Jump to content

MikeMurphy

Members
  • Posts

    19
  • Joined

  • Last visited

Everything posted by MikeMurphy

  1. Everything seems to be working great! If this is it, I think you are amazing! Thanks for spending the time! Mike
  2. FixLog Fix result of Farbar Recovery Scan Tool (x64) Version: 25-06-2017 01 Ran by murph (27-06-2017 22:22:45) Run:4 Running from C:\Users\murph\Desktop\fix Loaded Profiles: murph (Available Profiles: murph) Boot Mode: Normal ============================================== fixlist content: ***************** HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "Chromium" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "PCCleaner" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "Ca013i5M8Y.exe" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "WindowsUpdate" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "fade4cca898c41f1d25eea0bcf1504f0" ***************** HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\Chromium => value removed successfully HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Chromium => value not found. HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\PCCleaner => value removed successfully HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\PCCleaner => value not found. HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\Ca013i5M8Y.exe => value removed successfully HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\Ca013i5M8Y.exe => value not found. HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\WindowsUpdate => value removed successfully HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\WindowsUpdate => value not found. HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run\\fade4cca898c41f1d25eea0bcf1504f0 => value removed successfully HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\fade4cca898c41f1d25eea0bcf1504f0 => value not found. ==== End of Fixlog 22:22:45 ====
  3. OOPS. Sorry Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 25-06-2017 01 Ran by murph (administrator) on DESKTOP-3FHNIRL (26-06-2017 19:47:00) Running from C:\Users\murph\Desktop\fix Loaded Profiles: murph (Available Profiles: murph) Platform: Windows 10 Home Version 1703 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: Edge) Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (Intel Corporation) C:\Windows\System32\ibtsiva.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfemms.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe (Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe (Intel Security, Inc.) C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\McCSPServiceHost.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\VSCore_15_6\mcapexe.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe (Dell Inc.) C:\Program Files (x86)\Dell Customer Connect\DCCService.exe (Dell) C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe (Dell Inc.) C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe (Dell Products, LP.) C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpService.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Dell) C:\Program Files\Dell\Dell Product Registration\PRSvc.exe (Dell Inc.) C:\Program Files (x86)\Dell Update\DellUpTray.exe (Dell) C:\Program Files\Dell\Dell Foundation Services\DFS.Common.Agent.exe (Microsoft Corporation) C:\Program Files\WindowsApps\Microsoft.WindowsStore_11705.1001.21.0_x64__8wekyb3d8bbwe\WinStore.App.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.40985.0_x64__8wekyb3d8bbwe\HxOutlook.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.40985.0_x64__8wekyb3d8bbwe\HxTsr.exe (Microsoft Corporation) C:\Windows\ImmersiveControlPanel\SystemSettings.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe (Intel Security) C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe (Microsoft Corporation) C:\Windows\System32\smartscreen.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [8512760 2015-12-01] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1411320 2015-12-01] (Realtek Semiconductor) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM\...\Run: [WavesSvc] => "C:\Program Files\Waves\MaxxAudio\WavesSvc64.exe" HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [322472 2015-06-23] (Intel Corporation) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [508128 2016-07-01] (Adobe Systems Incorporated) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2780112 2017-01-20] (Malwarebytes) HKLM-x32\...\Run: [ConnectionCenter] => C:\Program Files (x86)\Citrix\ICA Client\concentr.exe [309184 2012-03-28] (Citrix Systems, Inc.) HKLM-x32\...\Run: [IJNetworkScannerSelectorEX] => C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe [452272 2012-08-31] (CANON INC.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2016-12-12] (Oracle Corporation) HKLM-x32\...\Run: [Adobe Creative Cloud] => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2404952 2017-03-27] (Adobe Systems Incorporated) HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\Run: [GoogleDriveSync] => "C:\Program Files (x86)\Google\Drive\googledrivesync.exe" /autostart HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\Run: [Lync] => C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe [23348928 2017-06-18] (Microsoft Corporation) HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation) ShellIconOverlayIdentifiers: [ AccExtIco1] -> {AB9CF9F8-8A96-4F9D-BF21-CE85714C3A47} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco2] -> {853B7E05-C47D-4985-909A-D0DC5C6D7303} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ShellIconOverlayIdentifiers: [ AccExtIco3] -> {42D38F2E-98E9-4382-B546-E24E4D6D04BB} => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll [2016-10-25] () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 24.226.1.93 24.226.10.193 24.226.10.194 24.226.1.94 Tcpip\..\Interfaces\{0fed2df0-84c8-410e-b863-fcc9da4bc7c2}: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{448b1f29-b75b-4743-af62-a293b833dd0d}: [DhcpNameServer] 24.226.1.93 24.226.10.193 24.226.10.194 24.226.1.94 Internet Explorer: ================== SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-1523608283-3295547807-88052705-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxps://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IESR02&pc=UE04 BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2017-06-18] (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_121\bin\ssv.dll [2017-03-25] (Oracle Corporation) BHO: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-05-16] (McAfee, Inc.) BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2017-06-18] (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-25] (Oracle Corporation) BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2017-06-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\ssv.dll [2017-03-25] (Oracle Corporation) BHO-x32: McAfee WebAdvisor BHO -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-05-16] (McAfee, Inc.) BHO-x32: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\GROOVEEX.DLL [2017-06-18] (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\jp2ssv.dll [2017-03-25] (Oracle Corporation) DPF: HKLM-x32 {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} hxxps://secure.logmein.com/activex/RACtrl.cab?rnd=1624185773 Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-05-16] (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-05-16] (McAfee, Inc.) Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation) Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation) Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation) Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2017-06-18] (Microsoft Corporation) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll [2017-05-16] (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll [2017-05-16] (McAfee, Inc.) Filter-x32: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter-x32: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll [2017-04-17] (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll [2017-04-17] (McAfee, Inc.) Filter-x32: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll [2012-03-28] (Citrix Systems, Inc.) Edge: ====== Edge HomeButtonPage: HKU\S-1-5-21-1523608283-3295547807-88052705-1001 -> hxxp://www.google.ca/ FireFox: ======== FF DefaultProfile: 4j9chsr5.default FF ProfilePath: C:\Users\murph\AppData\Roaming\Mozilla\Firefox\Profiles\4j9chsr5.default [2017-06-25] FF Homepage: Mozilla\Firefox\Profiles\4j9chsr5.default -> user_pref("browser.startup.homepage", "hxxps://www.malwarebytes.org/restorebrowser/ FF NewTab: Mozilla\Firefox\Profiles\4j9chsr5.default -> about:newtab FF Extension: (SaveFrom.net - helper) - C:\Users\murph\AppData\Roaming\Mozilla\Firefox\Profiles\4j9chsr5.default\Extensions\helper-sig@savefrom.net.xpi [2016-08-24] FF Extension: (Skype) - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}.xpi [2016-05-25] FF HKLM\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi FF Extension: (McAfee WebAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi [2017-04-18] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor\saffplg.xpi FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: (McAfee Anti-Spam Thunderbird Extension) - C:\Program Files\McAfee\MSK [2017-03-29] [not signed] FF Plugin: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-25] (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-25] (Oracle Corporation) FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [2017-04-17] () FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll [2017-03-27] (Adobe Systems) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Program Files (x86)\Arc\plugins\flash\NPSWF32.dll [No File] FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1220162.dll [2015-08-31] (Adobe Systems, Inc.) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.68 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2015-04-21] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\dtplugin\npDeployJava1.dll [2017-03-25] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.121.2 -> C:\Program Files (x86)\Java\jre1.8.0_121\bin\plugin2\npjp2.dll [2017-03-25] (Oracle Corporation) FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL [2017-04-17] () FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2017-06-18] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2017-06-18] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-28] (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-04-04] (Adobe Systems Inc.) FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll [2017-03-27] (Adobe Systems) Chrome: ======= CHR DefaultProfile: Profile 3 CHR HomePage: Profile 3 -> mail.ru CHR StartupUrls: Profile 3 -> "hxxp://www.google.ca/" CHR Profile: C:\Users\murph\AppData\Local\Google\Chrome\User Data\Default [2017-06-25] CHR Profile: C:\Users\murph\AppData\Local\Google\Chrome\User Data\Profile 1 [2017-06-25] CHR Profile: C:\Users\murph\AppData\Local\Google\Chrome\User Data\Profile 3 [2017-06-25] CHR Extension: (Google Docs) - C:\Users\murph\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\aohghmighlieiainnegkcijnfilokake [2017-05-20] CHR Extension: (Домашняя страница Mail.Ru) - C:\Users\murph\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ccfifbojenkenpkmnbnndeadpfdiffof [2017-05-20] CHR Extension: (Tampermonkey) - C:\Users\murph\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\dhdgffkkebhmkfjojejmpbldmpobfkfo [2017-05-20] CHR Extension: (Adobe Acrobat) - C:\Users\murph\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-05-20] CHR Extension: (McAfee® WebAdvisor) - C:\Users\murph\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2017-05-20] CHR Extension: (Google Docs Offline) - C:\Users\murph\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-05-20] CHR Extension: (Skype) - C:\Users\murph\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2017-05-20] CHR Extension: (Application Launcher for Drive (by Google)) - C:\Users\murph\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\lmjegmlicamnimmfhcmpkclmigmmcbeh [2017-05-20] CHR Extension: (Chrome Web Store Payments) - C:\Users\murph\AppData\Local\Google\Chrome\User Data\Profile 3\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-05-20] CHR Profile: C:\Users\murph\AppData\Local\Google\Chrome\User Data\System Profile [2017-06-25] CHR HKLM\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [dhdgffkkebhmkfjojejmpbldmpobfkfo] - hxxp://clients2.google.com/service/update2/crx CHR HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [lmjegmlicamnimmfhcmpkclmigmmcbeh] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - hxxp://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AdobeUpdateService; C:\Program Files (x86)\Common Files\Adobe\Adobe Desktop Common\ElevationManager\AdobeUpdateService.exe [771672 2017-03-14] (Adobe Systems Incorporated) R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.) R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [3705544 2017-05-04] (Microsoft Corporation) R3 ClientAnalyticsService; C:\Program Files\Common Files\McAfee\ClientAnalytics\Legacy\McClientAnalytics.exe [1752992 2017-03-29] (Intel Security) R2 Dell Customer Connect; C:\Program Files (x86)\Dell Customer Connect\DCCService.exe [130936 2016-12-21] (Dell Inc.) R2 Dell Foundation Services; C:\Program Files\Dell\Dell Foundation Services\DFSSvc.exe [97616 2017-01-11] (Dell) R2 Dell Help & Support; C:\Program Files\Dell\Dell Help & Support\MDLCSvc.exe [78672 2016-09-13] (Dell Inc.) R2 DellUpdate; C:\Program Files (x86)\Dell Update\DellUpService.exe [237272 2015-08-27] (Dell Inc.) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 IAStorDataMgrSvc; C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [18856 2015-06-23] (Intel Corporation) S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [881152 2015-05-22] (Intel(R) Corporation) R3 Intel(R) Security Assist; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isa.exe [335872 2015-05-19] (Intel Corporation) [File not signed] S2 isaHelperSvc; C:\Program Files (x86)\Intel\Intel(R) Security Assist\isaHelperService.exe [7680 2015-05-19] () [File not signed] R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [223008 2015-06-24] (Intel Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4355024 2017-01-20] (Malwarebytes) R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\McSACore.exe [188256 2017-05-16] (McAfee, Inc.) R2 McAPExe; C:\Program Files\Common Files\McAfee\VSCore_15_6\McApExe.exe [994312 2017-04-04] (McAfee, Inc.) R2 McBootDelayStartSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 mccspsvc; C:\Program Files\Common Files\McAfee\CSP\2.3.322.0\\McCSPServiceHost.exe [2054080 2017-02-28] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [1344472 2017-02-24] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) R3 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [241040 2017-01-18] (McAfee, Inc.) R2 mfemms; C:\Program Files\Common Files\McAfee\SystemCore\\mfemms.exe [385112 2017-01-18] (McAfee, Inc.) R3 mfevtp; C:\WINDOWS\system32\mfevtps.exe [343792 2017-01-18] (McAfee, Inc.) R2 ModuleCoreService; C:\Program Files\Common Files\McAfee\ModuleCore\ModuleCoreService.exe [1551512 2017-02-26] (McAfee, Inc.) S3 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [641520 2017-02-22] (McAfee, Inc.) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [268192 2015-06-12] () R2 PEFService; C:\Program Files\Common Files\Intel Security\PEF\CORE\PEFService.exe [1104304 2016-11-15] (Intel Security, Inc.) R2 Product Registration; C:\Program Files\Dell\Dell Product Registration\PRSvc.exe [47144 2017-04-06] (Dell) R2 RtkAudioService; C:\Program Files\Realtek\Audio\HDA\RtkAudioService64.exe [312056 2015-12-01] (Realtek Semiconductor) S3 Te.Service; C:\Program Files (x86)\Windows Kits\10\Testing\Runtimes\TAEF\Wex.Services.exe [137216 2015-11-19] (Microsoft Corporation) [File not signed] S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-03-18] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [3831200 2015-06-12] (Intel® Corporation) R2 ibtsiva; %SystemRoot%\system32\ibtsiva [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) S0 amdkmafd; C:\Windows\System32\drivers\amdkmafd.sys [40720 2015-07-28] (Advanced Micro Devices, Inc.) R3 amdkmdag; C:\Windows\System32\DriverStore\FileRepository\c0313676.inf_amd64_96bbc33bec5c7fae\atikmdag.sys [36558208 2017-05-16] (Advanced Micro Devices, Inc.) R3 amdkmdap; C:\Windows\System32\DriverStore\FileRepository\c0313676.inf_amd64_96bbc33bec5c7fae\atikmpag.sys [528760 2017-05-16] (Advanced Micro Devices, Inc.) S3 AsusVBus; C:\Windows\System32\drivers\AsusVBus.sys [39704 2016-11-03] (Windows (R) Win 7 DDK provider) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdWT6.sys [102912 2015-07-22] (Advanced Micro Devices) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [88464 2017-01-20] (McAfee, Inc.) R1 ESProtectionDriver; C:\WINDOWS\system32\drivers\mbae64.sys [77440 2017-04-13] () S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [225432 2017-04-01] (McAfee, Inc.) R3 ibtusb; C:\Windows\system32\DRIVERS\ibtusb.sys [230144 2016-11-11] (Intel Corporation) U5 mbamchameleon; C:\Windows\System32\Drivers\mbamchameleon.sys [109272 2017-06-24] (Malwarebytes) R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [111544 2017-06-26] (Malwarebytes) R3 MBAMProtection; C:\WINDOWS\system32\drivers\mbam.sys [43968 2017-06-26] (Malwarebytes) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [251832 2017-06-26] (Malwarebytes) R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [92096 2017-06-26] (Malwarebytes) R3 mfeaack; C:\Windows\System32\drivers\mfeaack.sys [487184 2017-01-20] (McAfee, Inc.) R3 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [366328 2017-01-20] (McAfee, Inc.) S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [85048 2017-04-03] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [518704 2017-01-20] (McAfee, Inc.) R0 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [923640 2017-01-20] (McAfee, Inc.) R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [498648 2017-01-19] (McAfee, Inc.) S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [109320 2017-01-19] (McAfee, Inc.) R3 mfeplk; C:\Windows\System32\drivers\mfeplk.sys [110256 2017-01-20] (McAfee, Inc.) R3 mfesapsn; C:\Program Files (x86)\McAfee\SiteAdvisor\x64\mfesapsn.sys [46240 2016-06-06] (McAfee, Inc.) R0 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [254800 2017-01-20] (McAfee, Inc.) R3 NETwNb64; C:\Windows\System32\drivers\Netwbw02.sys [3776792 2015-06-22] (Intel Corporation) R3 rt640x64; C:\Windows\System32\drivers\rt640x64.sys [886528 2015-05-29] (Realtek ) R3 RTSUER; C:\Windows\system32\Drivers\RtsUer.sys [402136 2015-05-27] (Realsil Semiconductor Corporation) S3 SDFRd; C:\Windows\System32\drivers\SDFRd.sys [31128 2017-03-18] () S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation) S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation) S3 wdm_usb; C:\Windows\system32\DRIVERS\usb2ser.sys [159936 2016-08-16] (MBB) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation) S3 xhunter1; C:\Windows\xhunter1.sys [35880 2015-11-15] (Wellbia.com Co., Ltd.) S3 XSplit_Dummy; C:\Windows\system32\drivers\xspltspk.sys [26200 2015-05-25] (SplitmediaLabs Limited) R3 XtuAcpiDriver; C:\Windows\System32\drivers\XtuAcpiDriver.sys [63840 2015-12-01] (Intel Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-06-26 18:25 - 2017-06-26 18:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee 2017-06-26 17:41 - 2017-06-26 18:24 - 00000551 _____ C:\Users\murph\Desktop\JRT.txt 2017-06-26 17:38 - 2017-06-26 17:38 - 01663672 _____ (Malwarebytes) C:\Users\murph\Desktop\JRT.exe 2017-06-26 17:22 - 2017-06-26 18:21 - 00000000 ___DC C:\AdwCleaner 2017-06-26 17:20 - 2017-06-26 17:20 - 04110280 _____ C:\Users\murph\Desktop\AdwCleaner.exe 2017-06-26 13:25 - 2017-06-26 13:25 - 00049133 _____ C:\Users\murph\Downloads\fixlist.txt 2017-06-25 17:59 - 2017-06-03 05:36 - 01150784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ucrtbase.dll 2017-06-25 17:59 - 2017-06-03 05:23 - 20373920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2017-06-25 17:59 - 2017-06-03 05:23 - 06760024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.Protection.PlayReady.dll 2017-06-25 17:59 - 2017-06-03 05:23 - 00573856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comctl32.dll 2017-06-25 17:59 - 2017-06-03 05:11 - 02958848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\win32kfull.sys 2017-06-25 17:59 - 2017-06-03 05:09 - 00094720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UserDataTimeUtil.dll 2017-06-25 17:59 - 2017-06-03 05:05 - 00198656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll 2017-06-25 17:59 - 2017-06-03 05:05 - 00169984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\devicengccredprov.dll 2017-06-25 17:59 - 2017-06-03 05:03 - 00467456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TpmCoreProvisioning.dll 2017-06-25 17:59 - 2017-06-03 05:00 - 00358400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieproxy.dll 2017-06-25 17:59 - 2017-06-03 04:59 - 02672128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll 2017-06-25 17:59 - 2017-06-03 04:59 - 00636416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WpcWebFilter.dll 2017-06-25 17:59 - 2017-06-03 04:57 - 11870720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2017-06-25 17:59 - 2017-06-03 04:57 - 06535168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mspaint.exe 2017-06-25 17:59 - 2017-06-03 04:57 - 01248768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AzureSettingSyncProvider.dll 2017-06-25 17:59 - 2017-06-03 04:57 - 00797184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe 2017-06-25 17:59 - 2017-06-03 04:56 - 06292992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Chakra.dll 2017-06-25 17:59 - 2017-06-03 04:55 - 03656192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2017-06-25 17:59 - 2017-06-03 04:55 - 02132480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll 2017-06-25 17:59 - 2017-06-03 04:55 - 01019904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aadtb.dll 2017-06-25 17:59 - 2017-06-03 04:53 - 04559360 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dbgeng.dll 2017-06-25 17:59 - 2017-05-20 05:13 - 01333136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msctf.dll 2017-06-25 17:59 - 2017-05-20 04:55 - 00606960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2017-06-25 17:59 - 2017-05-20 04:47 - 01474800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.dll 2017-06-25 17:59 - 2017-05-20 04:46 - 05821496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\windows.storage.dll 2017-06-25 17:59 - 2017-05-20 04:46 - 01266544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinapi.appcore.dll 2017-06-25 17:59 - 2017-05-20 04:46 - 00754080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\LicenseManager.dll 2017-06-25 17:59 - 2017-05-20 04:45 - 00349600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2017-06-25 17:59 - 2017-05-20 04:44 - 00181664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppxAllUserStore.dll 2017-06-25 17:59 - 2017-05-20 04:43 - 05802968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Media.dll 2017-06-25 17:59 - 2017-05-20 04:43 - 04672848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2017-06-25 17:59 - 2017-05-20 04:43 - 02424016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfmp4srcsnk.dll 2017-06-25 17:59 - 2017-05-20 04:43 - 01529384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winmde.dll 2017-06-25 17:59 - 2017-05-20 04:43 - 01455592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll 2017-06-25 17:59 - 2017-05-20 04:43 - 01120864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfsvr.dll 2017-06-25 17:59 - 2017-05-20 04:43 - 00354400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MMDevAPI.dll 2017-06-25 17:59 - 2017-05-20 04:29 - 00584192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIRibbonRes.dll 2017-06-25 17:59 - 2017-05-20 04:27 - 00141824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\smartscreenps.dll 2017-06-25 17:59 - 2017-05-20 04:26 - 00059904 _____ C:\Windows\SysWOW64\xboxgipsynthetic.dll 2017-06-25 17:59 - 2017-05-20 04:26 - 00025088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\odbcconf.dll 2017-06-25 17:59 - 2017-05-20 04:25 - 00826368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NPSMDesktopProvider.dll 2017-06-25 17:59 - 2017-05-20 04:25 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Web.Diagnostics.dll 2017-06-25 17:59 - 2017-05-20 04:23 - 06728192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.dll 2017-06-25 17:59 - 2017-05-20 04:22 - 01292288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSVPXENC.dll 2017-06-25 17:59 - 2017-05-20 04:21 - 00476672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\OneDriveSettingSyncProvider.dll 2017-06-25 17:59 - 2017-05-20 04:21 - 00444928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.System.Launcher.dll 2017-06-25 17:59 - 2017-05-20 04:20 - 00807424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StoreAgent.dll 2017-06-25 17:59 - 2017-05-20 04:20 - 00507392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2017-06-25 17:59 - 2017-05-20 04:20 - 00368128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgentUserBroker.exe 2017-06-25 17:59 - 2017-05-20 04:19 - 05719040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\BingMaps.dll 2017-06-25 17:59 - 2017-05-20 04:18 - 01450496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\UIAutomationCore.dll 2017-06-25 17:59 - 2017-05-20 04:17 - 04544000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\VsGraphicsDesktopEngine.exe 2017-06-25 17:59 - 2017-05-20 04:17 - 00952832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\comdlg32.dll 2017-06-25 17:59 - 2017-05-20 04:17 - 00909312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SettingSyncCore.dll 2017-06-25 17:59 - 2017-05-20 04:17 - 00329728 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InstallAgent.exe 2017-06-25 17:59 - 2017-05-20 04:17 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cldapi.dll 2017-06-25 17:59 - 2017-05-20 04:16 - 02588160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapRouter.dll 2017-06-25 17:59 - 2017-05-20 04:16 - 00899584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\twinui.appcore.dll 2017-06-25 17:59 - 2017-05-20 04:15 - 02088960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MapGeocoder.dll 2017-06-25 17:59 - 2017-05-20 04:14 - 04056576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MFMediaEngine.dll 2017-06-25 17:59 - 2017-05-20 04:14 - 02679296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SRH.dll 2017-06-25 17:59 - 2017-05-20 04:14 - 02211328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\InputService.dll 2017-06-25 17:59 - 2017-05-20 04:11 - 01536512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Immersive.dll 2017-06-25 17:59 - 2017-05-20 04:10 - 00128000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\NPSM.dll 2017-06-25 17:59 - 2017-05-20 04:10 - 00089088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\olepro32.dll 2017-06-25 17:59 - 2017-05-20 04:08 - 00174080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RstrtMgr.dll 2017-06-25 17:58 - 2017-06-03 05:59 - 01409048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32full.dll 2017-06-25 17:58 - 2017-06-03 05:59 - 00626528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontdrvhost.exe 2017-06-25 17:58 - 2017-06-03 05:59 - 00311200 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll 2017-06-25 17:58 - 2017-06-03 05:58 - 07904784 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.Protection.PlayReady.dll 2017-06-25 17:58 - 2017-06-03 05:35 - 02259768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreUIComponents.dll 2017-06-25 17:58 - 2017-06-03 05:26 - 00266640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capauthz.dll 2017-06-25 17:58 - 2017-06-03 05:20 - 00583160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\CoreMessaging.dll 2017-06-25 17:58 - 2017-06-03 05:11 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\mssprxy.dll 2017-06-25 17:58 - 2017-06-03 05:11 - 00038912 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll 2017-06-25 17:58 - 2017-06-03 05:07 - 00002560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll 2017-06-25 17:58 - 2017-06-03 05:05 - 20506624 _____ (Microsoft Corporation) C:\Windows\SysWOW64\edgehtml.dll 2017-06-25 17:58 - 2017-06-03 05:03 - 19336192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2017-06-25 17:58 - 2017-06-03 05:00 - 03379200 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll 2017-06-25 17:58 - 2017-06-03 05:00 - 00933376 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe 2017-06-25 17:58 - 2017-06-03 04:59 - 02597376 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll 2017-06-25 17:58 - 2017-06-03 04:58 - 05961216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll 2017-06-25 17:58 - 2017-06-03 04:54 - 02341376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2017-06-25 17:58 - 2017-06-03 04:54 - 02298368 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2017-06-25 17:58 - 2017-05-20 04:48 - 04469832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2017-06-25 17:58 - 2017-05-20 04:44 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AppXDeploymentClient.dll 2017-06-25 17:58 - 2017-05-20 04:29 - 13840384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.dll 2017-06-25 17:58 - 2017-05-20 04:27 - 02199552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.UI.Xaml.Resources.dll 2017-06-25 17:58 - 2017-05-20 04:24 - 00362496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\daxexec.dll 2017-06-25 17:58 - 2017-05-20 04:22 - 00754176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MessagingDataModel2.dll 2017-06-25 17:58 - 2017-05-20 04:22 - 00394240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DictationManager.dll 2017-06-25 17:58 - 2017-05-20 04:21 - 01984000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DeviceFlows.DataModel.dll 2017-06-25 17:58 - 2017-05-20 04:20 - 00354304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ActivationManager.dll 2017-06-25 17:58 - 2017-05-20 04:16 - 05225984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll 2017-06-25 17:58 - 2017-05-20 04:16 - 03667456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_47.dll 2017-06-25 17:58 - 2017-05-20 04:14 - 04417024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ExplorerFrame.dll 2017-06-25 17:58 - 2017-05-20 04:14 - 01035264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ShareHost.dll 2017-06-25 17:58 - 2017-05-20 04:10 - 00332800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Devices.Midi.dll 2017-06-25 17:58 - 2017-05-20 02:54 - 00144288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storahci.sys 2017-06-25 17:58 - 2017-05-20 02:53 - 00335808 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthService.exe 2017-06-25 17:58 - 2017-05-20 02:10 - 00809472 _____ (Microsoft Corporation) C:\Windows\system32\SecurityHealthSSO.dll 2017-06-25 17:58 - 2017-05-20 02:08 - 00086016 _____ C:\Windows\system32\xboxgipsynthetic.dll 2017-06-25 17:58 - 2017-05-20 02:07 - 00133120 _____ (Microsoft Corporation) C:\Windows\system32\XblGameSaveExt.dll 2017-06-25 17:58 - 2017-05-20 02:02 - 00601088 _____ (Microsoft Corporation) C:\Windows\system32\Windows.System.Launcher.dll 2017-06-25 17:58 - 2017-05-20 02:00 - 01067008 _____ (Microsoft