:28 - 2018-05-11 22:07 - 000076800 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2018-06-13 16:28 - 2018-05-11 22:07 - 000033152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-06-13 16:28 - 2018-05-11 22:07 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2018-06-13 16:28 - 2018-05-11 17:19 - 000977408 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2018-06-13 16:28 - 2018-05-11 17:19 - 000109568 _____ (Microsoft Corporation) C:\Windows\system32\hlink.dll
2018-06-13 16:28 - 2018-05-11 17:19 - 000084480 _____ (Microsoft Corporation) C:\Windows\system32\INETRES.dll
2018-06-13 16:28 - 2018-05-10 20:40 - 000741888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2018-06-13 16:28 - 2018-05-10 20:40 - 000084480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\INETRES.dll
2018-06-13 16:28 - 2018-05-10 20:39 - 000084992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\hlink.dll
2018-06-13 16:28 - 2018-04-06 12:39 - 000002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2018-06-13 16:28 - 2018-04-06 12:38 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-06-29 16:43 - 2017-05-17 12:59 - 000016345 _____ C:\Users\Tony\Documents\5-21-new way.ods
2018-06-29 16:35 - 2018-04-05 17:14 - 000016358 _____ C:\Users\Tony\Documents\Untitled 1.ods
2018-06-29 14:13 - 2009-07-14 00:45 - 000024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-06-29 14:13 - 2009-07-14 00:45 - 000024608 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-06-29 13:58 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-06-27 13:44 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf
2018-06-27 10:42 - 2009-07-14 01:13 - 000782510 _____ C:\Windows\system32\PerfStringBackup.INI
2018-06-27 06:49 - 2018-03-17 19:37 - 000002233 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-25 11:16 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\NDF
2018-06-25 11:12 - 2013-04-15 19:05 - 000000000 ____D C:\Windows\system32\Macromed
2018-06-23 08:59 - 2013-05-25 15:20 - 000000000 ____D C:\Users\Tony\AppData\Local\Deployment
2018-06-22 20:24 - 2014-04-19 08:18 - 000000000 ___HD C:\Windows\msdownld.tmp
2018-06-21 09:46 - 2009-07-14 01:08 - 000032648 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2018-06-20 11:07 - 2018-03-07 19:18 - 000000000 ____D C:\Users\Tony\Downloads\finance - Google Search_files
2018-06-13 20:58 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\rescache
2018-06-13 16:11 - 2013-08-14 13:04 - 000000000 ____D C:\Windows\system32\MRT
2018-06-13 16:03 - 2017-10-11 09:31 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-06-13 16:03 - 2013-04-05 19:03 - 133315992 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-06-07 15:29 - 2017-09-19 09:23 - 000004470 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2018-06-07 15:29 - 2013-04-15 19:05 - 000842240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-06-07 15:29 - 2013-04-15 19:05 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2018-06-07 15:29 - 2011-08-10 08:01 - 000175104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-06-07 15:29 - 2011-08-10 08:01 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-06-07 14:29 - 2018-03-13 09:29 - 000004458 _____ C:\Windows\System32\Tasks\Adobe Flash Player NPAPI Notifier
2018-06-04 14:42 - 2011-08-10 08:01 - 000000000 ____D C:\ProgramData\Norton
2018-06-04 13:58 - 2018-01-02 10:29 - 000000000 ____D C:\Users\Public\Downloads\Norton
2018-06-04 13:03 - 2013-04-04 09:42 - 000000000 ____D C:\Users\Tony\AppData\Local\CrashDumps
==================== Files in the root of some directories =======
2014-11-29 09:22 - 2014-12-01 19:19 - 000000115 _____ () C:\Users\Tony\AppData\Roaming\LogFile.txt
2014-12-16 15:04 - 2014-12-16 15:04 - 000000600 _____ () C:\Users\Tony\AppData\Roaming\winscp.rnd
2016-05-30 14:50 - 2017-11-23 11:42 - 000007601 _____ () C:\Users\Tony\AppData\Local\resmon.resmoncfg
2014-12-16 14:59 - 2014-05-13 11:15 - 000010240 _____ () C:\Users\Tony\AppData\Local\Z@!-9f71b30d-7b27-44e2-a606-a256cc0d5988.tmp
