Jump to content

bsacco

Honorary Members
  • Posts

    40
  • Joined

  • Last visited

Reputation

0 Neutral
  1. left click on PC mouse to scan a specific file? Can Malware bytes do this?
  2. Still getting Pup virus Optional.ASK even after restart. please advise.
  3. # AdwCleaner 7.0.4.0 - Logfile created on Thu Nov 16 19:25:08 2017 # Updated on 2017/27/10 by Malwarebytes # Database: 11-15-2017.1 # Running on Windows 7 Professional (X64) # Mode: scan # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** No malicious registry entries found. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries. ***** [ Chromium (and derivatives) ] ***** PUP.Optional.Legacy, SearchProvider found: Ask Search - ask search /!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271 ************************* C:/AdwCleaner/AdwCleaner[C0].txt - [1198 B] - [2017/11/11 17:53:11] C:/AdwCleaner/AdwCleaner[C1].txt - [1336 B] - [2017/11/11 18:31:9] C:/AdwCleaner/AdwCleaner[C2].txt - [1426 B] - [2017/11/11 22:25:22] C:/AdwCleaner/AdwCleaner[C3].txt - [1630 B] - [2017/11/16 0:29:27] C:/AdwCleaner/AdwCleaner[S0].txt - [1193 B] - [2017/11/11 17:52:13] C:/AdwCleaner/AdwCleaner[S1].txt - [1331 B] - [2017/11/11 18:16:11] C:/AdwCleaner/AdwCleaner[S2].txt - [1403 B] - [2017/11/11 18:34:10] C:/AdwCleaner/AdwCleaner[S3].txt - [1365 B] - [2017/11/11 22:29:0] C:/AdwCleaner/AdwCleaner[S4].txt - [1608 B] - [2017/11/16 0:29:5] ########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt ########## Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 16-11-2017 Ran by Administrator (administrator) on DELL8700-PC (16-11-2017 12:06:30) Running from E:\DOWNLOADS Loaded Profiles: Administrator (Available Profiles: Bob & Administrator) Platform: Windows 7 Professional Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Chrome) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ESET) C:\Program Files\ESET\ESET Security\ekrn.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe () C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AdminService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Microsoft Office 15\ClientX64\officeclicktorun.exe (Code 42 Software) C:\Program Files\CrashPlan\CrashPlanService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe (TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Atheros) C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Dell Inc.) C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe () C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Qualcomm®Atheros®) C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Amazon Services LLC) C:\Users\Administrator\AppData\Local\Amazon Music\Amazon Music Helper.exe () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Logitech, Inc.) C:\Program Files\Logitech\SetPointP\SetPoint.exe (Code 42 Software, Inc.) C:\Program Files\CrashPlan\CrashPlanTray.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe (ESET) C:\Program Files\ESET\ESET Security\egui.exe (Logitech, Inc.) C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.exe (Dell) C:\Users\Administrator\AppData\Local\Apps\2.0\C2AYRA27.C60\QDQ7MZTB.GXR\dell..tion_831211ca63b981c5_0008.0008_b150a6542eb950c1\DellSystemDetect.exe (TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 13\Snagit32.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Acronis International GmbH) C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (CANON INC.) C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 13\SnagPriv.exe (TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 13\SnagitEditor.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (PreSonus) C:\Program Files (x86)\PreSonus\Studio One 3\Studio One.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\taskmgr.exe (Malwarebytes) E:\BOB GUITAR SHEET MUSIC\JAZZ FUSION PROJECT\Melinda's Atlas\AdwCleaner.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe () C:\Program Files (x86)\Acronis\TrueImageHome\SystemReport.exe (Microsoft Corporation) C:\Windows\System32\msinfo32.exe (Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7188040 2013-05-10] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1307720 2013-04-24] (Realtek Semiconductor) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [286704 2013-04-30] (Intel Corporation) HKLM\...\Run: [Acronis Scheduler2 Service] => C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [567088 2017-06-23] () HKLM\...\Run: [EvtMgr6] => C:\Program Files\Logitech\SetPointP\SetPoint.exe [3113592 2015-08-25] (Logitech, Inc.) HKLM\...\Run: [CrashPlanTray] => C:\Program Files\CrashPlan\CrashPlanTray.exe [462816 2017-07-27] (Code 42 Software, Inc.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [303928 2017-07-14] (Apple Inc.) HKLM\...\Run: [egui] => C:\Program Files\ESET\ESET Security\ecmdS.exe [324216 2017-11-12] (ESET) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [640376 2008-06-11] (Adobe Systems Inc.) HKLM-x32\...\Run: [AcronisTibMounterMonitor] => C:\Program Files (x86)\Common Files\Acronis\TibMounter\TibMounterMonitor.exe [421768 2016-04-25] (Acronis International GmbH) HKLM-x32\...\Run: [TrueImageMonitor.exe] => C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [7390424 2017-06-23] () HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452272 2012-08-31] (CANON INC.) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-08-04] (Advanced Micro Devices, Inc.) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe [134784 2014-10-28] (Qualcomm®Atheros®) HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8912088 2016-08-26] (Piriform Ltd) HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\Run: [GoogleChromeAutoLaunch_361C1DD22E1256C6B68316A32E8B1949] => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe [1556312 2017-11-10] (Google Inc.) HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\Run: [DellSystemDetect] => C:\Users\Administrator\AppData\Local\Apps\2.0\C2AYRA27.C60\QDQ7MZTB.GXR\dell..tion_831211ca63b981c5_0008.0008_b150a6542eb950c1\DellSystemDetect.exe [314544 2017-09-26] (Dell) HKU\S-1-5-21-709187934-3287193120-2459991863-500\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Bubbles.scr [899584 2010-11-20] (Microsoft Corporation) AppInit_DLLs: acaptuser64.dll => C:\Windows\system32\acaptuser64.dll [119160 2008-06-11] (Adobe Systems, Inc.) AppInit_DLLs-x32: acaptuser32.dll => C:\Windows\SysWOW64\acaptuser32.dll [111992 2008-06-11] (Adobe Systems, Inc.) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TSC_SI_13.lnk [2017-11-14] ShortcutTarget: TSC_SI_13.lnk -> C:\Program Files (x86)\TechSmith\Snagit 13\Snagit32.exe (TechSmith Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Hosts: 127.0.0.1 activation.acronis.com Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{54277E84-CFB4-4787-BDE2-40E01907A7D7}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{7D2DB1FE-201A-4404-833B-88BAE3979F52}: [DhcpNameServer] 192.168.1.1 Internet Explorer: ================== HKU\S-1-5-21-709187934-3287193120-2459991863-500\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/?ocid=iehp BHO: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\OCHelper.dll [2017-09-05] (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.) BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\URLREDIR.DLL [2017-09-05] (Microsoft Corporation) BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\GROOVEEX.DLL [2017-09-05] (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11] (Adobe Systems Incorporated) BHO-x32: Skype for Business Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files\Microsoft Office 15\root\Office15\OCHelper.dll [2017-08-15] (Microsoft Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated) BHO-x32: Logitech SetPoint -> {AF949550-9094-4807-95EC-D1C317803333} -> C:\Program Files\Logitech\SetPointP\32-bit\SetPointSmooth.dll [2015-08-25] (Logitech, Inc.) BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office 15\root\Office15\URLREDIR.DLL [2017-09-05] (Microsoft Corporation) BHO-x32: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office 15\root\Office15\GROOVEEX.DLL [2017-09-05] (Microsoft Corporation) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2008-06-11] (Adobe Systems Incorporated) IE Session Restore: HKU\S-1-5-21-709187934-3287193120-2459991863-500 -> is enabled. Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2016-01-04] (Belarc, Inc.) Handler-x32: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office 15\root\Office15\MSOSB.DLL [2017-07-18] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\96k4i7wt.default [2017-11-16] FF HKLM-x32\...\Firefox\Extensions: [{F003DA68-8256-4b37-A6C4-350FA04494DF}] - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt FF Extension: (Logitech SetPoint) - C:\Program Files\Logitech\SetPointP\LogiSmoothFirefoxExt [2016-08-28] [Lagacy] [not signed] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_187.dll [2017-11-14] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_187.dll [2017-11-14] () FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2016-04-13] (CANON INC.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.0.72 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2013-01-24] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2013-01-24] (Intel Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2016-08-24] (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files\Microsoft Office 15\root\Office15\NPSPWRAP.DLL [2016-08-24] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-13] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN) FF Plugin HKU\S-1-5-21-709187934-3287193120-2459991863-500: @zoom.us/ZoomVideoPlugin -> C:\Users\Administrator\AppData\Roaming\Zoom\bin\npzoomplugin.dll [2017-10-12] (Zoom Video Communications, Inc.) Chrome: ======= CHR HomePage: Default -> hxxp://www.google.com/ CHR StartupUrls: Default -> "","hxxp://www.google.com/","hxxp://www.bigwest.org/sports/msoccer/","hxxp://www.ncaa.com/sports/soccer-men/d1","hxxp://www.nytimes.com/","hxxps://energyreview.apparent.com/site/view/id/145","hxxp://dealnews.com/c51/Computers/Storage/","hxxp://www.linkedin.com/","hxxp://ucsbgauchos.com/sports/m-soccer/2016-17/news" CHR Profile: C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default [2017-11-16] CHR Extension: (Slides) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2017-10-12] CHR Extension: (Docs) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2017-10-12] CHR Extension: (Google Drive) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2016-09-07] CHR Extension: (YouTube) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2016-09-07] CHR Extension: (Honey) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmnlcjabgnpnenekpadlanbbkooimhnj [2017-11-16] CHR Extension: (Adblock Plus) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2017-09-26] CHR Extension: (Scroll To Top Button) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\chinfkfmaefdlchhempbfgbdagheknoj [2017-09-13] CHR Extension: (Lead Website Tracking for Gmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckcfbaabfiikgfbjmndbpmegifphmjkp [2017-11-08] CHR Extension: (FullContact for Gmail & Inbox) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\cnaibnehbbinoohhjafknihmlopdhhip [2017-11-14] CHR Extension: (RokuCast) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\colepknnmkjpnooobdflkniegcfgaahg [2017-10-07] CHR Extension: (Listango Bookmark Manager) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\dmbdkkenkdllkpiognpnmlaglmojagnh [2016-09-07] CHR Extension: (Solitaire Games) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\eljmkmbmhmgmpmmbkagbobpmpocacdbo [2016-09-07] CHR Extension: (Sheets) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2017-10-12] CHR Extension: (Wunderlist - To-do and Task list) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjliknjliaohjgjajlgolhijphojjdkc [2016-09-07] CHR Extension: (Page Analytics (by Google)) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnbdnhhicmebfgdgglcdacdapkcihcoh [2016-10-08] CHR Extension: (Updentity Data Grabber) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gananjllhfdmdhkkgeffhfamjfggdodj [2017-09-29] CHR Extension: (Google Docs Offline) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-09-15] CHR Extension: (AdBlock) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2017-11-14] CHR Extension: (Fast Bookmark Scanner) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gjcmklpilmpfhfjpebhnapnglcppdbic [2017-01-31] CHR Extension: (Mailto:) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\gppbppehiogfokmpligejhaepeopajdf [2017-01-31] CHR Extension: (Scroll To Top) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hegiignepmecppikdlbohnnbfjdoaghj [2017-07-13] CHR Extension: (Checker Plus for Google Calendar™) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkhggnncdpfibdhinjiegagmopldibha [2017-09-13] CHR Extension: (Kindle Cloud Reader) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd [2016-09-07] CHR Extension: (Remove ads from Pirate Bay) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\imkpamgpfalmdaikobnkefcmmkpgljjd [2017-05-10] CHR Extension: (Color Enhancer) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ipkjmjaledkapilfdigkgfmpekpfnkih [2017-04-05] CHR Extension: (WhatFont) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jabopobgcpjmedljpbcaablpmlmfcogm [2017-05-10] CHR Extension: (Yet Another Google Bookmarks Extension) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jdnejaepfmacfdmhkplckpfdcjgbeode [2016-10-22] CHR Extension: (Bookmarks Menu) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhlkofhkkahcpbmgbgmopdjephahdeej [2016-09-07] CHR Extension: (Gmail Sender Icons) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\jniljaamodclkmphgkgkooplflhkadpg [2017-08-31] CHR Extension: (Grammarly for Chrome) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kbfnbcaeplbcioakkpcpgfkobkghlhen [2017-11-11] CHR Extension: (Support Free Content) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kffpbhfpflaacppoegnbknokchggcoao [2017-10-16] CHR Extension: (ToutApp Sales Communications) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfjjpjjnmkhalkjiaomecjddeapodgob [2016-09-07] CHR Extension: (Chrome Audio Capture) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfokdmfpdnokpmpbjhjbcabgligoelgp [2017-11-15] CHR Extension: (LinkedIn Export Tool) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgipmhdegifoehfbbffcfbmpfmbjaiem [2017-07-20] CHR Extension: (Zoom Scheduler) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kgjfgplpablkjnlkjmjdecgdpfankdle [2017-11-15] CHR Extension: (OBTrack for Gmail Tracking & Email Opens) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\kncjjpadnffmhejaokhcneeihhneiepp [2017-10-19] CHR Extension: (Google Hangouts) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\knipolnnllmklapflnccelgolnpehhpl [2017-05-10] CHR Extension: (Evernote Web) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol [2016-09-07] CHR Extension: (Bookmark Checker) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\lnboppjpcdnckcklbmjmdahfkpmgglec [2017-06-23] CHR Extension: (Scraper) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbigbapnjcgaffohmbkdlecaccepngjd [2017-10-16] CHR Extension: (Multilingual TTS Engine) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\megclklaoidjbomplbhbdgbelkoebbdl [2016-09-07] CHR Extension: (Ghostery) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij [2017-11-08] CHR Extension: (Mailtrack for Gmail & Inbox: Email tracking) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndnaehgpjlnokgebbaldlmgkapkpjkkb [2017-11-16] CHR Extension: (Similar Sites - Discover Related Websites) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\necpbmbhhdiplmfhmjicabdeighkndkn [2017-09-26] CHR Extension: (Chrome Web Store Payments) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-27] CHR Extension: (Data Scraper - Easy Web Scraping) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\nndknepjnldbdbepjfgmncbggmopgden [2017-10-16] CHR Extension: (Neater Bookmarks) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofgjggbjanlhbgaemjbkiegeebmccifi [2017-01-31] CHR Extension: (Bookmax - Online Bookmark Manager) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\ofjpkfadmfhloombfmmlllnbhkoehckm [2016-09-07] CHR Extension: (HubSpot Sales) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiiaigjnkhngdbnoookogelabohpglmd [2017-11-14] CHR Extension: (WeVideo - Video Editor and Maker) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\okgjbfikepgflmlelgfgecmgjnmnmnnb [2016-09-07] CHR Extension: (Send from Gmail (by Google)) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc [2016-09-07] CHR Extension: (Gmail) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2016-09-07] CHR Extension: (Chrome Media Router) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-11-16] CHR Extension: (Metronome) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\plhigbggmkcenbdicegndnfdkggfppae [2016-09-07] CHR Extension: (Scraper) - C:\Users\Administrator\AppData\Local\Google\Chrome\User Data\Default\Extensions\poegfpiagjgnenagjphgdklmgcpjaofi [2016-09-07] ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AcrSch2Svc; C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe [1244408 2017-06-23] () R2 afcdpsrv; C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe [4463592 2017-08-29] () R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-04-03] (Apple Inc.) R2 AtherosSvc; C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe [322176 2014-10-28] (Windows (R) Win 7 DDK provider) [File not signed] R2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [3058416 2017-09-05] (Microsoft Corporation) R2 CrashPlanService; C:\Program Files\CrashPlan\CrashPlanService.exe [267744 2017-07-27] (Code 42 Software) R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [230248 2017-05-01] (Dell Inc.) R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2648184 2017-11-12] (ESET) S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2016-08-22] (Macrovision Europe Ltd.) [File not signed] R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [15344 2013-04-30] (Intel Corporation) R2 IconMan_R; C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2451456 2012-07-13] (Realsil Microelectronics Inc.) [File not signed] R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [167736 2013-01-31] (Intel Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes) R2 mmsminisrv; C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe [4884064 2015-08-11] (Acronis) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [224840 2013-05-10] (Realtek Semiconductor) R2 SupportAssistAgent; C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssistAgent.exe [53208 2017-09-22] (Dell Inc.) R2 syncagentsrv; C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe [9698296 2016-04-16] () R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3661096 2015-09-14] (TechSmith