IE - Chrome - FireFox Problems

You guys helped me a few years ago, I have problems again.  I have Dell 660:   Windows 7 Home Premium. 

1) FireFox / Chrome? = "Adobe Flash plugin has crashed." "Shockwave Flash may be busy." "Shockwave just crashed." System locks up and I go to Windows task manager to individually end task, and all web sites I'm on disappear. 

2) Chrome = "Aw Snap."  Same as above.

3) Internet Explorer = "...Stopped working."  It hangs up & stops working, also shuts down and restarts.  I've run Malwarebytes "Free" that I have on my PC, as well as AVG.  Neither shows anything wrong, but there is obviously something wrong. 

None of my scans show any malware, but something is wrong... 

Is there anything you could point me to and help me figure this out?  Thanks in advance... 

  Replies 51
  Created
  Last Reply

Top Posters In This Topic

Just letting you know that I moved your topic to the General Computer Help area of our Forums. Thanks for coming to the Malwarebytes Forums!!

While you are awaiting for assistance, try seeing if the issues go away in Safe Mode with Networking.

@ArizonaEagle, since there hasn't been anyone to come in and help you yet, I thought I would offer some guidance to help get the ball rolling. While I don't feel you are infected, many of the logs that are asked for in the Malware Removal for Windows area would help in getting a better idea of the state of your PC.

Can you by chance post a FRST.txt and Additions.txt file via the FARBAR Tool discussed here? https://forums.malwarebytes.org/topic/9573-im-infected-what-do-i-do-now/


Hi Alex,
I just logged on to check emails and have to be at an appointment in 40 minutes.
I'll do this later this after noon and I know it's a long holiday weekend, so I don't expect you to spend any time on this over the weekend.
I'm sure you have family where you'd rather spend time with.
I'll do as you suggest here, and I have 2 other questions. 
1) Since I have CC Cleaner, and haven't run it in several months, would that be an option - AFTER I POST what you want?
2) Is there something I can do daily or weekly to keep my computer "clean," such as CC Cleaner, or other daily or weekly tasks?

If there is a post on your web site, I'll follow that as well, to keep my computer clean.
Ooops..., last question:
Should I be concerned that I have - in my area - I have a strong wireless signal of something I don't feel should be there.
I have the usual Comcast and AT&T signals with varying degrees of strength, along with one that reads:
Security Type WPA2-PSX
Radio Type 802.11N
SSID (Same as number above)
From your experience, can this be a hacker in my neighborhood?? 
Just concerned because this is a relatively new signal on my "Open Network and Sharing Center."

Thank you!!!! 

Here is the results of FRST

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016
Ran by Arizona Eagle (administrator) on ARIZONAEAGLE-PC (02-09-2016 16:56:48)
Running from C:\Users\Arizona Eagle\Downloads
Loaded Profiles: Arizona Eagle (Available Profiles: Arizona Eagle)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Thanks for posting all of that info. My first suggestion here is to see if removing AVG changes any of the symptoms. I would also recommend removing and reinstalling the latest version of Java and Flash. Try that and let me know if the issue goes away.

As far as the SSID thing goes, I wouldn't worry about that. Looks like someone nearby likes to have a unique and secure SSID that you can't easily pinpoint who it belongs to. It's certainly not a sign of a hacker or anything of that nature.

Link to post
Share on other sites


By the way, AVG sold me an AVG PC Tune Up program.  I initially thought I was just upgrading their "Free" anti-virus.  I was wrong as it's a different program.  I also have Malwarebytes "Free" antivirus and want to upgrade that.  Can I "assume" I'm better off getting rid of everything but Malwarebytes?  I'll let you know later if the symptoms go away. 

Link to post
Share on other sites

18 minutes ago, ArizonaEagle said:


By the way, AVG sold me an AVG PC Tune Up program.  I initially thought I was just upgrading their "Free" anti-virus.  I was wrong as it's a different program.  I also have Malwarebytes "Free" antivirus and want to upgrade that.  Can I "assume" I'm better off getting rid of everything but Malwarebytes?  I'll let you know later if the symptoms go away. 

AVG has been interesting lately. That's for sure. The Tune Up program isn't really going to help keep your PC secure and it may or may not actually improve the performance of your PC.

