Hi!
Need help my laptop an error keeps popping up, computer slows down and desktop wallpaper keeps returning to its default theme every time I open it.
Please see below Frst Txt
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 30-11-2017
Ran by Jerome (administrator) on ALEAH-PC (05-12-2017 00:19:42)
Running from C:\Users\Jerome\Downloads
Loaded Profiles: Jerome (Available Profiles: Jerome)
Platform: Windows 7 Ultimate (X64) Language: English (United States)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.599\SSScheduler.exe
(AbeGunnerZ Lab) C:\Program Files (x86)\USB Disk Security\USBGuard.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Users\Jerome\AppData\Local\Temp\01d30382.exe
() C:\Users\Jerome\AppData\Local\Temp\01d30382.exe
() C:\Users\Jerome\M-50500586850859759959469767487936945749799505950\winmgr.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
() C:\Users\Jerome\AppData\Local\Temp\csznadbyeh.exe
() C:\Users\Jerome\AppData\Local\Temp\bxyieaimyc.exe
() C:\Users\Jerome\AppData\Roaming\svchostx64.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Apoint] => C:\Program Files\Apoint\Apoint.exe [242552 2013-09-26] (Alps Electric Co., Ltd.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2778864 2014-01-31] (Synaptics Incorporated)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1021128 2014-12-03] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [USB Security] => C:\Program Files (x86)\USB Disk Security\USBGuard.exe [2347008 2011-11-10] (AbeGunnerZ Lab)
HKU\S-1-5-21-1141224537-1566625622-1964642510-1000\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [27832272 2017-08-25] (Skype Technologies S.A.)
HKU\S-1-5-21-1141224537-1566625622-1964642510-1000\...\Run: [RESTART_STICKY_NOTES] => C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
HKU\S-1-5-21-1141224537-1566625622-1964642510-1000\...\Run: [Microsoft Windows Manager] => C:\Users\Jerome\M-50500586850859759959469767487936945749799505950\winmgr.exe [97063 2017-12-04] ()
HKU\S-1-5-21-1141224537-1566625622-1964642510-1000\...\RunOnce: [Adobe Speed Launcher] => 1512343532
HKU\S-1-5-21-1141224537-1566625622-1964642510-1000\...\CurrentVersion\Windows: [Load] C:\Users\Jerome\LOCALS~1\Temp\mszibaih.scr <==== ATTENTION
HKU\S-1-5-21-1141224537-1566625622-1964642510-1000\...\MountPoints2: F - F:\USBNB.exe
HKU\S-1-5-21-1141224537-1566625622-1964642510-1000\...\MountPoints2: {eb59c5d0-ab00-11e7-bf81-3c77e6d88d6c} - F:\USBNB.exe
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2017-09-30]
ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.599\SSScheduler.exe (McAfee, Inc.)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Hosts: 0.0.0.1 mssplus.mcafee.com
Tcpip\Parameters: [DhcpNameServer] 192.168.22.1
Tcpip\..\Interfaces\{2DCE6236-84C4-4BF9-BE5C-3542EFF0DB10}: [DhcpNameServer] 192.168.42.129
Tcpip\..\Interfaces\{3463424D-9329-4D2B-BF92-7D2A7834773B}: [DhcpNameServer] 192.168.22.1
Tcpip\..\Interfaces\{C1EAB9E2-5F32-4361-B97A-E85AAEE37779}: [DhcpNameServer] 192.168.22.1
Internet Explorer:
==================
HKU\S-1-5-21-1141224537-1566625622-1964642510-1000\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com/ie
HKU\S-1-5-21-1141224537-1566625622-1964642510-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp
SearchScopes: HKU\S-1-5-21-1141224537-1566625622-1964642510-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.google.com/search?q={sear
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\Office15\OCHelper.dll [2012-10-01] (Microsoft Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office15\URLREDIR.DLL [2012-10-01] (Microsoft Corporation)
BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\Office15\GROOVEEX.DLL [2012-10-01] (Microsoft Corporation)
Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2012-10-01] (Microsoft Corporation)
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2009-07-14] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2009-07-14] (Microsoft Corporation)
FireFox:
========
FF DefaultProfile: oi0my0ey.default
FF ProfilePath: C:\Users\Jerome\AppData\Roaming\Mozilla\Firefox\Profiles\oi0my0ey.default [2017-12-05]
FF Extension: (Disable Media WMF NV12 format) - C:\Users\Jerome\AppData\Roaming\Mozilla\Firefox\Profiles\oi0my0ey.default\features\{b3598417-3003-4bc3-a996-ed336f95439a}\disable-media-wmf-nv12@mozilla.org.xpi [2017-11-22] [Lagacy]
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_144.dll [2017-04-01] ()
FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~2\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.2.1 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.2.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_144.dll [2017-04-01] ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2015-02-13] (Google, Inc.)