Corporation) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation) R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [81536 2014-05-13] (Atheros) [File not signed] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 BTATH_LWFLT; C:\Windows\System32\DRIVERS\btath_lwflt.sys [77464 2014-10-28] (Qualcomm Atheros) S3 DDDriver; C:\Windows\System32\drivers\DDDriver64Dcsa.sys [32352 2016-10-13] (Dell Inc.) S3 DellProf; C:\Windows\System32\drivers\DellProf.sys [32952 2016-10-13] (Dell Computer Corporation) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [132848 2017-11-12] (ESET) R0 edevmon; C:\Windows\System32\DRIVERS\edevmon.sys [107344 2017-04-25] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [180088 2017-11-12] (ESET) R2 ekbdflt; C:\Windows\System32\DRIVERS\ekbdflt.sys [50752 2017-04-25] (ESET) R1 epfw; C:\Windows\System32\DRIVERS\epfw.sys [78192 2017-04-25] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [60544 2017-04-25] (ESET) R1 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [102160 2017-11-12] (ESET) S3 ESETCleanersDriver; C:\Windows\system32\Drivers\ESETCleanersDriver.sys [181160 2017-08-29] (ESET) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-08-24] () R0 file_tracker; C:\Windows\System32\DRIVERS\file_tracker.sys [366432 2017-08-29] (Acronis International GmbH) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [28656 2013-04-30] (Intel Corporation) R3 L6TPortB; C:\Windows\System32\Drivers\L6TPortB64.sys [777728 2015-08-21] (Line 6) R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [192960 2017-11-11] (Malwarebytes) R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [101824 2017-11-15] (Malwarebytes) R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [45472 2017-11-15] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [253888 2017-11-15] (Malwarebytes) R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [84256 2017-11-16] (Malwarebytes) R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [116736 2014-02-19] (Intel Corporation) S3 RDID1115; C:\Windows\System32\Drivers\rdwm1115.sys [82304 2012-10-23] (Roland Corporation) R3 teVirtualMIDI64; C:\Windows\System32\DRIVERS\teVirtualMIDI64.sys [41016 2015-07-12] (Tobias Erichsen) R0 tib; C:\Windows\System32\DRIVERS\tib.sys [1267552 2017-08-29] (Acronis International GmbH) R2 tib_mounter; C:\Windows\System32\DRIVERS\tib_mounter.sys [193376 2017-08-29] (Acronis International GmbH) S3 tnd; C:\Windows\System32\DRIVERS\tnd.sys [601432 2017-08-29] (Acronis International GmbH) S3 VBAudioVACMME; C:\Windows\System32\DRIVERS\vbaudio_cable64_win7.sys [41192 2015-12-04] (Windows (R) Win 7 DDK provider) R2 virtual_file; C:\Windows\System32\DRIVERS\virtual_file.sys [279392 2016-08-25] (Acronis International GmbH) R3 XtuAcpiDriver; C:\Windows\System32\DRIVERS\XtuAcpiDriver.sys [54344 2016-11-22] (Intel Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-11-16 12:05 - 2017-11-16 12:06 - 000000000 ____D C:\FRST 2017-11-16 08:32 - 2017-11-16 08:32 - 000000000 ___RD C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2017-11-15 07:53 - 2017-11-15 07:53 - 000001909 _____ C:\Users\Administrator\Desktop\Zoom.lnk 2017-11-15 01:14 - 2017-10-17 23:31 - 000395976 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2017-11-15 01:14 - 2017-10-17 22:45 - 000347336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2017-11-15 01:14 - 2017-10-17 18:34 - 000134376 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe 2017-11-15 01:14 - 2017-10-17 18:30 - 000605184 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2017-11-15 01:14 - 2017-10-17 18:06 - 000344064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2017-11-15 01:14 - 2017-10-17 18:06 - 000327168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2017-11-15 01:14 - 2017-10-17 18:06 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2017-11-15 01:14 - 2017-10-17 18:06 - 000056320 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2017-11-15 01:14 - 2017-10-17 18:06 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2017-11-15 01:14 - 2017-10-17 18:06 - 000025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2017-11-15 01:14 - 2017-10-17 18:06 - 000007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2017-11-15 01:14 - 2017-10-16 15:07 - 001680616 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2017-11-15 01:14 - 2017-10-16 14:34 - 003222528 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2017-11-15 01:14 - 2017-10-16 13:55 - 000339968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msexcl40.dll 2017-11-15 01:14 - 2017-10-15 14:04 - 000407392 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll 2017-11-15 01:14 - 2017-10-14 00:38 - 025731584 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-11-15 01:14 - 2017-10-14 00:23 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2017-11-15 01:14 - 2017-10-14 00:23 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2017-11-15 01:14 - 2017-10-14 00:13 - 002903552 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2017-11-15 01:14 - 2017-10-14 00:12 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2017-11-15 01:14 - 2017-10-14 00:11 - 000576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-11-15 01:14 - 2017-10-14 00:11 - 000417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2017-11-15 01:14 - 2017-10-14 00:11 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2017-11-15 01:14 - 2017-10-14 00:11 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2017-11-15 01:14 - 2017-10-14 00:09 - 005979648 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-11-15 01:14 - 2017-10-14 00:05 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2017-11-15 01:14 - 2017-10-14 00:04 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2017-11-15 01:14 - 2017-10-14 00:02 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2017-11-15 01:14 - 2017-10-14 00:01 - 000816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2017-11-15 01:14 - 2017-10-14 00:01 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2017-11-15 01:14 - 2017-10-14 00:01 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2017-11-15 01:14 - 2017-10-14 00:00 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2017-11-15 01:14 - 2017-10-13 23:55 - 000968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2017-11-15 01:14 - 2017-10-13 23:53 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2017-11-15 01:14 - 2017-10-13 23:47 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2017-11-15 01:14 - 2017-10-13 23:47 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2017-11-15 01:14 - 2017-10-13 23:46 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2017-11-15 01:14 - 2017-10-13 23:43 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2017-11-15 01:14 - 2017-10-13 23:43 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2017-11-15 01:14 - 2017-10-13 23:41 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2017-11-15 01:14 - 2017-10-13 23:40 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2017-11-15 01:14 - 2017-10-13 23:31 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2017-11-15 01:14 - 2017-10-13 23:30 - 015266816 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-11-15 01:14 - 2017-10-13 23:30 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2017-11-15 01:14 - 2017-10-13 23:29 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2017-11-15 01:14 - 2017-10-13 23:28 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2017-11-15 01:14 - 2017-10-13 23:27 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2017-11-15 01:14 - 2017-10-13 23:21 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2017-11-15 01:14 - 2017-10-13 23:14 - 020269056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-11-15 01:14 - 2017-10-13 23:09 - 001544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2017-11-15 01:14 - 2017-10-13 23:03 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2017-11-15 01:14 - 2017-10-13 22:58 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2017-11-15 01:14 - 2017-10-13 22:53 - 000499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-11-15 01:14 - 2017-10-13 22:53 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2017-11-15 01:14 - 2017-10-13 22:52 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2017-11-15 01:14 - 2017-10-13 22:52 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2017-11-15 01:14 - 2017-10-13 22:51 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2017-11-15 01:14 - 2017-10-13 22:50 - 002293760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2017-11-15 01:14 - 2017-10-13 22:47 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2017-11-15 01:14 - 2017-10-13 22:47 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2017-11-15 01:14 - 2017-10-13 22:46 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2017-11-15 01:14 - 2017-10-13 22:45 - 000662016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2017-11-15 01:14 - 2017-10-13 22:45 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2017-11-15 01:14 - 2017-10-13 22:45 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2017-11-15 01:14 - 2017-10-13 22:38 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2017-11-15 01:14 - 2017-10-13 22:35 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2017-11-15 01:14 - 2017-10-13 22:35 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2017-11-15 01:14 - 2017-10-13 22:34 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2017-11-15 01:14 - 2017-10-13 22:33 - 004542464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-11-15 01:14 - 2017-10-13 22:33 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2017-11-15 01:14 - 2017-10-13 22:32 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2017-11-15 01:14 - 2017-10-13 22:31 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2017-11-15 01:14 - 2017-10-13 22:30 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2017-11-15 01:14 - 2017-10-13 22:28 - 013680128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-11-15 01:14 - 2017-10-13 22:25 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2017-11-15 01:14 - 2017-10-13 22:24 - 000694272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2017-11-15 01:14 - 2017-10-13 22:23 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2017-11-15 01:14 - 2017-10-13 22:23 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2017-11-15 01:14 - 2017-10-13 22:10 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2017-11-15 01:14 - 2017-10-13 22:07 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2017-11-15 01:14 - 2017-10-13 22:04 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2017-11-15 01:14 - 2017-10-11 16:58 - 000382696 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 014635008 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 012574720 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2017-11-15 01:14 - 2017-10-11 16:55 - 002319872 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 002222080 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 002058240 _____ (Microsoft Corporation) C:\Windows\system32\Query.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000778240 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000491520 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000288256 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000151552 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000115200 _____ (Microsoft Corporation) C:\Windows\system32\mssitlb.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000099840 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000075264 _____ (Microsoft Corporation) C:\Windows\system32\msscntrs.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\msshooks.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll 2017-11-15 01:14 - 2017-10-11 16:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx 2017-11-15 01:14 - 2017-10-11 16:55 - 000005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll 2017-11-15 01:14 - 2017-10-11 16:40 - 000308456 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2017-11-15 01:14 - 2017-10-11 16:39 - 000591872 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2017-11-15 01:14 - 2017-10-11 16:38 - 000249856 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe 2017-11-15 01:14 - 2017-10-11 16:38 - 000113664 _____ (Microsoft Corporation) C:\Windows\system32\SearchFilterHost.exe 2017-11-15 01:14 - 2017-10-11 16:37 - 012574208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL 2017-11-15 01:14 - 2017-10-11 16:37 - 011410944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 001549824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 001400320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 001363968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Query.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 000666624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 000337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 000197120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssphtb.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 000111104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 000104448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssitlb.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 000070656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 000059392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscntrs.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 000034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssprxy.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll 2017-11-15 01:14 - 2017-10-11 16:37 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll 2017-11-15 01:14 - 2017-10-11 16:26 - 000427520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2017-11-15 01:14 - 2017-10-11 16:26 - 000164352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe 2017-11-15 01:14 - 2017-10-11 16:25 - 000086528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchFilterHost.exe 2017-11-15 01:14 - 2017-10-11 16:25 - 000009728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msshooks.dll 2017-11-15 01:14 - 2017-10-11 16:24 - 000008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll 2017-11-15 01:14 - 2017-10-11 16:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx 2017-11-15 01:14 - 2017-10-11 16:24 - 000004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll 2017-11-15 01:14 - 2017-10-11 16:20 - 000113152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\luafv.sys 2017-11-15 01:14 - 2017-10-11 16:16 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2017-11-15 01:14 - 2017-10-04 05:04 - 002023936 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2017-11-15 01:14 - 2017-10-04 05:04 - 001570304 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2017-11-15 01:14 - 2017-10-04 05:04 - 000670208 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2017-11-15 01:14 - 2017-10-04 05:04 - 000603648 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2017-11-15 01:14 - 2017-10-04 05:04 - 000370688 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2017-11-15 01:14 - 2017-10-04 05:04 - 000241664 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2017-11-15 01:14 - 2017-10-04 05:04 - 000181760 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000995272 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000922432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000066400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-private-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000063840 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-private-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000022368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-math-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000020832 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-math-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000019808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-multibyte-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000019808 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-multibyte-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-string-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-stdio-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-string-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000017760 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-stdio-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000016224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-runtime-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000016224 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-runtime-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000015712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-convert-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000015712 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-convert-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-time-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-2-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-time-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000014176 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-2-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000013664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-filesystem-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000013664 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-filesystem-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-process-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-heap-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-conio-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-process-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-heap-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012640 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-conio-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-utility-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-locale-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-crt-environment-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-2-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-1.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-utility-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-locale-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-crt-environment-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-2-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000012128 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-1.