As far as proper protection goes, it's good to have a multi-layered approach to help prevent malware from effecting you. So that means keeping your PC up to date (e.g. latest updates and drivers) in conjunction with having a good anti-malware solution, a good anti-exploit solution, a good anti-virus solution, and a solid data backup solution (local and in the cloud with versioning support).

Personally, we offer the best anti-malware and anti-exploit protection out their with our Malwarebytes Anti-Malware Premium and Malwarebytes Anti-Exploit Premium. We are also working on a new anti-ransomware product that will change the industry in my mind. If you want to know more, check out the FAQs in the Malwarebytes Anti-Malware and Malwarebytes Anti-Exploit sections of the forums.

Currently though, you need to bring along your own anti-virus solution as our products do not provide a traditional anti-virus engine. That could be something from Kaspersky, Bit Defender, Webroot, or even AVG. That choice is up to you.

Link to post
Share on other sites

Here ya' go...

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 31-08-2016
Ran by Arizona Eagle (administrator) on ARIZONAEAGLE-PC (06-09-2016 09:15:53)
Running from C:\Users\Arizona Eagle\Downloads
Loaded Profiles: Arizona Eagle (Available Profiles: Arizona Eagle)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
(SoftThinks SAS) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Atheros) C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVHSVC.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
() C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Toaster.exe
() C:\Program Files (x86)\Dell DataSafe Local Backup\Components\Scheduler\STService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(SoftThinks - Dell) C:\Program Files (x86)\Dell DataSafe Local Backup\Components\DSUpdate\DSUpd.exe
() C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\Framework\Common\avguix.exe
() C:\Program Files (x86)\Dell\Stage Remote\StageRemoteService.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe
(Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PrivacyIconClient.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\CVH.EXE
() Q:\140066.enu\Office14\WINWORDC.EXE
() C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
() Q:\140066.ENU\OFFICE14\OffSpon.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\taskmgr.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil64_22_0_0_210_ActiveX.exe
(Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_22_0_0_209.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_22_0_0_209.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Arizona Eagle\Downloads\FRST64(2).exe

==================== Registry (Whitelisted) ===========================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [Stage Remote] => C:\Program Files (x86)\Dell\Stage Remote\StageRemote.exe [2022976 2011-06-27] ()
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-28] (Adobe Systems Incorporated)
HKLM\...\Run: [DellStage] => C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe [2195824 2012-02-01] ()
HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [133400 2011-12-16] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation)
HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [Dell DataSafe Online] => C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-25] (Dell, Inc.)
HKLM-x32\...\Run: [NeroLauncher] => C:\Program Files (x86)\Nero\SyncUP\NeroLauncher.exe [66872 2011-12-31] ()
HKLM-x32\...\Run: [AccuWeatherWidget] => C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe [968048 2012-02-01] ()
HKLM-x32\...\Run: [AvgUi] => C:\Program Files (x86)\AVG\Framework\Common\avguirna.exe [204560 2016-08-18] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\Av\avgui.exe [6709008 2016-07-28] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-1018525127-3197894228-3462546734-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8455960 2015-08-19] (Piriform Ltd)
HKU\S-1-5-21-1018525127-3197894228-3462546734-1000\...\RunOnce: [Uninstall C:\Users\Arizona Eagle\AppData\Local\Microsoft\OneDrive\17.3.5849.0427\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Arizona Eagle\AppData\Local\Microsoft\OneDrive\17.3.5849.0427\amd64"
HKU\S-1-5-21-1018525127-3197894228-3462546734-1000\...\RunOnce: [Uninstall C:\Users\Arizona Eagle\AppData\Local\Microsoft\OneDrive\17.3.5849.0427] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Arizona Eagle\AppData\Local\Microsoft\OneDrive\17.3.5849.0427"
ShellIconOverlayIdentifiers: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Arizona Eagle\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Arizona Eagle\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Arizona Eagle\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\amd64\FileSyncShell64.dll [2015-08-25] (Microsoft Corporation)
ShellIconOverlayIdentifiers-x32: [ SkyDrive1] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\Arizona Eagle\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\FileSyncShell.dll No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive2] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\Arizona Eagle\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\FileSyncShell.dll No File
ShellIconOverlayIdentifiers-x32: [ SkyDrive3] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\Arizona Eagle\AppData\Local\Microsoft\OneDrive\17.3.5930.0814\FileSyncShell.dll No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

