Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Lost folder content from Desktop


  • This topic is locked This topic is locked
39 replies to this topic

#1 TJWIL

TJWIL

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:07:17 PM

Posted 02 March 2018 - 11:00 AM

Hi everyone, this is my first post so go gentle with me. As the title says virtually all folders that I had on the desktop for quick access have lost all their content. Some are photos, some are PDF's etc. I have managed to find some of them but many seem to be missing completely. I tried to do a restore from an earlier point but this hung up. After that happened I could not access office 365 even to uninstall it. I spent 4 hours on the phone with their help desk trying. I also could not open Chrome. The pc is also not recognising anything new plugged in to USB ports.

I now have 365 working again as well as Chrome but the files are still missing.

I have had a friendly IT guy looking at it , he has run Recuva and various other utilities and got it this far. I don't want to put too much on him if I can help it.

I have run a HJT scan and run an automatic interpretation of it and there are things on that, that say must be corrected immediately but that is beyond me I am afraid. Any thoughts? Sorry if I have done anything wrong I think I am even worse on forums than I am with computers

 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28.02.2018
Ran by Trevor (administrator) on TREVOR-PC (02-03-2018 15:53:18)
Running from C:\Users\Trevor\Downloads
Loaded Profiles: Trevor & Andy (Available Profiles: Trevor & Andy)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(AVAST Software) C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupSvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Piriform Ltd) C:\Program Files\Recuva\recuva64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\AppVShNotify.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Data Recorder\SDRService.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Network Threat Protection\bin\SntpService.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsAgent.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsClient.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos System Protection\ssp.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Microsoft Corporation) C:\Windows\System32\LogonUI.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMUPDT.EXE
(CANON INC.) C:\Program Files (x86)\Canon\Quick Menu\CNQMSWCS.EXE
(CANON INC.) C:\Program Files (x86)\Canon\My Image Garden\cnmigmain.exe
(Soeperman Enterprises Ltd.) C:\Users\Trevor\Old_Machine_Recovery\Trevor\My Documents\HijackThis.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587800 2017-12-19] (Oracle Corporation)
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1516096 2018-02-24] (Sophos Limited)
HKLM-x32\...\Run: [Dell DataSafe Online] => C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-26] (Dell, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-09-14] (Apple Inc.)
HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\RunOnce: [Uninstall C:\Users\Trevor\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Trevor\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"
HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
HKU\S-1-5-21-105084621-2470936660-356980580-1022\...\RunOnce: [Uninstall 17.3.6743.1212\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Andy\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64"
HKU\S-1-5-21-105084621-2470936660-356980580-1022\...\RunOnce: [Uninstall 17.3.6743.1212] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Andy\AppData\Local\Microsoft\OneDrive\17.3.6743.1212"
IFEO\backup_central10.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\creator12oem.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\discimageloader12oem.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\fsui.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\itunes.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\moviemaker.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\msnmsgr.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\retrieve12oem.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\roxio burn.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\roxiocentralfx.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\softwareupdate.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\stax.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\systemmechanic.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\uninstaler_skipuac.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\windowslivewriter.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\winzip64.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\wlmail.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\wlxphotogallery.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Avast Cleanup Premium.lnk [2018-02-02]