2014-12-16 14:59 - 2014-05-13 11:15 - 000009216 _____ () C:\Users\Tony\AppData\Local\Z@S!-ff6c6c67-859b-4911-a61f-5f6bc529b9b2.tmp
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-06-27 07:10
==================== End of FRST.txt ============================
Here is the addition log:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by Tony (29-06-2018 17:09:26)
Running from C:\Users\Tony\Desktop
Windows 7 Home Premium Service Pack 1 (X64) (2013-04-01 10:12:01)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1688004940-62920522-2967697596-500 - Administrator - Disabled)
Guest (S-1-5-21-1688004940-62920522-2967697596-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1688004940-62920522-2967697596-1002 - Limited - Enabled)
Tony (S-1-5-21-1688004940-62920522-2967697596-1000 - Administrator - Enabled) => C:\Users\Tony
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Microsoft Security Essentials (Enabled - Up to date) {71A27EC9-3DA6-45FC-60A7-004F623C6189}
AS: Microsoft Security Essentials (Enabled - Up to date) {CAC39F2D-1B9C-4A72-5A17-3B3D19BB2B34}
AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20040 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.144 - Adobe Systems Incorporated)
Adobe Flash Player 30 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Adobe Flash Player 30 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Adobe Flash Player 30 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.9.199 - Adobe Systems, Inc.)
Agatha Christie - Death on the Nile (HKLM-x32\...\WTA-5c2e059b-617b-4fed-82b6-4fc634d1aefa) (Version: 2.2.0.98 - WildTangent) Hidden
ATI AVIVO64 Codecs (HKLM\...\{40D63515-FF59-9430-BFF0-BF2D26A6AB76}) (Version: 11.6.0.10524 - ATI Technologies Inc.) Hidden
ATI Catalyst Install Manager (HKLM\...\{F7F1A2DA-481A-1B41-8959-4B224C6B20B6}) (Version: 3.0.829.0 - ATI Technologies, Inc.)
Bejeweled 2 Deluxe (HKLM-x32\...\WTA-deb3040b-c90c-4e4c-aaad-ca5864fa08ea) (Version: 2.2.0.95 - WildTangent) Hidden
Build-a-lot 4 - Power Source (HKLM-x32\...\WTA-3a716b28-e8a2-4cf3-883a-a3b8caeb2a75) (Version: 2.2.0.97 - WildTangent) Hidden
Cash Back Assistant (HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\{644CF48B-61FE-43E4-8B2E-7EAE916B49C4}_is1) (Version: 2017.4.7.1 - Capital Intellect, Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.40 - Piriform)
Chronicles of Albian (HKLM-x32\...\WTA-ca657c69-8bfb-489b-a19f-807c4bf073cb) (Version: 2.2.0.95 - WildTangent) Hidden
Common Desktop Agent (HKLM\...\{031A0E14-0413-4C97-9772-2639B782F46F}) (Version: 1.62.0 - OEM) Hidden
Cradle of Rome 2 (HKLM-x32\...\WTA-d5450cc6-46c2-4a19-b61f-ab408f55b4a3) (Version: 2.2.0.95 - WildTangent) Hidden
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Do Not Track Me Add-on 2.2.9.515 (HKLM-x32\...\Do Not Track Me Add-on_is1) (Version: 2.2.9.515 - Abine Inc)
Dora's World Adventure (HKLM-x32\...\WTA-db8a00c1-c07d-49f9-907f-85392ba2e198) (Version: 2.2.0.95 - WildTangent) Hidden
eBay Worldwide (HKLM-x32\...\{D3E5A972-9A15-427D-AE78-8181A5FD943C}) (Version: 2.2.0409 - OEM)
eMachines Games (HKLM-x32\...\WildTangent emachines Master Uninstall) (Version: 1.0.2.5 - WildTangent)
eMachines Recovery Management (HKLM-x32\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 5.00.3502 - Acer Incorporated)
eMachines Registration (HKLM-x32\...\eMachines Registration) (Version: 1.04.3503 - Acer Incorporated)
eMachines ScreenSaver (HKLM-x32\...\eMachines Screensaver) (Version: 1.1.0221.2011 - Acer Incorporated)
eMachines Updater (HKLM-x32\...\{EE171732-BEB4-4576-887D-CB62727F01CA}) (Version: 1.02.3504 - Acer Incorporated)
Etron USB3.0 Host Controller (HKLM-x32\...\{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.96 - Etron Technology) Hidden
Etron USB3.0 Host Controller (HKLM-x32\...\InstallShield_{DFBB738C-71D8-4DC5-B8D2-D65C37680E27}) (Version: 0.96 - Etron Technology)
Evernote v. 4.5.1 (HKLM-x32\...\{28921580-E4BB-11E0-9FD7-1CC1DEF07CBE}) (Version: 4.5.1.5451 - Evernote Corp.)