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office15\NPSPWRAP.DLL [2012-10-01] (Microsoft Corporation)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-03] (Adobe Systems Inc.)
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.599\McCHSvc.exe [404376 2017-09-05] (McAfee, Inc.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [172760 2015-04-09] (Broadcom Corporation.)
R3 CnxtHdmiAudService; C:\Windows\System32\drivers\CHDMI64.sys [722488 2010-04-29] (Conexant Systems Inc.)
R3 RTSPER; C:\Windows\System32\DRIVERS\RtsPer.sys [827096 2015-02-06] (Realsil Semiconductor Corporation)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-12-05 00:19 - 2017-12-05 00:19 - 000000000 ____D C:\Users\Jerome\Downloads\FRST-OlderVersion
2017-12-04 16:07 - 2017-12-04 16:18 - 000000000 ____H C:\Users\Jerome\AppData\Roaming\winmgr.txt
2017-12-04 16:05 - 2017-12-04 16:05 - 000000000 _RSHD C:\Users\Jerome\M-50500586850859759959469767487936945749799505950
2017-12-04 15:56 - 2017-12-04 15:56 - 000003482 _____ C:\Windows\System32\Tasks\Adasdsadas3id
2017-12-04 15:56 - 2017-12-04 15:55 - 000411133 ___SH C:\Users\Jerome\AppData\Roaming\svchostx64.exe
2017-12-03 12:30 - 2017-12-03 12:33 - 000000000 ____D C:\Users\Jerome\Documents\keisha's poem
2017-12-01 22:09 - 2017-12-01 22:09 - 000035797 _____ C:\Users\Jerome\Documents\Presentation1.pptx
2017-12-01 21:59 - 2017-12-01 21:59 - 000000037 ____H C:\Users\Jerome\Downloads\.picasa.ini
2017-11-21 09:08 - 2017-11-21 09:09 - 000018933 _____ C:\Users\Jerome\Downloads\Addition.txt
2017-11-21 09:07 - 2017-12-05 00:20 - 000009407 _____ C:\Users\Jerome\Downloads\FRST.txt
2017-11-21 09:07 - 2017-12-05 00:19 - 000000000 ____D C:\FRST
2017-11-21 09:04 - 2017-12-05 00:19 - 002391552 _____ (Farbar) C:\Users\Jerome\Downloads\FRST64.exe
2017-11-21 08:31 - 2017-12-04 07:53 - 000004960 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for ALEAH-PC-Jerome Aleah-PC
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-12-04 23:25 - 2009-07-14 12:45 - 000009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2017-12-04 23:25 - 2009-07-14 12:45 - 000009584 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2017-12-04 18:40 - 2017-06-20 08:41 - 000000000 ____D C:\Users\Jerome\AppData\Roaming\Skype
2017-12-04 16:05 - 2017-04-01 11:31 - 000000000 ____D C:\Users\Jerome
2017-12-04 07:31 - 2009-07-14 13:13 - 000781298 _____ C:\Windows\system32\PerfStringBackup.INI
2017-12-04 07:31 - 2009-07-14 11:20 - 000000000 ____D C:\Windows\inf
2017-12-04 07:26 - 2017-04-11 09:43 - 000000000 ____D C:\Users\Jerome\AppData\LocalLow\Mozilla
2017-12-04 07:25 - 2009-07-14 13:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2017-12-04 00:55 - 2017-04-01 12:20 - 000065536 _____ C:\Windows\system32\spu_storage.bin
2017-12-03 11:36 - 2017-04-01 15:34 - 000000000 ____D C:\Users\Jerome\AppData\Roaming\vlc
2017-12-02 14:50 - 2017-10-21 13:22 - 000000000 ____D C:\Users\Jerome\Documents\keisha's wallpapers
2017-12-01 19:54 - 2017-10-07 14:19 - 000000000 ____D C:\Users\Jerome\Documents\Zac world
2017-11-27 08:25 - 2009-07-14 13:08 - 000032624 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2017-11-26 15:59 - 2009-07-14 15:45 - 000000000 ___RD C:\Users\Public\Recorded TV
2017-11-26 15:44 - 2017-04-05 12:31 - 000000000 ____D C:\Users\Jerome\Documents\Custom Office Templates
2017-11-25 09:53 - 2017-05-28 02:14 - 000000000 ____D C:\Users\Jerome\Documents\Chad
2017-11-21 08:18 - 2017-05-07 15:48 - 000004966 _____ C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for Jerome-PC-Jerome Jerome-PC
2017-11-19 02:02 - 2017-08-17 19:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2017-11-18 09:15 - 2017-04-01 12:53 - 000000000 ____D C:\Users\Jerome\AppData\Roaming\Mozilla