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l2-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-timezone-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l2-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-2-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l2-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-timezone-l1-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l2-1-0.dll 2017-11-15 01:14 - 2017-09-07 05:05 - 000011616 _____ (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-2-0.dll 2017-11-14 13:06 - 2017-11-14 13:06 - 000000000 ____D C:\Users\Administrator\Documents\Zoom 2017-11-14 07:00 - 2017-11-14 07:00 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechSmith 2017-11-12 10:37 - 2017-11-12 10:37 - 000000000 ____D C:\Users\Administrator\Documents\MuseScore2 2017-11-11 14:20 - 2017-11-11 14:20 - 000000000 ____D C:\KVRT_Data 2017-11-11 14:18 - 2017-11-11 14:19 - 131370792 _____ (Kaspersky Lab ZAO) C:\Users\Administrator\Downloads\KVRT.exe 2017-11-11 09:51 - 2017-11-16 11:25 - 000000000 ____D C:\AdwCleaner 2017-11-11 09:50 - 2017-11-11 09:50 - 008261584 _____ (Malwarebytes) C:\Users\Administrator\Downloads\AdwCleaner.exe 2017-11-11 09:16 - 2017-11-16 11:54 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2017-11-11 09:16 - 2017-11-15 16:30 - 000101824 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2017-11-11 09:16 - 2017-11-11 09:16 - 000192960 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys 2017-11-11 09:16 - 2017-11-11 09:16 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-11-11 09:16 - 2017-11-11 09:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-11-08 08:31 - 2017-11-08 08:31 - 000000000 ___HD C:\Users\Administrator\AppData\LocalLow\Temp 2017-11-07 18:01 - 2017-11-07 18:01 - 000536064 ____H () C:\Users\Administrator\Downloads\setup (1).exe 2017-10-30 15:43 - 2017-10-30 15:43 - 000977655 ____H C:\Users\Administrator\Downloads\1 page executive summary _TRILITHON2 (3).pages 2017-10-30 15:42 - 2017-10-30 15:42 - 000977655 ____H C:\Users\Administrator\Downloads\1 page executive summary _TRILITHON2.pages 2017-10-30 15:42 - 2017-10-30 15:42 - 000977655 ____H C:\Users\Administrator\Downloads\1 page executive summary _TRILITHON2 (2).pages 2017-10-30 15:42 - 2017-10-30 15:42 - 000977655 ____H C:\Users\Administrator\Downloads\1 page executive summary _TRILITHON2 (1).pages 2017-10-26 08:21 - 2017-10-26 08:21 - 000133640 ____H (Zoom Video Communications, Inc.) C:\Users\Administrator\Downloads\Zoom_launcher (2).exe 2017-10-26 01:23 - 2017-10-26 01:23 - 081633120 ____H (Logitech Inc.) C:\Users\Administrator\Downloads\SetPoint6.67.83_64.exe 2017-10-26 01:23 - 2017-10-26 01:23 - 004147600 ____H ($Co_Name Inc.) C:\Users\Administrator\Downloads\unifying250.exe 2017-10-24 12:45 - 2017-10-24 12:43 - 000040340 ____H C:\Users\Administrator\Desktop\Arvo-Regular.ttf 2017-10-23 10:48 - 2017-10-23 10:48 - 044066456 ____H C:\Users\Administrator\Downloads\AirfoilInstaller.exe 2017-10-21 16:02 - 2017-10-21 16:02 - 000000000 ___HD C:\Users\Administrator\Documents\Toontrack 2017-10-21 15:43 - 2017-10-21 16:02 - 000000000 ___HD C:\Users\Administrator\AppData\Roaming\Toontrack 2017-10-21 15:42 - 2017-10-21 15:42 - 000000000 ____D C:\ProgramData\Toontrack 2017-10-21 11:34 - 2017-10-21 11:34 - 000000000 ___HD C:\Users\Administrator\TruePianos Settings 2017-10-19 08:51 - 2017-10-19 08:51 - 002489979 ____H C:\Users\Administrator\Downloads\videolumascape2011-06-06-110606094021-phpapp01.pdf ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-11-16 11:17 - 2017-08-11 15:28 - 000000000 ___HD C:\Users\Administrator\AppData\Roaming\Celemony Software GmbH 2017-11-16 08:33 - 2016-09-15 09:19 - 000000000 ____D C:\Windows\Minidump 2017-11-16 08:33 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\inf 2017-11-16 03:31 - 2016-08-22 01:38 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk 2017-11-16 03:31 - 2016-08-22 01:38 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2017-11-16 03:27 - 2009-07-13 20:45 - 000031504 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-11-16 03:27 - 2009-07-13 20:45 - 000031504 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-11-15 16:36 - 2009-07-13 21:13 - 000804410 _____ C:\Windows\system32\PerfStringBackup.INI 2017-11-15 16:30 - 2017-05-28 09:33 - 000045472 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-11-15 16:30 - 2017-05-28 09:32 - 000253888 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-11-15 16:30 - 2009-07-13 21:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT 2017-11-15 15:25 - 2009-07-13 21:09 - 000000000 ____D C:\Windows\System32\Tasks\WPD 2017-11-15 15:20 - 2017-06-27 08:00 - 000000000 ___HD C:\Users\Administrator\AppData\Roaming\Arobas Music 2017-11-15 15:13 - 2016-10-15 15:28 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASAP Utilities 2017-11-15 15:13 - 2016-10-15 15:28 - 000000000 ____D C:\Program Files (x86)\ASAP Utilities 2017-11-15 14:56 - 2017-02-17 11:40 - 000000000 ___HD C:\Users\Administrator\AppData\Roaming\Skype 2017-11-15 13:29 - 2009-07-13 20:57 - 000001547 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk 2017-11-15 05:32 - 2009-07-13 19:20 - 000000000 ____D C:\Windows\rescache 2017-11-15 03:19 - 2009-07-13 20:45 - 000510768 _____ C:\Windows\system32\FNTCACHE.DAT 2017-11-15 03:18 - 2016-08-24 03:48 - 000000000 ____D C:\Windows\system32\appraiser 2017-11-15 03:01 - 2016-08-21 19:04 - 000796532 _____ C:\Windows\SysWOW64\PerfStringBackup.INI 2017-11-14 14:19 - 2016-11-19 10:41 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2017-11-14 14:19 - 2016-10-05 10:28 - 000004472 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2017-11-14 14:19 - 2016-08-31 12:57 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2017-11-14 14:19 - 2016-08-31 12:57 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2017-11-14 14:19 - 2016-08-31 12:57 - 000000000 ____D C:\Windows\SysWOW64\Macromed 2017-11-14 14:19 - 2016-08-31 12:57 - 000000000 ____D C:\Windows\system32\Macromed 2017-11-13 14:25 - 2016-08-22 01:37 - 000003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2017-11-13 14:25 - 2016-08-22 01:37 - 000003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2017-11-12 18:27 - 2017-07-08 09:23 - 000000000 ___HD C:\Users\Administrator\AppData\Roaming\MuseScore 2017-11-12 08:30 - 2017-04-25 12:19 - 000180088 _____ (ESET) C:\Windows\system32\Drivers\ehdrv.sys 2017-11-12 08:30 - 2017-04-25 12:19 - 000132848 _____ (ESET) C:\Windows\system32\Drivers\eamonm.sys 2017-11-12 08:30 - 2017-04-25 12:19 - 000102160 _____ (ESET) C:\Windows\system32\Drivers\epfwwfp.sys 2017-11-11 09:13 - 2016-09-18 12:44 - 000000000 ___HD C:\Users\Administrator\AppData\Local\CrashDumps 2017-11-11 08:39 - 2017-06-30 08:38 - 000000000 ____D C:\Program Files (x86)\VSTPlugins 2017-11-11 08:39 - 2017-01-04 12:18 - 000000000 ____D C:\Program Files (x86)\Plugins 2017-11-10 08:53 - 2017-09-26 07:38 - 000000000 ___HD C:\Users\Administrator\Downloads\Sound Cloud 2017-11-09 18:34 - 2017-09-26 15:20 - 000000000 ___HD C:\Users\Administrator\AppData\Local\ElevatedDiagnostics 2017-11-08 15:28 - 2016-08-21 21:51 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-11-08 15:26 - 2016-08-22 10:16 - 000000000 ____D C:\Program Files\Microsoft Office 15 2017-11-05 18:34 - 2010-11-20 23:16 - 000000000 ___RD C:\Users\Public\Recorded TV 2017-11-04 07:36 - 2017-08-14 12:41 - 000000000 ____D C:\Program Files (x86)\GoToMeeting 2017-10-26 01:31 - 2016-08-28 16:39 - 000018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2017-10-26 01:24 - 2016-08-28 16:39 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Logitech 2017-10-26 01:24 - 2016-08-28 16:38 - 000000000 ____D C:\ProgramData\Logishrd 2017-10-26 01:24 - 2016-08-28 16:38 - 000000000 ____D C:\Program Files\Common Files\LogiShrd 2017-10-24 13:06 - 2016-09-07 09:13 - 000127216 ____H C:\Users\Administrator\AppData\Local\GDIPFONTCACHEV1.DAT 2017-10-23 10:48 - 2016-08-29 11:44 - 000000000 ____D C:\Program Files (x86)\Airfoil 2017-10-21 11:34 - 2016-09-07 09:12 - 000000000 ___HD C:\Users\Administrator ==================== Files in the root of some directories ======= 2016-08-21 11:06 - 2017-01-04 12:18 - 000036312 _____ (Irfan Skiljan, IrfanView) C:\Program Files (x86)\iv_uninstall.exe 2015-07-26 19:48 - 2017-01-04 12:18 - 000002286 _____ () C:\Program Files (x86)\i_about.txt 2016-12-20 12:01 - 2017-01-04 12:18 - 000097096 _____ () C:\Program Files (x86)\i_changes.txt 2007-10-03 14:43 - 2017-01-04 12:18 - 000000765 _____ () C:\Program Files (x86)\i_languages.txt 2016-12-10 14:08 - 2017-01-04 12:18 - 000020615 _____ () C:\Program Files (x86)\i_options.txt 2016-12-13 18:16 - 2017-01-04 12:18 - 000014586 _____ () C:\Program Files (x86)\i_plugins.txt 2016-12-13 09:09 - 2017-01-04 12:18 - 000276960 _____ () C:\Program Files (x86)\i_view32.chm 2016-12-19 11:37 - 2017-01-04 12:18 - 000653272 _____ (Irfan Skiljan) C:\Program Files (x86)\i_view32.exe 2017-08-29 20:14 - 2017-08-29 20:15 - 503043688 ____H () C:\Users\Administrator\AppData\Local\AcronisTrueImage2016_6595.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-11-09 00:02 ==================== End of FRST.txt ============================ Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-11-2017 Ran by Administrator (16-11-2017 12:06:48) Running from E:\DOWNLOADS Windows 7 Professional Service Pack 1 (X64) (2016-08-21 22:09:32) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-709187934-3287193120-2459991863-500 - Administrator - Enabled) => C:\Users\Administrator Bob (S-1-5-21-709187934-3287193120-2459991863-1000 - Administrator - Enabled) => C:\Users\Bob Guest (S-1-5-21-709187934-3287193120-2459991863-501 - Limited - Enabled) John (S-1-5-21-709187934-3287193120-2459991863-1001 - Limited - Enabled) ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AV: ESET Smart Security (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70} AS: ESET Smart Security (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: ESET Personal firewall (Enabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 15.14 (x64) (HKLM\...\7-Zip) (Version: 15.14 - Igor Pavlov) Acronis True Image (HKLM-x32\...\{752A2878-1904-4B19-88A8-A07E58C8CE93}) (Version: 19.0.6595 - Acronis) Hidden Acronis True Image (HKLM-x32\...\{752A2878-1904-4B19-88A8-A07E58C8CE93}Visible) (Version: 19.0.6595 - Acronis) Acronis Universal Restore Bootable Media Builder (HKLM-x32\...\{04D88DAA-D470-401C-82F4-1ED699C626E9}) (Version: 11.5.40028 - Acronis) Adapter (HKLM-x32\...\{86085790-0A1A-4098-8CA9-579DB8F2771D}_is1) (Version: - Macroplant, LLC) Adobe Acrobat 9 Pro Extended - English, Français, Deutsch (HKLM-x32\...\{AC76BA86-1033-F400-7761-000000000004}{AC76BA86-1033-F400-7761-000000000004}) (Version: 9.0.0 - Adobe Systems) Adobe Acrobat 9 Pro Extended 64-bit Add-On (HKLM\...\{AC76BA86-1033-0000-0064-0003D0000004}) (Version: 9.0.0 - Adobe Systems Incorporated) Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.187 - Adobe Systems Incorporated) Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.187 - Adobe Systems Incorporated) Adobe Flash Player 27 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 27.0.0.187 - Adobe Systems Incorporated) Airfoil (HKLM-x32\...\Airfoil) (Version: 5.1.7 - Rogue Amoeba) Amazon Drive (HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\Amazon Drive) (Version: 4.0.19 - Amazon.com, Inc.) Amazon Music (HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\Amazon Amazon Music) (Version: 5.6.1.1094 - Amazon Services LLC) AMD Catalyst Install Manager (HKLM\...\{7E5DC2C5-115A-322B-976C-219237FAED66}) (Version: 8.0.916.0 - Advanced Micro Devices, Inc.) Apple Application Support (32-bit) (HKLM-x32\...\{D2FE6376-E549-4F63-A2C5-CA24DA035DE4}) (Version: 5.6 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{BB109E24-EE90-485B-A28B-ADDEFB40540B}) (Version: 5.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{0A596141-97D5-45FA-9281-98DFAF48D579}) (Version: 10.3.2.3 - Apple Inc.) Apple Software Update (HKLM-x32\...\{52D87F32-70E4-4348-8148-C0B9F35B1314}) (Version: 2.3.0.177 - Apple Inc.) ASAP Utilities (HKLM-x32\...\ASAP Utilities_is1) (Version: 7.4 - Bastien Mensink - A Must in Every Office BV) ASUS MultiFrame (HKLM-x32\...\{FB4D076A-DEFD-4EAF-AD63-70D5A3BC262A}) (Version: 1.1.1 - ASUS) ASUS Wireless Router Device Discovery Utility (HKLM-x32\...\{09CDCA35-23FF-4ED6-AFDA-BBD55235CE4B}) (Version: 1.4.8.0 - ASUS) Audacity 2.1.2 (HKLM-x32\...\Audacity®_is1) (Version: 2.1.2 - Audacity Team) Belarc Advisor 8.5c (HKLM-x32\...\Belarc Advisor) (Version: 8.5.3.0 - Belarc Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: 4.7.0 - Canon Inc.) Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - Canon Inc.) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.2.0 - Canon Inc.) Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.) Canon MX920 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX920_series) (Version: 1.01 - Canon Inc.) Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 3.5.1 - Canon Inc.) Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 3.5.0 - Canon Inc.) CCleaner (HKLM\...\CCleaner) (Version: 5.22 - Piriform) Chordastic (HKLM-x32\...\{4BB22EAF-4DFD-4D83-841E-BC38FD2934E9}) (Version: 1.3.6 - Chordastic) CrashPlan (HKLM\...\{879BBD10-45D3-4752-AA6B-FB789392946C}) (Version: 4.8.0.323 - Code 42 Software) CrashPlan PRO (HKLM\...\{FB02D7E4-5CD4-47C4-8562-C30110056794}) (Version: 4.9.0.33 - Code 42 Software) D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden Data Lifeguard Diagnostic for Windows 1.29 (HKLM-x32\...\{519C4DB6-B53B-4F5C-8297-89B2BE949FA5}_is1) (Version: - Western Digital Corporation) Dell Digital Delivery (HKLM-x32\...\{693A23FB-F28B-4F7A-A720-4C1263F97F43}) (Version: 3.1.1002.0 - Dell Products, LP) Dell SupportAssist (HKLM\...\PC-Doctor for Windows) (Version: 1.3.6817.133 - Dell) Dell SupportAssistAgent (HKLM\...\{18EF001B-B005-46CB-917B-112BA69ED85E}) (Version: 2.0.3.10 - Dell) Dell System Detect (HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\d24084d039586cae) (Version: 8.8.0.1 - Dell) Dell Update (HKLM-x32\...\{F91263FA-BE4D-439D-9C0A-2E7204E0E9E3}) (Version: 1.9.20.0 - Dell Inc.) Dell WLAN and Bluetooth Client Installation (HKLM-x32\...\{28006915-2739-4EBE-B5E8-49B25D32EB33}) (Version: 10.0 - Dell Inc.) DreamStation DXi2 (HKLM-x32\...\DreamStation DXi2) (Version: - ) ESET Smart Security (HKLM\...\{A8DEFAC8-2DD9-4BD8-902B-F026199F9916}) (Version: 10.1.210.0 - ESET, spol. s r.o.) EZdrummer (HKLM-x32\...\{43E8D9E7-AFC9-4BA3-8106-B95E02B87AB7}) (Version: 1.0 - Toontrack) EZXCocktail (HKLM-x32\...\{147567F0-8575-4BE0-B5B3-62706C67FA5A}) (Version: 1.0 - Toontrack) EZXFunkmasters (HKLM-x32\...\{BB5A44CB-3045-43E2-BEB0-B64E477D4633}) (Version: 1.0.0 - Toontrack) EZXJazz (HKLM-x32\...\{EED8D44F-CEBB-4298-8D0E-E01AF6AC0663}) (Version: 1.0.0 - Toontrack) EZXNashville (HKLM-x32\...\{82DF9225-13EC-41BD-BE31-AAB121B38166}) (Version: 1.0 - Toontrack) EZXPercussion (HKLM-x32\...\{2CC4BC82-41CF-43D3-B533-7283AA8BB86F}) (Version: 1.0 - Toontrack) EZXVintage (HKLM-x32\...\{430399DC-98BC-4A7F-8F8E-77981CABAE05}) (Version: 1.0 - Toontrack) File Renamer - Basic (HKLM-x32\...\File Renamer - Basic) (Version: 6.3 - Sherrod Computers) FlacSquisher 1.3.8 (HKLM-x32\...\FlacSquisher) (Version: 1.3.8 - FlacSquisher) Glary Duplicate Cleaner 5.0.1.22 (HKLM-x32\...\Glary Duplicate Cleaner) (Version: 5.0.1.22 - Glarysoft Ltd) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.94 - Google Inc.) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden GoTo Opener (HKLM-x32\...\{8B2D47CC-1558-4939-B27F-41E30530072A}) (Version: 1.0.467 - LogMeIn, Inc.) GoToMeeting 8.16.0.7881 (HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\GoToMeeting) (Version: 8.16.0.7881 - LogMeIn, Inc.) Grammarly (HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\GrammarlyForWindows) (Version: 1.5.29 - Grammarly) Grammarly for Microsoft® Office Suite (HKLM\...\{A7CA0D32-2DB1-44B7-9A23-1EB8412DE0E4}) (Version: 6.6.115 - Grammarly) Hidden Grammarly for Microsoft® Office Suite (HKLM\...\{F7C0146C-30D1-4DB5-9D84-D02453CA6BBB}) (Version: 6.5.85 - Grammarly) Hidden Grammarly for Microsoft® Office Suite (HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\{221c9b72-21d0-4d4e-8ee7-f35ebc4214f5}) (Version: 6.6.115 - Grammarly) Guitar Pro 6 (HKLM-x32\...\{14A487F2-1259-4E6C-AE3C-3C888DDBCB60}_is1) (Version: - Arobas Music) Guitar Pro 7 - Soundbanks (HKLM-x32\...\com.arobas-music.guitarpro7-soundbanks_is1) (Version: 1.0.69 - Arobas Music) Guitar Pro 7 (HKLM-x32\...\{BF4EDCFF-ED20-4AF6-A636-EBAC931336CD}_is1) (Version: 7.0.6.810 - Arobas Music) iCloud (HKLM\...\{5B1A59DA-D1EC-4C3A-A996-DF011A0A9668}) (Version: 6.2.2.39 - Apple Inc.) Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 10.0.0.1168 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.0.0.1310 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.6.0.1033 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 2.5.0.19 - Intel Corporation) iTunes (HKLM\...\{02F95875-9527-49CC-B32F-970ADAEBD1EF}) (Version: 12.6.2.20 - Apple Inc.) Kutools for Excel 16.50 (HKLM-x32\...\{A095BA43-4A97-4D55-8E25-A0BC46F10765}_is1) (Version: 16.50 - Addin Technology Inc.) LilyPond (HKLM-x32\...\LilyPond) (Version: - ) Line 6 Uninstaller (HKLM-x32\...\Line 6 Uninstaller) (Version: - Line 6) Logitech SetPoint 6.67 (HKLM\...\sp6) (Version: 6.67.83 - Logitech) Logitech Unifying Software 2.50 (HKLM\...\Logitech Unifying) (Version: 2.50.25 - Logitech) loopMIDI (HKLM-x32\...\{55c0d955-4cee-452c-b393-d4c020a967d7}) (Version: 1.0.13.24 - Tobias Erichsen) loopMIDI (HKLM-x32\...\{9E69C6CD-820A-44A9-9A0A-B7A56AD62A1E}) (Version: 1.0.13.24 - Tobias Erichsen) Hidden loopMIDIBlockLegacy (HKLM-x32\...\{AEAF7978-3204-451D-8593-BC53EBDDA31D}) (Version: 9.9.9.9 - Tobias Erichsen) Hidden Magic ISO Maker v5.5 (build 0281) (HKLM-x32\...\Magic ISO Maker v5.5 (build 0281)) (Version: - ) Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes) Melodyne editor Demo Arrangements (HKLM-x32\...\{56667F33-C777-40DB-9332-39F8A313F6F4}) (Version: 1.03.0001 - Celemony Software GmbH) Melodyne Runtime 4.1 (x64) (HKLM\...\{53EE2829-E9DB-4913-B3EA-96F10F84E98B}) (Version: 1.0.1 - Celemony Software GmbH) Microsoft .NET Framework 4.7 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02053 - Microsoft Corporation) Microsoft Office Professional Plus 2013 - en-us (HKLM\...\ProPlusRetail - en-us) (Version: 15.0.4971.1002 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24123 (HKLM-x32\...\{2cbcedbb-f38c-48a3-a3e1-6c6fd821a7f4}) (Version: 14.0.24123.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24215 (HKLM-x32\...\{e2803110-78b3-4664-a479-3611a381656a}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Movie Maker (HKLM-x32\...\{38F03569-A636-4CF3-BDDE-032C8C251304}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Movie Maker (HKLM-x32\...\{DD67BE4B-7E62-4215-AFA3-F123A800A389}) (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Mozilla Firefox 32.0.2 (x86 en-US) (HKLM-x32\...\Mozilla Firefox 32.0.2 (x86 en-US)) (Version: 32.0.2 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 32.0.2 - Mozilla) MuseScore 2 (HKLM-x32\...\{DC8A2B29-D9A7-4D67-A049-BC0A659A2B57}) (Version: 2.1.0 - Werner Schweer and Others) MusicBrainz Picard (HKLM-x32\...\MusicBrainz Picard) (Version: 1.4.2 - MusicBrainz) Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.4971.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.4971.1002 - Microsoft Corporation) Hidden Office 15 Click-to-Run Localization Component (HKLM-x32\...