Final Drive: Nitro (HKLM-x32\...\WTA-002781fd-bcba-4892-b9cd-42f5ec0eaa62) (Version: 2.2.0.95 - WildTangent) Hidden
Flash Cookie Cleaner (HKLM-x32\...\{E4E1D7C7-6561-4462-96B5-E6439488ED41}) (Version: 2.0 - ConsumerSoft)
Fooz Kids (HKLM-x32\...\{A4E908E5-EE02-843C-9D01-9EA69410B3AB}) (Version: 3.0.8 - FUHU, Inc.) Hidden
Fooz Kids (HKLM-x32\...\FoozKids) (Version: 3.0.8 - FUHU, Inc.)
Fooz Kids Platform (HKLM-x32\...\{8D68CE08-9A14-4B7B-9857-3C646A2F34C7}) (Version: 2.1 - FUHU, Inc.)
Galerie de photos Windows Live (HKLM-x32\...\{488F0347-C4A7-4374-91A7-30818BEDA710}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.99 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Governor of Poker 2 Premium Edition (HKLM-x32\...\WTA-4a7a1f8b-95ef-4b1c-b7f3-8e6121735af5) (Version: 2.2.0.95 - WildTangent) Hidden
Hotkey Utility (HKLM-x32\...\Hotkey Utility) (Version: 2.05.3505 - Acer Incorporated)
Identity Card (HKLM-x32\...\Identity Card) (Version: 1.00.3501 - Acer Incorporated)
Jewel Match 3 (HKLM-x32\...\WTA-07b35df1-23d6-4993-938a-ded40b164203) (Version: 2.2.0.97 - WildTangent) Hidden
Junk Mail filter update (HKLM-x32\...\{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}) (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
LibreOffice 4.4 Help Pack (English (United States)) (HKLM-x32\...\{70B711C0-15AF-41A7-AA74-214B821C9EB6}) (Version: 4.4.4.3 - The Document Foundation)
LibreOffice 5.4.2.2 (HKLM\...\{71F5B603-BA9F-41E1-BC94-9839DFE5A83E}) (Version: 5.4.2.2 - The Document Foundation)
Mesh Runtime (HKLM-x32\...\{8C6D6116-B724-4810-8F2D-D047E6B7D68E}) (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.10.209.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24212 (HKLM-x32\...\{323dad84-0974-4d90-a1c1-e006c7fdbb7d}) (Version: 14.0.24212.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
Mystery of Mortlake Mansion (HKLM-x32\...\WTA-2ae1e4a1-1a74-4b95-aa2e-bd1d1b4ee6b0) (Version: 2.2.0.98 - WildTangent) Hidden
Nero DiscSpeed 10 (HKLM-x32\...\{34490F4E-48D0-492E-8249-B48BECF0537C}) (Version: 6.2.10500.2.100 - Nero AG)
Nero Express 10 (HKLM-x32\...\{70550193-1C22-445C-8FA4-564E155DB1A7}) (Version: 10.2.12000.21.100 - Nero AG)
Nero Multimedia Suite 10 Essentials (HKLM-x32\...\{62BF4BD3-B1F6-4FA2-8388-CC0647ACBF86}) (Version: 10.5.10300 - Nero AG)
Nero StartSmart 10 (HKLM-x32\...\{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}) (Version: 10.2.11600.14.100 - Nero AG)
Nero Update (HKLM-x32\...\{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}) (Version: 1.0.0018 - Nero AG)
NETGEAR WNDA3100v3 (HKLM-x32\...\{60C50FCC-545B-4D5D-B0D1-4A773143BCE7}) (Version: 1.0.0.10 - NETGEAR) Hidden
NETGEAR WNDA3100v3 Genie (HKLM-x32\...\InstallShield_{60C50FCC-545B-4D5D-B0D1-4A773143BCE7}) (Version: 1.0.0.10 - NETGEAR)
NOOK for PC (HKLM-x32\...\BN_DesktopReader) (Version: 2.5.4.7070 - Barnesandnoble.com)
Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation)
OpenOffice 4.1.1 (HKLM-x32\...\{9395F41D-0F80-432E-9A59-B8E477E7E163}) (Version: 4.11.9775 - Apache Software Foundation)