2017-11-18 09:15 - 2017-04-01 12:47 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2017-11-16 21:34 - 2017-10-07 14:21 - 000000000 ____D C:\Users\Jerome\Documents\subject projects
2017-11-16 21:24 - 2017-04-07 18:51 - 000000000 ___RD C:\Users\Jerome\Documents\Notes
2017-11-16 21:23 - 2017-07-15 17:11 - 000000000 ____D C:\Users\Jerome\Documents\Border's
2017-11-15 18:13 - 2017-04-24 16:58 - 000000000 ____D C:\Users\Jerome\AppData\Roaming\uTorrent
2017-11-13 08:28 - 2017-11-04 18:47 - 000183028 _____ C:\Users\Jerome\Documents\resume-new.pdf
2017-11-08 16:40 - 2017-04-24 17:05 - 000000000 ___SD C:\Users\Jerome\AppData\LocalLow\Temp
==================== Files in the root of some directories =======
2017-12-04 15:56 - 2017-12-04 15:55 - 000411133 ___SH () C:\Users\Jerome\AppData\Roaming\svchostx64.exe
2017-12-04 16:07 - 2017-12-04 16:18 - 000000000 ____H () C:\Users\Jerome\AppData\Roaming\winmgr.txt
Some files in TEMP:
====================
2017-12-04 15:55 - 2017-12-04 15:55 - 000411133 ___SH () C:\Users\Jerome\AppData\Local\Temp\01d30382.exe
2017-12-04 15:59 - 2017-12-04 15:59 - 000411133 ___SH () C:\Users\Jerome\AppData\Local\Temp\01d6c1f0.exe
2017-12-04 16:39 - 2017-12-04 16:39 - 000411133 ___SH () C:\Users\Jerome\AppData\Local\Temp\01fbaf4c.exe
2017-12-04 16:40 - 2017-12-04 16:40 - 000411133 ___SH () C:\Users\Jerome\AppData\Local\Temp\01fc09aa.exe
2017-12-04 16:40 - 2017-12-04 16:40 - 000097063 ___SH () C:\Users\Jerome\AppData\Local\Temp\01fcc03c.exe
2017-12-04 16:41 - 2017-12-04 16:41 - 000097063 ___SH () C:\Users\Jerome\AppData\Local\Temp\01fd68bb.exe
2017-12-04 16:54 - 2017-12-04 16:54 - 000097063 ___SH () C:\Users\Jerome\AppData\Local\Temp\02095de2.exe
2017-12-04 16:54 - 2017-12-04 16:54 - 000097063 ___SH () C:\Users\Jerome\AppData\Local\Temp\0209aceb.exe
2017-12-04 21:09 - 2017-12-04 21:09 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\agvwojdopp.exe
2017-12-05 00:15 - 2017-12-05 00:15 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\bxyieaimyc.exe
2017-12-05 00:14 - 2017-12-05 00:14 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\csznadbyeh.exe
2017-12-04 17:01 - 2017-12-04 17:01 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\cvrvjmskyn.exe
2017-12-04 21:09 - 2017-12-04 21:09 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\duaobocteq.exe
2017-12-04 21:30 - 2017-12-04 21:30 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\ehsqtrhzpj.exe
2017-12-04 18:15 - 2017-12-04 18:15 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\eqcowpxtcw.exe
2017-12-04 23:54 - 2017-12-04 23:54 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\fhzhrtfyvp.exe
2017-12-04 16:41 - 2017-12-04 16:41 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\fjornqobgd.exe
2017-12-04 22:31 - 2017-12-04 22:31 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\fufqyokkdv.exe
2017-12-04 22:00 - 2017-12-04 22:00 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\gumsbguive.exe
2017-12-04 17:54 - 2017-12-04 17:54 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\gurabohpse.exe
2017-12-04 23:54 - 2017-12-04 23:54 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\hktssgkiaq.exe
2017-12-04 18:15 - 2017-12-04 18:15 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\hlwyxdcdhf.exe
2017-12-04 23:44 - 2017-12-04 23:44 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\hojjqnvoco.exe
2017-12-04 17:33 - 2017-12-04 17:33 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\htwtsipxqo.exe
2017-12-04 21:30 - 2017-12-04 21:30 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\hvxipwgmvk.exe
2017-12-04 23:44 - 2017-12-04 23:44 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\hzvwtscjpb.exe
2017-12-04 20:07 - 2017-12-04 20:07 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\ilrysuvzku.exe
2017-12-04 23:02 - 2017-12-04 23:02 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\imcfhndokt.exe