\{90150000-008C-0409-0000-0000000FF1CE}) (Version: 15.0.4971.1002 - Microsoft Corporation) Hidden Power Tab Editor 1.7 (HKLM-x32\...\{6B3CA80E-6AC0-4725-BABF-9B0FEF880CB3}) (Version: 1.7.0 - Power Tab Software) PreSonus Studio One 3 (HKLM-x32\...\PreSonus Studio One 3) (Version: 3.3.4.41933 - PreSonus Audio Electronics) Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.334 - Qualcomm Atheros Communications) QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.) Realtek Ethernet Controller All-In-One Windows Driver (HKLM-x32\...\{F7E7F0CB-AA41-4D5A-B6F2-8E6738EB063F}) (Version: 7.67.1226.2012 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6909 - Realtek Semiconductor Corp.) Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.2.8400.30137 - Realtek Semiconductor Corp.) REAPER (x64) (HKLM\...\REAPER) (Version: - ) RiffMaster Pro version 4.0 (HKLM-x32\...\{44F47460-0A4F-414E-923C-E673D3184546}_is1) (Version: 4.0 - RiffMaster Pro) rtpMIDIBlockLegacy (HKLM-x32\...\{FD937297-84C3-41A5-B5DF-1FAEEE669D68}) (Version: 9.9.9.9 - Tobias Erichsen) Hidden Shoebox (HKLM-x32\...\{7685FA06-8E94-40B1-99D6-43851CAA4FB9}) (Version: 3.0.4 - Couch Labs) Skype™ 7.33 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.33.105 - Skype Technologies S.A.) Snagit 13 (HKLM-x32\...\{6B4ED247-7A7C-499D-8942-79F88F592B57}) (Version: 13.1.5 - TechSmith Corporation) SONAR 8.0 Producer Edition (HKLM-x32\...\SONAR8Producer_is1) (Version: 17.0 - Cakewalk Music Software) Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform) Spotify (HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\Spotify) (Version: 1.0.60.492.gbb40dab8 - Spotify AB) teVirtualMIDI64 (HKLM\...\{9084640A-366B-4C44-BDB1-74864B460B13}) (Version: 1.2.10.38 - Tobias Erichsen) Hidden TuxGuitar (HKLM-x32\...\TuxGuitar 1.4) (Version: 1.4 - TuxGuitar) UM-ONE Driver (HKLM\...\RolandRDID0115) (Version: - Roland Corporation) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN) Waves Mercury Bundle (HKLM-x32\...\Waves Mercury Bundle) (Version: 5.0 - Team AiR) WIDI Recognition System Pro 4.4 (remove only) (HKLM-x32\...\WIDI Recognition System Pro 4.4) (Version: - ) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) WinRAR 4.01 (64-bit) (HKLM\...\WinRAR archiver) (Version: 4.01.0 - win.rar GmbH) Wise Duplicate Finder 1.21 (HKLM-x32\...\Wise Duplicate Finder_is1) (Version: 1.21 - WiseCleaner.com, Inc.) Zoom (HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\ZoomUMX) (Version: 4.0 - Zoom Video Communications, Inc.) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-709187934-3287193120-2459991863-500_Classes\CLSID\{2AD206F1-152C-4F9D-A24E-6F93FE7A4AFC}\InprocServer32 -> C:\Users\Administrator\AppData\Local\Grammarly\Grammarly for Microsoft Office Suite\6.6.115\E647AAD80A\GrammarlyShim64.dll (CompanyName) CustomCLSID: HKU\S-1-5-21-709187934-3287193120-2459991863-500_Classes\CLSID\{4BE56754-B616-4998-B825-D16983AEE1B2}\InprocServer32 -> C:\Windows\system32\mscoree.dll (Microsoft Corporation) CustomCLSID: HKU\S-1-5-21-709187934-3287193120-2459991863-500_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Program Files (x86)\GoToMeeting\7297\G2MOutlookAddin64.dll (LogMeIn, Inc.) ShellIconOverlayIdentifiers: [AcronisSyncError] -> {934BC6C0-FEC2-4df5-A100-961DE2C8A0ED} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2016-03-18] (Acronis) ShellIconOverlayIdentifiers: [AcronisSyncInProgress] -> {00F848DC-B1D4-4892-9C25-CAADC86A215D} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2016-03-18] (Acronis) ShellIconOverlayIdentifiers: [AcronisSyncOk] -> {71573297-552E-46fc-BE3D-3DFAF88D47B7} => C:\Program Files (x86)\Acronis\TrueImageHome\tishell64.dll [2016-03-18] (Acronis) ContextMenuHandlers1: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov) ContextMenuHandlers1: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [2008-06-11] (Adobe Systems Inc.) ContextMenuHandlers1: [Atheros] -> [CC]{B8952421-0E55-400B-94A6-FA858FC0A39F} => -> No File ContextMenuHandlers1: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-11-12] (ESET) ContextMenuHandlers1: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File ContextMenuHandlers1: [MagicISO] -> [CC]{DB85C504-C730-49DD-BEC1-7B39C6103B7A} => -> No File ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2017-05-09] (Apple Inc.) ContextMenuHandlers1: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 13\DLLx64\SnagitShellExt64.dll [2017-11-03] (TechSmith Corporation) ContextMenuHandlers1-x32: [VersionsPageShellExt] -> {9E42900A-85F9-4E67-9778-575FBBA0A81C} => C:\Program Files (x86)\Acronis\TrueImageHome\versions_page.dll [2016-03-18] (Acronis International GmbH) ContextMenuHandlers1-x32: [WinRAR] -> {B41DB860-64E4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext.dll [2011-05-28] () ContextMenuHandlers1-x32-x32: [WinRAR32] -> {B41DB860-8EE4-11D2-9906-E49FADC173CA} => C:\Program Files\WinRAR\rarext32.dll [2011-05-28] () ContextMenuHandlers2: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-11-12] (ESET) ContextMenuHandlers2: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File ContextMenuHandlers3: [FTShellContext] -> [CC]{AFF81F7B-6942-40c4-AADA-7214EF7B6DD1} => -> No File ContextMenuHandlers4: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2015-12-31] (Igor Pavlov) ContextMenuHandlers4: [MagicISO] -> [CC]{DB85C504-C730-49DD-BEC1-7B39C6103B7A} => -> No File ContextMenuHandlers4: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 13\DLLx64\SnagitShellExt64.dll [2017-11-03] (TechSmith Corporation) ContextMenuHandlers5: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\AMD\ATI.ACE\Core-Static\atiacm64.dll [2015-08-04] (Advanced Micro Devices, Inc.) ContextMenuHandlers6: [Adobe.Acrobat.ContextMenu] -> {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802} => C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\..\Acrobat Elements\ContextMenu64.dll [2008-06-11] (Adobe Systems Inc.) ContextMenuHandlers6: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-11-12] (ESET) ContextMenuHandlers6: [Glary Utilities] -> {B3C418F8-922B-4faf-915E-59BC14448CF7} => -> No File ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {077C8A52-7DB6-4F4B-818C-BA9F9B3FB048} - System32\Tasks\Shoebox\ShoeboxUploader-2fc1c0be => C:\Program Files (x86)\Couch Labs\Shoebox\Shoebox.exe [2016-10-24] (Couch Labs) Task: {14E91229-3BF0-40BC-A756-0671B93DF69D} - System32\Tasks\{21D34D01-32FA-4325-A47C-D746A761FF2A} => C:\Windows\system32\pcalua.exe -a D:\PROGRAMS\windirstat1_1_2_setup.exe -d D:\PROGRAMS Task: {164E5D37-2F6B-4991-88AD-CF60E30E338C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-22] (Google Inc.) Task: {19527976-9AEA-415B-8F4B-EF85F2A3D42D} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_27_0_0_187_pepper.exe [2017-11-14] (Adobe Systems Incorporated) Task: {1B2A8CF7-0E38-4AE7-9C35-54FD47D1B648} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2017-03-14] (Microsoft Corporation) Task: {1B567027-1DA8-460C-9CD2-96AD1258FF6B} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office 15\root\Office15\msoia.exe [2017-03-14] (Microsoft Corporation) Task: {37698B7D-8102-4EEE-AEFE-C34143EF017C} - System32\Tasks\Dell SupportAssistAgent AnonymousRegistration => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [2017-09-22] (Dell Inc.) Task: {388352D7-F331-44B0-9970-874019E2803E} - System32\Tasks\Dell SupportAssistAgent AutoUpdate => C:\Program Files\Dell\SupportAssistAgent\bin\SupportAssist.exe [2017-09-22] (Dell Inc.) Task: {4C6B044A-34B5-4759-9BAA-89E18213A6C6} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2016-08-26] (Piriform Ltd) Task: {6B84FC2B-E564-4B2D-92E6-64B3B5DE5091} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-09-05] (Microsoft Corporation) Task: {7CFD7089-D5AE-431D-AF94-022BFF07596A} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-02-14] (Apple Inc.) Task: {85F6CD3E-4F1C-4A93-9712-FAACDD9505A4} - System32\Tasks\TechSmith Updater => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe [2017-05-12] (TechSmith Corporation) Task: {956070BA-BEBF-4824-AE45-40B0196A7F7C} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-11-14] (Adobe Systems Incorporated) Task: {95D6BCD8-199B-4C17-B898-CE86ED98E9A0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-08-22] (Google Inc.) Task: {973939EB-B88B-4F83-8F4E-EA4C466A2E13} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Microsoft Office 15\ClientX64\OfficeC2RClient.exe [2017-09-05] (Microsoft Corporation) Task: {ECB3FB06-7570-4001-A115-D73FC8739D58} - System32\Tasks\Amazon Music Helper => C:\Users\Administrator\AppData\Local\Amazon Music\Amazon Music Helper.exe [2017-07-18] (Amazon Services LLC) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Hangouts.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory=Default --app-id=knipolnnllmklapflnccelgolnpehhpl ==================== Loaded Modules (Whitelisted) ============== 2017-06-23 10:04 - 2017-06-23 10:04 - 001244408 _____ () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe 2017-08-29 20:17 - 2017-08-29 20:17 - 004463592 _____ () C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe 2017-07-13 19:50 - 2017-07-13 19:50 - 001354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2017-05-08 23:44 - 2017-05-08 23:44 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-08-22 12:55 - 2017-01-17 03:25 - 000117440 _____ () C:\Program Files\Microsoft Office 15\ClientX64\ApiClient.dll 2017-07-27 14:48 - 2017-07-27 14:48 - 000014848 _____ () C:\Program Files\CrashPlan\md564.dll 2017-07-27 14:48 - 2017-07-27 14:48 - 000238592 _____ () \\?\C:\Program Files\CrashPlan\cpnative64.dll 2017-07-27 14:48 - 2017-07-27 14:48 - 000082432 _____ () \\?\C:\Program Files\CrashPlan\c42archive64.dll 2017-07-27 14:48 - 2017-07-27 14:48 - 000484864 _____ () \\?\C:\Program Files\CrashPlan\libleveldb64.dll 2017-05-28 09:32 - 2017-08-24 11:27 - 002264528 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2016-04-16 11:56 - 2016-04-16 11:56 - 009698296 _____ () C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe 2016-08-24 04:09 - 2017-01-31 04:34 - 008909512 _____ () C:\Program Files\Microsoft Office 15\root\VFS\ProgramFilesX64\Microsoft Office\Office15\1033\GrooveIntlResource.dll 2014-10-28 00:26 - 2014-10-28 00:26 - 000086016 _____ () C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\Modules\Map\MAP.dll 2017-06-23 09:56 - 2017-06-23 09:56 - 000567088 _____ () C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe 2017-07-14 09:26 - 2017-07-14 09:26 - 001354040 _____ () C:\Program Files\iTunes\libxml2.dll 2017-07-14 09:27 - 2017-07-14 09:27 - 000092472 _____ () C:\Program Files\iTunes\zlib1.dll 2017-06-23 10:50 - 2017-06-23 10:50 - 007390424 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe 2017-11-16 03:31 - 2017-11-10 01:57 - 004135768 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.94\libglesv2.dll 2017-11-16 03:31 - 2017-11-10 01:57 - 000100184 _____ () C:\Program Files (x86)\Google\Chrome\Application\62.0.3202.94\libegl.dll 2017-06-23 10:13 - 2017-06-23 10:13 - 010074960 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\SystemReport.exe 2015-08-11 14:36 - 2015-08-11 14:36 - 000024896 _____ () C:\Program Files (x86)\Common Files\Acronis\Infrastructure\core_workers_shared_context.dll 2017-06-23 09:53 - 2017-06-23 09:53 - 000037808 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\thread_pool.dll 2017-06-23 10:49 - 2017-06-23 10:49 - 004355768 _____ () C:\Program Files (x86)\Common Files\Acronis\Infrastructure\atih_mms_addon.dll 2015-08-23 14:59 - 2015-08-23 14:59 - 000606672 _____ () C:\Program Files (x86)\Common Files\Acronis\Infrastructure\sqlite3.dll 2017-06-23 10:48 - 2017-06-23 10:48 - 020614072 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\ti_managers.dll 2015-11-16 17:05 - 2015-11-16 17:05 - 000126928 _____ () C:\Program Files (x86)\Acronis\TrueImageHome\afcdpapi.dll 2016-04-16 11:45 - 2016-04-16 11:45 - 000248240 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\sync_agent_api.dll 2015-03-16 10:28 - 2015-03-16 10:28 - 000155528 _____ () C:\Program Files (x86)\Dell Digital Delivery\ServiceTagPlusPlus.dll 2017-05-01 14:27 - 2017-05-01 14:27 - 000133992 _____ () C:\Program Files (x86)\Dell Update\ServiceTagPlusPlus.dll 2017-09-26 14:32 - 2013-01-24 05:57 - 001199576 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll 2017-06-23 09:53 - 2017-06-23 09:53 - 000445872 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\ulxmlrpcpp.dll 2017-06-23 09:50 - 2017-06-23 09:50 - 000115632 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\EXPAT.dll 2017-10-19 13:55 - 2017-10-19 13:55 - 001651200 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\cairo.dll 2016-08-15 13:39 - 2016-08-15 13:39 - 000165888 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\libpng16.dll 2017-10-19 13:55 - 2017-10-19 13:55 - 000074240 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\zlib1.dll 2017-10-19 13:55 - 2017-10-19 13:55 - 000657920 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\fontconfig.dll 2017-10-19 13:55 - 2017-10-19 13:55 - 001023488 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\libxml2.dll 2017-10-19 13:55 - 2017-10-19 13:55 - 000042496 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\iconv.dll 2017-10-19 13:55 - 2017-10-19 13:55 - 000868864 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\harfbuzz-vs14.dll 2017-01-20 08:11 - 2017-01-20 08:11 - 000800768 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\opencv_photo310.dll 2017-01-20 08:11 - 2017-01-20 08:11 - 020629504 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\opencv_imgproc310.dll 2017-01-20 08:11 - 2017-01-20 08:11 - 008968192 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\opencv_core310.dll 2016-08-15 13:37 - 2016-08-15 13:37 - 008968192 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\opencv_core300.dll 2016-08-15 13:37 - 2016-08-15 13:37 - 020629504 _____ () C:\Program Files (x86)\TechSmith\Snagit 13\opencv_imgproc300.dll 2017-06-23 09:53 - 2017-06-23 09:53 - 000333744 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\resource.dll 2017-06-23 09:53 - 2017-06-23 09:53 - 000050096 _____ () C:\Program Files (x86)\Common Files\Acronis\Home\rpc_client.dll 2016-08-24 04:09 - 2017-01-31 02:14 - 008909512 _____ () C:\Program Files\Microsoft Office 15\root\Office15\1033\GrooveIntlResource.dll 2017-02-17 03:53 - 2017-02-17 03:53 - 003227648 _____ () C:\Program Files (x86)\PreSonus\Studio One 3\ipp.dll 2017-01-09 07:37 - 2017-01-09 07:37 - 000348672 _____ () C:\Program Files (x86)\PreSonus\Studio One 3\libmpg123.dll 2017-02-17 04:02 - 2017-02-17 04:02 - 000189440 _____ () C:\Program Files (x86)\PreSonus\Studio One 3\lame.dll 2016-09-22 20:42 - 2005-12-14 14:46 - 000057344 _____ () C:\Program Files (x86)\Waves\ReWire\WavesReWireDevice.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) AlternateDataStreams: C:\ProgramData\Reprise:wupeogjxldtlfudivq`qsp`27hfm [0] AlternateDataStreams: C:\Users\Public\.DS_Store:AFP_AfpInfo [122] AlternateDataStreams: C:\Users\Public\Documents\.DS_Store:AFP_AfpInfo [122] ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-709187934-3287193120-2459991863-500\...\dell.com -> dell.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-13 18:34 - 2016-08-25 16:16 - 000000861 _____ C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 activation.acronis.com ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-709187934-3287193120-2459991863-500\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\startupreg: Adobe Acrobat Speed Launcher => "C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" MSCONFIG\startupreg: Amazon Drive => "C:\Users\Administrator\AppData\Local\Amazon Drive\AmazonDrive.exe" --source-autostart MSCONFIG\startupreg: loopMIDI => C:\Program Files (x86)\Tobias Erichsen\loopMIDI\loopMIDI.exe MSCONFIG\startupreg: Malwarebytes TrayApp => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe MSCONFIG\startupreg: Spotify => C:\Users\Administrator\AppData\Roaming\Spotify\Spotify.exe --autostart --minimized MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe FirewallRules: [TCP Query User{08B65D57-6CF8-41B5-AFA1-4E6C7F7B00F1}D:\crashplan\crashplanservice.exe] => (Allow) D:\crashplan\crashplanservice.exe FirewallRules: [UDP Query User{E9F99E93-C5E2-4B32-810C-477BE4D640F2}D:\crashplan\crashplanservice.exe] => (Allow) D:\crashplan\crashplanservice.exe FirewallRules: [TCP Query User{4A7FCB7D-6ACC-4F6F-A693-5C8E3917947F}D:\crashplan\crashplanservice.exe] => (Block) D:\crashplan\crashplanservice.exe FirewallRules: [UDP Query User{3BA90772-9505-4065-A05A-6A5754FFB540}D:\crashplan\crashplanservice.exe] => (Block) D:\crashplan\crashplanservice.exe FirewallRules: [{73FA2DBD-1253-4A5F-856D-7DED57AD9F5F}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{3BC92718-016C-407A-B847-EBCC811137A4}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [{616E5618-71A4-4F43-A995-9FC90D053336}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\outlook.exe FirewallRules: [{73BDB2C9-4E62-40B6-9F1E-F891E411B048}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\Lync.exe FirewallRules: [{528AC485-5DB8-4271-AA6A-FA5934C23D41}] => (Allow) C:\Program Files\Microsoft Office 15\root\Office15\UcMapi.exe FirewallRules: [{E1D30374-37FE-4B82-9084-1184D50259BB}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{95B9CFE0-60EC-4DB4-BA34-A27DC9F7BDE0}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe FirewallRules: [{AE279C19-ED1A-464F-A77D-C4A761E60887}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{A71EAA6B-6DA0-4AB4-94B6-9D269E35EA41}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{55E19969-1B55-40E2-AA35-5FF68F617F19}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{B649B7CE-0DA0-4EDF-96A4-8C4B5D9DF636}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{38199FDA-2C83-4DC9-97AC-88882E74EFF4}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe FirewallRules: [TCP Query User{E299499D-65B2-4AE0-8D6C-3B6403374735}C:\program files (x86)\airfoil\airfoil.exe] => (Allow) C:\program files (x86)\airfoil\airfoil.exe FirewallRules: [UDP Query User{D4364AF8-764F-42BF-8151-A264CCE962B2}C:\program files (x86)\airfoil\airfoil.exe] => (Allow) C:\program files (x86)\airfoil\airfoil.exe FirewallRules: [{9A325B9E-DA26-42A2-8D09-98BC8A4FA47B}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{7F48C4B6-5D16-4A3C-9887-6C8F1983E3A0}] => (Allow) LPort=2869 FirewallRules: [{B69A91C4-ACB3-42C4-B075-2EF66A992849}] => (Allow) LPort=1900 FirewallRules: [{F6A921FC-2B39-4054-9550-AE689338E373}] => (Allow) LPort=8298 FirewallRules: [TCP Query User{CE2D7806-1FEB-4A9E-AC68-2ECC9FA8C2C0}C:\program files (x86)\airfoil\airfoil.exe] => (Allow) C:\program files (x86)\airfoil\airfoil.exe FirewallRules: [UDP Query User{C604A3DF-AA89-4343-95D7-1637C9B5B0A8}C:\program files (x86)\airfoil\airfoil.exe] => (Allow) C:\program files (x86)\airfoil\airfoil.exe FirewallRules: [{FEF1BF08-4FE7-47F5-BA74-678A655F521F}] => (Allow) C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe FirewallRules: [{05A7560E-CC08-49AE-AEC4-2C544527ED80}] => (Allow) C:\Program Files (x86)\ASUS\Wireless Router\Device Discovery\Discovery.exe FirewallRules: [{2594FB6F-62C3-4616-BD35-AA23B0EFA58A}] => (Allow) C:\Program Files (x86)\PreSonus\Studio One 3\Studio One.exe FirewallRules: [TCP Query User{A85585DA-5C03-4EA4-9091-47FED87FDF97}C:\users\administrator\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\administrator\appdata\roaming\spotify\spotify.exe FirewallRules: [UDP Query User{F469A937-7AC7-4191-824D-F5BA4AA1ADD7}C:\users\administrator\appdata\roaming\spotify\spotify.exe] => (Block) C:\users\administrator\appdata\roaming\spotify\spotify.exe FirewallRules: [{C62604B8-B6A8-4DA6-BCAC-C3032C720AAE}] => (Allow) C:\Program Files\CrashPlan\CrashPlanService.exe FirewallRules: [{3639AA59-43B0-4B9B-8CBF-F78996D00EC4}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe FirewallRules: [{90679C83-E6C2-4A87-BC8D-E23971E24C00}] => (Allow) C:\Program Files (x86)\Common Files\Acronis\Infrastructure\mms_mini.exe FirewallRules: [{E6362E22-4343-4395-BA11-6938C3D9BADB}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{3CBE183C-3469-4C6A-85B7-58BB010EDC09}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Restore Points ========================= 14-11-2017 03:53:06 Windows Update 15-11-2017 03:00:11 Windows Update ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/16/2017 11:24:55 AM) (Source: Application Hang) (EventID: 1002) (User: ) Description: The program Studio One.exe version 3.3.4.41933 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: 2428 Start Time: 01d35f0f7deb6d81 Termination Time: 60000 Application Path: C:\Program Files (x86)\PreSonus\Studio One 3\Studio One.exe Report Id: Error: (11/16/2017 08:32:24 AM) (Source: Dell System Detect) (EventID: 0) (User: ) Description: <Exception><Type>System.UnauthorizedAccessException</Type><Message><![CDATA[Access to the path 'C:\Users\Administrator\AppData\Local\Apps\2.0\C2AYRA27.C60\QDQ7MZTB.GXR\dell..tion_831211ca63b981c5_0008.0008_b150a6542eb950c1\Resources\Config.xml' is denied.]]