Penguins! (HKLM-x32\...\WTA-5ad9af41-4bb6-43c2-b7b7-e89d08bda186) (Version: 2.2.0.95 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (HKLM-x32\...\WTA-b2c12114-0d47-4098-9eeb-dea1d02a1a75) (Version: 2.2.0.95 - WildTangent) Hidden
Polar Bowler (HKLM-x32\...\WTA-a63d6f7f-3614-4ae3-8ad4-fc2b996cbd7e) (Version: 2.2.0.97 - WildTangent) Hidden
Polar Golfer (HKLM-x32\...\WTA-eccd2bc6-2552-4459-9ffd-b1e54b6d3350) (Version: 2.2.0.95 - WildTangent) Hidden
Quick Maps And Directions (HKU\S-1-5-21-1688004940-62920522-2967697596-1000\...\{28e56cfb-e30e-4f66-85d8-339885b726b8}) (Version: 4.4.0.3 - SpringTech Ltd.)
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.45.516.2011 - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6242 - Realtek Semiconductor Corp.)
Samsung Easy Printer Manager (HKLM-x32\...\Samsung Easy Printer Manager) (Version: 1.05.79.00(3/26/2015) - Samsung Electronics Co., Ltd.)
Samsung M283x Series (HKLM-x32\...\Samsung M283x Series) (Version: 1.14 (7/17/2015) - Samsung Electronics Co., Ltd.)
Samsung Printer Diagnostics (HKLM-x32\...\Samsung Printer Diagnostics) (Version: 1.0.4.7 - Samsung Electronics Co., Ltd.)
Samsung Printer Live Update (HKLM-x32\...\Samsung Printer Live Update) (Version: 1.01.00:04(2013-04-22) - Samsung Electronics Co., Ltd.)
Speedtest by Ookla (HKLM\...\{4CB99888-11EE-4B49-BC91-447FF7FCD975}) (Version: 1.0.14.001 - Ookla)
swMSM (HKLM-x32\...\{612C34C7-5E90-47D8-9B5C-0F717DD82726}) (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Torchlight (HKLM-x32\...\WTA-9bfbe13d-2761-454a-9fcd-fe12eb3e3eef) (Version: 2.2.0.97 - WildTangent) Hidden
Update Installer for WildTangent Games App (HKLM-x32\...\{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App) (Version: - WildTangent) Hidden
Virtual Villagers 5 - New Believers (HKLM-x32\...\WTA-79d63b1a-26dc-4afa-bedf-5a9f56b1c6d7) (Version: 2.2.0.97 - WildTangent) Hidden
Welcome Center (HKLM-x32\...\eMachines Welcome Center) (Version: 1.02.3504 - Acer Incorporated)
WildTangent Games App (eMachines Games) (HKLM-x32\...\{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-emachines) (Version: 4.0.5.14 - WildTangent) Hidden
Windows 7 Upgrade Advisor (HKLM-x32\...\{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}) (Version: 2.0.5000.0 - Microsoft Corporation)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Yahoo Toolbar (HKLM-x32\...\Yahoo! Companion) (Version: - Yahoo Inc.)
Zuma's Revenge (HKLM-x32\...\WTA-e53f302b-7388-4065-8d00-7fa84715f49f) (Version: 2.2.0.97 - WildTangent) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ShellIconOverlayIdentifiers-x32: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => -> No File
ContextMenuHandlers1: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers3: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => -> No File
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2016-11-14] (Microsoft Corporation)
ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2011-05-25] (Advanced Micro Devices, Inc.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {01823A1A-8875-451C-BD04-8F7467DD9A45} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-03-17] (Google Inc.)