2017-12-04 18:56 - 2017-12-04 18:56 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\islzhskhtm.exe
2017-12-04 22:42 - 2017-12-04 22:42 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\jgqbtvcnro.exe
2017-12-04 19:37 - 2017-12-04 19:37 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\jjfeqotigp.exe
2017-12-04 17:54 - 2017-12-04 17:54 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\jptkublzff.exe
2017-12-04 18:04 - 2017-12-04 18:04 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\jspawpsuwf.exe
2017-12-04 23:02 - 2017-12-04 23:02 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\kljvfkrjqb.exe
2017-12-04 20:39 - 2017-12-04 20:39 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\ladkysjdbf.exe
2017-12-04 20:49 - 2017-12-04 20:49 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\ldjlgudsgg.exe
2017-12-04 20:38 - 2017-12-04 20:38 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\lhaceapzif.exe
2017-12-04 18:56 - 2017-12-04 18:56 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\lkcefbioui.exe
2017-12-04 22:11 - 2017-12-04 22:11 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\lkfwwrqxpm.exe
2017-12-04 22:11 - 2017-12-04 22:11 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\lnqbzwpacz.exe
2016-09-16 09:46 - 2016-09-16 09:46 - 000038400 _____ (NVIDIA Corporation) C:\Users\Jerome\AppData\Local\Temp\lovelies.dll
2017-12-04 18:25 - 2017-12-04 18:25 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\lpfhumbmkc.exe
2017-12-04 20:49 - 2017-12-04 20:49 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\lsygdpxytt.exe
2017-12-04 23:13 - 2017-12-04 23:13 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\ltmehqnrms.exe
2017-12-04 18:04 - 2017-12-04 18:04 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\msfguzqbxt.exe
2017-12-04 19:37 - 2017-12-04 19:37 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\mxkwdtkvmy.exe
2017-12-05 00:04 - 2017-12-05 00:04 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\mzkpzxrplh.exe
2016-09-14 13:45 - 2016-09-14 13:45 - 000025600 _____ (Dell Inc.) C:\Users\Jerome\AppData\Local\Temp\neutralism.dll
2017-12-04 16:40 - 2017-12-04 16:40 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\nmeupvbive.exe
2017-12-05 00:04 - 2017-12-05 00:04 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\nvgcwtsmzu.exe
2017-12-04 21:19 - 2017-12-04 21:19 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\oobshsblet.exe
2017-12-04 20:28 - 2017-12-04 20:28 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\ooouglthbj.exe
2017-12-04 18:25 - 2017-12-04 18:25 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\oownknzbdq.exe
2017-12-04 21:19 - 2017-12-04 21:19 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\osnfkxifrg.exe
2017-12-04 23:23 - 2017-12-04 23:23 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\oyjmzdunrp.exe
2017-12-04 16:18 - 2017-12-04 16:18 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\pbgffrsjjf.exe
2017-12-04 17:44 - 2017-12-04 17:44 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\ppbctsvxja.exe
2017-12-04 17:44 - 2017-12-04 17:44 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\psnowwbrwn.exe
2017-12-04 17:22 - 2017-12-04 17:22 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\qcoeobirbv.exe
2017-12-04 21:51 - 2017-12-04 21:51 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\qgxzspjopb.exe
2017-12-04 21:51 - 2017-12-04 21:51 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\qkimvuqrco.exe
2017-12-04 22:21 - 2017-12-04 22:21 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\qqbhvzqdxz.exe
2017-12-04 22:52 - 2017-12-04 22:52 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\qvxmecmgrf.exe
2017-12-04 22:52 - 2017-12-04 22:52 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\qyizghlaes.exe