ShortcutTarget: Avast Cleanup Premium.lnk -> C:\Program Files (x86)\AVAST Software\Avast Cleanup\TuneupUI.exe (AVAST Software)
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-105084621-2470936660-356980580-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyServer: [S-1-5-21-105084621-2470936660-356980580-1001] => localhost:8080
Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{4203D66C-69BE-429D-AE78-2193EA9AA5EF}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{F9419E88-BAD8-4C2E-A8A2-461912EFF709}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{F9419E88-BAD8-4C2E-A8A2-461912EFF709}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-105084621-2470936660-356980580-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-105084621-2470936660-356980580-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bbc.co.uk/
SearchScopes: HKLM -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = 
SearchScopes: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit)
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-02-23] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-06-06] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2018-02-23] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2018-02-23] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-09-21] (Sun Microsystems, Inc.)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-02-23] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_162\bin\ssv.dll [2018-01-25] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-06-06] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2018-02-23] (Microsoft Corporation)
BHO-x32: No Name -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> No File
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_162\bin\jp2ssv.dll [2018-01-25] (Oracle Corporation)
BHO-x32: IObit Ads Removal -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll [2016-06-23] (IObit)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-06-06] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-06-06] (Google Inc.)
Toolbar: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-06-06] (Google Inc.)
Toolbar: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
DPF: HKLM-x32 {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect121.cab
DPF: HKLM-x32 {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} hxxps://secure.logmein.com/activex/RACtrl.cab
Handler: intu-help-qb2 - No CLSID Value
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-23] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-23] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-23] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-23] (Microsoft Corporation)
Filter: application/x-mfe-ipt - No CLSID Value
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28.02.2018
Ran by Trevor (02-03-2018 15:55:07)
Running from C:\Users\Trevor\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2011-11-30 16:47:28)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-105084621-2470936660-356980580-500 - Administrator - Disabled)
Andy (S-1-5-21-105084621-2470936660-356980580-1022 - Administrator - Enabled) => C:\Users\Andy
Guest (S-1-5-21-105084621-2470936660-356980580-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-105084621-2470936660-356980580-1002 - Limited - Enabled)
SophosSAUTREVOR-Paaa (S-1-5-21-105084621-2470936660-356980580-1023 - Limited - Enabled)
Trevor (S-1-5-21-105084621-2470936660-356980580-1001 - Administrator - Enabled) => C:\Users\Trevor
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Sophos Home (Enabled - Up to date) {FFADE7EA-DC92-4602-D6B2-626CD3450A0F}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Sophos Home (Enabled - Up to date) {44CC060E-FAA8-498C-EC02-591EA8C240B2}
AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 28.0.0.127 - Adobe Systems Incorporated)