Task: {0875BB75-B060-47BB-BCA3-F43E5FF4E093} - System32\Tasks\UALU notificatin => C:\Program Files\eMachines\eMachines Updater\UALU.exe [2016-06-08] (Acer Incorporated)
Task: {0B7703B3-6C47-4EC9-B8AA-9F43C929A738} - System32\Tasks\{8B1863CD-1CF8-4BE4-B2E1-DEDA7FCF0539} => C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe [2016-04-01] ()
Task: {0C0F0F2F-C147-42D4-B194-F5306A1AA20B} - System32\Tasks\{A21E57C9-325E-49F4-8636-93FE02FB2729} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Task: {0D964143-9C9A-4563-8CE1-DF0F19ADBB15} - System32\Tasks\{B3FD088A-0FED-4B3C-80BF-580CDA018E1F} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {164263C4-E99F-4BEE-BF5B-E4D75DCF0ACB} - System32\Tasks\{DFFC1542-E027-4B8E-AEA3-90D776E41A3E} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Task: {21D664C5-B280-4D0D-8144-76B08CA4D39B} - System32\Tasks\{78B31507-B117-43EA-BAC7-6F373578569B} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Task: {2849E99A-35B9-4F47-98CA-0196A6A403F6} - System32\Tasks\{38A67DA2-9BE9-4DC0-BB9E-C02671D7A523} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {2C9CE3E8-F32F-4343-8056-AAD0F400F438} - System32\Tasks\{0EB495D6-8C40-4BE6-8E30-A9E75F5AD142} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {383761C9-B287-4F11-ABBB-2F4D949B8D0D} - System32\Tasks\Adobe Reader Speed Launcher => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe
Task: {3B7477A8-1C15-4125-A4B0-6ABCA569E476} - System32\Tasks\{58DD7D4B-946E-4F55-B746-EB4B9C4A53C3} => C:\Windows\system32\pcalua.exe -a D:\setup.exe -d D:\
Task: {3DC36A66-0360-4886-A1D8-B4FC6EA0D1BD} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-02-07] (Piriform Ltd)
Task: {40990DEB-CA08-41F7-847D-512FE2992193} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {412F3D00-C5DB-4D53-963B-E2A47AE25BAF} - System32\Tasks\Adobe Flash Player NPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_113_Plugin.exe [2018-06-07] (Adobe Systems Incorporated)
Task: {5EAB325A-5033-4F04-A766-0F0EC1BD5ED7} - System32\Tasks\{D1943BA7-09D0-4318-BA3F-2C47D2200F97} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Task: {66FD9F74-5DF1-4F77-BBCC-7A581766A831} - System32\Tasks\{C5C4C726-EF2D-4BDB-BDA7-7F73692629F1} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {68C9C3E2-B945-4B32-AB2C-9805917FC7CD} - System32\Tasks\{766F8B29-7A29-4659-9689-CC6E637EAC6D} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {6FC4D8C0-EE31-4E10-953C-3780BDF2EFAB} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {6FC4D8C0-EE31-4E10-953C-3780BDF2EFAB} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(2): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshContent
Task: {6FC4D8C0-EE31-4E10-953C-3780BDF2EFAB} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(3): C:\Windows\system32\GWX\GWXDetector.exe [2015-12-08] (Microsoft Corporation)
Task: {7341CFE4-483D-49B8-899E-05CCA0AF4FFC} - System32\Tasks\{D10355E7-55CD-447A-8FA1-E020748CF2EA} => C:\Program Files (x86)\NETGEAR\WNDA3100v3\WNDA3100v3.EXE [2015-01-15] (NETGEAR)
Task: {7366A2EA-94AE-4289-AE55-E35107F2D7BF} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {7366A2EA-94AE-4289-AE55-E35107F2D7BF} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2015-12-08] (Microsoft Corporation)
Task: {7CABCE86-561C-4148-8E29-94D3A74D2B1B} - System32\Tasks\{F6104194-9F54-4D00-AE42-E2ED93E726B7} => C:\Users\Tony\Desktop\DesktopTickerSetup(1).exe