2017-12-04 20:59 - 2017-12-04 20:59 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\raadwxgjxs.exe
2017-12-04 20:28 - 2017-12-04 20:28 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\rffzfurxcx.exe
2017-12-04 17:22 - 2017-12-04 17:22 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\rylrlwjwoh.exe
2017-12-04 20:18 - 2017-12-04 20:18 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\sczjkdadja.exe
2017-12-04 22:31 - 2017-12-04 22:31 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\shniyxbgic.exe
2017-12-04 20:08 - 2017-12-04 20:08 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\slenfgmpyd.exe
2017-12-04 23:33 - 2017-12-04 23:33 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\snzalkgqrj.exe
2017-12-04 20:18 - 2017-12-04 20:18 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\sokwnhhfvn.exe
2017-12-04 16:19 - 2017-12-04 16:19 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\ssxldairjt.exe
2017-12-04 22:21 - 2017-12-04 22:21 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\stdawevnca.exe
2017-12-04 19:17 - 2017-12-04 19:17 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\tawpqrhsgw.exe
2017-12-04 19:58 - 2017-12-04 19:58 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\tdmcagibxv.exe
2017-12-04 23:33 - 2017-12-04 23:33 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\tkwnifzoew.exe
2017-12-04 22:00 - 2017-12-04 22:00 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\tlinmbbgkb.exe
2017-12-04 18:46 - 2017-12-04 18:46 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\tsvthezpna.exe
2017-12-04 21:40 - 2017-12-04 21:40 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\tvhrpxpoqp.exe
2017-12-04 18:46 - 2017-12-04 18:46 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\uokgehbvan.exe
2017-12-04 17:11 - 2017-12-04 17:11 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\uuodldzcdy.exe
2017-12-04 19:17 - 2017-12-04 19:17 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\uxlcnniyuj.exe
2017-12-04 17:12 - 2017-12-04 17:12 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\uxziohgeqm.exe
2017-12-04 19:57 - 2017-12-04 19:57 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\vcdzyigjyj.exe
2017-12-04 16:30 - 2017-12-04 16:30 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\vdstglisus.exe
2017-06-28 09:45 - 2017-06-28 09:46 - 032100680 _____ () C:\Users\Jerome\AppData\Local\Temp\vlc-2.2.6-win64.exe
2017-12-04 16:30 - 2017-12-04 16:30 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\vsggehjxhf.exe
2017-12-04 23:12 - 2017-12-04 23:12 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\vtybzovrmr.exe
2017-12-04 16:08 - 2017-12-04 16:08 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\vveazqzfeg.exe
2017-12-04 23:23 - 2017-12-04 23:23 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\wgxmlsdxzz.exe
2017-12-04 19:47 - 2017-12-04 19:47 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\wkhuryixzj.exe
2017-12-04 21:40 - 2017-12-04 21:40 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\wmxwohnwjd.exe
2017-12-04 19:47 - 2017-12-04 19:47 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\woshucpzlw.exe
2017-12-04 16:51 - 2017-12-04 16:51 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\wqaclipczk.exe
2017-12-04 18:35 - 2017-12-04 18:35 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\wsrdtqkjds.exe
2017-12-04 18:35 - 2017-12-04 18:35 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\wvdqvurlpf.exe
2017-12-04 21:00 - 2017-12-04 21:00 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\xopurwgoir.exe
2017-12-04 17:33 - 2017-12-04 17:33 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\xtrdopxhbe.exe
2017-12-04 19:06 - 2017-12-04 19:06 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\yaqkntowsz.exe