Tcpip\Parameters: [DhcpNameServer]
Tcpip\..\Interfaces\{978EA2B4-9D05-40C7-B460-6E329CF28234}: [DhcpNameServer]
Tcpip\..\Interfaces\{FDE6EDD0-0090-4794-8F0E-7EF701D9C6C7}: [DhcpNameServer]

Internet Explorer:
HKU\S-1-5-21-1018525127-3197894228-3462546734-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKU\S-1-5-21-1018525127-3197894228-3462546734-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/USCON/1
SearchScopes: HKLM -> DefaultScope {5989B38D-2131-4DB9-AA04-3ED82D99B3A3} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM -> {5989B38D-2131-4DB9-AA04-3ED82D99B3A3} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> DefaultScope {5989B38D-2131-4DB9-AA04-3ED82D99B3A3} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKLM-x32 -> {5989B38D-2131-4DB9-AA04-3ED82D99B3A3} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDR&src=IE-SearchBox
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\ssv.dll [2016-09-03] (Oracle Corporation)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2012-07-17] (Microsoft Corp.)
BHO-x32: Bing Bar Helper -> {d2ce3e00-f94a-4740-988e-03dc2f38c34f} -> C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-06-07] (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\jp2ssv.dll [2016-09-03] (Oracle Corporation)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll [2011-06-07] (Microsoft Corporation.)
Handler-x32: cozi - {5356518D-FE9C-4E08-9C1F-1E872ECD367F} - c:\Program Files (x86)\Cozi Express\CoziProtocolHandler.dll [2011-05-05] (Cozi Group, Inc.)

FF ProfilePath: C:\Users\Arizona Eagle\AppData\Roaming\Mozilla\Firefox\Profiles\07y94zzs.default
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_22_0_0_209.dll [2016-08-06] ()
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_22_0_0_209.dll [2016-08-06] ()
FF Plugin-x32: @java.com/DTPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\dtplugin\npDeployJava1.dll [2016-09-03] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.101.2 -> C:\Program Files (x86)\Java\jre1.8.0_101\bin\plugin2\npjp2.dll [2016-09-03] (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll [2016-07-28] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-06-30] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1018525127-3197894228-3462546734-1000: @citrixonline.com/appdetectorplugin -> C:\Users\Arizona Eagle\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-09-16] (Citrix Online)
FF Extension: (Yahoo! Toolbar) - C:\Users\Arizona Eagle\AppData\Roaming\Mozilla\Firefox\Profiles\07y94zzs.default\Extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1} [2015-08-26] [not signed]

CHR Profile: C:\Users\Arizona Eagle\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Slides) - C:\Users\Arizona Eagle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-11]
CHR Extension: (Google Docs) - C:\Users\Arizona Eagle\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-11]
CHR Extension: (Google Drive) - C:\Users\Arizona Eagle\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-10-30]
CHR Extension: (YouTube) - C:\Users\Arizona Eagle\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-03]
CHR Extension: (Google Search) - C:\Users\Arizona Eagle\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-10-30]
CHR Extension: (Google Sheets) - C:\Users\Arizona Eagle\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-11]
CHR Extension: (Google Docs Offline) - C:\Users\Arizona Eagle\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2016-03-23]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Arizona Eagle\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-04-12]
CHR Extension: (Gmail) - C:\Users\Arizona Eagle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-03-27]
CHR Extension: (Chrome Media Router) - C:\Users\Arizona Eagle\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2016-09-01]

==================== Services (Whitelisted) ========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

R2 avgsvc; C:\Program Files (x86)\AVG\Framework\Common\avgsvca.exe [1097488 2016-08-18] (AVG Technologies CZ, s.r.o.)
S2 avgwd; C:\Program Files (x86)\AVG\Av\avgwdsvca.exe [760024 2016-07-28] (AVG Technologies CZ, s.r.o.)
S2 DellDigitalDelivery; c:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [162816 2011-10-26] (Dell Products, LP.) [File not signed]
R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [4878096 2016-08-19] (AVG Technologies CZ, s.r.o.)
R2 UxTuneUp; C:\Windows\System32\uxtuneup.dll [56080 2016-08-19] (AVG Technologies CZ, s.r.o.)
R2 UxTuneUp; C:\Windows\SysWOW64\uxtuneup.dll [49424 2016-08-19] (AVG Technologies CZ, s.r.o.)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
R2 ZAtheros Wlan Agent; C:\Program Files (x86)\Dell Wireless\Ath_WlanAgent.exe [73728 2012-02-07] (Atheros) [File not signed]

===================== Drivers (Whitelisted) ==========================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [32304 2016-03-29] (AVG Netherlands B.V.)