Corporation) C:\Windows\system32\XboxNetApiSvc.dll 2017-06-25 17:57 - 2017-06-26 13:52 - 00004222 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse 2017-06-25 17:57 - 2017-06-26 13:52 - 00004034 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse 2017-06-25 17:57 - 2017-06-03 06:15 - 01596600 _____ (Microsoft Corporation) C:\Windows\system32\gdi32full.dll 2017-06-25 17:57 - 2017-06-03 06:15 - 00750560 _____ (Microsoft Corporation) C:\Windows\system32\fontdrvhost.exe 2017-06-25 17:57 - 2017-06-03 06:15 - 00382368 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll 2017-06-25 17:57 - 2017-06-03 06:14 - 01147296 _____ (Microsoft Corporation) C:\Windows\system32\hvix64.exe 2017-06-25 17:57 - 2017-06-03 06:14 - 01024928 _____ (Microsoft Corporation) C:\Windows\system32\hvax64.exe 2017-06-25 17:57 - 2017-06-03 06:10 - 00130464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tm.sys 2017-06-25 17:57 - 2017-06-03 06:09 - 08318880 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2017-06-25 17:57 - 2017-06-03 06:09 - 01003624 _____ (Microsoft Corporation) C:\Windows\system32\ucrtbase.dll 2017-06-25 17:57 - 2017-06-03 06:08 - 02969880 _____ (Microsoft Corporation) C:\Windows\system32\CoreUIComponents.dll 2017-06-25 17:57 - 2017-06-03 06:07 - 00923048 _____ (Microsoft Corporation) C:\Windows\system32\CoreMessaging.dll 2017-06-25 17:57 - 2017-06-03 06:07 - 00119712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys 2017-06-25 17:57 - 2017-06-03 06:02 - 02444192 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgkrnl.sys 2017-06-25 17:57 - 2017-06-03 06:01 - 05477096 _____ (Microsoft Corporation) C:\Windows\system32\OneCoreUAPCommonProxyStub.dll 2017-06-25 17:57 - 2017-06-03 06:00 - 00872472 _____ (Microsoft Corporation) C:\Windows\system32\ClipSVC.dll 2017-06-25 17:57 - 2017-06-03 06:00 - 00321376 _____ (Microsoft Corporation) C:\Windows\system32\capauthz.dll 2017-06-25 17:57 - 2017-06-03 06:00 - 00219040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tpm.sys 2017-06-25 17:57 - 2017-06-03 05:59 - 00259400 _____ (Microsoft Corporation) C:\Windows\system32\MusNotifyIcon.exe 2017-06-25 17:57 - 2017-06-03 05:58 - 21352696 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2017-06-25 17:57 - 2017-06-03 05:58 - 00660384 _____ (Microsoft Corporation) C:\Windows\system32\comctl32.dll 2017-06-25 17:57 - 2017-06-03 05:58 - 00254176 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll 2017-06-25 17:57 - 2017-06-03 05:57 - 00371616 _____ (Microsoft Corporation) C:\Windows\system32\CloudExperienceHost.dll 2017-06-25 17:57 - 2017-06-03 05:55 - 02681760 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2017-06-25 17:57 - 2017-06-03 05:28 - 23677440 _____ (Microsoft Corporation) C:\Windows\system32\edgehtml.dll 2017-06-25 17:57 - 2017-06-03 05:14 - 03673088 _____ (Microsoft Corporation) C:\Windows\system32\win32kfull.sys 2017-06-25 17:57 - 2017-06-03 05:14 - 00443392 _____ (Microsoft Corporation) C:\Windows\system32\PerceptionSimulationExtensions.dll 2017-06-25 17:57 - 2017-06-03 05:14 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\dwmredir.dll 2017-06-25 17:57 - 2017-06-03 05:14 - 00099328 _____ (Microsoft Corporation) C:\Windows\system32\utcutil.dll 2017-06-25 17:57 - 2017-06-03 05:14 - 00047104 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll 2017-06-25 17:57 - 2017-06-03 05:12 - 00119296 _____ (Microsoft Corporation) C:\Windows\system32\UserDataTimeUtil.dll 2017-06-25 17:57 - 2017-06-03 05:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\musdialoghandlers.dll 2017-06-25 17:57 - 2017-06-03 05:11 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BasicRender.sys 2017-06-25 17:57 - 2017-06-03 05:11 - 00002560 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2017-06-25 17:57 - 2017-06-03 05:10 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\MusNotification.exe 2017-06-25 17:57 - 2017-06-03 05:10 - 00102400 _____ (Microsoft Corporation) C:\Windows\system32\MusNotificationUx.exe 2017-06-25 17:57 - 2017-06-03 05:10 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\DeviceCredentialDeployment.exe 2017-06-25 17:57 - 2017-06-03 05:09 - 00271872 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Security.Authentication.Identity.Provider.dll 2017-06-25 17:57 - 2017-06-03 05:09 - 00221184 _____ (Microsoft Corporation) C:\Windows\system32\devicengccredprov.dll 2017-06-25 17:57 - 2017-06-03 05:09 - 00064512 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll 2017-06-25 17:57 - 2017-06-03 05:07 - 23682048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2017-06-25 17:57 - 2017-06-03 05:07 - 00778240 _____ C:\Windows\system32\MBR2GPT.EXE 2017-06-25 17:57 - 2017-06-03 05:07 - 00721920 _____ (Microsoft Corporation) C:\Windows\system32\MusUpdateHandlers.dll 2017-06-25 17:57 - 2017-06-03 05:07 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\bcdboot.exe 2017-06-25 17:57 - 2017-06-03 05:06 - 00551936 _____ (Microsoft Corporation) C:\Windows\system32\TpmCoreProvisioning.dll 2017-06-25 17:57 - 2017-06-03 05:05 - 07336448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll 2017-06-25 17:57 - 2017-06-03 05:05 - 01878016 _____ (Microsoft Corporation) C:\Windows\system32\AzureSettingSyncProvider.dll 2017-06-25 17:57 - 2017-06-03 05:04 - 12787200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2017-06-25 17:57 - 2017-06-03 05:04 - 00925696 _____ (Microsoft Corporation) C:\Windows\system32\WpcWebFilter.dll 2017-06-25 17:57 - 2017-06-03 05:04 - 00805888 _____ (Microsoft Corporation) C:\Windows\system32\ieproxy.dll 2017-06-25 17:57 - 2017-06-03 05:03 - 01260544 _____ (Microsoft Corporation) C:\Windows\system32\GamePanel.exe 2017-06-25 17:57 - 2017-06-03 05:02 - 08245760 _____ (Microsoft Corporation) C:\Windows\system32\Chakra.dll 2017-06-25 17:57 - 2017-06-03 05:01 - 06726656 _____ (Microsoft Corporation) C:\Windows\system32\mspaint.exe 2017-06-25 17:57 - 2017-06-03 05:01 - 02804736 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentServer.dll 2017-06-25 17:57 - 2017-06-03 04:59 - 04730368 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2017-06-25 17:57 - 2017-06-03 04:59 - 02625024 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Logon.dll 2017-06-25 17:57 - 2017-06-03 04:59 - 02056192 _____ (Microsoft Corporation) C:\Windows\system32\win32kbase.sys 2017-06-25 17:57 - 2017-06-03 04:59 - 01293824 _____ (Microsoft Corporation) C:\Windows\system32\aadtb.dll 2017-06-25 17:57 - 2017-06-03 04:59 - 01142784 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll 2017-06-25 17:57 - 2017-06-03 04:59 - 00975360 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe 2017-06-25 17:57 - 2017-06-03 04:58 - 02650112 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2017-06-25 17:57 - 2017-06-03 04:58 - 02516480 _____ (Microsoft Corporation) C:\Windows\system32\diagtrack.dll 2017-06-25 17:57 - 2017-06-03 04:58 - 01888256 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2017-06-25 17:57 - 2017-06-03 04:58 - 01046016 _____ (Microsoft Corporation) C:\Windows\system32\ngcsvc.dll 2017-06-25 17:57 - 2017-06-03 04:58 - 00827392 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll 2017-06-25 17:57 - 2017-06-03 04:57 - 05557760 _____ (Microsoft Corporation) C:\Windows\system32\dbgeng.dll 2017-06-25 17:57 - 2017-06-03 04:57 - 02829824 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2017-06-25 17:57 - 2017-06-03 04:57 - 01675264 _____ (Microsoft Corporation) C:\Windows\system32\wpncore.dll 2017-06-25 17:57 - 2017-06-03 04:51 - 00064512 _____ (Microsoft Corporation) C:\Windows\bfsvc.exe 2017-06-25 17:57 - 2017-05-20 03:08 - 01459728 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2017-06-25 17:57 - 2017-05-20 03:08 - 00543648 _____ (Microsoft Corporation) C:\Windows\system32\securekernel.exe 2017-06-25 17:57 - 2017-05-20 03:07 - 00287648 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2017-06-25 17:57 - 2017-05-20 03:03 - 00777400 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2017-06-25 17:57 - 2017-05-20 02:59 - 00112544 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dam.sys 2017-06-25 17:57 - 2017-05-20 02:58 - 00188824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2017-06-25 17:57 - 2017-05-20 02:56 - 04847928 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2017-06-25 17:57 - 2017-05-20 02:56 - 00712608 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dxgmms2.sys 2017-06-25 17:57 - 2017-05-20 02:56 - 00370928 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsAdminFlows.exe 2017-06-25 17:57 - 2017-05-20 02:55 - 07325584 _____ (Microsoft Corporation) C:\Windows\system32\windows.storage.dll 2017-06-25 17:57 - 2017-05-20 02:55 - 01911752 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.dll 2017-06-25 17:57 - 2017-05-20 02:55 - 01506712 _____ (Microsoft Corporation) C:\Windows\system32\twinapi.appcore.dll 2017-06-25 17:57 - 2017-05-20 02:55 - 01055648 _____ (Microsoft Corporation) C:\Windows\system32\LicenseManager.dll 2017-06-25 17:57 - 2017-05-20 02:55 - 00961952 _____ (Microsoft Corporation) C:\Windows\system32\efscore.dll 2017-06-25 17:57 - 2017-05-20 02:55 - 00211872 _____ (Microsoft Corporation) C:\Windows\system32\browserbroker.dll 2017-06-25 17:57 - 2017-05-20 02:54 - 00730016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vhdmp.sys 2017-06-25 17:57 - 2017-05-20 02:54 - 00546208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2017-06-25 17:57 - 2017-05-20 02:53 - 00654976 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentClient.dll 2017-06-25 17:57 - 2017-05-20 02:53 - 00411040 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2017-06-25 17:57 - 2017-05-20 02:53 - 00363424 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\fastfat.sys 2017-06-25 17:57 - 2017-05-20 02:53 - 00255904 _____ (Microsoft Corporation) C:\Windows\system32\AppxAllUserStore.dll 2017-06-25 17:57 - 2017-05-20 02:52 - 04709528 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2017-06-25 17:57 - 2017-05-20 02:52 - 01700408 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll 2017-06-25 17:57 - 2017-05-20 02:51 - 06551856 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Media.dll 2017-06-25 17:57 - 2017-05-20 02:51 - 02604256 _____ (Microsoft Corporation) C:\Windows\system32\mfmp4srcsnk.dll 2017-06-25 17:57 - 2017-05-20 02:51 - 01670496 _____ (Microsoft Corporation) C:\Windows\system32\winmde.dll 2017-06-25 17:57 - 2017-05-20 02:51 - 01219560 _____ (Microsoft Corporation) C:\Windows\system32\mfsvr.dll 2017-06-25 17:57 - 2017-05-20 02:51 - 00406064 _____ (Microsoft Corporation) C:\Windows\system32\MMDevAPI.dll 2017-06-25 17:57 - 2017-05-20 02:48 - 00387928 _____ (Microsoft Corporation) C:\Windows\system32\wmpps.dll 2017-06-25 17:57 - 2017-05-20 02:10 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\UIRibbonRes.dll 2017-06-25 17:57 - 2017-05-20 02:10 - 00361472 _____ (Microsoft Corporation) C:\Windows\system32\ConhostV2.dll 2017-06-25 17:57 - 2017-05-20 02:10 - 00088576 _____ (Microsoft Corporation) C:\Windows\system32\winsrvext.dll 2017-06-25 17:57 - 2017-05-20 02:10 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksthunk.sys 2017-06-25 17:57 - 2017-05-20 02:09 - 17365504 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.dll 2017-06-25 17:57 - 2017-05-20 02:09 - 02199552 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Xaml.Resources.dll 2017-06-25 17:57 - 2017-05-20 02:09 - 00209408 _____ (Microsoft Corporation) C:\Windows\system32\smartscreenps.dll 2017-06-25 17:57 - 2017-05-20 02:08 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\odbcconf.dll 2017-06-25 17:57 - 2017-05-20 02:08 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rootmdm.sys 2017-06-25 17:57 - 2017-05-20 02:07 - 00277504 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\xboxgip.sys 2017-06-25 17:57 - 2017-05-20 02:07 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\snmptrap.exe 2017-06-25 17:57 - 2017-05-20 02:06 - 00866816 _____ (Microsoft Corporation) C:\Windows\system32\NPSMDesktopProvider.dll 2017-06-25 17:57 - 2017-05-20 02:06 - 00232448 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Web.Diagnostics.dll 2017-06-25 17:57 - 2017-05-20 02:06 - 00192512 _____ (Microsoft Corporation) C:\Windows\system32\Windows.SharedPC.AccountManager.dll 2017-06-25 17:57 - 2017-05-20 02:05 - 07931392 _____ (Microsoft Corporation) C:\Windows\system32\twinui.dll 2017-06-25 17:57 - 2017-05-20 02:05 - 00518144 _____ (Microsoft Corporation) C:\Windows\system32\daxexec.dll 2017-06-25 17:57 - 2017-05-20 02:03 - 08331264 _____ (Microsoft Corporation) C:\Windows\system32\BingMaps.dll 2017-06-25 17:57 - 2017-05-20 02:03 - 00892416 _____ (Microsoft Corporation) C:\Windows\system32\MessagingDataModel2.dll 2017-06-25 17:57 - 2017-05-20 02:03 - 00549888 _____ (Microsoft Corporation) C:\Windows\system32\DictationManager.dll 2017-06-25 17:57 - 2017-05-20 02:03 - 00527360 _____ (Microsoft Corporation) C:\Windows\system32\aadcloudap.dll 2017-06-25 17:57 - 2017-05-20 02:03 - 00491520 _____ (Microsoft Corporation) C:\Windows\system32\SettingsHandlers_Display.dll 2017-06-25 17:57 - 2017-05-20 02:03 - 00427008 _____ (Microsoft Corporation) C:\Windows\system32\provengine.dll 2017-06-25 17:57 - 2017-05-20 02:02 - 00616960 _____ (Microsoft Corporation) C:\Windows\system32\WindowManagement.dll 2017-06-25 17:57 - 2017-05-20 02:01 - 02347520 _____ (Microsoft Corporation) C:\Windows\system32\DeviceFlows.DataModel.dll 2017-06-25 17:57 - 2017-05-20 02:01 - 00970240 _____ (Microsoft Corporation) C:\Windows\system32\cdpsvc.dll 2017-06-25 17:57 - 2017-05-20 02:01 - 00590848 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2017-06-25 17:57 - 2017-05-20 02:01 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\OneDriveSettingSyncProvider.dll 2017-06-25 17:57 - 2017-05-20 02:01 - 00409600 _____ (Microsoft Corporation) C:\Windows\system32\updatehandlers.dll 2017-06-25 17:57 - 2017-05-20 02:01 - 00408064 _____ (Microsoft Corporation) C:\Windows\system32\ActivationManager.dll 2017-06-25 17:57 - 2017-05-20 02:01 - 00299520 _____ (Microsoft Corporation) C:\Windows\system32\AboveLockAppHost.dll 2017-06-25 17:57 - 2017-05-20 02:01 - 00149504 _____ (Microsoft Corporation) C:\Windows\system32\embeddedmodesvc.dll 2017-06-25 17:57 - 2017-05-20 02:00 - 05776384 _____ (Microsoft Corporation) C:\Windows\system32\VsGraphicsDesktopEngine.exe 2017-06-25 17:57 - 2017-05-20 02:00 - 01078272 _____ (Microsoft Corporation) C:\Windows\system32\StoreAgent.dll 2017-06-25 17:57 - 2017-05-20 02:00 - 00846848 _____ (Microsoft Corporation) C:\Windows\system32\bisrv.dll 2017-06-25 17:57 - 2017-05-20 02:00 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgentUserBroker.exe 2017-06-25 17:57 - 2017-05-20 02:00 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\cldapi.dll 2017-06-25 17:57 - 2017-05-20 01:59 - 01818624 _____ (Microsoft Corporation) C:\Windows\system32\UIAutomationCore.dll 2017-06-25 17:57 - 2017-05-20 01:59 - 01468416 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.desktop.dll 2017-06-25 17:57 - 2017-05-20 01:59 - 01141760 _____ (Microsoft Corporation) C:\Windows\system32\MapsStore.dll 2017-06-25 17:57 - 2017-05-20 01:59 - 01028608 _____ (Microsoft Corporation) C:\Windows\system32\modernexecserver.dll 2017-06-25 17:57 - 2017-05-20 01:59 - 00972800 _____ (Microsoft Corporation) C:\Windows\system32\sysmain.dll 2017-06-25 17:57 - 2017-05-20 01:59 - 00687104 _____ (Microsoft Corporation) C:\Windows\system32\LogonController.dll 2017-06-25 17:57 - 2017-05-20 01:59 - 00585216 _____ (Microsoft Corporation) C:\Windows\system32\AppReadiness.dll 2017-06-25 17:57 - 2017-05-20 01:58 - 03784704 _____ (Microsoft Corporation) C:\Windows\system32\MapRouter.dll 2017-06-25 17:57 - 2017-05-20 01:58 - 03135488 _____ (Microsoft Corporation) C:\Windows\system32\MapGeocoder.dll 2017-06-25 17:57 - 2017-05-20 01:58 - 01886208 _____ (Microsoft Corporation) C:\Windows\system32\AppXDeploymentExtensions.onecore.dll 2017-06-25 17:57 - 2017-05-20 01:58 - 01046016 _____ (Microsoft Corporation) C:\Windows\system32\comdlg32.dll 2017-06-25 17:57 - 2017-05-20 01:58 - 00909824 _____ (Microsoft Corporation) C:\Windows\system32\ISM.dll 2017-06-25 17:57 - 2017-05-20 01:58 - 00374784 _____ (Microsoft Corporation) C:\Windows\system32\InstallAgent.exe 2017-06-25 17:57 - 2017-05-20 01:57 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\usocore.dll 2017-06-25 17:57 - 2017-05-20 01:56 - 02730496 _____ (Microsoft Corporation) C:\Windows\system32\smartscreen.exe 2017-06-25 17:57 - 2017-05-20 01:56 - 01076736 _____ (Microsoft Corporation) C:\Windows\system32\twinui.appcore.dll 2017-06-25 17:57 - 2017-05-20 01:55 - 04396032 _____ (Microsoft Corporation) C:\Windows\system32\D3DCompiler_47.dll 2017-06-25 17:57 - 2017-05-20 01:55 - 03332096 _____ (Microsoft Corporation) C:\Windows\system32\SRH.dll 2017-06-25 17:57 - 2017-05-20 01:55 - 02499584 _____ (Microsoft Corporation) C:\Windows\system32\twinui.pcshell.dll 2017-06-25 17:57 - 2017-05-20 01:55 - 01102848 _____ (Microsoft Corporation) C:\Windows\system32\SettingSyncCore.dll 2017-06-25 17:57 - 2017-05-20 01:54 - 04707840 _____ (Microsoft Corporation) C:\Windows\system32\ExplorerFrame.dll 2017-06-25 17:57 - 2017-05-20 01:54 - 04537344 _____ (Microsoft Corporation) C:\Windows\system32\MFMediaEngine.dll 2017-06-25 17:57 - 2017-05-20 01:54 - 03803136 _____ (Microsoft Corporation) C:\Windows\system32\SystemSettingsThresholdAdminFlowUI.dll 2017-06-25 17:57 - 2017-05-20 01:54 - 02938880 _____ (Microsoft Corporation) C:\Windows\system32\InputService.dll 2017-06-25 17:57 - 2017-05-20 01:54 - 01275904 _____ (Microsoft Corporation) C:\Windows\system32\ShareHost.dll 2017-06-25 17:57 - 2017-05-20 01:52 - 01356800 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2017-06-25 17:57 - 2017-05-20 01:52 - 00624640 _____ (Microsoft Corporation) C:\Windows\system32\AudioEndpointBuilder.dll 2017-06-25 17:57 - 2017-05-20 01:52 - 00557568 _____ (Microsoft Corporation) C:\Windows\system32\wpnprv.dll 2017-06-25 17:57 - 2017-05-20 01:52 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Core.TextInput.dll 2017-06-25 17:57 - 2017-05-20 01:51 - 01706496 _____ (Microsoft Corporation) C:\Windows\system32\Windows.UI.Immersive.dll 2017-06-25 17:57 - 2017-05-20 01:51 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\umpo.dll 2017-06-25 17:57 - 2017-05-20 01:50 - 00439808 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Devices.Midi.dll 2017-06-25 17:57 - 2017-05-20 01:50 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\NPSM.dll 2017-06-25 17:57 - 2017-05-20 01:48 - 02438656 _____ (Microsoft Corporation) C:\Windows\system32\ResetEngine.dll 2017-06-25 17:57 - 2017-05-20 01:48 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\vss_ps.dll 2017-06-25 17:57 - 2017-05-20 01:47 - 00641536 _____ (Microsoft Corporation) C:\Windows\system32\rdbui.dll 2017-06-25 17:57 - 2017-05-20 01:47 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\RstrtMgr.dll 2017-06-25 17:56 - 2017-06-25 17:56 - 00003442 _____ C:\Windows\System32\Tasks\McAfee Remediation (Prepare) 2017-06-25 17:41 - 2017-06-26 19:47 - 00000000 ____D C:\Users\murph\Desktop\fix 2017-06-25 16:28 - 2017-06-25 16:48 - 00150361 _____ C:\Users\murph\Downloads\Fixlog.txt 2017-06-25 16:00 - 2017-06-25 16:00 - 00097496 _____ C:\Users\murph\Desktop\Fix.pdf 2017-06-25 15:21 - 2017-06-25 15:21 - 00000000 ____D C:\Users\murph\Downloads\FRST-OlderVersion 2017-06-24 20:32 - 2017-06-24 20:33 - 00072350 _____ C:\Users\murph\Downloads\Addition.txt 2017-06-24 20:31 - 2017-06-24 20:32 - 00063972 _____ C:\Users\murph\Downloads\FRST.txt 2017-06-24 20:29 - 2017-06-26 19:47 - 00000000 ___DC C:\FRST 2017-06-24 20:14 - 2017-06-24 20:14 - 00000000 ____D C:\Users\murph\Desktop\tdsskiller 2017-06-24 20:13 - 2017-06-24 20:13 - 04830473 _____ C:\Users\murph\Desktop\tdsskiller.zip 2017-06-24 20:08 - 2017-06-24 20:08 - 00784152 _____ (McAfee, Inc.) C:\Users\murph\Downloads\rootkitremover.exe 2017-06-24 00:17 - 2017-06-24 01:50 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2017-06-24 00:03 - 2017-06-24 21:02 - 00000000 ____D C:\Users\murph\Desktop\mbar 2017-06-24 00:02 - 2017-06-24 00:02 - 16563352 _____ (Malwarebytes Corp.) C:\Users\murph\Downloads\mbar-1.09.3.1001.exe 2017-06-23 16:38 - 2017-06-23 16:38 - 00000017 _____ C:\Users\murph\AppData\Local\resmon.resmoncfg 2017-06-22 23:41 - 2017-06-23 15:34 - 00000000 ___DC C:\Windows.old 2017-06-18 17:22 - 2017-06-18 17:22 - 64232976 _____ (Malwarebytes ) C:\Users\murph\Downloads\mb3-setup-consumer-3.1.2.1733-1.0.141-1.0.2092 (1).exe 2017-06-18 17:20 - 2017-06-18 17:21 - 64232976 _____ (Malwarebytes ) C:\Users\murph\Downloads\mb3-setup-consumer-3.1.2.1733-1.0.141-1.0.2092.exe 2017-06-18 16:25 - 2017-06-18 16:25 - 00000000 ____D C:\ProgramData\XLPlatform 2017-06-18 16:16 - 2017-06-18 16:16 - 00000000 ____D C:\Users\murph\Documents\Custom Office Templates 2017-06-18 15:46 - 2017-06-18 15:46 - 00281510 _____ C:\Users\murph\Downloads\applicant_signature (2).pdf 2017-06-18 15:44 - 2017-06-18 15:44 - 00320702 _____ C:\Users\murph\Downloads\parent_signature.pdf 2017-06-18 15:44 - 2017-06-18 15:44 - 00281541 _____ C:\Users\murph\Desktop\applicant_signature (1).pdf 2017-06-18 15:42 - 2017-06-18 15:42 - 00281541 _____ C:\Users\murph\Downloads\applicant_signature (1).pdf 2017-06-18 15:41 - 2017-06-18 15:41 - 00343956 _____ C:\Users\murph\Desktop\master_student_financial_assistance_agreements (4) (1).pdf 2017-06-18 15:37 - 2017-06-18 15:37 - 00343956 _____ C:\Users\murph\Downloads\master_student_financial_assistance_agreements (4).pdf 2017-06-18 15:36 - 2017-06-18 15:36 - 00281585 _____ C:\Users\murph\Downloads\applicant_signature.pdf 2017-06-18 15:35 - 2017-06-18 15:35 - 00343902 _____ C:\Users\murph\Downloads\master_student_financial_assistance_agreements (3).pdf 2017-06-18 15:30 - 2017-06-18 15:30 - 00344075 _____ C:\Users\murph\Downloads\master_student_financial_assistance_agreements (2).pdf 2017-06-18 15:30 - 2017-06-18 15:30 - 00343990 _____ C:\Users\murph\Downloads\master_student_financial_assistance_agreements.pdf 2017-06-18 15:30 - 2017-06-18 15:30 - 00343886 _____ C:\Users\murph\Downloads\master_student_financial_assistance_agreements (1).pdf 2017-06-12 20:17 - 2017-06-12 20:17 - 00000000 ____D C:\Users\murph\AppData\Roaming\Google 2017-06-03 14:38 - 2017-06-03 14:59 - 00000000 ____D C:\Users\murph\AppData\Local\Deployment 2017-06-03 14:21 - 2017-06-03 14:21 - 00000000 ____D C:\Users\murph\AppData\Roaming\Unity 2017-06-03 14:21 - 2017-06-03 14:21 - 00000000 ____D C:\ProgramData\Unity 2017-06-03 14:14 - 2017-06-12 20:08 - 00000000 ____D C:\Users\murph\AppData\Local\Facebook 2017-06-03 14:14 - 2017-06-03 14:16 - 00000000 ____D C:\Users\murph\AppData\Roaming\Visual Studio Setup 2017-06-03 14:14 - 2017-06-03 14:14 - 00000000 ____D C:\Users\murph\AppData\Roaming\vstelemetry 2017-06-03 14:14 - 2017-06-03 14:14 - 00000000 ____D C:\Users\murph\AppData\Local\ServiceHub 2017-06-03 14:14 - 2017-06-03 14:14 - 00000000 ____D C:\Program Files (x86)\Microsoft Visual Studio 2017-06-03 14:13 - 2017-06-03 14:13 - 00000000 ____D C:\Users\Public\Documents\Unity Projects 2017-06-03 14:12 - 2017-06-03 14:12 - 00000000 ____D C:\Program Files (x86)\GtkSharp 2017-06-03 14:11 - 2017-06-03 14:34 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Unity 2017.1.0b8 (64-bit) 2017-05-30 19:57 - 2017-05-30 19:57 - 01006047 _____ C:\Users\murph\Documents\IMG_20170530_0002.pdf 2017-05-30 19:56 - 2017-05-30 19:56 - 01999566 _____ C:\Users\murph\Documents\IMG_20170530_0001.pdf 2017-05-30 19:53 - 2017-05-30 19:53 - 00000000 ____D C:\Users\murph\AppData\Roaming\Macromedia 2017-05-29 19:50 - 2017-05-29 19:50 - 00000000 ____D C:\Users\murph\AppData\Roaming\.minecraft 2017-05-29 19:36 - 2017-06-18 17:25 - 00000000 ____D C:\Program Files (x86)\Minecraft 2017-05-28 16:32 - 2017-05-28 16:32 - 00515135 _____ C:\Users\murph\Downloads\189_panda_powerpoint.zip 2017-05-28 16:32 - 2017-05-28 16:32 - 00000000 ____D C:\Users\murph\Downloads\189_panda_powerpoint 2017-05-27 13:05 - 2017-05-27 13:05 - 00000000 ____D C:\Users\murph\Documents\Adobe 2017-05-27 13:01 - 2017-05-28 16:38 - 00000000 ___RD C:\Users\murph\Creative Cloud Files 2017-05-27 11:52 - 2017-05-27 11:52 - 00000000 ____D C:\Users\murph\Documents\My Games ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-06-26 19:45 - 2017-05-14 15:42 - 00004164 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{7FEA68E3-0D39-4A59-8F16-335A8EFF25A0} 2017-06-26 19:44 - 2017-05-14 15:19 - 00000000 ____D C:\Windows\system32\SleepStudy 2017-06-26 18:26 - 2017-05-14 15:32 - 01450514 _____ C:\Windows\system32\PerfStringBackup.INI 2017-06-26 18:22 - 2017-05-14 15:42 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-06-26 18:22 - 2017-03-24 12:58 - 00111544 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2017-06-26 18:22 - 2017-03-24 12:58 - 00092096 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2017-06-26 18:22 - 2016-10-08 12:13 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-06-26 18:22 - 2015-09-16 14:24 - 00251832 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-06-26 18:21 - 2017-05-14 15:25 - 00065536 _____ C:\Windows\system32\spu_storage.bin 2017-06-26 18:21 - 2017-03-18 07:40 - 01310720 _____ C:\Windows\system32\config\BBI 2017-06-26 17:30 - 2017-03-18 17:03 - 00000000 ___HD C:\Program Files\WindowsApps 2017-06-26 17:30 - 2017-03-18 17:03 - 00000000 ____D C:\Windows\AppReadiness 2017-06-26 13:33 - 2015-09-14 15:01 - 00000214 _____ C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job 2017-06-26 13:26 - 2017-03-18 17:01 - 00000000 ____D C:\Windows\INF 2017-06-26 13:26 - 2015-09-04 14:06 - 00000000 ____D C:\Users\murph\AppData\Local\Adobe 2017-06-26 13:20 - 2015-09-14 14:59 - 00000000 ____D C:\Windows\pss 2017-06-26 13:18 - 2017-05-14 15:32 - 00000000 ____D C:\Users\murph 2017-06-25 19:29 - 2015-08-14 18:40 - 00000000 ____D C:\ProgramData\McAfee 2017-06-25 19:28 - 2015-08-14 18:30 - 00000000 __RHD C:\Users\Public\AccountPictures 2017-06-25 19:26 - 2017-05-14 15:19 - 05200712 _____ C:\Windows\system32\FNTCACHE.DAT 2017-06-25 19:26 - 2017-03-18 17:03 - 00000000 ___SD C:\Windows\SysWOW64\F12 2017-06-25 19:26 - 2017-03-18 17:03 - 00000000 ___SD C:\Windows\system32\F12 2017-06-25 19:26 - 2017-03-18 17:03 - 00000000 ___RD C:\Program Files\Windows Defender 2017-06-25 19:26 - 2017-03-18 17:03 - 00000000 ____D C:\Windows\system32\WinBioPlugIns 2017-06-25 19:26 - 2017-03-18 17:03 - 00000000 ____D C:\Windows\system32\oobe 2017-06-25 19:26 - 2017-03-18 17:03 - 00000000 ____D C:\Windows\system32\appraiser 2017-06-25 19:26 - 2017-03-18 17:03 - 00000000 ____D C:\Windows\ShellExperiences 2017-06-25 19:26 - 2017-03-18 17:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2017-06-25 19:26 - 2017-03-18 17:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer 2017-06-25 18:06 - 2017-03-18 16:51 - 00000000 ____D C:\Windows\CbsTemp 2017-06-25 17:56 - 2016-11-14 21:26 - 00000000 ____D C:\Program Files (x86)\McAfee 2017-06-25 17:50 - 2017-03-18 07:40 - 00008192 _____ C:\Windows\system32\config\ELAM 2017-06-25 16:32 - 2015-08-28 12:59 - 00000000 ____D C:\Users\murph\AppData\LocalLow\Temp 2017-06-25 16:28 - 2017-03-18 17:03 - 00000000 ____D C:\Windows\SysWOW64\GroupPolicy 2017-06-25 16:28 - 2015-07-10 07:04 - 00000000 ___HD C:\Windows\system32\GroupPolicy 2017-06-25 14:02 - 2015-12-08 15:08 - 00000000 ____D C:\Users\murph\AppData\Local\ElevatedDiagnostics 2017-06-24 21:02 - 2017-03-24 12:58 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys 2017-06-24 20:15 - 2017-04-18 11:36 - 04922400 _____ (AO Kaspersky Lab) C:\Users\murph\Desktop\TDSSKiller.exe 2017-06-24 20:14 - 2017-04-18 11:36 - 04922400 _____ (AO Kaspersky Lab) C:\Users\murph\Documents\TDSSKiller.exe 2017-06-24 01:49 - 2016-12-25 21:04 - 00000000 ____D C:\Program Files (x86)\Steam 2017-06-24 01:43 - 2017-03-24 12:58 - 00002095 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-06-24 01:43 - 2016-11-14 21:28 - 00002131 _____ C:\Users\Public\Desktop\McAfee LiveSafe.lnk 2017-06-24 00:26 - 2017-05-14 19:14 - 00000000 ____D C:\Windows\ServiceProfiles 2017-06-24 00:20 - 2017-01-31 17:52 - 00000000 ____D C:\Users\murph\Desktop\TS LoC 2017 2017-06-24 00:17 - 2015-09-16 14:24 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-06-23 17:07 - 2017-05-14 15:42 - 00003290 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task v2 2017-06-23 17:07 - 2015-09-14 20:46 - 00002365 _____ C:\Users\murph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk 2017-06-23 17:07 - 2015-08-26 19:53 - 00000000 ___RD C:\Users\murph\OneDrive 2017-06-23 16:33 - 2016-11-18 22:16 - 00000000 ____D C:\Users\murph\Desktop\Voyageur 2017-06-23 14:34 - 2015-09-14 20:28 - 00000000 ____D C:\ProgramData\LogMeIn 2017-06-23 00:00 - 2015-09-14 20:28 - 00000000 ____D C:\Users\murph\AppData\Local\LogMeInIgnition 2017-06-20 20:35 - 2015-08-14 18:40 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2017-06-18 20:36 - 2017-03-18 17:03 - 00000000 ___SD C:\Windows\system32\Nui 2017-06-18 20:36 - 2017-03-18 17:03 - 00000000 ___RD C:\Windows\PrintDialog 2017-06-18 20:36 - 2017-03-18 17:03 - 00000000 ___RD C:\Windows\ImmersiveControlPanel 2017-06-18 20:36 - 2017-03-18 17:03 - 00000000 ____D C:\Windows\Provisioning 2017-06-18 20:36 - 2017-03-18 17:03 - 00000000 ____D C:\Windows\PolicyDefinitions 2017-06-18 20:36 - 2017-03-18 17:03 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2017-06-18 20:36 - 2017-03-18 07:40 - 00000000 ____D C:\Windows\servicing 2017-06-18 20:36 - 2015-08-14 18:35 - 00000000 ___HD C:\Windows\system32\WLANProfiles 2017-06-18 20:35 - 2017-05-14 15:26 - 00000000 ____D C:\ProgramData\Package Cache 2017-06-18 20:35 - 2016-02-11 15:35 - 00000000 ____D C:\ProgramData\FLEXnet 2017-06-18 20:33 - 2017-03-18 17:03 - 00000000 ____D C:\Windows\registration 2017-06-18 20:32 - 2017-03-18 17:03 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2017-06-18 20:32 - 2015-09-23 08:20 - 00000000 ____D C:\Program Files (x86)\Google 2017-06-18 17:28 - 2017-05-14 15:25 - 00000000 ____D C:\Program Files\AMD 2017-06-18 17:26 - 2016-03-26 16:35 - 00000000 ____D C:\Users\murph\AppData\Local\Sony 2017-06-18 17:26 - 2016-03-26 16:35 - 00000000 ____D C:\ProgramData\Sony 2017-06-18 17:26 - 2016-03-26 16:35 - 00000000 ____D C:\Program Files (x86)\Sony 2017-06-18 17:25 - 2017-05-16 06:41 - 00000000 ____D C:\Program Files\paint.net 2017-06-18 16:49 - 2017-05-21 17:02 - 00038503 ____H C:\Users\murph\AppData\Local\IconCache.db.backup 2017-06-18 16:48 - 2015-08-27 19:15 - 00000000 ____D C:\Windows\system32\MRT 2017-06-18 16:46 - 2015-08-27 19:15 - 133627792 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe 2017-06-18 16:24 - 2017-03-18 17:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft 2017-06-18 16:21 - 2015-08-26 19:51 - 00000000 ____D C:\Users\murph\AppData\Local\Packages 2017-06-18 15:31 - 2017-03-18 17:03 - 00000000 ____D C:\Windows\LiveKernelReports 2017-05-28 16:39 - 2015-12-26 13:57 - 00000000 ____D C:\Program Files\Common Files\Adobe 2017-05-28 16:39 - 2015-09-04 14:07 - 00000000 ____D C:\ProgramData\Adobe 2017-05-28 16:38 - 2017-05-14 15:42 - 00002310 _____ C:\Windows\System32\Tasks\Adobe Uninstaller 2017-05-28 16:38 - 2015-12-26 13:52 - 00000000 ____D C:\ProgramData\boost_interprocess 2017-05-27 11:57 - 2015-08-14 18:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell 2017-05-27 11:57 - 2015-08-14 18:31 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information ==================== Files in the root of some directories ======= 2017-05-14 12:50 - 2017-05-14 12:50 - 0000033 _____ () C:\Users\murph\AppData\Roaming\AdobeWLCMCache.dat 2016-11-20 20:13 - 2016-11-20 20:15 - 0002682 _____ () C:\Users\murph\AppData\Roaming\droid4xinstaller.log 2017-05-17 18:40 - 2017-05-17 18:40 - 0001167 _____ () C:\Users\murph\AppData\Roaming\trace_FilterInstaller.1.txt 2017-05-17 18:40 - 2017-05-20 17:36 - 0000905 _____ () C:\Users\murph\AppData\Roaming\trace_FilterInstaller.txt 2017-05-17 18:40 - 2017-05-20 17:36 - 0000000 _____ () C:\Users\murph\AppData\Roaming\trace_FilterInstaller.txt-CRT.txt 2016-03-27 13:29 - 2016-08-08 13:38 - 0000158 _____ () C:\Users\murph\AppData\Roaming\WB.CFG 2016-12-11 09:44 - 2016-12-11 09:44 - 0000867 _____ () C:\Users\murph\AppData\Local\recently-used.xbel 2017-06-23 16:38 - 2017-06-23 16:38 - 0000017 _____ () C:\Users\murph\AppData\Local\resmon.resmoncfg 2015-12-16 14:03 - 2015-12-16 14:03 - 0353118 _____ () C:\Users\murph\AppData\Local\SquareClock.Production_HBMV1Icon.ico 2016-04-27 15:30 - 2016-12-04 18:58 - 0000037 _____ () C:\Users\murph\AppData\Local\X-Plane Installer.prf 2016-12-04 18:58 - 2016-12-04 18:58 - 0000015 _____ () C:\Users\murph\AppData\Local\X-Plane_drm_11.prf 2015-12-21 19:13 - 2015-12-21 19:13 - 0000040 _____ () C:\Users\murph\AppData\Local\x-plane_install.txt 2016-12-04 18:35 - 2016-12-04 18:35 - 0000056 _____ () C:\Users\murph\AppData\Local\x-plane_install_11.txt 2017-05-14 15:20 - 2017-05-14 15:20 - 0000000 ____H () C:\ProgramData\DP45977C.lfl 2016-02-11 15:29 - 2016-02-11 15:29 - 0000133 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc Files to move or delete: ==================== C:\Users\murph\worldpainter_64_2.0.2.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-06-25 17:59 ==================== End of FRST.txt ============================