2017-12-04 19:06 - 2017-12-04 19:06 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\ypektctsrz.exe
2017-12-04 22:42 - 2017-12-04 22:42 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\yvzuaznxyi.exe
2017-12-04 16:51 - 2017-12-04 16:51 - 000097063 _____ () C:\Users\Jerome\AppData\Local\Temp\zhqhjsnkzy.exe
2017-12-04 17:01 - 2017-12-04 17:01 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\zsxkigvalm.exe
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-12-01 15:27
==================== End of FRST.txt ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 30-11-2017
Ran by Jerome (05-12-2017 00:21:37)
Running from C:\Users\Jerome\Downloads
Windows 7 Ultimate (X64) (2017-04-01 03:30:49)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-1141224537-1566625622-1964642510-500 - Administrator - Disabled)
Guest (S-1-5-21-1141224537-1566625622-1964642510-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-1141224537-1566625622-1964642510-1002 - Limited - Enabled)
Jerome (S-1-5-21-1141224537-1566625622-1964642510-1000 - Administrator - Enabled) => C:\Users\Jerome
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
µTorrent (HKU\S-1-5-21-1141224537-1566625622-1964642510-1000\...\uTorrent) (Version: 3.5.0.44090 - BitTorrent Inc.)
Adobe Flash Player 18 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 18.0.0.144 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Alps Pointing-device for VAIO (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: - ALPS ELECTRIC CO., LTD.)
Conexant Audio Driver For AMD HDMI/DP Codec (HKLM\...\CNXT_AUDIO_HDA_HDMI) (Version: 4.98.32.50 - Conexant)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.599.11 - McAfee, Inc.)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Office Professional Plus 2013 (HKLM\...\Office15.PROPLUS) (Version: 15.0.4420.1017 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation)
Mozilla Firefox 57.0 (x64 en-US) (HKLM\...\Mozilla Firefox 57.0 (x64 en-US)) (Version: 57.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 57.0.0.6525 - Mozilla)
Outils de vérification linguistique 2013 de Microsoft Office - Français (HKLM\...\{90150000-001F-040C-1000-0000000FF1CE}) (Version: 15.0.4420.1017 - Microsoft Corporation) Hidden
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
Program4Pc PC Image Editor (HKLM-x32\...\{29A01513-64A8-4543-AF3C-C2E4CD7FFE1A}_is1) (Version: 5.9.0.0 - Program4Pc Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7496 - Realtek Semiconductor Corp.)
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.9.10 - Synaptics Incorporated)
USB Disk Security (HKLM-x32\...\USB Disk Security_is1) (Version: - Zbshareware Lab)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.6 - VideoLAN)
WinRAR 5.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ContextMenuHandlers1: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-12-01] (Alexander Roshal)
ContextMenuHandlers1-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-12-01] (Alexander Roshal)
ContextMenuHandlers6: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2013-12-01] (Alexander Roshal)
ContextMenuHandlers6-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2013-12-01] (Alexander Roshal)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {141DD205-C192-426B-9947-A32FC27B3FD6} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
Task: {1512A98F-446E-4F60-BE9E-CFB6A3E8F436} - System32\Tasks\Games\UpdateCheck_S-1-5-21-1141224537-1566625622-1964642510-1000
Task: {469FC81D-D0E9-45C3-837F-85BF42A1188D} - System32\Tasks\Adasdsadas3id => C:\Users\Jerome\AppData\Roaming\svchostx64.exe [2017-12-04] () <==== ATTENTION
Task: {5123A322-EFC0-4EA0-8DA4-64987853CEC9} - System32\Tasks\{7B68003A-F945-4E7C-A61D-DA828A60B41D} => "c:\program files (x86)\mozilla firefox\firefox.exe" hxxps://ui.skype.com/ui/0/7.37.0.103/en/abandoninstall?source=lightinstaller&page=tsInstall