></Message><Source><![CDATA[mscorlib]]></Source><StackTrace><![CDATA[ at System.IO.__Error.WinIOError(Int32 errorCode, String maybeFullPath) at System.IO.FileStream.Init(String path, FileMode mode, FileAccess access, Int32 rights, Boolean useRights, FileShare share, Int32 bufferSize, FileOptions options, SECURITY_ATTRIBUTES secAttrs, String msgPath, Boolean bFromProxy, Boolean useLongPath, Boolean checkHost) at System.IO.FileStream..ctor(String path, FileMode mode, FileAccess access, FileShare share) at System.Xml.XmlDocument.Save(String filename) at A.cfa225d52c5d09e6cb436129be8e65a5b.c977fe2ec996ff6f0f32ef1f877cc2d9d(XmlDocument c8499b7db7d388e61daaa572bbb517c67)]]></StackTrace><SysInfo STag="CLCL7Y1" SMBIOSMajVer="2" SMBIOSMinVer="7" SMBIOSBIOSVer="A11" SMBIOSPresent="True" Rel_Date="20150709000000.000000+000" DSDVersion="8.8.0.1" Vendor="Dell Inc." PName="XPS 8700" Ident_Num="DELL8700-PC" TimeZone="(UTC-08:00) Pacific Time (US & Canada)" OSName="Microsoft Windows 7 Professional"/><Method>SynchronizeConfig</Method><HostIP>192.168.1.221</HostIP></Exception> Error: (11/16/2017 06:30:41 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1542) (User: NT AUTHORITY) Description: Windows cannot load classes registry file. DETAIL - The process cannot access the file because it is being used by another process. Error: (11/16/2017 06:30:41 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT AUTHORITY) Description: Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights. DETAIL - The process cannot access the file because it is being used by another process. for C:\Users\Bob\AppData\Local\Microsoft\Windows\\UsrClass.dat Error: (11/16/2017 06:30:40 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1542) (User: NT AUTHORITY) Description: Windows cannot load classes registry file. DETAIL - The process cannot access the file because it is being used by another process. Error: (11/16/2017 06:30:40 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT AUTHORITY) Description: Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights. DETAIL - The process cannot access the file because it is being used by another process. for C:\Users\Administrator\AppData\Local\Microsoft\Windows\\UsrClass.dat Error: (11/16/2017 04:30:40 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1542) (User: NT AUTHORITY) Description: Windows cannot load classes registry file. DETAIL - The process cannot access the file because it is being used by another process. Error: (11/16/2017 04:30:40 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT AUTHORITY) Description: Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights. DETAIL - The process cannot access the file because it is being used by another process. for C:\Users\Bob\AppData\Local\Microsoft\Windows\\UsrClass.dat Error: (11/16/2017 04:30:39 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1542) (User: NT AUTHORITY) Description: Windows cannot load classes registry file. DETAIL - The process cannot access the file because it is being used by another process. Error: (11/16/2017 04:30:39 AM) (Source: Microsoft-Windows-User Profiles Service) (EventID: 1508) (User: NT AUTHORITY) Description: Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights. DETAIL - The process cannot access the file because it is being used by another process. for C:\Users\Administrator\AppData\Local\Microsoft\Windows\\UsrClass.dat System errors: ============= Error: (11/16/2017 11:25:07 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 70. Error: (11/16/2017 11:25:07 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 70. Error: (11/15/2017 04:31:30 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. Error: (11/15/2017 04:31:30 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. Error: (11/15/2017 04:29:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Acronis Sync Agent Service service failed to start due to the following error: The pipe has been ended. Error: (11/15/2017 04:29:33 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Windows Live ID Sign-in Assistant service failed to start due to the following error: The pipe has been ended. Error: (11/15/2017 04:29:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\Windows\system32\athihvs.dll Error: (11/15/2017 04:29:33 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\Windows\system32\athihvs.dll Error: (11/15/2017 04:29:31 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\Windows\system32\athihvs.dll Error: (11/15/2017 04:29:27 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY) Description: The following fatal alert was received: 70. CodeIntegrity: =================================== Date: 2017-09-27 11:05:21.785 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\MaxxVoiceAPO2064.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-27 10:57:10.051 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\MaxxVoiceAPO2064.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-27 10:52:27.707 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\MaxxVoiceAPO2064.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-27 10:43:14.998 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\MaxxVoiceAPO2064.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-27 10:33:41.871 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\MaxxVoiceAPO2064.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-27 10:22:54.737 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\MaxxVoiceAPO2064.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-26 16:38:28.347 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\MaxxVoiceAPO2064.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-26 15:42:36.867 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\MaxxVoiceAPO2064.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-26 15:37:14.819 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\MaxxVoiceAPO2064.dll because the set of per-page image hashes could not be found on the system. Date: 2017-09-26 15:25:31.896 Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\MaxxVoiceAPO2064.dll because the set of per-page image hashes could not be found on the system. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4770 CPU @ 3.40GHz Percentage of memory in use: 47% Total physical RAM: 32717.8 MB Available physical RAM: 17162.2 MB Total Virtual: 65433.79 MB Available Virtual: 48634.18 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:223.47 GB) (Free:57.43 GB) NTFS Drive d: (New Volume) (Fixed) (Total:931.51 GB) (Free:298.6 GB) NTFS Drive e: (Local Disk ) (Fixed) (Total:1862.89 GB) (Free:701.6 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 223.6 GB) (Disk ID: 6D633CE7) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=223.5 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 13F4B6BF) Partition 1: (Not Active) - (Size=931.5 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 00000000) Partition: GPT. ==================== End of Addition.txt ============================
  4. # AdwCleaner 7.0.4.0 - Logfile created on Thu Nov 16 19:25:08 2017 # Updated on 2017/27/10 by Malwarebytes # Database: 11-15-2017.1 # Running on Windows 7 Professional (X64) # Mode: scan # Support: https://www.malwarebytes.com/support ***** [ Services ] ***** No malicious services found. ***** [ Folders ] ***** No malicious folders found. ***** [ Files ] ***** No malicious files found. ***** [ DLL ] ***** No malicious DLLs found. ***** [ WMI ] ***** No malicious WMI found. ***** [ Shortcuts ] ***** No malicious shortcuts found. ***** [ Tasks ] ***** No malicious tasks found. ***** [ Registry ] ***** No malicious registry entries found. ***** [ Firefox (and derivatives) ] ***** No malicious Firefox entries. ***** [ Chromium (and derivatives) ] ***** PUP.Optional.Legacy, SearchProvider found: Ask Search - ask search /!\ Please Reset the Chrome Synchronization before cleaning the Chrome Preferences: https://support.google.com/chrome/answer/3097271 ************************* C:/AdwCleaner/AdwCleaner[C0].txt - [1198 B] - [2017/11/11 17:53:11] C:/AdwCleaner/AdwCleaner[C1].txt - [1336 B] - [2017/11/11 18:31:9] C:/AdwCleaner/AdwCleaner[C2].txt - [1426 B] - [2017/11/11 22:25:22] C:/AdwCleaner/AdwCleaner[C3].txt - [1630 B] - [2017/11/16 0:29:27] C:/AdwCleaner/AdwCleaner[S0].txt - [1193 B] - [2017/11/11 17:52:13] C:/AdwCleaner/AdwCleaner[S1].txt - [1331 B] - [2017/11/11 18:16:11] C:/AdwCleaner/AdwCleaner[S2].txt - [1403 B] - [2017/11/11 18:34:10] C:/AdwCleaner/AdwCleaner[S3].txt - [1365 B] - [2017/11/11 22:29:0] C:/AdwCleaner/AdwCleaner[S4].txt - [1608 B] - [2017/11/16 0:29:5] ########## EOF - C:\AdwCleaner\AdwCleaner[S5].txt ##########
  5. ADWCleaner found PUP virus Optional.legacy. I ran the scan, cleaned it, restarted but it does not die! How do I kill this monster?
  6. Malwarebytes found nothing....but..... Eset online found the following: Win32/Bundled.Toolbar.Google D application Win32/OpenCandy application A varient of Win32/InstallCore.CH application Why is Malwarebytes consistently missing viruses on my PC even though its updated? This sucks;(
  7. I'm running Windows XP on a PC and I recently installed a great SSD to speed up startup. After I did the startup was BLAZINGLY FAST. Then 2 months later I must have downloaded something bad because now my PC takes forever the startup...like 5 minutes. Whereas it used to take about 12 seconds before. Below is all the required scans. Let me know if you can help. Thanks in advance. ---------- HiJackThis Log: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 7:53:54 PM, on 1/16/2014 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: E:\WINDOWS\System32\smss.exe E:\WINDOWS\system32\winlogon.exe E:\WINDOWS\system32\services.exe E:\WINDOWS\system32\lsass.exe E:\WINDOWS\system32\Ati2evxx.exe E:\WINDOWS\system32\svchost.exe e:\Program Files\Microsoft Security Client\MsMpEng.exe E:\WINDOWS\System32\svchost.exe E:\WINDOWS\system32\spoolsv.exe E:\WINDOWS\system32\Ati2evxx.exe E:\WINDOWS\Explorer.EXE E:\Program Files\Intel\ASF Agent\ASFAgent.exe E:\Program Files\Bonjour\mDNSResponder.exe E:\Program Files\Java\jre7\bin\jqs.exe E:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe E:\WINDOWS\system32\svchost.exe E:\Program Files\Microsoft IntelliPoint\ipoint.exe E:\Program Files\Microsoft Security Client\msseces.exe E:\Program Files\Common Files\Java\Java Update\jusched.exe E:\WINDOWS\system32\ctfmon.exe E:\Documents and Settings\bob\Local Settings\Application Data\FluxSoftware\Flux\flux.exe E:\Program Files\WinZip\WZQKPICK.EXE E:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE E:\Documents and Settings\bob\Application Data\Dropbox\bin\Dropbox.exe E:\Program Files\ATI Technologies\ATI.ACE\cli.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Documents and Settings\bob\My Documents\Downloads\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - E:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files\Java\jre7\bin\ssv.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - E:\Program Files\Java\jre7\bin\jp2ssv.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - E:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - E:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll O4 - HKLM\..\Run: [intelliPoint] "e:\Program Files\Microsoft IntelliPoint\ipoint.exe" O4 - HKLM\..\Run: [MSC] "e:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKLM\..\Run: [sunJavaUpdateSched] "E:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKLM\..\Run: [ATICCC] "E:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" O4 - HKCU\..\Run: [ctfmon.exe] E:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [f.lux] "E:\Documents and Settings\bob\Local Settings\Application Data\FluxSoftware\Flux\flux.exe" /noshow O4 - Startup: Dropbox.lnk = E:\Documents and Settings\bob\Application Data\Dropbox\bin\Dropbox.exe O4 - Global Startup: WinZip Quick Pick.lnk = E:\Program Files\WinZip\WZQKPICK.EXE O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Program Files\Messenger\msmsgs.exe O15 - Trusted Zone: *.dell.com O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -http://update.microsoft.com/microsof...?1384467701750 O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O20 - AppInit_DLLs: AirfoilInject3.dll O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - E:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - E:\WINDOWS\system32\browseui.dll O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - E:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe O23 - Service: ASF Agent (ASFAgent) - Intel Corporation - E:\Program Files\Intel\ASF Agent\ASFAgent.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - E:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - E:\WINDOWS\system32\ati2sgag.exe O23 - Service: Bonjour Service - Apple Inc. - E:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - E:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - E:\Program Files\Google\Update\GoogleUpdate.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - E:\Program Files\Java\jre7\bin\jqs.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - E:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - E:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - E:\Program Files\Skype\Updater\Updater.exe -- End of file - 8275 bytes --------------------------------------------------- Attach Text LOG: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows XP Professional Boot Device: \Device\HarddiskVolume1 Install Date: 9/25/2013 9:29:35 PM System Uptime: 1/16/2014 5:29:31 PM (2 hours ago) . Motherboard: Dell Inc. | | 0GM819 Processor: Intel Pentium III Xeon processor | CPU | 2659/1333mhz . ==== Disk Partitions ========================= . . ==== Installed Programs ====================== . µTorrent Add or Remove Adobe Creative Suite 3 Design Premium Adobe Acrobat 8 Professional Adobe Anchor Service CS3 Adobe Asset Services CS3 Adobe Bridge CS3 Adobe Bridge Start Meeting Adobe BridgeTalk Plugin CS3 Adobe Camera Raw 4.0 Adobe CMaps Adobe Color - Photoshop Specific Adobe Color Common Settings Adobe Color EU Extra Settings Adobe Color JA Extra Settings Adobe Color NA Recommended Settings Adobe Creative Suite 3 Design Premium Adobe Default Language CS3 Adobe Device Central CS3 Adobe Dreamweaver CS3 Adobe ExtendScript Toolkit 2 Adobe Extension Manager CS3 Adobe Flash CS3 Adobe Flash Player 9 ActiveX Adobe Flash Player 9 Plugin Adobe Flash Video Encoder Adobe Fonts All Adobe Help Viewer CS3 Adobe Illustrator CS3 Adobe InDesign CS3 Adobe InDesign CS3 Icon Handler Adobe Linguistics CS3 Adobe MotionPicture Color Files Adobe PDF Library Files Adobe Photoshop CS3 Adobe Setup Adobe SING CS3 Adobe Stock Photos CS3 Adobe Type Support Adobe Update Manager CS3 Adobe Version Cue CS3 Client Adobe Version Cue CS3 Server Adobe WAS CS3 Adobe WinSoft Linguistics Plugin Adobe XMP Panels CS3 AHV content for Acrobat and Flash Airfoil AirPort Apple Software Update ATI - Software Uninstall Utility ATI Catalyst Control Center ATI Display Driver Bonjour Broadcom Gigabit Integrated Controller Canon Easy-PhotoPrint EX Canon MX870 series MP Drivers CDBurnerXP CloudReading dBpoweramp Music Converter Dell Resource CD Dell System Detect Dropbox f.lux Foxit Reader Google Chrome Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB942288-v3) Hotfix for Windows XP (KB952287) Hotfix for Windows XP (KB954550-v5) Hotfix for Windows XP (KB961118) Intel® Management Engine Interface Intel® PRO Alerting Agent Intel® PRO Network Connections Drivers Java 7 Update 45 Java Auto Updater Malwarebytes Anti-Malware version 1.75.0.1300 Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft .NET Framework 4 Extended Microsoft Application Error Reporting Microsoft Compression Client Pack 1.0 for Windows XP Microsoft IntelliPoint 8.2 Microsoft Kernel-Mode Driver Framework Feature Pack 1.9 Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Small Business 2007 Microsoft Office Word MUI (English) 2007 Microsoft Security Client Microsoft Security Essentials Microsoft Software Update for Web Folders (English) 12 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Mozilla Firefox 25.0.1 (x86 en-US) Mozilla Maintenance Service MSXML 6.0 Parser (KB933579) Native Instruments Guitar Rig 3 Native Instruments Service Center PDF Settings Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2736416) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2840629) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2861697) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2729449) Security Update for Microsoft .NET Framework 4 Client Profile (KB2736428) Security Update for Microsoft .NET Framework 4 Client Profile (KB2737019) Security Update for Microsoft .NET Framework 4 Client Profile (KB2742595) Security Update for Microsoft .NET Framework 4 Client Profile (KB2789642) Security Update for Microsoft .NET Framework 4 Client Profile (KB2835393) Security Update for Microsoft .NET Framework 4 Client Profile (KB2840628v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2858302v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2861188) Security Update for Microsoft .NET Framework 4 Extended (KB2487367) Security Update for Microsoft .NET Framework 4 Extended (KB2736428) Security Update for Microsoft .NET Framework 4 Extended (KB2742595) Security Update for Microsoft .NET Framework 4 Extended (KB2858302v2) Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687441) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760415) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2817641) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2837615) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2850022) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office Outlook 2007 (KB2825644) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2837617) 32-Bit Edition Security Update for Microsoft Windows (KB2564958) Security Update for Windows Internet Explorer 8 (KB2510531) Security Update for Windows Internet Explorer 8 (KB2618444) Security Update for Windows Internet Explorer 8 (KB2744842) Security Update for Windows Internet Explorer 8 (KB2862772) Security Update for Windows Internet Explorer 8 (KB2888505) Security Update for Windows Internet Explorer 8 (KB2898785) Security Update for Windows Internet Explorer 8 (KB982381) Security Update for Windows Media Player (KB2378111) Security Update for Windows Media Player (KB2803821-v2) Security Update for Windows Media Player (KB2834903-v2) Security Update for Windows Media Player (KB2834904-v2) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player (KB954155) Security Update for Windows Media Player (KB973540) Security Update for Windows Media Player (KB975558) Security Update for Windows Media Player (KB978695) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB2115168) Security Update for Windows XP (KB2229593) Security Update for Windows XP (KB2296011) Security Update for Windows XP (KB2347290) Security Update for Windows XP (KB2387149) Security Update for Windows XP (KB2393802) Security Update for Windows XP (KB2419632) Security Update for Windows XP (KB2423089) Security Update for Windows XP (KB2440591) Security Update for Windows XP (KB2443105) Security Update for Windows XP (KB2478960) Security Update for Windows XP (KB2478971) Security Update for Windows XP (KB2479943) Security Update for Windows XP (KB2481109) Security Update for Windows XP (KB2483185) Security Update for Windows XP (KB2485663) Security Update for Windows XP (KB2506212) Security Update for Windows XP (KB2507938) Security Update for Windows XP (KB2508429) Security Update for Windows XP (KB2509553) Security Update for Windows XP (KB2510581) Security Update for Windows XP (KB2535512) Security Update for Windows XP (KB2536276-v2) Security Update for Windows XP (KB2544893-v2) Security Update for Windows XP (KB2566454) Security Update for Windows XP (KB2570947) Security Update for Windows XP (KB2584146) Security Update for Windows XP (KB2585542) Security Update for Windows XP (KB2592799) Security Update for Windows XP (KB2598479) Security Update for Windows XP (KB2603381) Security Update for Windows XP (KB2619339) Security Update for Windows XP (KB2620712) Security Update for Windows XP (KB2631813) Security Update for Windows XP (KB2653956) Security Update for Windows XP (KB2655992) Security Update for Windows XP (KB2659262) Security Update for Windows XP (KB2661637) Security Update for Windows XP (KB2676562) Security Update for Windows XP (KB2686509) Security Update for Windows XP (KB2691442) Security Update for Windows XP (KB2698365) Security Update for Windows XP (KB2705219-v2) Security Update for Windows XP (KB2712808) Security Update for Windows XP (KB2719985) Security Update for Windows XP (KB2723135-v2) Security Update for Windows XP (KB2727528) Security Update for Windows XP (KB2757638) Security Update for Windows XP (KB2758857) Security Update for Windows XP (KB2770660) Security Update for Windows XP (KB2780091) Security Update for Windows XP (KB2802968) Security Update for Windows XP (KB2807986) Security Update for Windows XP (KB2813345) Security Update for Windows XP (KB2820917) Security Update for Windows XP (KB2834886) Security Update for Windows XP (KB2845187) Security Update for Windows XP (KB2847311) Security Update for Windows XP (KB2849470) Security Update for Windows XP (KB2850869) Security Update for Windows XP (KB2859537) Security Update for Windows XP (KB2862152) Security Update for Windows XP (KB2862330) Security Update for Windows XP (KB2862335) Security Update for Windows XP (KB2864063) Security Update for Windows XP (KB2868038) Security Update for Windows XP (KB2868626) Security Update for Windows XP (KB2876217) Security Update for Windows XP (KB2876331) Security Update for Windows XP (KB2883150) Security Update for Windows XP (KB2888505) Security Update for Windows XP (KB2892075) Security Update for Windows XP (KB2893294) Security Update for Windows XP (KB2893984) Security Update for Windows XP (KB2898715) Security Update for Windows XP (KB2900986) Security Update for Windows XP (KB2914368) Security Update for Windows XP (KB923561) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB952004) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB956572) Security Update for Windows XP (KB956844) Security Update for Windows XP (KB959426) Security Update for Windows XP (KB960803) Security Update for Windows XP (KB960859) Security Update for Windows XP (KB969059) Security Update for Windows XP (KB970430) Security Update for Windows XP (KB971657) Security Update for Windows XP (KB972270) Security Update for Windows XP (KB973507) Security Update for Windows XP (KB973869) Security Update for Windows XP (KB973904) Security Update for Windows XP (KB974112) Security Update for Windows XP (KB974318) Security Update for Windows XP (KB974392) Security Update for Windows XP (KB974571) Security Update for Windows XP (KB975025) Security Update for Windows XP (KB975467) Security Update for Windows XP (KB975560) Security Update for Windows XP (KB975713) Security Update for Windows XP (KB977816) Security Update for Windows XP (KB977914) Security Update for Windows XP (KB978338) Security Update for Windows XP (KB978542) Security Update for Windows XP (KB978706) Security Update for Windows XP (KB979309) Security Update for Windows XP (KB979482) Security Update for Windows XP (KB979687) Security Update for Windows XP (KB981997) Security Update for Windows XP (KB982132) Security Update for Windows XP (KB982665) Sibelius Scorch (Firefox, Opera, Netscape, Chrome only) Skype™ 5.10 SnagIt 8 SONAR 8.0 Producer Edition Sony USB Driver System TuneUp Update for 2007 Microsoft Office System (KB967642) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2850085) 32-Bit Edition Update for Windows Internet Explorer 8 (KB2598845) Update for Windows XP (KB2345886) Update for Windows XP (KB2467659) Update for Windows XP (KB2749655) Update for Windows XP (KB2863058) Update for Windows XP (KB2904266) Update for Windows XP (KB898461) Update for Windows XP (KB951978) Update for Windows XP (KB955759) Update for Windows XP (KB968389) Update for Windows XP (KB971029) Update for Windows XP (KB973815) VLC media player 2.1.1 WebFldrs XP Winamp Windows Internet Explorer 8 Windows Media Format 11 runtime Windows Media Player 11 Windows XP Service Pack 3 WinZip 12.1 . ==== End Of File =========================== DDS Text: DDS (Ver_2012-11-20.01) - NTFS_x86 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 10.45.2 Run by bob at 19:56:43 on 2014-01-16 Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3326.2064 [GMT -8:00] . AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095} . ============== Running Processes ================ . E:\WINDOWS\system32\Ati2evxx.exe e:\Program Files\Microsoft Security Client\MsMpEng.exe E:\WINDOWS\system32\spoolsv.exe E:\WINDOWS\system32\Ati2evxx.exe E:\WINDOWS\Explorer.EXE E:\Program Files\Intel\ASF Agent\ASFAgent.exe E:\Program Files\Bonjour\mDNSResponder.exe E:\Program Files\Java\jre7\bin\jqs.exe E:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe E:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe E:\WINDOWS\System32\alg.exe E:\Program Files\Microsoft IntelliPoint\ipoint.exe E:\Program Files\Microsoft Security Client\msseces.exe E:\Program Files\Common Files\Java\Java Update\jusched.exe E:\WINDOWS\system32\ctfmon.exe E:\Documents and Settings\bob\Local Settings\Application Data\FluxSoftware\Flux\flux.exe E:\Program Files\WinZip\WZQKPICK.EXE E:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE E:\Documents and Settings\bob\Application Data\Dropbox\bin\Dropbox.exe E:\Program Files\ATI Technologies\ATI.ACE\cli.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\Program Files\Google\Chrome\Application\chrome.exe E:\WINDOWS\system32\wbem\wmiprvse.exe E:\WINDOWS\System32\svchost.exe -k netsvcs E:\WINDOWS\system32\svchost.exe -k NetworkService E:\WINDOWS\system32\svchost.exe -k LocalService E:\WINDOWS\system32\svchost.exe -k LocalService E:\WINDOWS\system32\svchost.exe -k imgsvc . ============== Pseudo HJT Report =============== . BHO: SnagIt Toolbar Loader: {00C6482D-C502-44C8-8409-FCE54AD9C208} - e:\program files\techsmith\snagit 8\SnagItBHO.dll BHO: Adobe PDF Reader Link Helper: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - e:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Java Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - e:\program files\java\jre7\bin\ssv.dll BHO: Adobe PDF Conversion Toolbar Helper: {AE7CD045-E861-484f-8273-0445EE161910} - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll BHO: Java Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - e:\program files\java\jre7\bin\jp2ssv.dll TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: Adobe PDF: {47833539-D0C5-4125-9FA8-0819E2EAAC93} - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll TB: SnagIt: {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - e:\program files\techsmith\snagit 8\SnagItIEAddin.dll EB: Adobe PDF: {182EC0BE-5110-49C8-A062-BEB1D02A220B} - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll uRun: [ctfmon.exe] e:\windows\system32\ctfmon.exe uRun: [f.lux] "e:\documents and settings\bob\local settings\application data\fluxsoftware\flux\flux.exe" /noshow mRun: [intelliPoint] "e:\program files\microsoft intellipoint\ipoint.exe" mRun: [MSC] "e:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [sunJavaUpdateSched] "e:\program files\common files\java\java update\jusched.exe" mRun: [ATICCC] "e:\program files\ati technologies\ati.ace\CLIStart.exe" StartupFolder: e:\docume~1\bob\startm~1\programs\startup\dropbox.lnk - e:\documents and settings\bob\application data\dropbox\bin\Dropbox.exe StartupFolder: e:\docume~1\alluse~1\startm~1\programs\startup\winzip~1.lnk - e:\program files\winzip\WZQKPICK.EXE uPolicies-Explorer: NoDriveTypeAutoRun = dword:145 mPolicies-Windows\System: Allow-LogonScript-NetbiosDisabled = dword:1 mPolicies-Explorer: NoDriveTypeAutoRun = dword:145 IE: Append to existing PDF - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert link target to Adobe PDF - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert link target to existing PDF - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert selected links to Adobe PDF - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html IE: Convert selected links to existing PDF - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html IE: Convert selection to Adobe PDF - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: Convert selection to existing PDF - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIEAppend.html IE: Convert to Adobe PDF - e:\program files\adobe\acrobat 8.0\acrobat\AcroIEFavClient.dll/AcroIECapture.html IE: E&xport to Microsoft Excel - e:\progra~1\micros~4\office12\EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - e:\program files\messenger\msmsgs.exe Trusted Zone: dell.com TCP: NameServer = 75.75.75.75 75.75.76.76 TCP: Interfaces\{22F8E353-EEE1-415A-A857-0C542F5EB7A0} : DHCPNameServer = 75.75.75.75 75.75.76.76 Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - e:\program files\common files\skype\Skype4COM.dll Notify: AtiExtEvent - Ati2evxx.dll AppInit_DLLs= AirfoilInject3.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - e:\windows\system32\WPDShServiceObj.dll mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "e:\program files\google\chrome\application\32.0.1700.76\installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome . ================= FIREFOX =================== . FF - ProfilePath - e:\documents and settings\bob\application data\mozilla\firefox\profiles\q858v1c9.default\ FF - plugin: e:\program files\canon\easy-photoprint ex\NPEZFFPI.DLL FF - plugin: e:\program files\foxit software\foxit reader\plugins\npFoxitReaderPlugin.dll FF - plugin: e:\program files\google\update\1.3.22.3\npGoogleUpdate3.dll FF - plugin: e:\program files\java\jre7\bin\dtplugin\npdeployJava1.dll FF - plugin: e:\program files\java\jre7\bin\plugin2\npjp2.dll . ============= SERVICES / DRIVERS =============== . R0 MpFilter;Microsoft Malware Protection Driver;e:\windows\system32\drivers\MpFilter.sys [2013-9-27 214696] R1 MpKsl942c0099;MpKsl942c0099;e:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3b31f13c-2d27-4ece-aa5e-049f31e41ff9}\MpKsl942c0099.sys [2014-1-16 40392] R2 ASFAgent;ASF Agent;e:\program files\intel\asf agent\ASFAgent.exe [2007-1-23 133968] R2 MBAMScheduler;MBAMScheduler;e:\program files\malwarebytes' anti-malware\mbamscheduler.exe [2013-11-29 418376] R2 MBAMService;MBAMService;e:\program files\malwarebytes' anti-malware\mbamservice.exe [2013-11-29 701512] R3 dc3d;MS Hardware Device Detection Driver;e:\windows\system32\drivers\dc3d.sys [2013-11-13 45288] R3 MBAMProtector;MBAMProtector;e:\windows\system32\drivers\mbam.sys [2013-11-29 22856] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;e:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 SkypeUpdate;Skype Updater;e:\program files\skype\updater\Updater.exe [2012-7-13 160944] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;e:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v040 0.exe [2013-7-20 754856] . =============== File Associations =============== . ShellExec: dreamweaver.exe: Open="e:\program files\adobe\adobe dreamweaver cs3\dreamweaver.exe", "%1" . =============== Created Last 30 ================ . 2014-01-17 01:35:45 40392 ----a-w- e:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3b31f13c-2d27-4ece-aa5e-049f31e41ff9}\MpKsl942c0099.sys 2014-01-16 23:58:07 -------- d-----w- e:\documents and settings\bob\local settings\application data\Foxit Reader 2014-01-16 17:59:06 -------- d-----w- e:\program files\Acelogix 2014-01-16 11:30:16 7760024 ----a-w- e:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{3b31f13c-2d27-4ece-aa5e-049f31e41ff9}\mpengine.dll 2014-01-15 03:03:03 7760024 ----a-w- e:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\backup\mpengine.dll 2014-01-14 03:12:43 -------- d-----w- e:\documents and settings\bob\local settings\application data\WMTools Downloaded Files 2014-01-14 02:42:55 6097 ----a-w- e:\windows\system32\drivers\sonyhcb.sys 2014-01-14 02:42:55 53248 ----a-w- e:\windows\system32\SONYHCY.DLL 2014-01-14 02:42:55 38739 ----a-w- e:\windows\system32\drivers\sonyhcc.sys 2014-01-14 02:42:55 3654 ----a-w- e:\windows\system32\drivers\Sonyhcp.dll 2014-01-14 02:42:55 299923 ----a-w- e:\windows\system32\drivers\sonyhcs.sys 2014-01-14 02:42:55 102220 ----a-w- e:\windows\system32\drivers\sonypvs1.sys 2014-01-14 02:42:55 -------- d-----w- E:\Drivers 2014-01-06 09:10:59 -------- d-----w- e:\documents and settings\bob\application data\uTorrent 2014-01-04 06:01:49 -------- d-----w- e:\documents and settings\bob\local settings\application data\FluxSoftware 2013-12-31 07:43:41 -------- d-----w- e:\program files\AirPort 2013-12-31 07:43:41 -------- d-----w- e:\documents and settings\bob\local settings\application data\Apple 2013-12-31 02:31:28 -------- d-----w- e:\documents and settings\bob\local settings\application data\Rogue Amoeba 2013-12-31 01:47:14 -------- d-----w- e:\program files\Airfoil 2013-12-30 17:53:22 5632 ----a-w- e:\windows\system32\ptpusb.dll 2013-12-30 17:53:21 159232 ----a-w- e:\windows\system32\ptpusd.dll 2013-12-28 19:40:05 -------- d-----w- e:\documents and settings\bob\application data\TonePrintEditor 2013-12-23 21:05:24 -------- d--h--w- e:\windows\msdownld.tmp 2013-12-22 11:00:42 -------- d-----r- e:\program files\Skype 2013-12-18 11:03:08 -------- d-----w- e:\windows\system32\XPSViewer 2013-12-18 11:02:58 89088 ----a-w- e:\windows\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll 2013-12-18 11:02:49 89088 -c----w- e:\windows\system32\dllcache\filterpipelineprintproc.dll 2013-12-18 11:02:49 597504 -c----w- e:\windows\system32\dllcache\printfilterpipelinesvc.exe 2013-12-18 11:02:49 597504 ------w- e:\windows\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe 2013-12-18 11:02:49 575488 -c----w- e:\windows\system32\dllcache\xpsshhdr.dll 2013-12-18 11:02:49 575488 ------w- e:\windows\system32\xpsshhdr.dll 2013-12-18 11:02:49 117760 ------w- e:\windows\system32\prntvpt.dll 2013-12-18 11:02:48 1676288 -c----w- e:\windows\system32\dllcache\xpssvcs.dll 2013-12-18 11:02:48 1676288 ------w- e:\windows\system32\xpssvcs.dll . ==================== Find3M ==================== . 2013-12-16 18:56:22 0 ----a-w- e:\windows\ativpsrm.bin 2013-12-12 02:38:00 7261768 ----a-w- e:\windows\system32\SpoonUninstall.exe 2013-11-30 00:46:17 94632 ----a-w- e:\windows\system32\WindowsAccessBridge.dll 2013-11-30 00:46:15 145408 ----a-w- e:\windows\system32\javacpl.cpl 2013-11-27 20:21:06 40960 ----a-w- e:\windows\system32\drivers\ndproxy.sys 2013-11-19 10:21:30 230048 ------w- e:\windows\system32\MpSigStub.exe 2013-11-13 02:59:42 150528 ----a-w- e:\windows\system32\imagehlp.dll 2013-11-07 05:38:51 591360 ----a-w- e:\windows\system32\rpcrt4.dll 2013-11-06 01:03:31 7168 ----a-w- e:\windows\system32\xpsp4res.dll 2013-10-30 02:26:17 1879040 ----a-w- e:\windows\system32\win32k.sys 2013-10-29 07:57:34 920064 ----a-w- e:\windows\system32\wininet.dll 2013-10-29 07:57:33 43520 ------w- e:\windows\system32\licmgr10.dll 2013-10-29 07:57:33 18944 ------w- e:\windows\system32\corpol.dll 2013-10-29 07:57:33 1469440 ------w- e:\windows\system32\inetcpl.cpl 2013-10-29 00:45:02 385024 ------w- e:\windows\system32\html.iec 2013-10-23 23:45:49 172032 ----a-w- e:\windows\system32\scrrun.dll . ============= FINISH: 19:56:58.20 ===============
  8. Sorry lost window so couldn't get export... you can close this case...
  9. I do not think Eset Online scanner produces a log file...or I could not find it. It's tricky...once it's done if you can click on one of two paths...see the quarantined file or see a list of the viruses. Once you click you cannot click back...then you have to run a complete scan over again....
  10. Found this virus using Eset online scanner (Virus found Win32FTPD32.A Application) but Malwarebytes did not pick it up. What is it?