Adobe Flash Player 28 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 28.0.0.161 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.161 - Adobe Systems Incorporated)
Advanced SystemCare 11 (HKLM-x32\...\Advanced SystemCare_is1) (Version: 11.0.3 - IObit)
Aid4Mail MBOX Converter (Remove only) (HKLM-x32\...\Aid4Mail MBOX Converter_is1) (Version: 1.0.0.0 - Fookes Holding Ltd)
Apple Application Support (32-bit) (HKLM-x32\...\{F1D83CEA-2855-4224-9935-D981785AA75D}) (Version: 6.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{E2A6344A-45BF-47A0-9AE1-848325E7FD88}) (Version: 6.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BD6778C5-6FA5-492A-ADD6-E706339C2A7B}) (Version: 11.0.2.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.)
Avast Cleanup Premium (HKLM-x32\...\{075CC190-59EE-499F-828B-0B5C098C8C15}_is1) (Version: 17.3.4040 - AVAST Software)
Bitser (HKLM-x32\...\{9BD25977-657C-421E-8E1B-71773690BE64}) (Version: 1.4.0 - Bitser)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.5.0.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version:  - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: 4.0.0 - Canon Inc.)
Canon MX720 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX720_series) (Version: 1.00 - Canon Inc.)
Canon MX720 series On-screen Manual (HKLM-x32\...\Canon MX720 series On-screen Manual) (Version: 7.6.0 - Canon Inc.)
Canon MX720 series User Registration (HKLM-x32\...\Canon MX720 series User Registration) (Version:  - ‭Canon Inc.)
Canon MX920 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX920_series) (Version: 1.00 - Canon Inc.)
Canon MX920 series On-screen Manual (HKLM-x32\...\Canon MX920 series On-screen Manual) (Version: 7.6.0 - Canon Inc.)
Canon MX920 series User Registration (HKLM-x32\...\Canon MX920 series User Registration) (Version:  - ‭Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 1.1.2 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 1.0.1 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.1.0 - Canon Inc.)
Canon Speed Dial Utility (HKLM-x32\...\Speed Dial Utility) (Version: 1.3.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.40 - Piriform)
Clone My DVD (HKLM-x32\...\{F27B8353-1F12-4814-B9F2-82A87C438315}) (Version: 1.7.1 - Streamware Development)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.50.4.0 - Conexant)
CyberLink PowerDVD 9.5 (HKLM-x32\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.5.1.4418 - CyberLink Corp.)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Dell DataSafe Online (HKLM-x32\...\{7EC66A95-AC2D-4127-940B-0445A526AB2F}) (Version: 2.1.19634 - Dell)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell MusicStage (HKLM-x32\...\{91AF2672-F5BC-42CF-8037-A9D2F92BBCC0}) (Version: 1.5.201.0 - Fingertapps)
Dell PhotoStage (HKLM-x32\...\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.65 - ArcSoft)
Dell Stage (HKLM-x32\...\{39901B4C-E954-4471-ADAB-E786AEE326D1}) (Version: 1.5.420.0 - Fingertapps)
Dell System Detect - 1  (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\73f463568823ebbe) (Version: 6.0.0.14 - Dell)
Dell System Detect (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\9204f5692a8faf3b) (Version: 5.8.1.1 - Dell)
Dell VideoStage  (HKLM-x32\...\{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.) Hidden
Dell VideoStage  (HKLM-x32\...\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.)
DirectX 9 Runtime (HKLM-x32\...\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}) (Version: 1.00.0000 - Sonic Solutions) Hidden
Driving Recorder Player (HKLM-x32\...\{4B214065-5C62-4ECA-B99F-D31924006F31}) (Version: 1.0.4989.27635 - Archlink Technology Corporation)
Driving Test Success 2003-2004 (HKLM-x32\...\{27A4C502-AAD6-402F-8A36-63ECB26B67D6}) (Version: 7.01.0001 - Focus Multimedia Ltd)
Dropbox (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
Duplicate Email Remover (HKLM-x32\...\{7AA36634-4324-4EF4-8C0C-D8EF1FC2BEA4}) (Version: 3.1.0 - MAPILab Ltd.)
Easy Duplicate Finder 4 (HKLM\...\{DA060B99-6B87-4D85-8B1A-29BCF6DF2B06}_is1) (Version:  - WebMinds, Inc.)
Express Zip File Compression (HKLM-x32\...\ExpressZip) (Version: 3.03 - NCH Software)
Extended Asian Language font pack for Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated)
FastStone Image Viewer 4.6 (HKLM-x32\...\FastStone Image Viewer) (Version: 4.6 - FastStone Soft)
Free Opener (HKLM\...\{A1F2C608-32D6-467D-B035-BBEF509042BA}_is1) (Version: 1.0 - EZ Freeware)