Task: {968A22A1-0275-4695-B2D4-042FD7ED05B8} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2012-10-01] (Microsoft Corporation)
Task: {9FBF3A29-503A-40E2-BD62-BF91332740F2} - System32\Tasks\Microsoft Office 15 Sync Maintenance for Jerome-PC-Jerome Jerome-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2012-10-01] (Microsoft Corporation)
Task: {E9C41C62-CCBF-4768-A386-F9F022DE1F22} - System32\Tasks\Microsoft Office 15 Sync Maintenance for ALEAH-PC-Jerome Aleah-PC => C:\Program Files\Microsoft Office\Office15\MsoSync.exe [2012-10-01] (Microsoft Corporation)
Task: {EAE5977A-9435-42D9-9298-0433ACDC0DA9} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2012-10-01] (Microsoft Corporation)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2012-10-01 20:36 - 2012-10-01 20:36 - 006522480 _____ () C:\Program Files\Microsoft Office\Office15\1033\GrooveIntlResource.dll
2017-12-04 15:55 - 2017-12-04 15:55 - 000411133 ___SH () C:\Users\Jerome\AppData\Local\Temp\01d30382.exe
2017-12-04 16:05 - 2017-12-04 16:01 - 000097063 __RSH () C:\Users\Jerome\M-50500586850859759959469767487936945749799505950\winmgr.exe
2017-04-01 12:49 - 2017-04-01 12:49 - 023621808 _____ () C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_144.dll
2017-12-05 00:14 - 2017-12-05 00:14 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\csznadbyeh.exe
2017-12-05 00:15 - 2017-12-05 00:15 - 000411133 _____ () C:\Users\Jerome\AppData\Local\Temp\bxyieaimyc.exe
2017-12-04 15:56 - 2017-12-04 15:55 - 000411133 ___SH () C:\Users\Jerome\AppData\Roaming\svchostx64.exe
2017-08-17 16:51 - 2017-08-17 16:51 - 001993184 ____R () C:\Program Files (x86)\Skype\Phone\skypert.dll
2012-10-01 20:37 - 2012-10-01 20:37 - 006522480 _____ () C:\Program Files (x86)\Microsoft Office\Office15\1033\GrooveIntlResource.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 10:34 - 2017-09-30 08:00 - 000000865 _____ C:\Windows\system32\Drivers\etc\hosts
0.0.0.1 mssplus.mcafee.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-1141224537-1566625622-1964642510-1000\Control Panel\Desktop\\Wallpaper ->
DNS Servers: 192.168.22.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [{F6ADCFF5-F884-44F8-A4EF-0F5CF759F8E3}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{5A1FCF24-4A30-491B-8E0E-C700C2684268}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{CFE2533A-1A8E-4694-ACB1-4968CC0CB40F}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{121A1CC9-D3EE-4109-B01B-DE56BF7B480A}] => (Allow) C:\Program Files\Microsoft Office\Office15\lync.exe
FirewallRules: [{DC237C0E-5807-4373-A20F-ECCFD872276A}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{2E15237F-3E9F-43AA-A6C4-C5104ED25683}] => (Allow) C:\Program Files\Microsoft Office\Office15\UcMapi.exe
FirewallRules: [{E7951274-B8D0-4EBC-92D6-2ECAA1CED349}] => (Allow) C:\Users\Jerome\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{A9065BA6-0B98-4C01-949D-C7053958A067}] => (Allow) C:\Users\Jerome\AppData\Roaming\uTorrent\uTorrent.exe
FirewallRules: [{065FA1A5-5BBC-4D77-A166-64DC3D6A7FF7}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{4751BB15-B1F8-47C3-98D5-81D7274EE0DC}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe
FirewallRules: [UDP Query User{DCC8924E-C16F-47AE-9FEA-23301FE857AE}C:\program files\videolan\vlc\vlc.exe] => (Block) C:\program files\videolan\vlc\vlc.exe
==================== Restore Points =========================
24-11-2017 12:24:28 Scheduled Checkpoint
01-12-2017 15:34:31 Scheduled Checkpoint
==================== Faulty Device Manager Devices =============
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Bluetooth Peripheral Device
Description: Bluetooth Peripheral Device
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (12/05/2017 12:21:35 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.