  4. OK here it is Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-06-2017 01 Ran by murph (26-06-2017 19:47:23) Running from C:\Users\murph\Desktop\fix Windows 10 Home Version 1703 (X64) (2017-05-14 19:50:52) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-1523608283-3295547807-88052705-500 - Administrator - Disabled) DefaultAccount (S-1-5-21-1523608283-3295547807-88052705-503 - Limited - Disabled) Guest (S-1-5-21-1523608283-3295547807-88052705-501 - Limited - Disabled) murph (S-1-5-21-1523608283-3295547807-88052705-1001 - Administrator - Enabled) => C:\Users\murph ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B} AV: McAfee VirusScan (Disabled - Up to date) {8BCDACFA-D264-3528-5EF8-E94FD0BC1FBC} AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: McAfee VirusScan (Disabled - Up to date) {30AC4D1E-F45E-3AA6-6448-D23DAB3B5501} FW: McAfee Firewall (Disabled) {B3F62DDF-980B-3470-75A7-407A2E6F58C7} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.009.20044 - Adobe Systems Incorporated) Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 1.5.3.9120 - Adobe Systems Inc.) Adobe Creative Cloud (HKLM-x32\...\Adobe Creative Cloud) (Version: 4.0.1.188 - Adobe Systems Incorporated) Adobe Photoshop CC 2017 (HKLM-x32\...\PHSP_18_1_1) (Version: 18.1.1 - Adobe Systems Incorporated) Adobe Shockwave Player 12.2 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.2.0.162 - Adobe Systems, Inc.) Age of Conan: Unchained (HKLM\...\Steam App 217750) (Version: - Funcom) AMD Settings (HKLM\...\WUCCCApp) (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Apple Application Support (32-bit) (HKLM-x32\...\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) Autodesk AutoCAD Utility Design 2016 - English (HKLM\...\AutoCAD Utility Design 2016 - English) (Version: - ) Call of Duty: Black Ops III – Mod Tools (HKLM\...\Steam App 455130) (Version: - Treyarch) Call of Duty: Black Ops III (HKLM\...\Steam App 311210) (Version: - Treyarch) Canon IJ Network Scanner Selector EX (HKLM-x32\...\Canon_IJ_Network_Scanner_Selector_EX) (Version: - Canon Inc.) Canon IJ Network Tool (HKLM-x32\...\Canon_IJ_Network_UTILITY) (Version: 3.2.0 - Canon Inc.) Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version: - Canon Inc.) Canon MX920 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX920_series) (Version: 1.01 - Canon Inc.) Catalyst Control Center Next Localization BR (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization BR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization BR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization BR (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHS (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CHT (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization CS (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DA (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization DE (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization EL (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization ES (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FI (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization FR (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization HU (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization IT (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization JA (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization KO (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NL (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization NO (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization PL (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization RU (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization SV (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TH (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.0624.1251.21301 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.0916.1515.27418 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2016.1121.1657.30480 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Next Localization TR (Version: 2017.0424.2119.36535 - Advanced Micro Devices, Inc.) Hidden Citrix online plug-in - web (HKLM-x32\...\CitrixOnlinePluginPackWeb) (Version: 12.3.0.8 - Citrix Systems, Inc.) CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version: 3.0 - Acro Software Inc.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dell Customer Connect (HKLM-x32\...\{4FA72FF9-DD64-43A8-8704-6380A11F11D5}) (Version: 1.4.15.0 - Dell Inc.) Dell Digital Delivery (HKLM-x32\...\{AB7F2792-2ED1-4C5C-9F28-680E5110BF72}) (Version: 3.1.1018.0 - Dell Products, LP) Dell Foundation Services (HKLM\...\{BDB50421-E961-42F3-B803-6DAC6F173834}) (Version: 3.4.16100.0 - Dell Inc.) Dell Help & Support (HKLM-x32\...\InstallShield_{7E780845-303D-4B46-9746-9D49D94D16AB}) (Version: 2.3.22.0 - Dell Inc.) Dell Help & Support (Version: 2.3.22.0 - Dell Inc.) Hidden Dell Product Registration (HKLM-x32\...\InstallShield_{48114909-3C3B-43E6-BF98-AE9C396500A3}) (Version: 3.0.127.0 - Dell Inc.) Dell System Detect (HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\58d94f3ce2c27db0) (Version: 7.11.0.6 - Dell) Dell Update - SupportAssist Update Plugin (HKLM\...\{5F641343-FA40-4084-855A-7FA3251783DC}) (Version: 2.0.2.1840 - Dell Inc.) Dell Update (HKLM-x32\...\{DB82968B-57A4-4397-81A5-ECAB21B5DFCD}) (Version: 1.7.1015.0 - Dell Inc.) Dropbox Update Helper (x32 Version: 1.3.59.1 - Dropbox, Inc.) Hidden Google Update Helper (x32 Version: 1.3.33.5 - Google Inc.) Hidden iCloud (HKLM\...\{724A887F-2B55-4306-B6F9-8F0E7A04B1B5}) (Version: 5.2.2.87 - Apple Inc.) Intel(R) C++ Redistributables on Intel(R) 64 (HKLM-x32\...\{F70BCE36-25F2-4475-A918-6209B3D85BF3}) (Version: 15.0.179 - Intel Corporation) Intel(R) Chipset Device Software (x32 Version: 10.1.1.7 - Intel(R) Corporation) Hidden Intel(R) Management Engine Components (HKLM\...\{1CEAC85D-2590-4760-800F-8DE5E91F3700}) (Version: 11.0.0.1153 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 14.5.0.1081 - Intel Corporation) Intel(R) Wireless Bluetooth(R) (HKLM-x32\...\{DC5673D2-228D-45BC-B9BB-9610CE67DFC0}) (Version: 17.1.1524.1353 - Intel Corporation) Intel® Hardware Accelerated Execution Manager (HKLM\...\{27276DC1-66AA-4B16-918D-5AB1EEDF09C6}) (Version: 6.0.5 - Intel Corporation) Intel® PROSet/Wireless Software (HKLM-x32\...\{29388fa1-af6a-4a46-8c5e-69cab61379d8}) (Version: 18.11.0 - Intel Corporation) Intel® Security Assist (HKLM-x32\...\{4B230374-6475-4A73-BA6E-41015E9C5013}) (Version: 1.0.0.532 - Intel Corporation) iTunes (HKLM\...\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.) Java 8 Update 121 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F64180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Java 8 Update 121 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180121F0}) (Version: 8.0.1210.13 - Oracle Corporation) Java SE Development Kit 8 Update 92 (64-bit) (HKLM\...\{64A3A4F4-B792-11D6-A78A-00B0D0180920}) (Version: 8.0.920.14 - Oracle Corporation) Junk Mail filter update (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Macromedia Extension Manager (HKLM-x32\...\{5546CDB5-2CE2-498B-B059-5B3BF81FC41F}) (Version: 1.7.240 - Macromedia, Inc.) Macromedia Flash 8 Video Encoder (HKLM-x32\...\{8BF2C401-02CE-424D-BC26-6C4F9FB446B6}) (Version: 1.00.0000 - Macromedia) Macromedia Flash Player 8 Plugin (HKLM-x32\...\{91057632-CA70-413C-B628-2D3CDBBB906B}) (Version: 8.0.22.0 - Macromedia) Malwarebytes version 3.0.6.1469 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.6.1469 - Malwarebytes) Maxx Audio Installer (x64) (Version: 2.6.6168.1 - Waves Audio Ltd.) Hidden McAfee LiveSafe (HKLM-x32\...\MSC) (Version: 14.0 R13 - McAfee, Inc.) McAfee WebAdvisor (HKLM-x32\...\{35ED3F83-4BDC-4c44-8EC6-6A8301C7413A}) (Version: 4.0.139 - McAfee, Inc.) Microsoft .NET Framework 4.5.1 Multi-Targeting Pack (HKLM-x32\...\{6A0C6700-EA93-372C-8871-DCCF13D160A4}) (Version: 4.5.50932 - Microsoft Corporation) Microsoft .NET Framework 4.6 SDK (HKLM-x32\...\{B5915D37-0637-4A26-A3AA-C5DC9F856370}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6 Targeting Pack (HKLM-x32\...\{2CC6A4A7-AAC2-46C9-9DBB-3727B5954F65}) (Version: 4.6.00081 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 SDK (HKLM-x32\...\{2F0ECC80-B9E4-4485-8083-CD32F22ABD92}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (ENU) (HKLM-x32\...\{8EEB28EE-5141-411C-9CF0-9952264FE4AF}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft .NET Framework 4.6.1 Targeting Pack (HKLM-x32\...\{8BC3EEC9-090F-4C53-A8DA-1BEC913040F9}) (Version: 4.6.01055 - Microsoft Corporation) Microsoft Access database engine 2010 (English) (HKLM\...\{90140000-00D1-0409-1000-0000000FF1CE}) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Help Viewer 2.2 (HKLM-x32\...\Microsoft Help Viewer 2.2) (Version: 2.2.24720 - Microsoft Corporation) Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.8201.2102 - Microsoft Corporation) Microsoft OneDrive (HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2012 Native Client (HKLM\...\{49D665A2-4C2A-476E-9AB8-FCC425F526FC}) (Version: 11.0.2100.60 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (HKLM-x32\...\{2774595F-BC2A-4B12-A25B-0C37A37049B0}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Management Objects (x64) (HKLM\...\{1F9EB3B6-AED7-4AA7-B8F1-8E314B74B2A5}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 Transact-SQL ScriptDom (HKLM\...\{020CDFE0-C127-4047-B571-37C82396B662}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server 2014 T-SQL Language Service (HKLM-x32\...\{47D08E7A-92A1-489B-B0BF-415516497BCE}) (Version: 12.0.2000.8 - Microsoft Corporation) Microsoft SQL Server Compact 4.0 SP1 x64 ENU (HKLM\...\{78909610-D229-459C-A936-25D92283D3FD}) (Version: 4.0.8876.1 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM\...\{FC3BB979-AA54-4B60-BBA3-2C4DA6E08D80}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft System CLR Types for SQL Server 2014 (HKLM-x32\...\{091CE6AA-2753-4F6E-AD1C-0E875744EB54}) (Version: 12.0.2402.29 - Microsoft Corporation) Microsoft Visual Basic PowerPacks 10.0 (HKLM-x32\...\{2D9F8079-7D50-3EFD-B3BD-ED642E4EE756}) (Version: 10.0.20911 - Microsoft) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729 (HKLM\...\{2DFD8316-9EF1-3210-908C-4CB61961C1AC}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{527BBE2F-1FED-3D8B-91CB-4DB0F838E69E}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.24215 (HKLM-x32\...\{d992c12e-cab2-426f-bde3-fb8c53950b0d}) (Version: 14.0.24215.1 - Microsoft Corporation) Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.24210 (HKLM-x32\...\{23658c02-145e-483d-ba6b-1eb82c580529}) (Version: 14.0.24210.0 - Microsoft Corporation) Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation) Microsoft Visual Studio 2015 Tools for Unity (HKLM-x32\...\{D68E6605-F852-4936-AB64-04B80E0C85AD}) (Version: 2.2.0.0 - Microsoft Corporation) Microsoft WSE 3.0 Runtime (HKLM-x32\...\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}) (Version: 3.0.5305.0 - Microsoft Corp.) Movie Maker (x32 Version: 16.4.3528.0331 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component (x32 Version: 16.0.8201.2102 - Microsoft Corporation) Hidden Office 16 Click-to-Run Extensibility Component 64-bit Registration (Version: 16.0.8201.2102 - Microsoft Corporation) Hidden Office 16 Click-to-Run Licensing Component (Version: 16.0.8201.2102 - Microsoft Corporation) Hidden Office 16 Click-to-Run Localization Component (x32 Version: 16.0.8201.2075 - Microsoft Corporation) Hidden OnePlus USB Drivers 1.00 (HKLM-x32\...\OnePlus USB Drivers 1.00) (Version: 1.00 - OnePlus, Inc) Oracle VM VirtualBox 4.3.12_ZZZZ (HKLM\...\{B5121457-0126-4E62-BCBF-6DC7C73D9E4A}) (Version: 4.3.12 - Oracle Corporation) Product Registration (Version: 3.0.127.0 - Dell Inc.) Hidden Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10125.31214 - Realtek Semiconductor Corp.) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7544 - Realtek Semiconductor Corp.) Realtek USB Audio (HKLM-x32\...\{0A46A65D-89AC-464C-8026-3CD44960BD04}) (Version: 6.3.9600.41 - Realtek Semiconductor Corp.) Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation) Steam (HKLM-x32\...\Steam) (Version: 2.10.91.91 - Valve Corporation) swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden The Elder Scrolls V: Skyrim Special Edition (HKLM\...\Steam App 489830) (Version: - Bethesda Game Studios) Universal CRT Redistributable (x32 Version: 10.1.10586.15 - Microsoft Corporation) Hidden Universal CRT Tools x64 (Version: 10.1.10586.15 - Microsoft Corporation) Hidden Universal CRT Tools x86 (x32 Version: 10.1.10586.15 - Microsoft Corporation) Hidden Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{6DA2B636-698A-3294-BF4A-B5E11B238CDD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{8CCEA24C-51AE-3B71-9092-7D0C44DDA2DF}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{C3A57BB3-9AA6-3F6F-9395-6C062BDD5FC4}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x64 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{F6F09DD8-F39B-3A16-ADB9-C9E6B56903F9}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{04B34E21-5BEE-3D2B-8D3D-E3E80D253F64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{14866AAD-1F23-39AC-A62B-7091ED1ADE64}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{4B90093A-5D9C-3956-8ABB-95848BE6EFAD}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Visual C++ 2008 - x86 (KB958357) - v9.0.30729.177 (HKLM-x32\...\{B42E259C-E4D4-37F1-A1B2-EB9C4FC5A04D}.KB958357) (Version: 9.0.30729.177 - Microsoft Corporation) Windows 10 Update and Privacy Settings (HKLM\...\{293F2009-0145-450B-B4AA-063D43FB368C}) (Version: 1.0.13.0 - Microsoft Corporation) Windows 10 Upgrade Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17387 - Microsoft Corporation) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation) Windows SDK AddOn (HKLM-x32\...\{E65EDBCC-C437-45DF-96BE-46B672317F41}) (Version: 10.1.0.0 - Microsoft Corporation) Windows Software Development Kit - Windows 10.0.10586.15 (HKLM-x32\...