==================== NetSvcs (Whitelisted) ===================

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

==================== One Month Created files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-06 09:15 - 2016-09-06 09:15 - 02397696 _____ (Farbar) C:\Users\Arizona Eagle\Downloads\FRST64(2).exe
2016-09-03 12:26 - 2016-09-03 12:26 - 00097856 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2016-09-03 12:26 - 2016-09-03 12:26 - 00000000 ____D C:\Users\Arizona Eagle\AppData\Roaming\Sun
2016-09-03 12:26 - 2016-09-03 12:26 - 00000000 ____D C:\Users\Arizona Eagle\AppData\LocalLow\Sun
2016-09-03 12:26 - 2016-09-03 12:26 - 00000000 ____D C:\Users\Arizona Eagle\.oracle_jre_usage
2016-09-03 12:26 - 2016-09-03 12:26 - 00000000 ____D C:\ProgramData\Oracle
2016-09-03 12:26 - 2016-09-03 12:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2016-09-03 12:26 - 2016-09-03 12:26 - 00000000 ____D C:\Program Files (x86)\Java
2016-09-02 16:58 - 2016-09-02 16:59 - 00033683 _____ C:\Users\Arizona Eagle\Downloads\Addition.txt
2016-09-02 16:56 - 2016-09-06 09:15 - 00018067 _____ C:\Users\Arizona Eagle\Downloads\FRST.txt
2016-09-02 16:56 - 2016-09-06 09:15 - 00000000 ____D C:\FRST
2016-09-02 16:49 - 2016-09-02 16:55 - 02397696 _____ (Farbar) C:\Users\Arizona Eagle\Downloads\FRST64(1).exe
2016-09-02 16:44 - 2016-09-02 16:45 - 02397696 _____ (Farbar) C:\Users\Arizona Eagle\Downloads\FRST64.exe
2016-09-01 13:11 - 2016-09-01 13:11 - 00057290 _____ C:\Windows\ntbtlog.txt
2016-09-01 13:07 - 2016-09-01 13:07 - 00014371 _____ C:\Users\Arizona Eagle\Downloads\Lay Mission - Small Group Roster.xlsx
2016-09-01 12:57 - 2016-09-01 12:57 - 02738911 _____ C:\Users\Arizona Eagle\Downloads\Lay Vocation - Course Reader - 2016_08_12 (1).pdf
2016-08-31 21:03 - 2016-08-31 21:03 - 02738911 _____ C:\Users\Arizona Eagle\Downloads\The Lay Vocation - Course Reader - 2016_08_12.pdf
2016-08-30 18:30 - 2016-08-30 18:30 - 00014359 _____ C:\Users\Arizona Eagle\Downloads\Small group roster.xlsx
2016-08-24 22:37 - 2016-08-26 13:41 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2016-08-24 19:49 - 2016-08-24 19:49 - 00000000 ____D C:\Users\Arizona Eagle\Documents\New folder
2016-08-23 09:22 - 2016-08-19 16:30 - 00056080 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\uxtuneup.dll
2016-08-23 09:22 - 2016-08-19 16:30 - 00049424 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\SysWOW64\uxtuneup.dll
2016-08-23 09:22 - 2016-08-19 16:30 - 00044304 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\authuitu.dll
2016-08-23 09:22 - 2016-08-19 16:30 - 00039696 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\SysWOW64\authuitu.dll
2016-08-20 12:40 - 2016-08-20 12:40 - 00005653 _____ C:\Users\Arizona Eagle\Documents\Envelope - Lay Mission Project.odt
2016-08-16 14:02 - 2016-07-08 08:32 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2016-08-16 14:02 - 2016-07-08 08:16 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2016-08-10 01:27 - 2016-08-02 07:54 - 00394440 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2016-08-10 01:27 - 2016-08-02 07:08 - 00346312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2016-08-10 01:27 - 2016-08-01 23:54 - 25808384 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2016-08-10 01:27 - 2016-08-01 23:47 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2016-08-10 01:27 - 2016-08-01 23:47 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2016-08-10 01:27 - 2016-08-01 23:32 - 02894336 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2016-08-10 01:27 - 2016-08-01 23:32 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2016-08-10 01:27 - 2016-08-01 23:31 - 00572416 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2016-08-10 01:27 - 2016-08-01 23:31 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2016-08-10 01:27 - 2016-08-01 23:31 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2016-08-10 01:27 - 2016-08-01 23:31 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2016-08-10 01:27 - 2016-08-01 23:24 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2016-08-10 01:27 - 2016-08-01 23:23 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2016-08-10 01:27 - 2016-08-01 23:20 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2016-08-10 01:27 - 2016-08-01 23:19 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2016-08-10 01:27 - 2016-08-01 23:19 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2016-08-10 01:27 - 2016-08-01 23:18 - 06047744 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2016-08-10 01:27 - 2016-08-01 23:18 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2016-08-10 01:27 - 2016-08-01 23:18 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2016-08-10 01:27 - 2016-08-01 23:11 - 00969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2016-08-10 01:27 - 2016-08-01 23:08 - 00489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2016-08-10 01:27 - 2016-08-01 23:03 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2016-08-10 01:27 - 2016-08-01 23:00 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2016-08-10 01:27 - 2016-08-01 22:59 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2016-08-10 01:27 - 2016-08-01 22:56 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2016-08-10 01:27 - 2016-08-01 22:55 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2016-08-10 01:27 - 2016-08-01 22:54 - 20343808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2016-08-10 01:27 - 2016-08-01 22:53 - 00315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2016-08-10 01:27 - 2016-08-01 22:51 - 00497664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2016-08-10 