Freemake Video Converter version 3.2.1 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 3.2.1 - Ellora Assets Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 64.0.3282.186 - Google Inc.)
Google Earth Pro (HKLM-x32\...\{FA1BBF34-E994-4310-95D7-BE93092B8E61}) (Version: 7.3.1.4507 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
GWX Control Panel (HKLM-x32\...\UltimateOutsider_GwxControlPanel) (Version:  - UltimateOutsider)
Hazard Perception Training 2003-2004 (HKLM-x32\...\{6112DD9A-2A3B-4487-8271-ADBA4A390287}) (Version: 3.02.00.00 - Focus Multimedia Ltd)
HP450 (HKLM-x32\...\ST6UNST #1) (Version:  - )
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
iCloud (HKLM\...\{EAFB2AD8-D92B-464C-8D97-B9CB94703C4A}) (Version: 3.0.2.163 - Apple Inc.)
InstallConverter bundle uninstaller (HKLM-x32\...\InstallConverter bundle uninstaller) (Version: 2.0.0.5 - InstallConverter)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)
Internet Explorer (Enable DEP) (HKLM\...\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb) (Version:  - )
IObit Uninstaller (HKLM-x32\...\IObitUninstall) (Version: 6.1.0.510 - IObit)
iTunes (HKLM\...\{C9355099-E68D-4802-ABB2-03757A1AB4BD}) (Version: 12.7.2.58 - Apple Inc.)
Java 8 Update 151 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180151F0}) (Version: 8.0.1510.12 - Oracle Corporation)
Java 8 Update 162 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180162F0}) (Version: 8.0.1620.12 - Oracle Corporation)
Junk Mail filter update (HKLM-x32\...\{F6F30C28-38AA-4DBA-AE0B-7E30238E61BB}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
K-Lite Codec Pack 7.0.0 (Standard) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 7.0.0 - )
Kodi (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\Kodi) (Version:  - XBMC-Foundation)
LogMeIn (HKLM-x32\...\{976475B8-63E9-4559-BE2C-D26086BE4C40}) (Version: 4.1.2126 - LogMeIn, Inc.)
Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.8431.2215 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-0081-0409-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\OneDriveSetup.exe) (Version: 17.005.0107.0008 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-105084621-2470936660-356980580-1022\...\OneDriveSetup.exe) (Version: 17.3.7294.0108 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Support and Recovery Assistant for Office 365 (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\dacae1bed46e81d5) (Version: 16.0.2146.9 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.10.25017 (HKLM-x32\...\{d6f233bd-3f8c-43f6-878b-07bd0568d595}) (Version: 14.10.25017.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25017 (HKLM-x32\...\{cb7c3049-21de-415b-bd85-b65c14e547df}) (Version: 14.10.25017.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.0 (HKLM-x32\...\{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}) (Version: 3.0.11010.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
MiVue Manager (HKLM-x32\...\{123BDDDC-D02F-4C6E-A011-9CB265E2483E}) (Version: 1.0.30.4 - Mio Technology Corporation)
Movie Maker (HKLM-x32\...\{3C5F91EF-5C0B-4D13-BCBE-0FC6FC3ED7F9}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{45898170-E68C-4F02-AA35-C2186BF347A3}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{B39A6825-EA20-43EA-AB2D-A6BC0298D9A1}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 56.0 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 56.0 (x86 en-GB)) (Version: 56.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 49.0.2 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8431.2215 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2215 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2215 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden
Open Contacts v6 (HKLM-x32\...\{A592374A-82CB-4BB3-A7CB-58D8FABA031F}_is1) (Version: 6 - Fonlow IT)
OutlookTools 2 (HKLM-x32\...\{E69BB189-4B20-46AE-93CF-59099F05FC3F}) (Version: 2.3.0 - HowTo-Outlook)
PDF Creator (HKLM\...\PDF Creator) (Version:  - )
PhotoShowExpress (HKLM-x32\...\{3250260C-7A95-4632-893B-89657EB5545B}) (Version: 2.0.063 - Sonic Solutions) Hidden
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
Plusnet Assist (HKLM-x32\...\Plusnet Assist) (Version:  - )
QuickBooks (HKLM-x32\...\{1D972553-29C8-442F-97F1-136B7F15E7E6}) (Version: 19.0.4004.1100 - Intuit Limited) Hidden
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Rapport (HKLM-x32\...\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}) (Version: 3.5.1908.137 - Trusteer) Hidden