Task: {7F154A77-266E-4372-A56A-CB7B95115C0A} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfigAndContent
Task: {7F154A77-266E-4372-A56A-CB7B95115C0A} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2015-12-08] (Microsoft Corporation)
Task: {7F6D0E45-51D7-4D0C-835C-B27A7DD11C69} - System32\Tasks\Adobe ARM => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {85311682-456F-428D-B427-B4C2F223CBE2} - System32\Tasks\{8774AC72-491C-4B5A-96C1-F79B9773A292} => C:\Program Files (x86)\NETGEAR\WNDA3100v3\WNDA3100v3.EXE [2015-01-15] (NETGEAR)
Task: {862549AC-EC08-4807-91D6-7EC3D2C72CE0} - System32\Tasks\Microsoft\Microsoft Antimalware\Microsoft Antimalware Scheduled Scan => c:\Program Files\Microsoft Security Client\\MpCmdRun.exe [2016-11-14] (Microsoft Corporation)
Task: {8BC1865B-2F55-4F35-AF33-BBD04831036A} - System32\Tasks\{487234CC-9FD4-4AB7-9B87-C41A810C7A82} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {9DE717A9-DD4B-4DC8-AF0C-6063699B7AD6} - System32\Tasks\{576DF417-9B1D-479E-9DF4-D3E9114919BD} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {A21B8774-2D10-4BCE-A6C5-617447885C83} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-02-07] (Piriform Ltd)
Task: {A43FCCBE-20CD-4732-814B-4CBEB822F279} - System32\Tasks\{11517C53-4E54-4183-B20B-F085912AF9E5} => C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe [2016-04-01] ()
Task: {A817C154-E8A1-49E3-B86E-F4AA4E9E2445} - System32\Tasks\{F78F1D0A-75C4-491D-A268-624A274D0579} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {A9B056E1-E75E-4FE2-BDA0-5C185B0AC06B} - System32\Tasks\{F0858436-8187-4706-8D44-16FB5E143267} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {AB3998E9-E1BA-4EAA-8040-93396EC91016} - System32\Tasks\{17618F22-8943-45FE-9076-1EE6845A1CCE} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe [2018-05-10] (Adobe Systems Incorporated)
Task: {AF1A5F95-3B7A-401A-BC4C-DEFC53DA615D} - System32\Tasks\{D2F1A770-5A8B-46B2-BEE2-FB4299A395A7} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe [2018-05-10] (Adobe Systems Incorporated)
Task: {B2822BCB-9CAC-4576-8A99-84AE4EC11C4B} - System32\Tasks\{183FCDF8-1471-4094-9CE5-706CBD3D458F} => C:\Program Files (x86)\Malwarebytes Anti-Malware\mbam.exe
Task: {BDAF9086-3863-48A0-B529-FACDE727584F} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(1): %windir%\system32\GWX\GWXUXWorker.exe -> /ScheduleUpgradeReminderTime
Task: {BDAF9086-3863-48A0-B529-FACDE727584F} - System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2015-12-08] (Microsoft Corporation)
Task: {C005BFE8-BEA5-45A0-8959-008ADEA03D3B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-06-07] (Adobe Systems Incorporated)
Task: {CDAB0BED-7A76-40EA-8AC8-0FE3C98BF4FA} - System32\Tasks\{EE46ACE3-7E41-42D7-B540-4D559ABCBF99} => C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe [2016-04-01] ()
Task: {D3122B84-1007-4BC9-85A2-90139B748022} - System32\Tasks\{9C0D182F-40EE-4D88-B090-12EF71DC90CF} => C:\Windows\system32\pcalua.exe -a "C:\Users\Tony\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CTNBT9KD\BingDesktopSetup.exe" -d C:\Users\Tony\Desktop
Task: {D5AB5270-8C0D-4C3F-A63A-BFCB60D9F9DA} - System32\Tasks\{1A9630D5-2ABC-41A9-8E4A-CDF5B32A20CA} => C:\Program Files (x86)\The Weather Channel\Desktop Weather\TWC.Win7.exe
Task: {D7768AFE-8167-4408-8B33-36549946B135} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-03-17] (Google Inc.)