01:27 - 2016-08-01 22:51 - 00341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2016-08-10 01:27 - 2016-08-01 22:51 - 00152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2016-08-10 01:27 - 2016-08-01 22:51 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2016-08-10 01:27 - 2016-08-01 22:51 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2016-08-10 01:27 - 2016-08-01 22:50 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2016-08-10 01:27 - 2016-08-01 22:47 - 02286592 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2016-08-10 01:27 - 2016-08-01 22:45 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2016-08-10 01:27 - 2016-08-01 22:44 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2016-08-10 01:27 - 2016-08-01 22:42 - 00476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2016-08-10 01:27 - 2016-08-01 22:41 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2016-08-10 01:27 - 2016-08-01 22:41 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2016-08-10 01:27 - 2016-08-01 22:41 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2016-08-10 01:27 - 2016-08-01 22:40 - 00262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2016-08-10 01:27 - 2016-08-01 22:38 - 00806400 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2016-08-10 01:27 - 2016-08-01 22:38 - 00724992 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2016-08-10 01:27 - 2016-08-01 22:37 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2016-08-10 01:27 - 2016-08-01 22:36 - 02131456 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2016-08-10 01:27 - 2016-08-01 22:33 - 00416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2016-08-10 01:27 - 2016-08-01 22:29 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2016-08-10 01:27 - 2016-08-01 22:28 - 15412224 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2016-08-10 01:27 - 2016-08-01 22:28 - 00091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2016-08-10 01:27 - 2016-08-01 22:26 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2016-08-10 01:27 - 2016-08-01 22:25 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2016-08-10 01:27 - 2016-08-01 22:24 - 00279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2016-08-10 01:27 - 2016-08-01 22:23 - 02868224 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2016-08-10 01:27 - 2016-08-01 22:22 - 00130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2016-08-10 01:27 - 2016-08-01 22:21 - 04608000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2016-08-10 01:27 - 2016-08-01 22:16 - 00230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2016-08-10 01:27 - 2016-08-01 22:15 - 00692736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2016-08-10 01:27 - 2016-08-01 22:14 - 02055680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2016-08-10 01:27 - 2016-08-01 22:14 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2016-08-10 01:27 - 2016-08-01 22:11 - 13808128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2016-08-10 01:27 - 2016-08-01 22:10 - 01550848 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2016-08-10 01:27 - 2016-08-01 21:59 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2016-08-10 01:27 - 2016-08-01 21:56 - 02393088 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2016-08-10 01:27 - 2016-08-01 21:53 - 01316352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2016-08-10 01:27 - 2016-08-01 21:51 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2016-08-10 01:27 - 2016-07-08 08:37 - 00154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2016-08-10 01:27 - 2016-07-08 08:37 - 00095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2016-08-10 01:27 - 2016-07-08 08:32 - 01464320 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 01212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00730624 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00343552 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00316416 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2016-08-10 01:27 - 2016-07-08 08:32 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2016-08-10 01:27 - 2016-07-08 08:17 - 00666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2016-08-10 01:27 - 2016-07-08 08:17 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00260608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00251392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2016-08-10 01:27 - 2016-07-08 08:16 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2016-08-10 01:27 - 2016-07-08 08:03 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2016-08-10 01:27 - 2016-07-08 07:57 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2016-08-10 01:27 - 2016-07-08 07:56 - 00291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2016-08-10 01:27 - 2016-07-08 07:56 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2016-08-10 01:27 - 2016-07-08 07:55 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2016-08-10 01:27 - 2016-07-08 07:55 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2016-08-10 01:27 - 2016-07-08 07:50 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2016-08-10 01:26 - 2016-07-08 08:01 - 03218944 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2016-08-09 19:32 - 2016-08-09 19:32 - 00261467 _____ C:\Users\Arizona Eagle\Downloads\Enterprise - Employment Application.xml
2016-08-08 20:39 - 2016-08-08 20:40 - 09532228 _____ C:\Users\Arizona Eagle\Downloads\FALL SCRIPTURE POSTER (1).pptx
2016-08-08 20:39 - 2016-08-08 20:39 - 09532228 _____ C:\Users\Arizona Eagle\Downloads\FALL SCRIPTURE POSTER.pptx