\{28a123e5-1799-4f20-9bd8-7c46f30eb7bf}) (Version: 10.1.10586.15 - Microsoft Corporation) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) CustomCLSID: HKU\S-1-5-21-1523608283-3295547807-88052705-1001_Classes\CLSID\{e8c77137-e224-5791-b6e9-ff0305797a13}\InprocServer32 -> C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {0947EAB8-1F11-4399-ACA2-767B19DD5C2A} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-18] () Task: {0A24D4D0-C179-4224-A1EE-1DFE9C7522F1} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-04-25] (Adobe Systems Incorporated) Task: {178C3895-C82F-47C3-8AB0-7F8C406988B1} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: {223F847C-0B20-455E-89F4-80C302A49F07} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe Task: {3E6F2A7D-B75F-4BB6-9B45-86CA596CDF85} - System32\Tasks\StartCN => C:\Program Files\AMD\CNext\CNext\cncmd.exe [2017-04-24] (Advanced Micro Devices, Inc.) Task: {4B42E385-F49D-432C-A203-9F13FF9A54B4} - System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [2017-02-22] (McAfee, Inc.) Task: {6DC90FC0-7B73-478F-A583-4E05732CD9D0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-23] (Google Inc.) Task: {71194591-46DF-4DC1-9F6F-07D143AC4C2D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-09-23] (Google Inc.) Task: {7CE116DA-C108-44B7-B0D8-5795D494D2C2} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-05-04] (Microsoft Corporation) Task: {7D66881A-79E6-4ABE-9BCB-D4C56A9BCEDE} - System32\Tasks\McAfee Remediation (Prepare) => C:\Program Files\Common Files\AV\McAfee VirusScan\upgrade.exe [2017-04-12] (McAfee, Inc.) Task: {8667127E-3E9F-4CCF-990E-47C4953A00E5} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.) Task: {8C4519CB-0929-4D3B-8544-17AE130011CD} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2017-05-04] (Microsoft Corporation) Task: {9D77F86C-7AAC-42A1-9C4E-5FF2471C782F} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-18] (Microsoft Corporation) Task: {9F7188B4-11D4-407A-832F-1D229B3A0747} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2017-06-18] () Task: {9F97135E-2258-4213-9A07-782264DC4B26} - System32\Tasks\RunAsStdUser Task => C:\Program Files (x86)\Pogo Games\PogoDGC.exe Task: {A3EC8BAC-4692-4F69-9A00-BFA972BAD49C} - System32\Tasks\McAfeeLogon => C:\Program Files\Common Files\McAfee\Platform\McUICnt.exe [2017-02-22] (McAfee, Inc.) Task: {A688D906-9C40-479B-86B0-13CC1F19B286} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2017-06-18] (Microsoft Corporation) Task: {BB422B9E-F1DC-476E-9BA2-2C14DB180D0B} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\WINDOWS\system32\MRT.exe [2017-06-18] (Microsoft Corporation) Task: {C84CEEE9-B2EF-4A0E-9AA5-2110CF61E4BC} - System32\Tasks\McAfee\McAfee Idle Detection Task Task: {CE012BC5-0FFD-4A58-8179-6728E67A06DD} - System32\Tasks\AdobeAAMUpdater-1.0-MicrosoftAccount-murphy@travel-net.com => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2016-07-01] (Adobe Systems Incorporated) Task: {DA9DF1E7-DA11-4E0F-875F-4A46E79AF6BF} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2017-06-18] (Microsoft Corporation) Task: {E58BE898-1E43-454C-8F88-18D2C0BAC4FE} - System32\Tasks\McAfee\McAfee Auto Maintenance Task Agent Task: {EA087B05-A1E9-45C9-9A80-2E8CB393E3EF} - System32\Tasks\Adobe Uninstaller => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2017-03-27] (Adobe Systems Incorporated) Task: {FCCB90A4-3691-4E03-9767-EFA403F2DD3C} - System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe [2017-02-22] (McAfee, Inc.) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\CreateExplorerShellUnelevatedTask.job => C:\Windows\explorer.exe ==================== Shortcuts & WMI ======================== (The entries could be listed to be restored or removed.) ==================== Loaded Modules (Whitelisted) ============== 2015-09-07 14:37 - 2013-10-23 15:24 - 00087600 _____ () C:\Windows\System32\cpwmon64.dll 2016-09-01 18:12 - 2016-09-01 18:12 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-09-01 18:12 - 2016-09-01 18:12 - 01353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2017-03-24 12:57 - 2017-04-13 15:52 - 02271520 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2017-03-24 12:58 - 2017-04-13 15:52 - 02267600 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2016-10-25 09:57 - 2016-10-25 09:57 - 00491184 _____ () C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncExtension\CoreSync_x64.dll 2016-12-12 21:50 - 2017-06-18 17:34 - 08931008 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll 2016-05-17 16:18 - 2010-07-29 18:19 - 00293888 _____ () C:\Program Files (x86)\Total Video Converter\TVCShellExtx64.dll 2017-03-18 16:58 - 2017-03-18 16:58 - 00138000 _____ () C:\Windows\SYSTEM32\inputhost.dll 2017-03-18 16:59 - 2017-03-18 22:31 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll 2017-06-20 20:38 - 2017-06-20 20:42 - 03139496 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11705.1001.21.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll 2017-06-24 00:14 - 2017-06-24 00:14 - 10628608 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11705.1001.21.0_x64__8wekyb3d8bbwe\WinStore.Entertainment.Mobile.dll 2017-06-24 00:14 - 2017-06-24 00:14 - 02640384 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11705.1001.21.0_x64__8wekyb3d8bbwe\MS.Entertainment.Common.Mobile.dll 2017-06-24 00:14 - 2017-06-24 00:14 - 00766464 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsStore_11705.1001.21.0_x64__8wekyb3d8bbwe\WinStore.Vui.dll 2017-06-24 00:13 - 2017-06-24 00:14 - 13207232 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.40985.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Core.dll 2017-06-24 00:13 - 2017-06-24 00:14 - 01199816 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.40985.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Word.dll 2016-12-21 11:24 - 2016-12-21 11:24 - 00134008 _____ () C:\Program Files (x86)\Dell Customer Connect\ServiceTagPlusPlus.dll 2015-06-23 19:26 - 2015-06-23 19:26 - 00155888 _____ () c:\Program Files (x86)\Dell Digital Delivery\ServiceTagPlusPlus.dll 2015-06-24 04:07 - 2015-06-24 04:07 - 01243936 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\McMPFSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) HKU\S-1-5-21-1523608283-3295547807-88052705-1001\Software\Classes\.scr: AutoCADLTScriptFile => ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) IE trusted site: HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\aeriagames.com -> hxxps://aeriagames.com IE trusted site: HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\aeriagames.com -> hxxp://aeriagames.com ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2015-07-10 07:04 - 2017-06-26 13:30 - 00000027 _____ C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-1523608283-3295547807-88052705-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\murph\AppData\Local\Microsoft\Windows\Themes\RoamedThemeFiles\DesktopBackground\img2.jpg DNS Servers: 24.226.1.93 - 24.226.10.193 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: Warn) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == MSCONFIG\Services: CDPUserSvc_49e8a => MSCONFIG\Services: lfsvc => 3 MSCONFIG\Services: MessagingService_49e8a => MSCONFIG\Services: OneSyncSvc_49e8a => HKLM\...\StartupApproved\StartupFolder: => "Ginger.lnk" HKLM\...\StartupApproved\Run: => "IAStorIcon" HKLM\...\StartupApproved\Run: => "RtHDVBg" HKLM\...\StartupApproved\Run: => "RTHDVCPL" HKLM\...\StartupApproved\Run: => "WavesSvc" HKLM\...\StartupApproved\Run: => "AdobeAAMUpdater-1.0" HKLM\...\StartupApproved\Run: => "iTunesHelper" HKLM\...\StartupApproved\Run: => "Wondershare Helper Compact.exe" HKLM\...\StartupApproved\Run32: => "ConnectionCenter" HKLM\...\StartupApproved\Run32: => "SunJavaUpdateSched" HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud" HKLM\...\StartupApproved\Run32: => "Dropbox" HKLM\...\StartupApproved\Run32: => "Autodesk Desktop App" HKLM\...\StartupApproved\Run32: => "Wondershare Helper Compact.exe" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "OneDrive" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "Skype" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "SmartSwitchPDLR.exe" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "Chromium" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "GoogleDriveSync" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "PCCleaner" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "Steam" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "SkypeVoiceChanger" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "Lync" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "Discord" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "Ca013i5M8Y.exe" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "WindowsUpdate" HKU\S-1-5-21-1523608283-3295547807-88052705-1001\...\StartupApproved\Run: => "fade4cca898c41f1d25eea0bcf1504f0" ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{E07CB711-5EC2-4115-B611-59FF8E8F09C3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe FirewallRules: [{A22C0D40-B15A-4C1A-A458-F62645B4F9D3}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{B2A19FE9-7667-4807-96D5-2A40C4CA2E02}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{AA4D86A6-E184-4C0A-B969-5EBC1E5F4A50}] => (Allow) D:\Chris\SteamLibrary\steamapps\common\Age of Conan\ConanPatcher.exe FirewallRules: [{D7941EF6-3CCC-49DC-9EAA-28883B155846}] => (Allow) D:\Chris\SteamLibrary\steamapps\common\Age of Conan\ConanPatcher.exe FirewallRules: [{2DAD1377-FB9A-4EB5-AF7F-8F0C0DC76283}] => (Allow) D:\Chris\SteamLibrary\steamapps\common\Call of Duty Black Ops III\BlackOps3.exe FirewallRules: [{E3E5822E-1330-471A-AE70-B76A00901CDA}] => (Allow) D:\Chris\SteamLibrary\steamapps\common\Call of Duty Black Ops III\BlackOps3.exe FirewallRules: [{CD0ED768-3689-4406-9945-A090549C1805}] => (Allow) D:\Chris\SteamLibrary\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe FirewallRules: [{C863E80B-2AA2-47CE-B5ED-FEDFD533D86A}] => (Allow) D:\Chris\SteamLibrary\steamapps\common\Skyrim Special Edition\SkyrimSELauncher.exe FirewallRules: [{68913FAA-448B-448A-BA69-30F07417186D}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\StarMade\StarMade-starter.exe FirewallRules: [{7CF0429A-9C0A-4C20-8214-17746992AB37}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\StarMade\StarMade-starter.exe FirewallRules: [{106CA344-CCBD-4425-B84B-D90D8BD0C974}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\StarMade\starmade-launcher.exe FirewallRules: [{AD4F16EA-ED43-4831-B18B-D14E45562FF7}] => (Allow) C:\Program Files (x86)\Steam\steamapps\common\StarMade\starmade-launcher.exe FirewallRules: [{0261BAA4-46B7-4398-9851-AC6120558325}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{A62DCAD5-A1E4-4CDC-8CF9-86AFBD5C7B29}] => (Allow) C:\Program Files (x86)\Steam\bin\cef\cef.win7\steamwebhelper.exe FirewallRules: [{F9DB859F-6D88-4978-BFD3-12542DBB7F7B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe FirewallRules: [{5B10DE85-0166-4766-8F9A-D7931922FEC8}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe FirewallRules: [{81DA241F-BFF8-4B2F-BF66-5FC37B9D2CE5}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe FirewallRules: [{55A5D427-B9F6-4D82-8856-A5E603685646}] => (Allow) C:\Users\murph\AppData\Local\Amigo\Application\amigo.exe FirewallRules: [UDP Query User{D9726B46-6960-4967-B113-35BEBB3E0C6C}C:\program files (x86)\asus\asus smart gesture\astpcenter\x64\asussgplusbtserver64.exe] => (Allow) C:\program files (x86)\asus\asus smart gesture\astpcenter\x64\asussgplusbtserver64.exe FirewallRules: [TCP Query User{B88F9FC9-B664-4165-B72A-E94E6592BB3C}C:\program files (x86)\asus\asus smart gesture\astpcenter\x64\asussgplusbtserver64.exe] => (Allow) C:\program files (x86)\asus\asus smart gesture\astpcenter\x64\asussgplusbtserver64.exe FirewallRules: [{5AB25F33-9F01-4019-B2AD-1E85A344FB9E}] => (Allow) C:\Program Files\Oracle\VirtualBox\vboxheadless.exe FirewallRules: [{96CB293D-0B64-401F-A199-E1446804A906}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe FirewallRules: [{00182BCA-3F68-4C34-8B84-CED14145CBA7}] => (Allow) C:\Program Files (x86)\Droid4X\download\MiniThunderPlatform.exe FirewallRules: [{72E96B9D-4F73-43DC-9AF1-A3003207483C}] => (Allow) C:\Program Files (x86)\Droid4X\Droid4X.exe FirewallRules: [{0558AE2C-A373-4D17-AED1-33B07B6A3027}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe FirewallRules: [{821C2C54-9DA3-4156-8AB0-BA18392A3456}] => (Allow) LPort=1900 FirewallRules: [{08AB3741-0414-47DC-912B-8B38CD2860FD}] => (Allow) LPort=2869 FirewallRules: [{C5AB5DEA-6E1E-4E79-ADB6-248E3EBA2BBE}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe FirewallRules: [{F153F251-F5B9-42F4-928D-7ABFCBDDB0BB}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe FirewallRules: [{EDAD0EE7-559B-41AA-96C4-83F847E17C09}] => (Allow) C:\Program Files (x86)\CyberLink\CyberLink Media Suite\PowerDirector12\PDR10.EXE FirewallRules: [TCP Query User{65B2586D-E47E-4D92-BBAD-FE89D0D67E73}C:\users\murph\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\murph\appdata\local\akamai\netsession_win.exe FirewallRules: [UDP Query User{ACE216FA-D8A1-46D6-9A26-6BDEF9E14CA8}C:\users\murph\appdata\local\akamai\netsession_win.exe] => (Block) C:\users\murph\appdata\local\akamai\netsession_win.exe FirewallRules: [{D2520006-6E77-4414-9D92-36A38DD240EA}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{82AA2CF0-AB8D-4E44-B04F-116177A499D0}] => (Allow) C:\Program Files (x86)\Raptr\raptr.exe FirewallRules: [{6CECB619-8E96-454D-9B3E-3D1B04041AF7}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{14982DF3-A5E0-4F81-B030-D14A82A61B20}] => (Allow) C:\Program Files (x86)\Raptr\raptr_im.exe FirewallRules: [{82BF7437-424C-4D05-A16D-5E68D3AABF12}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio Tools for Unity\2015\UnityVS.OpenFile.exe FirewallRules: [{E6DE731B-403E-4E1A-A8EB-7DCF6C073055}] => (Allow) C:\Program Files (x86)\Microsoft Visual Studio 14.0\Common7\IDE\devenv.exe FirewallRules: [{7D264EEE-A6DB-4116-B29C-978C9AD977AD}] => (Allow) D:\Unity\Editor\Unity.exe FirewallRules: [{9238FDDE-22E0-46C9-B738-9FD261397CBA}] => (Allow) C:\Users\murph\Downloads\ProductDetection.exe FirewallRules: [{6A725394-F786-4781-9670-273981CF0BDA}] => (Allow) C:\Users\murph\Downloads\ProductDetection.exe FirewallRules: [{D7039F5D-E891-4A70-AA71-D339AA0C4006}] => (Allow) C:\Program Files (x86)\McAfee\Supportability\MVT\MvtApp.exe FirewallRules: [{936513FE-F723-4C6A-958A-E43ED850705E}] => (Allow) C:\Program Files (x86)\McAfee\Supportability\MVT\MvtApp.exe FirewallRules: [{FA26D9E2-4FD2-4F6A-BD0C-EEEF0CD66FFA}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{6FFA2547-EDA4-4016-9983-DA747EC2DF7E}] => (Allow) C:\Program Files (x86)\Steam\Steam.exe FirewallRules: [{5275F6BC-38A1-42DA-B8E3-ED3B6870A016}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{BE626962-5228-4303-833A-5FCAC54B5E52}] => (Allow) C:\Program Files (x86)\Steam\bin\steamwebhelper.exe FirewallRules: [{9BD3F7AD-7906-40AC-9C27-4B545BCF235B}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{9E34866B-9DC4-4A63-9119-E4BFD69D933B}] => (Allow) C:\Windows\SysWOW64\muzapp.exe FirewallRules: [{0C236438-80EE-4574-86BD-098150FA8381}] => (Allow) C:\Users\murph\AppData\Local\Chromium\Application\chrome.exe FirewallRules: [TCP Query User{8E172064-1168-45F0-A9F8-719CD560A87E}C:\users\murph\appdata\local\logmein client\lmiignition.exe] => (Allow) C:\users\murph\appdata\local\logmein client\lmiignition.exe FirewallRules: [UDP Query User{ABFB0768-055C-4386-A10D-781DD5D81C3A}C:\users\murph\appdata\local\logmein client\lmiignition.exe] => (Allow) C:\users\murph\appdata\local\logmein client\lmiignition.exe FirewallRules: [{B76E4C7D-090E-436B-8108-20EF208B0D20}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{FCF61CB4-BB74-48EC-A617-3D3DA8348142}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{A2A70AC8-C9FD-4375-A40C-5CA4070C2C24}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{0E9BFCE7-1D56-4E10-9FAF-1291BEDA5ADC}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{21ADD971-4A43-4DB6-BABF-E2B95B076C6E}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [UDP Query User{45E87A96-5E71-422B-A720-D3D9C9E19A22}C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe] => (Allow) C:\program files (x86)\minecraft\runtime\jre-x64\1.8.0_25\bin\javaw.exe FirewallRules: [TCP Query User{8FD2739A-0D29-4F63-B686-DDF668D80742}C:\program files (x86)\athtek\voice changer for skype\skypevoicechanger.exe] => (Allow) C:\program files (x86)\athtek\voice changer for skype\skypevoicechanger.exe FirewallRules: [UDP Query User{34843BAD-8B6C-48C8-B7D6-EC962D2E3B0B}C:\program files (x86)\athtek\voice changer for skype\skypevoicechanger.exe] => (Allow) C:\program files (x86)\athtek\voice changer for skype\skypevoicechanger.exe FirewallRules: [{50624228-8B1B-4D15-BF07-0C4C1D651AE4}] => (Allow) D:\Steam2\Steam.exe FirewallRules: [{F2C02954-FAFB-4836-A989-4FAF9267456B}] => (Allow) D:\Steam2\Steam.exe FirewallRules: [{83659F5A-7CEF-436C-99FC-74E68672FB31}] => (Allow) D:\Steam2\bin\steamwebhelper.exe FirewallRules: [{BB4A431B-B308-44B8-AA71-34FD48344215}] => (Allow) D:\Steam2\bin\steamwebhelper.exe FirewallRules: [{10AC658C-C9EF-43F3-9C3E-4D620684CB16}] => (Allow) C:\Program Files\iTunes\iTunes.exe FirewallRules: [{07EFF5EE-762F-4AC2-AE0E-F23AEC446C3C}] => (Allow) C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe FirewallRules: [{49AEF82B-3F05-4A67-8257-0DDDDF7DA24E}] => (Allow) C:\Program Files (x86)\SrpnFiles\SrpnFiles.exe FirewallRules: [{C174E38A-D670-4CFF-86EC-D6F941817B2A}] => (Allow) C:\Program Files (x86)\SrpnFiles\downloader.exe FirewallRules: [{4D36C6D5-2261-4C05-9D65-A1217C23D1EC}] => (Allow) C:\Program Files (x86)\SrpnFiles\downloader.exe FirewallRules: [TCP Query User{53CB337F-92C9-456E-8D2D-A074A3B96D8B}C:\users\murph\appdata\local\temp\rarsfx1\rsync.exe] => (Allow) C:\users\murph\appdata\local\temp\rarsfx1\rsync.exe FirewallRules: [UDP Query User{6AD58E3A-7E47-451F-86E4-D2D22FB16A7A}C:\users\murph\appdata\local\temp\rarsfx1\rsync.exe] => (Allow) C:\users\murph\appdata\local\temp\rarsfx1\rsync.exe FirewallRules: [TCP Query User{4F4B304D-61E1-4B79-A4B1-B1846E169392}C:\program files\java\jdk1.8.0_60\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_60\bin\java.exe FirewallRules: [UDP Query User{3A0C5EF6-709F-4D35-87F4-89946A539C59}C:\program files\java\jdk1.8.0_60\bin\java.exe] => (Allow) C:\program files\java\jdk1.8.0_60\bin\java.exe FirewallRules: [TCP Query User{C73C5307-6A5F-4CFD-AF34-AD67DFE7005C}C:\program files\esri\cityengine2016.1\cityengine.exe] => (Allow) C:\program files\esri\cityengine2016.1\cityengine.exe FirewallRules: [UDP Query User{9DDADE94-9B19-41F5-A832-7660F4135E69}C:\program files\esri\cityengine2016.1\cityengine.exe] => (Allow) C:\program files\esri\cityengine2016.1\cityengine.exe FirewallRules: [{5543C3C2-40D8-49FC-8D40-2DDDB0D16955}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe FirewallRules: [{955743ED-44B0-44DE-ABE2-A1C183DE5283}] => (Allow) D:\SimCity\SimCity\SimCity.exe FirewallRules: [{732E8AE8-AE09-4C91-BC03-72A46EA6585F}] => (Allow) D:\SimCity\SimCity\SimCity.exe FirewallRules: [{77D1A871-6FFE-4A80-A7EA-EA67ADE553AE}] => (Allow) D:\SimCity 2013\SimCity 2013 Offline\SimCity\SimCity.exe FirewallRules: [{22BE5A2B-D776-4F1F-8DD2-A6837A9C5312}] => (Allow) D:\SimCity 2013\SimCity 2013 Offline\SimCity\SimCity.exe FirewallRules: [{EDD7ABA0-5F8E-4026-ACC3-75382805B251}] => (Allow) C:\WINDOWS\system32\rundll32.exe FirewallRules: [{F0FD86E8-C125-44E8-B0B3-9656A854B565}] => (Allow) C:\Users\murph\AppData\Local\BrowserAir\Application\BrowserairExec.exe FirewallRules: [{3760EE25-21F9-4D7D-9D52-C467B1354B97}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe FirewallRules: [TCP Query User{2738871C-A98D-47C7-85AC-CF56FAC0904B}C:\users\murph\appdata\local\logmein client\lmiignition.exe] => (Allow) C:\users\murph\appdata\local\logmein client\lmiignition.exe FirewallRules: [UDP Query User{17BB3131-ED78-4031-9C5E-EC171261839B}C:\users\murph\appdata\local\logmein client\lmiignition.exe] => (Allow) C:\users\murph\appdata\local\logmein client\lmiignition.exe FirewallRules: [{CF7A5ADD-9EFC-43C9-A18E-26D4CA5C668E}] => (Allow) C:\Windows\System32\rundll32.exe FirewallRules: [{22B27506-D1B6-42B5-A7B4-80CCCB12E718}] => (Allow) C:\Windows\System32\rundll32.exe ==================== Restore Points ========================= 25-06-2017 18:05:34 Windows Update 26-06-2017 17:40:04 JRT Pre-Junkware Removal 26-06-2017 18:23:05 JRT Pre-Junkware Removal ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (06/26/2017 07:46:58 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: Error: (06/26/2017 07:45:02 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: Error: (06/26/2017 06:35:06 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: Error: (06/26/2017 06:34:56 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: Error: (06/26/2017 06:34:44 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: Error: (06/26/2017 06:30:29 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: Error: (06/26/2017 06:29:58 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: Error: (06/26/2017 06:29:51 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: Error: (06/26/2017 06:26:46 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: Error: (06/26/2017 06:25:08 PM) (Source: ATIeRecord) (EventID: 16387) (User: ) Description: System errors: ============= Error: (06/26/2017 06:22:46 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Windows Image Acquisition (WIA) service terminated unexpectedly. It has done this 1 time(s). Error: (06/26/2017 06:22:29 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (06/26/2017 06:22:29 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52} and APPID {4839DDB7-58C2-48F5-8283-E1D1807D0D7D} to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool. Error: (06/26/2017 06:22:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The CldFlt service failed to start due to the following error: The request is not supported. Error: (06/26/2017 06:21:48 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\Windows\System32\IWMSSvc.dll Error: (06/26/2017 06:21:48 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\Windows\System32\IWMSSvc.dll Error: (06/26/2017 06:21:47 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (EventID: 10003) (User: NT AUTHORITY) Description: WLAN Extensibility Module has stopped unexpectedly. Module Path: C:\Windows\System32\IWMSSvc.dll Error: (06/26/2017 06:21:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Intel(R) Security Assist service terminated unexpectedly. It has done this 1 time(s). Error: (06/26/2017 06:21:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Intel(R) Dynamic Application Loader Host Interface Service service terminated unexpectedly. It has done this 1 time(s). Error: (06/26/2017 06:21:31 PM) (Source: Service Control Manager) (EventID: 7034) (User: ) Description: The Intel(R) Rapid Storage Technology service terminated unexpectedly. It has done this 1 time(s). CodeIntegrity: =================================== Date: 2017-06-26 18:28:51.564 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-26 18:27:15.303 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-26 18:26:42.376 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-26 18:26:42.257 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-26 18:26:42.129 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-26 18:17:57.376 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-26 18:16:30.777 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-26 18:07:21.072 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-26 18:06:50.098 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. Date: 2017-06-26 18:06:10.459 Description: Code Integrity determined that a process (\Device\HarddiskVolume5\Windows\SystemApps\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\MicrosoftEdgeCP.exe) attempted to load \Device\HarddiskVolume5\Program Files\Malwarebytes\Anti-Malware\mbae64.dll that did not meet the Store signing level requirements. ==================== Memory info =========================== Processor: Intel(R) Core(TM) i7-4790 CPU @ 3.60GHz Percentage of memory in use: 14% Total physical RAM: 24527.2 MB Available physical RAM: 20971.87 MB Total Virtual: 28111.2 MB Available Virtual: 24548.51 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:224.72 GB) (Free:34.31 GB) NTFS Drive d: (DATA) (Fixed) (Total:1862.89 GB) (Free:1657.07 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 1863 GB) (Disk ID: FDBC25E1) Partition: GPT. ======================================================== Disk: 1 (Size: 238.5 GB) (Disk ID: FDBC25B1) Partition: GPT. ==================== End of Addition.txt ============================
  5. JRT Log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Malwarebytes Version: 8.1.3 (04.10.2017) Operating System: Windows 10 Home x64 Ran by murph (Administrator) on Mon 26/06/17 at 17:40:03.45 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ File System: 7 Successfully deleted: C:\ProgramData\19a87fa1ec024bbcbb41931263354405 (Folder) Successfully deleted: C:\ProgramData\browser (Folder) Successfully deleted: C:\ProgramData\esellerate (Folder) Successfully deleted: C:\Users\murph\AppData\Local\{0F376500-DFBE-47DE-A1F0-B86761A82BF2} (Empty Folder) Successfully deleted: C:\Users\murph\AppData\Local\nico mak computing (Folder) Successfully deleted: C:\Users\Public\thunder network (Folder) Successfully deleted: C:\Windows\wininit.ini (File) Deleted the following from C:\Users\murph\AppData\Roaming\Mozilla\Firefox\Profiles\4j9chsr5.default\prefs.js user_pref(extensions.search@mail.ru.go_metric_url, hxxp://go.mail.ru/distib/mark/?product_id=%7BB5EDEDB9-EFB4-4375-816A-2B0DBA2973EA%7D&install_id=%7B49E13966-5212-41DD-935 user_pref(extensions.search@mail.ru.install_id, {49E13966-5212-41DD-9356-B967C2DDF81F}); user_pref(extensions.search@mail.ru.mrds_metric_url, hxxp://mrds.mail.ru/update/2/version.txt?type=product_online_metric&product_id=%7BB5EDEDB9-EFB4-4375-816A-2B0DBA2973EA% user_pref(extensions.search@mail.ru.partner_product_online_url, hxxp://ec2-54-229-84-172.eu-west-1.compute.amazonaws.com/affect?guid={guid}&sid=16045&homesearch=1&label=811 user_pref(extensions.search@mail.ru.product_id, {B5EDEDB9-EFB4-4375-816A-2B0DBA2973EA}); user_pref(extensions.search@mail.ru.product_type, ff_xtndse); user_pref(extensions.search@mail.ru.rfr, 811037); Registry: 0
  6. Here's the ADW Cleaner log. AdwCleaner[C0].txt
  7. Done. The Computer did go through the reboot process. when rebooted, Malware Bytes was not on. I double clicked to activate and could only find this 'Scan Report" and not a "Export Summary" log. Hope it's the same thing! Malwarebytes www.malwarebytes.com -Log Details- Scan Date: 6/26/17 Scan Time: 1:58 PM Logfile: MB Scan Report.txt Administrator: Yes -Software Information- Version: 3.0.6.1469 Components Version: 1.0.103 Update Package Version: 1.0.2235 License: Premium -System Information- OS: Windows 10 CPU: x64 File System: NTFS User: DESKTOP-3FHNIRL\murph -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 479958 Time Elapsed: 0 min, 58 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Disabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registry Key: 27 PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\CONSOLE\TASKENG.EXE, Quarantined, [9436], [408199],1.0.2235 PUP.Optional.BrowserAir, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\APP PATHS\BrowserairExec.exe, Quarantined, [1563], [335429],1.0.2235 PUP.Optional.InterStat, HKU\S-1-5-21-1523608283-3295547807-88052705-1001_Classes\APPLICATIONS\interstat.exe, Quarantined, [1426], [261503],1.0.2235 PUP.Optional.HDWallPaper, HKLM\SOFTWARE\HDWallpaper, Quarantined, [133], [404734],1.0.2235 PUP.Optional.SpeeDownloader, HKLM\SOFTWARE\Speedownloader0099, Quarantined, [9005], [384272],1.0.2235 PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROLEAVES\Online Application, Quarantined, [563], [360190],1.0.2235 PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROLEAVES\Online.io Application, Quarantined, [563], [317312],1.0.2235 PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROLEAVES\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}, Quarantined, [563], [339688],1.0.2235 Adware.DNSUnlocker, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\11598763487076930564, Quarantined, [407], [405303],1.0.2235 PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}, Quarantined, [563], [398592],1.0.2235 PUP.Optional.RussAd, HKLM\SOFTWARE\WOW6432NODE\GOOGLE\CHROME\EXTENSIONS\ccfifbojenkenpkmnbnndeadpfdiffof, Quarantined, [12], [405529],1.0.2235 PUP.Optional.PCCleanPlus, HKLM\SOFTWARE\WOW6432NODE\PC\CLEAN\Plus, Quarantined, [44], [256464],1.0.2235 PUP.Optional.InterStat, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\InterStat, Quarantined, [1426], [260518],1.0.2235 PUP.Optional.MaohaWiFi, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\JiSuZip, Quarantined, [720], [406943],1.0.2235 PUP.Optional.OneSystemCare, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\One System Care, Quarantined, [477], [311038],1.0.2235 PUP.Optional.YeaDesktop, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\YeaDesktop, Quarantined, [1554], [391400],1.0.2235 PUP.Optional.AppTrailers, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\APPDATALOW\SOFTWARE\AppTrailers, Quarantined, [869], [324090],1.0.2235 PUP.Optional.BrowserAir, HKLM\SOFTWARE\WOW6432NODE\BrowserAir, Quarantined, [1563], [186506],1.0.2235 Adware.Jawego, HKLM\SOFTWARE\WOW6432NODE\Jawego, Quarantined, [8919], [383598],1.0.2235 PUP.Optional.SpeeDownloader, HKLM\SOFTWARE\WOW6432NODE\Speedownloader0099, Quarantined, [9005], [384272],1.0.2235 PUP.Optional.BrowserAir, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\MEDIAPLAYER\SHIMINCLUSIONLIST\BrowserairExec.exe, Quarantined, [1563], [335431],1.0.2235 PUP.Optional.PSScriptLoad.SHHKRST, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE, Quarantined, [9484], [410614],1.0.2235 PUP.Optional.BitCoinMiner, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\gplyra, Quarantined, [199], [317317],1.0.2235 PUP.Optional.YeaDesktop, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\TRACING\yeadesktop_RASAPI32, Quarantined, [1554], [409418],1.0.2235 PUP.Optional.BrowserAir, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\CLIENTS\STARTMENUINTERNET\BrowserAir.U7T23XJHDBFVPYPM5GKQHNRYPI, Quarantined, [1563], [246846],1.0.2235 PUP.Optional.PCCleanPlus, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\PC\CLEAN\Plus, Quarantined, [44], [256462],1.0.2235 PUP.Optional.SystemHealer, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\SYSTEM HEALER, Quarantined, [997], [261796],1.0.2235 Registry Value: 10 PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\CONSOLE\TASKENG.EXE|WINDOWPOSITION, Quarantined, [9436], [408199],1.0.2235 PUP.Optional.AppTrailers, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UFH\SHC|68, Quarantined, [869], [393166],1.0.2235 PUP.Optional.AppTrailers, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UFH\SHC|69, Quarantined, [869], [393166],1.0.2235 PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}|CONTACT, Quarantined, [563], [333852],1.0.2235 PUP.Optional.OnlineIO, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}|URLINFOABOUT, Quarantined, [563], [321304],1.0.2235 PUP.Optional.PSScriptLoad.EncJob, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_WINDOWSPOWERSHELL_V1.0_POWERSHELL.EXE|WINDOWPOSITION, Quarantined, [9436], [408201],1.0.2235 