Details:
The system cannot find the file specified. (HRESULT : 0x80070002) (0x80070002)
Error: (12/05/2017 12:21:35 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.
Context: Windows Application
Details:
The system cannot find the file specified. (HRESULT : 0x80070002) (0x80070002)
Error: (12/05/2017 12:21:35 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: The gatherer object cannot be initialized.
Context: Windows Application, SystemIndex Catalog
Details:
The system cannot find the file specified. (HRESULT : 0x80070002) (0x80070002)
Error: (12/05/2017 12:21:35 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in <Search.TripoliIndexer> cannot be initialized.
Context: Windows Application, SystemIndex Catalog
Details:
The system cannot find the file specified. (HRESULT : 0x80070002) (0x80070002)
Error: (12/05/2017 12:20:38 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.
Details:
The system cannot find the file specified. (HRESULT : 0x80070002) (0x80070002)
Error: (12/05/2017 12:20:38 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.
Context: Windows Application
Details:
The system cannot find the file specified. (HRESULT : 0x80070002) (0x80070002)
Error: (12/05/2017 12:20:38 AM) (Source: Windows Search Service) (EventID: 3028) (User: )
Description: The gatherer object cannot be initialized.
Context: Windows Application, SystemIndex Catalog
Details:
The system cannot find the file specified. (HRESULT : 0x80070002) (0x80070002)
Error: (12/05/2017 12:20:38 AM) (Source: Windows Search Service) (EventID: 3029) (User: )
Description: The plug-in in <Search.TripoliIndexer> cannot be initialized.
Context: Windows Application, SystemIndex Catalog
Details:
The system cannot find the file specified. (HRESULT : 0x80070002) (0x80070002)
Error: (12/05/2017 12:20:01 AM) (Source: Windows Search Service) (EventID: 7010) (User: )
Description: The index cannot be initialized.
Details:
The system cannot find the file specified. (HRESULT : 0x80070002) (0x80070002)
Error: (12/05/2017 12:20:01 AM) (Source: Windows Search Service) (EventID: 3058) (User: )
Description: The application cannot be initialized.
Context: Windows Application
Details:
The system cannot find the file specified. (HRESULT : 0x80070002) (0x80070002)
System errors:
=============
Error: (12/05/2017 12:21:35 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 21 time(s).
Error: (12/05/2017 12:21:35 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Search service terminated with the following error:
The system cannot find the file specified.
Error: (12/05/2017 12:20:39 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 20 time(s).
Error: (12/05/2017 12:20:39 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Search service terminated with the following error:
The system cannot find the file specified.
Error: (12/05/2017 12:20:02 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 19 time(s).
Error: (12/05/2017 12:20:02 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Search service terminated with the following error:
The system cannot find the file specified.
Error: (12/05/2017 12:19:54 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 18 time(s).
Error: (12/05/2017 12:19:54 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Search service terminated with the following error:
The system cannot find the file specified.
Error: (12/05/2017 12:19:47 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
Description: The Windows Search service terminated unexpectedly. It has done this 17 time(s).
Error: (12/05/2017 12:19:47 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Windows Search service terminated with the following error:
The system cannot find the file specified.
CodeIntegrity:
===================================
Date: 2017-04-01 12:18:54.973
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\RTKVHD64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-04-01 12:18:54.911
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\RTKVHD64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-04-01 12:16:41.624
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\RTKVHD64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-04-01 12:16:41.515
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\RTKVHD64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-04-01 12:05:38.784
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\RTKVHD64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2017-04-01 12:05:38.737
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\drivers\RTKVHD64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
==================== Memory info ===========================
Processor: AMD A8-5545M APU with Radeon™ HD Graphics
Percentage of memory in use: 49%
Total physical RAM: 5321.89 MB
Available physical RAM: 2661.19 MB
Total Virtual: 10641.93 MB
Available Virtual: 7675.74 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:104.39 GB) (Free:15.11 GB) NTFS
Drive d: () (Fixed) (Total:361.27 GB) (Free:320.11 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 6CE6BB76)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=104.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=361.3 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================