==================== One Month Modified files and folders ========

(If an entry is included in the fixlist, the file/folder will be moved.)

2016-09-06 09:01 - 2016-07-28 14:56 - 00000898 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA1d1e91adabeeed1.job
2016-09-06 08:48 - 2009-07-13 21:45 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2016-09-06 08:48 - 2009-07-13 21:45 - 00028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2016-09-05 15:01 - 2016-07-28 14:56 - 00000894 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore1d1e91ada987a81.job
2016-09-05 14:02 - 2014-09-08 14:05 - 00000422 _____ C:\Windows\Tasks\SystemToolsDailyTest.job
2016-09-05 14:00 - 2014-09-09 12:00 - 00003488 _____ C:\Windows\System32\Tasks\PCDEventLauncher
2016-09-05 14:00 - 2014-09-08 14:05 - 00003478 _____ C:\Windows\System32\Tasks\SystemToolsDailyTest
2016-09-05 13:01 - 2012-06-01 09:48 - 00000000 ____D C:\Program Files (x86)\Dell DataSafe Local Backup
2016-09-03 12:26 - 2014-09-08 12:02 - 00000000 ____D C:\Users\Arizona Eagle
2016-09-03 12:22 - 2014-09-08 14:05 - 00000000 ____D C:\Users\Arizona Eagle\AppData\Local\Adobe
2016-09-03 12:22 - 2012-06-01 09:29 - 00796352 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2016-09-03 12:22 - 2012-06-01 09:29 - 00142528 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2016-09-03 12:19 - 2012-06-01 09:52 - 00000000 ____D C:\Users\Default\AppData\Local\SoftThinks
2016-09-03 12:19 - 2012-06-01 09:52 - 00000000 ____D C:\Users\Default User\AppData\Local\SoftThinks
2016-09-03 12:16 - 2009-07-13 22:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2016-09-02 18:52 - 2015-10-08 21:28 - 00000000 ____D C:\Users\Arizona Eagle\AppData\Local\Avg
2016-09-02 18:52 - 2015-10-08 21:28 - 00000000 ____D C:\ProgramData\MFAData
2016-09-02 18:51 - 2014-09-08 14:21 - 00000000 ____D C:\Users\Arizona Eagle\AppData\Roaming\SoftGrid Client
2016-09-01 17:38 - 2014-09-08 12:02 - 00059280 _____ C:\Users\Arizona Eagle\AppData\Local\GDIPFONTCACHEV1.DAT
2016-09-01 13:16 - 2015-08-07 13:58 - 00000000 ____D C:\Users\Arizona Eagle\AppData\Local\ElevatedDiagnostics
2016-08-26 13:41 - 2014-09-18 23:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2016-08-25 23:56 - 2009-07-13 20:20 - 00000000 ____D C:\Windows\rescache
2016-08-23 18:19 - 2014-09-08 14:05 - 00000564 _____ C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
2016-08-23 09:22 - 2016-04-23 21:14 - 00002554 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp.lnk
2016-08-23 09:22 - 2016-04-23 21:14 - 00002542 _____ C:\Users\Public\Desktop\AVG PC TuneUp.lnk
2016-08-23 09:22 - 2016-04-23 21:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC TuneUp
2016-08-21 18:00 - 2014-09-08 14:05 - 00004298 _____ C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask
2016-08-19 16:35 - 2016-04-23 21:14 - 00053008 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\TURegOpt.exe
2016-08-18 06:52 - 2016-02-24 19:20 - 00012140 _____ C:\Users\Arizona Eagle\Downloads\Budget 2016 Bob.xlsx
2016-08-10 03:21 - 2009-07-13 21:45 - 00265800 _____ C:\Windows\system32\FNTCACHE.DAT
2016-08-08 15:03 - 2014-09-08 14:15 - 00002197 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2016-08-08 15:02 - 2014-09-08 14:15 - 00002185 _____ C:\Users\Public\Desktop\Google Chrome.lnk