Task: {DB5410F5-CBF1-4132-A4AD-8D137ABAE05B} - System32\Tasks\{5F2D0EAE-1750-4B8E-A6C8-34FAF674B3CF} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {DCF1C83E-F79D-47F2-A0FD-609DD509303B} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_30_0_0_113_pepper.exe [2018-06-07] (Adobe Systems Incorporated)
Task: {E901DCC1-AB87-4E22-A623-9A1FF2FA8E0B} - System32\Tasks\{88607A67-2A8D-45E8-8457-CE546DBF4B20} => C:\Program Files\AVAST Software\Avast\AvastUI.exe
Task: {EA369158-4B44-458C-90F4-CA25D5A4D665} - System32\Tasks\{2B849E15-0960-4F9E-B30F-7F9574D58E11} => C:\Program Files\AVAST Software\Avast\avastui.exe
Task: {F0F68262-494D-4696-B54E-383A35DBDEC2} - System32\Tasks\{CD3C9149-F157-4F1B-9103-518BA35617ED} => C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe [2018-05-10] (Adobe Systems Incorporated)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2015-04-23 06:16 - 2015-06-26 11:27 - 000022528 _____ () C:\Windows\System32\ssk5mlm.dll
2015-02-20 08:01 - 2015-02-20 08:01 - 000022528 _____ () C:\Windows\System32\us001lm.dll
2015-12-17 13:21 - 2016-04-01 18:38 - 000498488 ____N () C:\Windows\SysWOW64\spdsvc.exe
2014-09-08 13:39 - 2014-09-08 13:39 - 000464608 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
2014-09-08 13:38 - 2014-09-08 13:38 - 000051200 _____ () C:\Program Files\Common Files\Common Desktop Agent\CDASrvPS.dll
2011-05-25 01:50 - 2011-05-25 01:50 - 000243712 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2011-11-09 12:55 - 2011-11-09 12:55 - 000016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-13 22:34 - 2009-06-10 17:00 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1688004940-62920522-2967697596-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Tony\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 75.75.75.75 - 75.75.76.76
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
MSCONFIG\Services: GamesAppService => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk => C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^NETGEAR WNDA3100v3 Genie.lnk => C:\Windows\pss\NETGEAR WNDA3100v3 Genie.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: CDAServer => C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
MSCONFIG\startupreg: Global Registration => "C:\Program Files (x86)\eMachines\Registration\GREG.exe" /boot
MSCONFIG\startupreg: Hotkey Utility => C:\Program Files (x86)\eMachines\Hotkey Utility\HotkeyUtility.exe
MSCONFIG\startupreg: HP Software Update => C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
MSCONFIG\startupreg: hpqSRMon => C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
MSCONFIG\startupreg: Norton Online Backup => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{37C1F83D-3D4F-4021-93AF-E804F9D4BC99}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{0AD4294E-60F3-4F96-BA43-EA6E64A90E1C}] => (Allow) LPort=2869
FirewallRules: [{2EA2A314-F20B-4113-A768-0282D8DD83D2}] => (Allow) LPort=1900
FirewallRules: [{D7A0D108-9495-45B3-9C0F-4E295C7A37A4}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
FirewallRules: [{AC0B9D9A-0CAD-41E4-B684-180DA8016CAA}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{7B2C0DE6-782A-4517-983E-5159B07E5DB8}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDS.Application.exe
FirewallRules: [{7DE2E58F-5350-4D7D-9D49-434E76172C2C}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\OrderSupplies.exe
FirewallRules: [{AFCE17FB-9DD5-4CAA-914E-342ED0B82D61}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\IDSAlert.exe
FirewallRules: [{47938683-F784-4091-86B3-2A88AF39294C}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\uninstall.exe
FirewallRules: [{1B7AB9D5-27F7-4778-8DE2-A9D78FE1694F}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\CDAS2PC.exe
FirewallRules: [{6ABE13B0-6850-4BB4-BD62-75480DC06535}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\ScanProcess.exe
FirewallRules: [{2407940A-BEE4-4EE9-ACDD-043795CFB6F6}] => (Allow) C:\Program Files (x86)\Samsung\Easy Printer Manager\CDAS2PC\Scan2PCNotify.exe
FirewallRules: [{06D04A50-B748-4D10-82D0-326290E5070F}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
FirewallRules: [{18597985-6BFF-4864-AC82-ECDCE55FB699}] => (Allow) C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
FirewallRules: [{BF850ADB-934C-4620-8572-BF8B808480CB}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe
FirewallRules: [{5687E6EB-DE0D-41A2-9A9F-0C038BBFE71C}] => (Allow) C:\Program Files (x86)\Samsung\Samsung Printer Diagnostics\SEInstall\SPD\ESM.exe
FirewallRules: [{77FB52CB-A9D9-4EAD-8EAB-AE035CDDED5C}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
25-04-2018 11:22:02 Scheduled Checkpoint
26-04-2018 04:55:26 Windows Update
29-04-2018 08:51:38 Windows Update
03-05-2018 14:38:14 Windows Update
07-05-2018 11:43:11 Windows Update
09-05-2018 12:47:28 Windows Update
13-05-2018 06:25:25 Windows Update
16-05-2018 09:30:02 Windows Update
17-05-2018 08:05:39 Removed Adobe Acrobat Reader DC.