PUP.Optional.BrowserAir, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\REGISTEREDAPPLICATIONS|BROWSERAIR.U7T23XJHDBFVPYPM5GKQHNRYPI, Quarantined, [1563], [258424],1.0.2235 PUP.Optional.PSScriptLoad.SHHKRST, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\CONSOLE\%SYSTEMROOT%_SYSTEM32_SVCHOST.EXE|WINDOWPOSITION, Quarantined, [9484], [410614],1.0.2235 PUP.Optional.YeaDesktop.ClnShrt, HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\INTERNET EXPLORER\MAIN\FEATURECONTROL\FEATURE_BROWSER_EMULATION|YEADESKTOP.EXE, Quarantined, [1375], [396226],1.0.2235 PUP.Optional.SystemHealer, HKU\S-1-5-21-1523608283-3295547807-88052705-1001\SOFTWARE\SYSTEM HEALER|CARTURL, Quarantined, [997], [261796],1.0.2235 Registry Data: 0 (No malicious items detected) Data Stream: 0 (No malicious items detected) Folder: 26 PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\77f4a3d7-4ae1-1, Quarantined, [9253], [407181],1.0.2235 PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\77f4a3d7-58f5-0, Quarantined, [9253], [407181],1.0.2235 PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\b9033da3-1da5-1, Quarantined, [9253], [407181],1.0.2235 PUP.Optional.BitsInstall.BITSRST, C:\PROGRAMDATA\b9033da3-5b47-0, Quarantined, [9253], [407181],1.0.2235 Adware.OnlineIO, C:\ProgramData\Microleaves\Online Application\updates, Quarantined, [9469], [399763],1.0.2235 Adware.OnlineIO, C:\ProgramData\Microleaves\Online Application, Quarantined, [9469], [399763],1.0.2235 Adware.OnlineIO, C:\PROGRAMDATA\Microleaves, Quarantined, [9469], [399763],1.0.2235 Adware.OnlineIO, C:\Users\murph\AppData\Roaming\Microleaves\Online Application 2.6.0\install\CFCBAA1, Quarantined, [9469], [399763],1.0.2235 Adware.OnlineIO, C:\Users\murph\AppData\Roaming\Microleaves\Online Application 2.6.0\install, Quarantined, [9469], [399763],1.0.2235 Adware.OnlineIO, C:\Users\murph\AppData\Roaming\Microleaves\Online Application 2.6.0, Quarantined, [9469], [399763],1.0.2235 Adware.OnlineIO, C:\USERS\MURPH\APPDATA\ROAMING\Microleaves, Quarantined, [9469], [399763],1.0.2235 PUP.Optional.Elex.ClnShrt, C:\USERS\MURPH\APPDATA\LOCAL\kemgadeojglibflomicgnfeopkdfflnk, Quarantined, [1373], [328066],1.0.2235 PUP.Optional.OnlineIO, C:\WINDOWS\INSTALLER\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}, Quarantined, [563], [391425],1.0.2235 PUP.Optional.BrowserAir, C:\USERS\MURPH\APPDATA\ROAMING\MICROSOFT\WINDOWS\START MENU\PROGRAMS\BROWSERAIR, Quarantined, [1563], [180783],1.0.2235 PUP.Optional.InternetMonitor, C:\Users\murph\AppData\Local\CrashRpt\UnsentCrashReports\BandwidthStat_389\Logs, Quarantined, [13032], [182462],1.0.2235 PUP.Optional.InternetMonitor, C:\USERS\MURPH\APPDATA\LOCAL\CRASHRPT\UNSENTCRASHREPORTS\BandwidthStat_389, Quarantined, [13032], [182462],1.0.2235 PUP.Optional.FastSearch, C:\USERS\MURPH\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\4J9CHSR5.DEFAULT\EXTENSIONS\AMCONTEXTMENU@LOUCYPHER, Quarantined, [1159], [329326],1.0.2235 PUP.Optional.InterStat, C:\Users\murph\AppData\Local\CrashRpt\UnsentCrashReports\Interstatnogui_389\Logs, Quarantined, [1426], [373566],1.0.2235 PUP.Optional.InterStat, C:\USERS\MURPH\APPDATA\LOCAL\CRASHRPT\UNSENTCRASHREPORTS\Interstatnogui_389, Quarantined, [1426], [373566],1.0.2235 PUP.Optional.Goobzo.BITSRST, C:\PROGRAM FILES\COMMON FILES\Noobzo, Quarantined, [9004], [384282],1.0.2235 PUP.Optional.YeaDesktop, C:\PROGRAMDATA\MICROSOFT\WINDOWS\START MENU\PROGRAMS\YEADESKTOP, Quarantined, [1554], [391395],1.0.2235 PUP.Optional.Goobzo, C:\PROGRAMDATA\SEARCHMODULE, Quarantined, [350], [189917],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\index-dir, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Local Storage, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\USERS\MURPH\APPDATA\LOCAL\APPTRAILERS, Quarantined, [869], [324095],1.0.2235 File: 119 PUP.Optional.BitsInstall.BITSRST, C:\ProgramData\b9033da3-1da5-1\BIT944F.tmp, Quarantined, [9253], [407181],1.0.2235 PUP.Optional.BitsInstall.BITSRST, C:\ProgramData\b9033da3-5b47-0\BIT947F.tmp, Quarantined, [9253], [407181],1.0.2235 Adware.OnlineIO, C:\ProgramData\Microleaves\Online Application\updates\basic_updates.aiu, Quarantined, [9469], [399763],1.0.2235 PUP.Optional.Elex.ClnShrt, C:\Users\murph\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk\close_white.png, Quarantined, [1373], [328066],1.0.2235 PUP.Optional.Elex.ClnShrt, C:\Users\murph\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk\content_script.js, Quarantined, [1373], [328066],1.0.2235 PUP.Optional.Elex.ClnShrt, C:\Users\murph\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk\icon.png, Quarantined, [1373], [328066],1.0.2235 PUP.Optional.Elex.ClnShrt, C:\Users\murph\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk\jquery-1.8.3.min.js, Quarantined, [1373], [328066],1.0.2235 PUP.Optional.Elex.ClnShrt, C:\Users\murph\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk\jquery.js, Quarantined, [1373], [328066],1.0.2235 PUP.Optional.Elex.ClnShrt, C:\Users\murph\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk\manifest.json, Quarantined, [1373], [328066],1.0.2235 PUP.Optional.Elex.ClnShrt, C:\Users\murph\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk\popup.html, Quarantined, [1373], [328066],1.0.2235 PUP.Optional.Elex.ClnShrt, C:\Users\murph\AppData\Local\kemgadeojglibflomicgnfeopkdfflnk\popup.js, Quarantined, [1373], [328066],1.0.2235 PUP.Optional.OnlineIO, C:\Windows\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}\online.exe, Quarantined, [563], [391425],1.0.2235 PUP.Optional.OnlineIO, C:\Windows\Installer\{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}\SystemFoldermsiexec.exe, Quarantined, [563], [391425],1.0.2235 PUP.Optional.BrowserAir, C:\Users\murph\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserAir\BrowserAir.lnk, Quarantined, [1563], [180783],1.0.2235 PUP.Optional.FastSearch, C:\Users\murph\AppData\Roaming\Mozilla\Firefox\Profiles\4j9chsr5.default\extensions\amcontextmenu@loucypher\0024397e, Quarantined, [1159], [329326],1.0.2235 PUP.Optional.YeaDesktop, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YeaDesktop\Uninstall YeaDesktop.lnk, Quarantined, [1554], [391395],1.0.2235 PUP.Optional.YeaDesktop, C:\ProgramData\Microsoft\Windows\Start Menu\Programs\YeaDesktop\YeaDesktop.lnk, Quarantined, [1554], [391395],1.0.2235 PUP.Optional.Goobzo, C:\PROGRAMDATA\SEARCHMODULE\SMHE.JS, Quarantined, [350], [189917],1.0.2235 PUP.Optional.BrowserAir, C:\USERS\MURPH\APPDATA\ROAMING\MICROSOFT\INTERNET EXPLORER\QUICK LAUNCH\BROWSERAIR.LNK, Quarantined, [1563], [186505],1.0.2235 PUP.Optional.Goobzo.BITSRST, C:\WINDOWS\SYSTEM32\BI3.EXE, Quarantined, [9004], [384278],1.0.2235 PUP.Optional.AppTrailers, C:\USERS\MURPH\APPDATA\LOCAL\APPTRAILERS\WEB DATA, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\index-dir\the-real-index, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\02cdb733b079655d_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\03aaed705acccd25_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\08b837b14d8218cc_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\08bc571418449ead_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\0e81b8ca739fd4c8_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\0ed73590870cfbd2_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\0ed7399215f555d7_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\0ef50d324e1bc502_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\0fc3db66b9cbe75d_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\66e510668b4796e9_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\6f4f7519af57d736_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\7e92e13dd1f7b2bc_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\8326a92c0f293bc4_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\83a226c1379f7a18_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\8d9b27c428a8f6a3_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\8e86714e0eac1f63_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\8f60e69a4afd6f60_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\8fa1b83958d62913_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\b3edef432256edd5_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\b5278b785f291640_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\bd48447363dfb226_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\be189d201694bf89_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\bfbe9938bbb38577_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\c0584297f688114e_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\c1257795007bdb90_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\c188bca037f9c189_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\c3329b5e71fb9773_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\317051006588faad_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\325c5635318a3cc4_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\35c4edc43432066e_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\38e33bb1bd911ef8_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\3a977894dc0fcd39_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\3c0a87873222db88_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\434433e6be31dddd_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\442182c02ee0a243_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\ddc9322c11c989c3_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\e0014de2058fb1bb_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\e63f5bc023a4b93f_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\ec05505395a4fd7f_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\eef197e99b9422a4_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\f552ab47376f113e_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\f6f9d04e245b41d0_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\f74a8c1655500d73_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\f7b4e8641fae46a9_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\fddd11ea475c5135_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\index, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\90b41a5adbd386b5_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\945c59636f75b4e1_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\9ab069da12c6f7cd_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\9cbde96546f624d1_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\9e12b0434ab20ee0_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\a1f309cd5a3eb6fa_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\a30b43a63e0219be_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\a6f29d74ef9a9c1a_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\a9423296c2c84f57_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\ab6bc8112cf834f6_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\15102e1fa0485514_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\3082972055161e5d_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\486189d52268f247_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\6418071a5a8b607b_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\902790b2feff6cb4_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\b3986aa6d1a5b1ca_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\c487316b1c7eb401_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\dc7c883ebdb4ce43_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\15335d1f278dcf91_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\198ac16932783652_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\1b72c2d37a2af109_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\1dff67c9badf383d_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\2025113059e1f43d_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\234986793e71f265_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\26968e7a0c71776d_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\2819c5233c1f77b4_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\c6cf943b3d6c7806_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\c8b0ae44d7e5cdd7_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\d02e816cfb2f6bd9_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\d0d85ae8ecd18438_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\d19a15ac54bfa3ba_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\d4828277431ff818_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\d48a903ae25fb25c_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\d91470973717d8e1_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\4ea8fca2fa3409fc_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\5125b9f58b582f46_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\52dad56aff91a0a2_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\5317f7f0b0bcadb9_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\56bf1901a2000606_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\590e23e6a898c0fc_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\5ede7465ad814101_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Cache\6407604f84430b55_0, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Local Storage\file__0.localstorage, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Local Storage\file__0.localstorage-journal, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Local Storage\http_www.imdb.com_0.localstorage, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Local Storage\http_www.imdb.com_0.localstorage-journal, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\cookies, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\cookies-journal, Quarantined, [869], [324095],1.0.2235 PUP.Optional.AppTrailers, C:\Users\murph\AppData\Local\AppTrailers\Web Data-journal, Quarantined, [869], [324095],1.0.2235 PUP.Optional.OnlineIO, C:\WINDOWS\INSTALLER\SOURCEHASH{5266F634-7B7D-4537-BDDC-98DD6CFCBAA1}, Quarantined, [563], [391431],1.0.2235 PUP.Optional.HDWallPaper, C:\WINDOWS\SYSTEM32\NETUTILS2016.DLL, Quarantined, [133], [392467],1.0.2235 Physical Sector: 0 (No malicious items detected) (end)
  8. Hi Aura. Booted in safe mode and ran as administrator. Here's the file! Fixlog.txt
  9. Hi Aura, When this all started a few weeks ago, there were two new programs installed that appear to use the Mandarin keyboard. Here's a Print Screen showing them. I forgot to mention this to you earlier. Sorry.
  10. Hi Aura. You are correct. I had not done it with admin rights. I just did that now, but when the computer rebooted, it started a Microsoft update. I'll attach the fix log.txt soon
  11. Thanks Aura I ran it, and here is the fixlog.txt Mike Fixlog.txt
  12. It seems that if I try opening it in a separate tab, it does it and then that tab shuts right away. It seems its the virus? Perhaps you can copy and paste the TXT into a post and I cann then copy/paste into a txt? Is there a PM functionality in the site?
  13. How do I download 'fixlist.txt'. I tried double clicking to open, right clicking to save it etc. I dragged to the desktop and it is just a link to this web address. Is there some easy functionality within this forum?
  14. Hi Aura,. I can't find "driver updater" in the list of programs that is shown in the delete programs in control panel. What should I do?
  15. Hi Aura, Thank you for responding quickly and for helping me! I will try to get rid of "driver updater". I'll also run farbar again and attach the files.
  16. Hello, My computer is already infected. I am unable to run Malware bytes. It "cannot connect to the service". I ran the anti rootkit tool. I gave me the "DDA Driver was not installed error". I downloaded the FARBAR toolkit, executed it, and it has created the attached 'FRST.txt' and the 'addition.txt file'. Please note that FARBAR crashed , so the .TXT files may not be complete. Please help! Thanks, Mike FRST.txt Addition.txt
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.