  11. Windows 8 PC with 7 viruses Found with Eset online scannerOK, I'm infected...Isn't this the first step to recovery...just admitting it? lol My PC starting running slow and I also noticed that I no longer could type URL address into the URL address bar without it being hijacked to some stupid site that redirected me...so i experience a takeover of some sort. I also noticed that my Hard drives malfunctioned and required a check-disk type of repair...so there was some kind of physical damage going on....very nasty. This PC is a i7 haswell but is running super slow so I know something is wrong... I'm running Windows 8 PC and need to set it up properly to avoid viruses in the future. I was hoping you guys could review my logs and suggest what programs to install to ensure a virus-free experience... Thanks, bob -------------------------------- HiJackThis log: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 10:06:25 AM, on 11/3/2013 Platform: Unknown Windows (WinNT 6.02.1008) MSIE: Internet Explorer v10.0 (10.00.9200.16537) Boot mode: Normal Running processes: C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe C:\Program Files\CrashPlan\CrashPlanTray.exe C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe C:\Program Files (x86)\TechSmith\Snagit 11\Snagit32.exe C:\Users\bob\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\TechSmith\Snagit 11\TSCHelp.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe C:\Program Files (x86)\TechSmith\Snagit 11\snagiteditor.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Users\bob\Downloads\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =http://dell13.msn.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =http://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =http://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe, O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" O4 - HKLM\..\Run: [iJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe O4 - HKLM\..\Run: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKCU\..\Run: [DellSystemDetect] C:\Users\bob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms O4 - HKCU\..\Run: [uTorrent] "C:\Users\bob\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED O4 - HKCU\..\Run: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe O4 - HKCU\..\Run: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe O4 - HKCU\..\Run: [spotify] "C:\Users\bob\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart O4 - HKCU\..\Run: [Amazon Cloud Player] C:\Users\bob\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe O4 - HKLM\..\Policies\Explorer\Run: [btvStack] "C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe" O4 - Startup: Dropbox.lnk = bob\AppData\Roaming\Dropbox\bin\Dropbox.exe O4 - Global Startup: CrashPlan Tray.lnk = C:\Program Files\CrashPlan\CrashPlanTray.exe O4 - Global Startup: Snagit 11.lnk = C:\Program Files (x86)\TechSmith\Snagit 11\Snagit32.exe O4 - Global Startup: Windows Home Server.lnk = ? O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~2\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O15 - Trusted Zone: *.dell.com O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} (OnlineScanner Control) -http://download.eset.com/special/eos/OnlineScanner.cab O18 - Protocol: osf-roaming - {C57E9882-B128-4E07-BA2D-FF83B8989C76} - C:\Users\bob\Microsoft Office 15\root\Office15\MSOSB.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - (no file) O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing) O23 - Service: AtherosSvc - Qualcomm Atheros Commnucations - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: CrashPlan Backup Service (CrashPlanService) - CrashPlan - C:\Program Files\CrashPlan\CrashPlanService.exe O23 - Service: Dell Digital Delivery Service (DellDigitalDelivery) - Dell Products, LP. - c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: HPMSSConnectorService (HPMSSConnectorSvc) - HP - C:\Program Files\Hewlett-Packard\HP MediaSmart Server\MSSConnectorService.exe O23 - Service: Intel® Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: IconMan_R - Realsil Microelectronics Inc. - C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe O23 - Service: Intel® Capability Licensing Service Interface - Intel® Corporation - c:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel® Capability Licensing Service TCP IP Interface - Intel® Corporation - c:\Program Files\Intel\iCLS Client\SocketHeciServer.exe O23 - Service: Intel® ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe O23 - Service: Intel® Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe O23 - Service: MBAMScheduler - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: MediaCollectorService - Hewlett-Packard Company - C:\Program Files\Hewlett-Packard\HP MediaSmart Server\MediaCollectorClient.exe O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NMSAccessU - Unknown owner - C:\Program Files (x86)\Illustrate\dBpoweramp\NMSAccessU.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: Realtek Audio Service (RtkAudioService) - Realtek Semiconductor - C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe O23 - Service: Skype Updater (SkypeUpdate) - Skype Technologies - C:\Program Files (x86)\Skype\Updater\Updater.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: StartMenu8 Service (StartMenuService) - IObit - C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: ZAtheros Wlan Agent - Atheros - C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe -- End of file - 12581 bytes ------------------------------------------------------- DDS LOG: DDS (Ver_2012-11-20.01) - NTFS_AMD64 Internet Explorer: 10.0.9200.16537 Run by bob at 10:15:47 on 2013-11-03 Microsoft Windows 8 6.2.9200.0.1252.1.1033.18.8128.4767 [GMT -8:00] . AV: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\system32\dwm.exe C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\atieclxx.exe C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\adminservice.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\CrashPlan\CrashPlanService.exe C:\Windows\system32\dashost.exe C:\Program Files\Hewlett-Packard\HP MediaSmart Server\MSSConnectorService.exe C:\Windows\system32\taskhostex.exe C:\Windows\Explorer.EXE c:\Program Files\Intel\iCLS Client\HeciServer.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe C:\Program Files (x86)\Illustrate\dBpoweramp\NMSAccessU.exe C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Windows Defender\MsMpEng.exe C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe C:\Program Files\Hewlett-Packard\HP MediaSmart Server\MediaCollectorClient.exe C:\Program Files\Windows Home Server\WHSConnector.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8w ekyb3d8bbwe\LiveComm.exe C:\Windows\System32\WUDFHost.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\SearchProtocolHost.exe C:\Program Files (x86)\IObit\Start Menu 8\StartMenu8.exe C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe C:\Program Files (x86)\IObit\Start Menu 8\InstallServices64.exe C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\ActivateDesktop.exe C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe C:\Windows\System32\RuntimeBroker.exe C:\Windows\Microsoft.NET\Framework64\v4.0.30319\dfsvc.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe C:\Program Files\CrashPlan\CrashPlanTray.exe C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe C:\Program Files (x86)\TechSmith\Snagit 11\Snagit32.exe C:\Program Files (x86)\IObit\Start Menu 8\StartMenu_Hook.exe C:\Program Files\Windows Home Server\WHSTrayApp.exe C:\Users\bob\AppData\Roaming\Dropbox\bin\Dropbox.exe C:\Program Files (x86)\TechSmith\Snagit 11\TSCHelp.exe C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Users\bob\AppData\Local\Apps\2.0\XYGPXERC.8EP\6RJQ4VGB.LNY\dell..tion_0f 612f649c4a10af_0005.0003_d2152cbf7ce307ec\DellSystemDetect.exe C:\Program Files (x86)\TechSmith\Snagit 11\SnagPriv.exe C:\Program Files (x86)\TechSmith\Snagit 11\snagiteditor.exe C:\Windows\splwow64.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtTray.exe c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\My Dell\uaclauncher.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Users\bob\Downloads\HijackThis.exe C:\Program Files (x86)\Google\Chrome\Application\chrome.exe C:\Program Files (x86)\Dell Backup and Recovery\TOASTER.EXE C:\Program Files (x86)\Dell Backup and Recovery\Components\Shell\DBRCrawler.exe C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\taskhost.exe C:\Program Files\Windows Defender\MpCmdRun.exe C:\Windows\System32\cscript.exe . ============== Pseudo HJT Report =============== . mWinlogon: Userinit = userinit.exe, uRun: [DellSystemDetect] C:\Users\bob\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dell\Dell System Detect.appref-ms uRun: [uTorrent] "C:\Users\bob\AppData\Roaming\uTorrent\uTorrent.exe" /MINIMIZED uRun: [iCloudServices] C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe uRun: [ApplePhotoStreams] C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe uRun: [spotify] "C:\Users\bob\AppData\Roaming\Spotify\Spotify.exe" /uri spotify:autostart uRun: [Amazon Cloud Player] C:\Users\bob\AppData\Local\Amazon Cloud Player\Amazon Music Helper.exe mRun: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe" mRun: [iJNetworkScanUtility] C:\Program Files (x86)\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe mRun: [startCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mExplorerRun: [btvStack] "C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe" StartupFolder: C:\Users\bob\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dro pbox.lnk - C:\Users\bob\AppData\Roaming\Dropbox\bin\Dropbox.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\CRASHP~1.LNK - C:\Program Files\CrashPlan\CrashPlanTray.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\SNAGIT~1.LNK - C:\Program Files (x86)\TechSmith\Snagit 11\Snagit32.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\StartUp\WINDOW~1.LNK - C:\Windows\Installer\{21E49794-7C13-4E84-8659-55BD378267D5}\WHSTrayApp.exe mPolicies-System: DisableCAD = dword:1 IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~2\Office12\EXCEL.EXE/3000 IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} Trusted Zone: dell.com TCP: NameServer = 75.75.75.75 75.75.76.76 TCP: Interfaces\{04AAAC81-4BDD-4D17-9949-6C483E200BB6} : DHCPNameServer = 75.75.75.75 75.75.76.76 TCP: Interfaces\{B60BCD14-6C4B-4E14-A7B6-E44B8F2F0696} : DHCPNameServer = 75.75.75.75 75.75.76.76 Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - <orphaned> Handler: osf-roaming - {C57E9882-B128-4E07-BA2D-FF83B8989C76} - C:\Users\bob\Microsoft Office 15\root\office15\MSOSB.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll SSODL: WebCheck - <orphaned> mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\30.0.1599.101\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome x64-BHO: CIESpeechBHO Class: {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll x64-BHO: BrowserHelper Class: {9A065C65-4EE7-4DDD-9918-F129089A894A} - C:\Program Files\Windows Home Server\WHSDeskBands.dll x64-TB: Home Server Banner: {D73E76A3-F902-45BD-8FC8-95AE8E014671} - C:\Program Files\Windows Home Server\WHSDeskBands.dll x64-Run: [iAStorIcon] "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIconLaunch.exe" "C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe" 60 x64-Run: [btPreLoad] "C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtPreLoad.exe" x64-Run: [RTHDVCPL] "C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe" -s x64-Run: [RtHDVBg] "C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" /MAXX5REC x64-ExplorerRun: [btvStack] "C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\BtvStack.exe" x64-mPolicies-System: DisableCAD = dword:1 x64-IE: {7815BE26-237D-41A8-A98F-F7BD75F71086} - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\IEPlugIn.dll x64-Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - <orphaned> x64-Handler: osf-roaming - {C57E9882-B128-4E07-BA2D-FF83B8989C76} - <orphaned> x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned> x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned> x64-SSODL: WebCheck - <orphaned> . ============= SERVICES / DRIVERS =============== . R0 iaStorA;iaStorA;C:\Windows\System32\Drivers\iaStorA.sys [2013-7-26 677360] R1 CLVirtualDrive;CLVirtualDrive;C:\Windows\System32\Drivers\CLVirtualDrive.sy s [2013-7-26 92536] R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2013-9-27 98208] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2013-9-27 241152] R2 AtherosSvc;AtherosSvc;C:\Program Files (x86)\Dell Wireless\Bluetooth Suite\AdminService.exe [2012-12-28 226944] R2 CrashPlanService;CrashPlan Backup Service;C:\Program Files\CrashPlan\CrashPlanService.exe [2013-4-8 222720] R2 DellDigitalDelivery;Dell Digital Delivery Service;C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [2013-8-7 199176] R2 HPMSSConnectorSvc;HPMSSConnectorService;C:\Program Files\Hewlett-Packard\HP MediaSmart Server\MSSConnectorService.exe [2009-8-11 20480] R2 IAStorDataMgrSvc;Intel® Rapid Storage Technology;C:\Program Files\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe [2013-4-30 15344] R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek USB 2.0 Card Reader\RIconMan.exe [2013-9-27 2451456] R2 Intel® Capability Licensing Service Interface;Intel® Capability Licensing Service Interface;C:\Program Files\Intel\iCLS Client\HeciServer.exe [2012-12-10 732160] R2 Intel® ME Service;Intel® ME Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [2013-7-26 129336] R2 jhi_service;Intel® Dynamic Application Loader Host Interface Service;C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe [2013-7-26 167736] R2 MBAMScheduler;MBAMScheduler;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [2013-8-26 418376] R2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2013-8-26 701512] R2 MediaCollectorService;MediaCollectorService;C:\Program Files\Hewlett-Packard\HP MediaSmart Server\MediaCollectorClient.exe [2009-8-11 83968] R2 RtkAudioService;Realtek Audio Service;C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [2013-9-27 224840] R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell Backup and Recovery\SftService.exe [2013-7-26 1915480] R2 StartMenuService;StartMenu8 Service;C:\Program Files (x86)\IObit\Start Menu 8\StartMenuServices.exe [2013-10-20 75584] R2 WHSConnector;Windows Home Server Connector Service;C:\Program Files\Windows Home Server\WHSConnector.exe [2009-10-7 489832] R2 ZAtheros Wlan Agent;ZAtheros Wlan Agent;C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [2013-9-27 81536] R3 AthBTPort;Qualcomm Atheros Virtual Bluetooth Class;C:\Windows\System32\Drivers\btath_flt.sys [2012-12-28 89320] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\System32\Drivers\AtihdW86.sys [2013-9-27 94208] R3 BTATH_A2DP;Bluetooth A2DP Audio Driver;C:\Windows\System32\Drivers\btath_a2dp.sys [2012-12-28 345832] R3 btath_avdt;Qualcomm Atheros Bluetooth AVDT Service;C:\Windows\System32\Drivers\btath_avdt.sys [2012-12-28 115432] R3 BTATH_BUS;Qualcomm Atheros Bluetooth Bus;C:\Windows\System32\Drivers\btath_bus.sys [2012-12-28 33944] R3 BTATH_HCRP;Bluetooth HCRP Server driver;C:\Windows\System32\Drivers\btath_hcrp.sys [2012-12-28 179432] R3 BTATH_LWFLT;Bluetooth LWFLT Device;C:\Windows\System32\Drivers\btath_lwflt.sys [2012-12-28 77464] R3 BTATH_RCP;Bluetooth AVRCP Device;C:\Windows\System32\Drivers\btath_rcp.sys [2012-12-28 136424] R3 BtFilter;BtFilter;C:\Windows\System32\Drivers\btfilter.sys [2012-12-28 578792] R3 BthLEEnum;Bluetooth Low Energy Driver;C:\Windows\System32\Drivers\BthLEEnum.sys [2012-7-25 202752] R3 lvpopf64;Logitech POP Suppression Filter;C:\Windows\System32\Drivers\lvpopf64.sys [2007-5-11 1361952] R3 LVUSBS64;Logitech USB Monitor Filter;C:\Windows\System32\Drivers\LVUSBS64.sys [2007-5-11 50208] R3 LVUVC64;@oem16.inf,%PID_08C5_DD%(UVC);Logitech QuickCam Pro 5000(UVC);C:\Windows\System32\Drivers\lvuvc64.sys [2007-5-11 3612704] R3 MBAMProtector;MBAMProtector;C:\Windows\System32\Drivers\mbam.sys [2013-8-26 25928] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;C:\Windows\System32\Drivers\RtsUStor.sys [2013-9-27 252048] R3 RTL8168;Realtek 8168 NT Driver;C:\Windows\System32\Drivers\Rt630x64.sys [2013-7-26 723088] R3 WSDScan;WSD Scan Support;C:\Windows\System32\Drivers\WSDScan.sys [2013-6-26 23552] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-7-25 162672] S3 HipShieldK;McAfee Inc. HipShieldK;C:\Windows\System32\Drivers\HipShieldK.sys [2012-5-28 197264] S3 Intel® Capability Licensing Service TCP IP Interface;Intel® Capability Licensing Service TCP IP Interface;C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [2012-12-10 803872] S3 PCDSRVC{D3412D80-CF3B4A27-06020200}_0;PCDSRVC{D3412D80-CF3B4A27-06020200}_0 - PCDR Kernel Mode Service Helper Driver;C:\Program Files\My Dell\pcdsrvc_x64.pkms [2013-5-2 25584] . =============== Created Last 30 ================ . 2013-11-03 15:28:30 10280728 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{5A6B1B16-8597-4FD5-8779-5FFEB6320FA2}\mpengine.dll 2013-11-03 11:01:39 10280728 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Backup\mpengine.dll 2013-11-03 03:34:27 -------- d-----w- C:\Users\bob\AppData\Roaming\TonePrintEditor 2013-10-31 12:22:06 304304 ----a-w- C:\ProgramData\Microsoft\Windows\Sqm\Manifest\Sqm10223.bin 2013-10-30 15:45:28 -------- d-----w- C:\Program Files (x86)\ESET 2013-10-29 22:22:23 -------- d-----w- C:\Users\bob\AppData\Local\Rogue Amoeba 2013-10-29 22:22:14 -------- d-----w- C:\Program Files (x86)\Airfoil 2013-10-29 09:21:02 -------- d-----w- C:\Windows Home Server Drivers for Restore 2013-10-19 14:14:11 -------- d-----w- C:\Program Files\CCleaner 2013-10-19 00:17:21 -------- d-----w- C:\ProgramData\CrashPlan 2013-10-19 00:17:21 -------- d-----w- C:\Program Files\CrashPlan 2013-10-19 00:15:12 -------- d-----w- C:\Users\bob\AppData\Roaming\CrashPlan 2013-10-17 17:31:49 -------- d-----w- C:\Users\bob\AppData\Roaming\com.amazon.music.uploader 2013-10-17 17:31:43 -------- d-----w- C:\Program Files (x86)\Amazon 2013-10-17 17:31:20 -------- d-----w- C:\Users\bob\AppData\Local\Adobe 2013-10-17 17:26:21 -------- d-----w- C:\Users\bob\AppData\Local\Amazon Cloud Player 2013-10-12 21:31:51 -------- d-----w- C:\Users\bob\AppData\Local\Spotify 2013-10-12 21:31:35 -------- d-----w- C:\Users\bob\AppData\Roaming\Spotify 2013-10-10 10:39:56 652288 ----a-w- C:\Windows\System32\comctl32.dll 2013-10-10 10:38:59 785624 ----a-w- C:\Windows\System32\drivers\Wdf01000.sys . ==================== Find3M ==================== . 