20-05-2018 07:52:36 Windows Update
23-05-2018 11:51:22 Windows Update
27-05-2018 09:16:13 Windows Update
27-05-2018 10:24:00 Restore Operation
27-05-2018 11:19:35 Windows Update
31-05-2018 11:21:19 Windows Update
04-06-2018 08:11:49 Windows Update
04-06-2018 14:38:39 Removed Norton Online Backup
04-06-2018 14:39:48 Removed Norton Online Backup
07-06-2018 13:42:05 Windows Update
11-06-2018 11:04:26 Windows Update
13-06-2018 16:02:44 Windows Update
13-06-2018 17:10:52 Windows Update
17-06-2018 10:01:48 Windows Update
21-06-2018 08:23:55 Windows Update
24-06-2018 20:54:42 Windows Update
28-06-2018 11:30:53 Windows Update
==================== Faulty Device Manager Devices =============
Name: Malwarebytes Anti-Exploit
Description: Malwarebytes Anti-Exploit
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer:
Service: ESProtectionDriver
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
==================== Event log errors: =========================
Application errors:
==================
Error: (06/29/2018 01:59:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (06/29/2018 01:16:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (06/29/2018 07:40:34 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (06/28/2018 08:43:12 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (06/28/2018 07:36:49 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (06/28/2018 07:15:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (06/28/2018 04:14:16 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Error: (06/28/2018 02:48:50 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
System errors:
=============
Error: (06/29/2018 01:58:24 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
ESProtectionDriver
Error: (06/29/2018 01:58:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VBoxAsw Support Driver service failed to start due to the following error:
The system cannot find the path specified.
Error: (06/29/2018 01:22:06 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} did not register with DCOM within the required timeout.
Error: (06/29/2018 01:21:42 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
ESProtectionDriver
Error: (06/29/2018 01:21:40 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VBoxAsw Support Driver service failed to start due to the following error:
The system cannot find the path specified.
Error: (06/29/2018 01:20:16 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: The server {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} did not register with DCOM within the required timeout.
Error: (06/29/2018 01:15:22 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
ESProtectionDriver
Error: (06/29/2018 01:15:20 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The VBoxAsw Support Driver service failed to start due to the following error:
The system cannot find the path specified.
Windows Defender:
===================================
Date: 2015-05-28 06:38:19.747
Description:
Windows Defender scan has been stopped before completion.
Scan ID:{D5B2BD5A-0510-4A45-A683-D26A899B54F4}
Scan Type:AntiSpyware
Scan Parameters:Quick Scan
Date: 2015-06-04 16:18:09.113
Description:
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified.
Signature version:0.0.0.0
Engine version:0.0.0.0
==================== Memory info ===========================
Processor: AMD E-350 APU with Radeon HD Graphics
Percentage of memory in use: 37%
Total physical RAM: 3576.26 MB
Available physical RAM: 2241.16 MB
Total Virtual: 7150.69 MB
Available Virtual: 5597.55 MB
==================== Drives ================================
Drive c: (eMachines) (Fixed) (Total:446.13 GB) (Free:337.09 GB) NTFS
\\?\Volume{8b9557a3-d226-11e1-939d-806e6f6e6963}\ (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.03 GB) NTFS
\\?\Volume{8b9557a2-d226-11e1-939d-806e6f6e6963}\ (PQSERVICE) (Fixed) (Total:19.53 GB) (Free:7.88 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: B25EC62F)
Partition 1: (Not Active) - (Size=19.5 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=446.1 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================