Some files in TEMP:
C:\Users\Arizona Eagle\AppData\Local\Temp\avguirn_081548299606.exe
C:\Users\Arizona Eagle\AppData\Local\Temp\avguirn_08156298752.exe
C:\Users\Arizona Eagle\AppData\Local\Temp\avguirn_081927633790.exe
C:\Users\Arizona Eagle\AppData\Local\Temp\avguirn_08479216649.exe
C:\Users\Arizona Eagle\AppData\Local\Temp\avguirn_08556981622.exe
C:\Users\Arizona Eagle\AppData\Local\Temp\avguirn_08638982554.exe

==================== Bamital & volsnap =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

LastRegBack: 2016-09-05 01:41

==================== End of FRST.txt ============================

 According to the logs AVG is still on here. Specifically the Tune Up software. Please remove that and let me know if that helps.

Also, do you need custom DNS and DHCP settings to access something?  Just asking in case that's the problem. 

Edited by AlexSmith
Link to post
Share on other sites

I don't want to sound like a dummy, but what is custom DNS and DHCP?  Meanwhile, I'll get rid of the AVG Tune Up software.  I wonder if AVG will give me a refund??  That's the thing I paid $39.99 for thinking I was buying their upgrade Anti-Virus.  :wacko: 

It may take several hours to know if it helps.  I know my PC was acting up prior to the purchase of the AVG Tune Up program.  I'll get back to you later today...

Link to post
Great question!! Your DNS Server settings are what Windows uses to find sites on the internet.  It translates the friendly website name to the actually ip address of the website server.  So it translates google.com to the actual ip address where google's servers actually reside. 

With that being said, the logs above show that DNS on your pc is set to a manual setting which may be the root problem here. You will want to set your network connection to automatically obtain the DNS Server settings. The following link has directions: http://www.thewindowsclub.com/how-to-change-dns-settings-in-windows-7-vista

Edited by AlexSmith
Auto correct hates me
I'm getting pretty fed up with the IE errors.  I post a lot on MLB.  I get part way through a post and IE decides to "stop working."  A box shows up stating that IE has stopped working, I can't post and when I click the box "X," - POOF..., my post disappears!!  It's just as bad as it was...  I reset the DNS back the way it was.  IE was worse... 

Link to post
Last night I ran Malwarebytes twice, just to see if anything was 'there.'  The first time I got 26 "PUP.Optional.MindSpark.Generic."  

The location is: C:\Users\ArizonaEagle\App...\07y94zzs.default\prefs.js     The second time I got 25 of these.  They are all identical.  I never got these before.  Also, I'm running without any anti-virus right now. 

Link to post