2013-10-02 01:38:13 78296 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-10-02 01:38:13 694232 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-09-28 13:31:08 175176 ----a-w- C:\Windows\SysWow64\AirfoilInject3.dll 2013-09-27 21:21:45 173944 ----a-w- C:\Windows\SysWow64\SpoonUninstall.exe 2013-09-22 23:28:06 1767936 ----a-w- C:\Windows\SysWow64\wininet.dll 2013-09-22 23:27:49 2876928 ----a-w- C:\Windows\SysWow64\jscript9.dll 2013-09-22 22:55:10 2241024 ----a-w- C:\Windows\System32\wininet.dll 2013-09-22 22:54:51 3959296 ----a-w- C:\Windows\System32\jscript9.dll 2013-08-23 05:11:57 4040192 ----a-w- C:\Windows\System32\win32k.sys 2013-08-16 05:41:13 58200 ----a-w- C:\Windows\System32\drivers\dam.sys 2013-08-16 05:39:26 2371728 ----a-w- C:\Windows\System32\WSService.dll 2013-08-16 05:32:48 209200 ----a-w- C:\Windows\System32\NotificationUI.exe 2013-08-16 05:22:22 40448 ----a-w- C:\Windows\System32\wuapp.exe 2013-08-16 05:22:11 4917760 ----a-w- C:\Windows\System32\sppsvc.exe 2013-08-16 05:20:30 105984 ----a-w- C:\Windows\System32\WinSetupUI.dll 2013-08-15 22:43:21 35328 ----a-w- C:\Windows\SysWow64\wuapp.exe 2013-08-15 22:43:07 84992 ----a-w- C:\Windows\SysWow64\wudriver.dll 2013-08-15 22:43:07 126976 ----a-w- C:\Windows\SysWow64\wuwebv.dll 2013-08-15 22:43:03 562688 ----a-w- C:\Windows\SysWow64\WSShared.dll 2013-08-15 22:43:03 159232 ----a-w- C:\Windows\SysWow64\WSSync.dll 2013-08-15 22:43:02 83968 ----a-w- C:\Windows\SysWow64\OEMLicense.dll 2013-08-15 22:43:02 167424 ----a-w- C:\Windows\SysWow64\WSClient.dll 2013-08-15 22:43:02 143872 ----a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.dll 2013-08-15 22:43:02 124928 ----a-w- C:\Windows\SysWow64\Windows.ApplicationModel.Store.TestingFramework.dll 2013-08-15 22:42:52 76800 ----a-w- C:\Windows\SysWow64\setupcln.dll 2013-08-15 22:42:47 91648 ----a-w- C:\Windows\SysWow64\sppc.dll 2013-08-10 05:21:51 448512 ----a-w- C:\Windows\System32\SettingSync.dll 2013-08-10 05:21:51 128512 ----a-w- C:\Windows\System32\SettingSyncInfo.dll 2013-08-10 03:58:51 356352 ----a-w- C:\Windows\SysWow64\SettingSync.dll 2013-08-07 05:15:02 144896 ----a-w- C:\Windows\System32\tssdisai.dll . ============= FINISH: 10:16:52.48 =============== ------------------------ ATTACH.txt LOG: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 8 Boot Device: \Device\HarddiskVolume1 Install Date: 8/26/2013 2:17:00 PM System Uptime: 11/3/2013 9:41:46 AM (1 hours ago) . Motherboard: Dell Inc. | | 0KWVT8 Processor: Intel® Core i7-4770 CPU @ 3.40GHz | CPU 1 | 3401/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 919 GiB total, 653.888 GiB free. D: is CDROM () E: is Removable F: is Removable G: is Removable H: is Removable I: is FIXED (NTFS) - 1863 GiB total, 0.012 GiB free. J: is CDROM () K: is FIXED (NTFS) - 3726 GiB total, 166.306 GiB free. L: is FIXED (NTFS) - 2048 GiB total, 554.968 GiB free. Y: is FIXED (NTFS) - 0 GiB total, 0.201 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP14: 10/18/2013 5:17:06 PM - Installed CrashPlan RP15: 10/27/2013 3:04:32 AM - Scheduled Checkpoint RP16: 11/3/2013 3:08:39 AM - Scheduled Checkpoint . ==== Installed Programs ====================== . µTorrent Adobe AIR Airfoil Amazon Cloud Player Amazon Music Importer AMD Accelerated Video Transcoding AMD APP SDK Runtime AMD Catalyst Install Manager Apple Software Update Bonjour Canon IJ Network Scan Utility Canon IJ Network Tool Canon MX870 series MP Drivers Catalyst Control Center Catalyst Control Center - Branding Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CCleaner CDBurnerXP CrashPlan CyberLink LabelPrint 2.5 CyberLink Media Suite 10 CyberLink Media Suite Essentials CyberLink Power2Go 8 CyberLink PowerDirector 10 CyberLink PowerDVD 10 D3DX10 dBpoweramp Batch Ripper dBpoweramp CD Writer dBpoweramp CD Writer Limited User Burning Service dBpoweramp DSP Effects dBpoweramp Music Converter Dell Backup and Recovery Dell Backup and Recovery - Support Software Dell Digital Delivery Dell System Detect Dell System Detect Bootstrapper Dell WLAN and Bluetooth Client Installation Dropbox DSC/AA Factory Installer ESET Online Scanner v3 Gmail Backup Google Chrome Google Update Helper GSmartControl Hard Disk Low Level Format Tool 4.25 HitmanPro 3.7 HP MediaSmart Server 3.0 (x64) iCloud Intel® Manageability Engine Firmware Recovery Agent Intel® Management Engine Components Intel® Rapid Storage Technology Intel® Trusted Connect Service Client Kernel Outlook PST Viewer ver 11.05.01 Malwarebytes Anti-Malware version 1.75.0.1300 Microsoft Application Error Reporting Microsoft Office Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (English) 2007 Microsoft Office Office 64-bit Components 2007 Microsoft Office on Demand Browser Add-ons Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared 64-bit MUI (English) 2007 Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Small Business 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Movie Maker Mozilla Maintenance Service Mozilla Thunderbird 24.0 (x86 en-US) MSVCRT MSVCRT110 MSVCRT110_amd64 My Dell Photo Common Photo Gallery Qualcomm Atheros Bluetooth Suite (64) Realtek High Definition Audio Driver Realtek USB 2.0 Card Reader SeaTools for Windows Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2827329) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office Outlook 2007 (KB2825999) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2827330) 32-Bit Edition Shared C Run-time for x64 Skype™ 6.7 Slice Audio File Splitter Snagit 11 Spotify Start Menu 8 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2827325) 32-Bit Edition Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) WavePad Sound Editor Winamp Winamp Detector Plug-in Windows Home Server Connector Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack . ==== Event Viewer Messages From Past Week ======== . 11/3/2013 9:42:06 AM, Error: Microsoft-Windows-Ntfs [98] - Volume I: (\Device\HarddiskVolume9) needs to be taken offline to perform a Full Chkdsk. Please run "CHKDSK /F" locally via the command line, or run "REPAIR-VOLUME <drive:>" locally or remotely via PowerShell. 11/3/2013 9:41:32 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk7\DR7. 11/3/2013 9:41:32 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk6\DR6. 11/3/2013 9:41:32 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk5\DR5. 11/3/2013 9:41:32 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk4\DR4. 11/3/2013 9:39:19 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {7022A3B3-D004-4F52-AF11-E9E987FEE25F} and APPID {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D} to the user Dell8700\bob SID (S-1-5-21-2209406391-1415407880-3894088312-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 11/3/2013 9:35:05 AM, Error: Service Control Manager [7031] - The Windows Defender Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 11/3/2013 10:00:02 AM, Error: Ntfs [137] - The default transaction resource manager on volume I: encountered a non-retryable error and could not start. The data contains the error code. 11/2/2013 2:24:25 PM, Error: Microsoft-Windows-Ntfs [98] - Volume I: (\Device\HarddiskVolume20) needs to be taken offline to perform a Full Chkdsk. Please run "CHKDSK /F" locally via the command line, or run "REPAIR-VOLUME <drive:>" locally or remotely via PowerShell. 11/1/2013 10:28:57 PM, Error: Microsoft-Windows-Ntfs [98] - Volume I: (\Device\HarddiskVolume19) needs to be taken offline to perform a Full Chkdsk. Please run "CHKDSK /F" locally via the command line, or run "REPAIR-VOLUME <drive:>" locally or remotely via PowerShell. 10/27/2013 8:59:24 PM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk3\DR3. 10/27/2013 8:59:24 PM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk2\DR2. 10/27/2013 8:59:24 PM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1. . ==== End Of File =========================== -------------------------------------------------------------------- GMER LOG: . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2012-11-20.01) . Microsoft Windows 8 Boot Device: \Device\HarddiskVolume1 Install Date: 8/26/2013 2:17:00 PM System Uptime: 11/3/2013 9:41:46 AM (1 hours ago) . Motherboard: Dell Inc. | | 0KWVT8 Processor: Intel® Core i7-4770 CPU @ 3.40GHz | CPU 1 | 3401/100mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 919 GiB total, 653.888 GiB free. D: is CDROM () E: is Removable F: is Removable G: is Removable H: is Removable I: is FIXED (NTFS) - 1863 GiB total, 0.012 GiB free. J: is CDROM () K: is FIXED (NTFS) - 3726 GiB total, 166.306 GiB free. L: is FIXED (NTFS) - 2048 GiB total, 554.968 GiB free. Y: is FIXED (NTFS) - 0 GiB total, 0.201 GiB free. . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP14: 10/18/2013 5:17:06 PM - Installed CrashPlan RP15: 10/27/2013 3:04:32 AM - Scheduled Checkpoint RP16: 11/3/2013 3:08:39 AM - Scheduled Checkpoint . ==== Installed Programs ====================== . µTorrent Adobe AIR Airfoil Amazon Cloud Player Amazon Music Importer AMD Accelerated Video Transcoding AMD APP SDK Runtime AMD Catalyst Install Manager Apple Software Update Bonjour Canon IJ Network Scan Utility Canon IJ Network Tool Canon MX870 series MP Drivers Catalyst Control Center Catalyst Control Center - Branding Catalyst Control Center InstallProxy Catalyst Control Center Localization All ccc-utility64 CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish CCleaner CDBurnerXP CrashPlan CyberLink LabelPrint 2.5 CyberLink Media Suite 10 CyberLink Media Suite Essentials CyberLink Power2Go 8 CyberLink PowerDirector 10 CyberLink PowerDVD 10 D3DX10 dBpoweramp Batch Ripper dBpoweramp CD Writer dBpoweramp CD Writer Limited User Burning Service dBpoweramp DSP Effects dBpoweramp Music Converter Dell Backup and Recovery Dell Backup and Recovery - Support Software Dell Digital Delivery Dell System Detect Dell System Detect Bootstrapper Dell WLAN and Bluetooth Client Installation Dropbox DSC/AA Factory Installer ESET Online Scanner v3 Gmail Backup Google Chrome Google Update Helper GSmartControl Hard Disk Low Level Format Tool 4.25 HitmanPro 3.7 HP MediaSmart Server 3.0 (x64) iCloud Intel® Manageability Engine Firmware Recovery Agent Intel® Management Engine Components Intel® Rapid Storage Technology Intel® Trusted Connect Service Client Kernel Outlook PST Viewer ver 11.05.01 Malwarebytes Anti-Malware version 1.75.0.1300 Microsoft Application Error Reporting Microsoft Office Microsoft Office 2007 Service Pack 3 (SP3) Microsoft Office Excel MUI (English) 2007 Microsoft Office Office 64-bit Components 2007 Microsoft Office on Demand Browser Add-ons Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared 64-bit MUI (English) 2007 Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Small Business 2007 Microsoft Office Word MUI (English) 2007 Microsoft Silverlight Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Movie Maker Mozilla Maintenance Service Mozilla Thunderbird 24.0 (x86 en-US) MSVCRT MSVCRT110 MSVCRT110_amd64 My Dell Photo Common Photo Gallery Qualcomm Atheros Bluetooth Suite (64) Realtek High Definition Audio Driver Realtek USB 2.0 Card Reader SeaTools for Windows Security Update for Microsoft Office 2007 suites (KB2596744) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596754) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596792) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596825) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2596871) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597969) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2597973) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2687309) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760411) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760585) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2760591) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2827326) 32-Bit Edition Security Update for Microsoft Office 2007 suites (KB2827329) 32-Bit Edition Security Update for Microsoft Office Excel 2007 (KB2827324) 32-Bit Edition Security Update for Microsoft Office InfoPath 2007 (KB2687440) 32-Bit Edition Security Update for Microsoft Office Outlook 2007 (KB2825999) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596764) 32-Bit Edition Security Update for Microsoft Office PowerPoint 2007 (KB2596912) 32-Bit Edition Security Update for Microsoft Office Publisher 2007 (KB2597971) 32-Bit Edition Security Update for Microsoft Office Word 2007 (KB2827330) 32-Bit Edition Shared C Run-time for x64 Skype™ 6.7 Slice Audio File Splitter Snagit 11 Spotify Start Menu 8 Update for 2007 Microsoft Office System (KB967642) Update for Microsoft Office 2007 Help for Common Features (KB963673) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition Update for Microsoft Office Excel 2007 Help (KB963678) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition Update for Microsoft Office Outlook 2007 Help (KB963677) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2827325) 32-Bit Edition Update for Microsoft Office Powerpoint 2007 Help (KB963669) Update for Microsoft Office Publisher 2007 Help (KB963667) Update for Microsoft Office Script Editor Help (KB963671) Update for Microsoft Office Word 2007 Help (KB963665) WavePad Sound Editor Winamp Winamp Detector Plug-in Windows Home Server Connector Windows Live Communications Platform Windows Live Essentials Windows Live Installer Windows Live Photo Common Windows Live PIMT Platform Windows Live SOXE Windows Live SOXE Definitions Windows Live UX Platform Windows Live UX Platform Language Pack . ==== Event Viewer Messages From Past Week ======== . 11/3/2013 9:42:06 AM, Error: Microsoft-Windows-Ntfs [98] - Volume I: (\Device\HarddiskVolume9) needs to be taken offline to perform a Full Chkdsk. Please run "CHKDSK /F" locally via the command line, or run "REPAIR-VOLUME <drive:>" locally or remotely via PowerShell. 11/3/2013 9:41:32 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk7\DR7. 11/3/2013 9:41:32 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk6\DR6. 11/3/2013 9:41:32 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk5\DR5. 11/3/2013 9:41:32 AM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk4\DR4. 11/3/2013 9:39:19 AM, Error: Microsoft-Windows-DistributedCOM [10016] - The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {7022A3B3-D004-4F52-AF11-E9E987FEE25F} and APPID {ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D} to the user Dell8700\bob SID (S-1-5-21-2209406391-1415407880-3894088312-1001) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. 11/3/2013 9:35:05 AM, Error: Service Control Manager [7031] - The Windows Defender Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 11/3/2013 10:00:02 AM, Error: Ntfs [137] - The default transaction resource manager on volume I: encountered a non-retryable error and could not start. The data contains the error code. 11/2/2013 2:24:25 PM, Error: Microsoft-Windows-Ntfs [98] - Volume I: (\Device\HarddiskVolume20) needs to be taken offline to perform a Full Chkdsk. Please run "CHKDSK /F" locally via the command line, or run "REPAIR-VOLUME <drive:>" locally or remotely via PowerShell. 11/1/2013 10:28:57 PM, Error: Microsoft-Windows-Ntfs [98] - Volume I: (\Device\HarddiskVolume19) needs to be taken offline to perform a Full Chkdsk. Please run "CHKDSK /F" locally via the command line, or run "REPAIR-VOLUME <drive:>" locally or remotely via PowerShell. 10/27/2013 8:59:24 PM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk3\DR3. 10/27/2013 8:59:24 PM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk2\DR2. 10/27/2013 8:59:24 PM, Error: disk [11] - The driver detected a controller error on \Device\Harddisk1\DR1. . ==== End Of File =========================== -----------------------
  12. Just ran full MB scan and found both of these nasty viruses even after I just concluded a thorough cleaning assist on this forum. Can someone assist in permanently removing all PUP viruses off my Windows XP desktop machine?
  13. Quick question. Why is it essential to remove all these virus fighting tools from my PC? Just curious because i kinda like having them in a folder on my desktop in case i need to use them again. I guess I was wondering if there was some risk leaving them installed?
  14. Zoek.exe Version 4.0.0.4 Updated 31-07-2013 Tool run by bsacco on Tue 08/06/2013 at 6:40:13.29. Microsoft Windows XP Professional 5.1.2600 Service Pack 3 x86 Running in: Normal Mode Internet Access Detected Launched: C:\Documents and Settings\Administrator\Desktop\VIRUS TOOL PACKAGE\zoek.exe [Checkboxes used] ==== System Restore Info ====================== 8/6/2013 6:44:27 AM Zoek.exe System Restore Point Created Succesfully. ==== Chrome Look ====================== HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions nbdbmopeebalgaeghmjoegpkngglikgn - C:\Program Files\FreeHDSport.TV\freehdsporttv10.crx[06/30/2013 01:44 AM] HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\Extensions nikpibnbobmbdbheedjfogjlikpgpnhp - C:\Program Files\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx[07/25/2013 02:18 PM] myPlex Queue Extension - Administrator - Default\Extensions\agmheakklldmclgmkfnncddgkiibboil Send using Gmail\u2122 no button - Administrator - Default\Extensions\ahldefgplekckalfcolhhnljbbgaiboc Changes to sync - Administrator - Default\Extensions\ajpgkpeckebdhofmmjfgcjjiiejpodla YouTube - Administrator - Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Replace New Tab Page - Administrator - Default\Extensions\cnkhddihkmmiiclaipbaaelfojkmlkja Google Search - Administrator - Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf Solitaire Games - Administrator - Default\Extensions\eljmkmbmhmgmpmmbkagbobpmpocacdbo Smartr Inbox for Gmail - Administrator - Default\Extensions\gakklmehjhhdfjjgnmpkjoemjmeomnli AdBlock - Administrator - Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom ToutApp for Gmail\u2122 - Administrator - Default\Extensions\gllmkcahdekdbapmdfnffclacbpnicaj Rapportive - Administrator - Default\Extensions\hihakjfhbmlmjdnnhegiciffjplmdhin Cloud Reader - Administrator - Default\Extensions\icdipabjmbhpdkjaihfjoikhjjeneebd Adblock for Pirate Bay - Administrator - Default\Extensions\imkpamgpfalmdaikobnkefcmmkpgljjd WhatFont - Administrator - Default\Extensions\jabopobgcpjmedljpbcaablpmlmfcogm Yet Another Google Bookmarks Extension - Administrator - Default\Extensions\jdnejaepfmacfdmhkplckpfdcjgbeode Disconnect - Administrator - Default\Extensions\jeoacafpbcihiomhlakheieifhpjdfeo Bookmarks Menu - Administrator - Default\Extensions\jhlkofhkkahcpbmgbgmopdjephahdeej Collabspot Highrise for Gmail - Administrator - Default\Extensions\kbmgfmocmjkhjamfenkdnkobjempbhjh Evernote Web - Administrator - Default\Extensions\lbfehkoinhhcknnbdgnnmjhiladcgbol Ghostery - Administrator - Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij Send from Gmail (by Google) - Administrator - Default\Extensions\pgphcomnlaojlmmcjmiddhdapjpbgeoc Evernote Web Clipper - Administrator - Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc Gmail - Administrator - Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia RSS Feed Reader - Administrator - Default\Extensions\pnjaodmkngahhkoihejjehlcdlnohgmp Google Docs - TEST - Default\Extensions\aohghmighlieiainnegkcijnfilokake Google Drive - TEST - Default\Extensions\apdfllckaahabafndbhieahigkjlhalf YouTube - TEST - Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo Google Search - TEST - Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf ToutApp for Gmail\u2122 - TEST - Default\Extensions\gllmkcahdekdbapmdfnffclacbpnicaj ToutApp Sales Communications - TEST - Default\Extensions\kfjjpjjnmkhalkjiaomecjddeapodgob Gmail - TEST - Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia ==== EOF on Tue 08/06/2013 at 6:45:12.00 ======================
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.