RBVirtualFolder64Inst (HKLM\...\{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}) (Version: 1.00.0000 - Roxio, Inc.) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31233 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio)
Roxio File Backup (HKLM\...\{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}) (Version: 1.3.2 - Roxio) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Shockwave (HKLM-x32\...\Shockwave) (Version:  - )
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.151 - Skype Technologies S.A.)
SmoothDraw version 4.0.5 (HKLM-x32\...\SmoothDraw_is1) (Version: 4.0.5 - )
Sonic CinePlayer Decoder Pack (HKLM-x32\...\{9A00EC4E-27E1-42C4-98DD-662F32AC8870}) (Version: 4.3.0 - Sonic Solutions) Hidden
Sophos Anti-Virus (HKLM-x32\...\{2519A41E-5D7C-429B-B2DB-1E943927CB3D}) (Version: 10.7.6.117 - Sophos Limited) Hidden
Sophos AutoUpdate (HKLM-x32\...\{AFBCA1B9-496C-4AE6-98AE-3EA1CFF65C54}) (Version: 5.8.335 - Sophos Limited) Hidden
Sophos Diagnostic Utility (HKLM-x32\...\{4627F5A1-E85A-4394-9DB3-875DF83AF6C2}) (Version: 1.20.0.4 - Sophos Limited) Hidden
Sophos Home (HKLM\...\Sophos Endpoint Agent) (Version: 1.2.11 - Sophos Ltd)
Sophos Home (HKLM-x32\...\{65174B13-CB1D-45A8-8B65-69F87AAAAFEB}) (Version: 2.1.137 - Sophos Limited) Hidden
Sophos Management Communications System (HKLM-x32\...\{2C14E1A2-C4EB-466E-8374-81286D723D3A}) (Version: 4.7.15 - Sophos Limited) Hidden
Sophos Network Threat Protection (HKLM\...\{66967E5F-43E8-4402-87A4-04685EE5C2CB}) (Version: 1.3.2.40 - Sophos Limited) Hidden
Sophos System Protection (HKLM\...\{934BEF80-B9D1-4A86-8B42-D8A6716A8D27}) (Version: 2.6.0.71 - Sophos Limited) Hidden
Sperry Software - Add Email Address (HKLM-x32\...\{D6479B35-26C4-42C1-B5AE-344CF6B53E0F}) (Version: 6.0 - Sperry Software)
Sperry Software - Duplicate Email Eliminator (HKLM-x32\...\{6FB099B2-8981-484A-8161-FF64880B5386}) (Version: 6.0 - Sperry Software)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1142 - SUPERAntiSpyware.com)
System Mechanic (HKLM-x32\...\{DD0DFA41-5139-45D0-986C-3C1A5C648CAA}) (Version: 16.5.3.1 - iolo technologies, LLC) Hidden
System Mechanic (HKLM-x32\...\InstallShield_{DD0DFA41-5139-45D0-986C-3C1A5C648CAA}) (Version: 16.5.3.1 - iolo technologies, LLC)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.0.6447 - TeamViewer)
TreeSize Free V4.1.2 (HKLM-x32\...\TreeSize Free_is1) (Version: 4.1.2 - JAM Software)
Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1908.137 - Trusteer)
VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 5.03 - NCH Software)
VSDC Free Video Editor version 3.3.0.394 (HKLM-x32\...\VSDC Free Video Editor_is1) (Version: 3.3.0.394 - Flash-Integro LLC)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Mail Recovery v.3.4.0 (HKLM\...\Windows Mail Recovery_is1) (Version:  - Email Adept, Ltd.)
WinZip 22.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C24119}) (Version: 22.0.12706 - Corel Corporation)
YouTube2DVD Burner v1.17.0.92 (HKLM-x32\...\{1ADE23D7-7A1E-4AEC-BA5D-EB8A21B1D943}) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-105084621-2470936660-356980580-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-105084621-2470936660-356980580-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-105084621-2470936660-356980580-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-105084621-2470936660-356980580-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-105084621-2470936660-356980580-1022_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\Andy\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileCoAuthLib64.dll => No File
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll [2017-09-26] (IObit)
ContextMenuHandlers1: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2017-06-30] ()
ContextMenuHandlers1: [Incinerator] -> {E8215BEA-3290-4C73-964B-75502B9B41B2} => C:\Program Files (x86)\System Mechanic\Incinerator.dll [2017-05-03] (iolo technologies, LLC)
ContextMenuHandlers1: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2016-05-23] (IObit)
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2013-09-15] (Apple Inc.)
ContextMenuHandlers1: [Roxio Burn] -> {E8CB9D53-A47A-42B5-9F5B-96B037C9DD4C} => C:\Program Files\Roxio\Roxio Burn\RB_ContextMenu64.dll [2010-11-11] (TODO: <Company name>)
ContextMenuHandlers1: [SophosHomeShellExt] -> {2FE0F6D6-426A-4728-B435-7CF2FE926449} => C:\Program Files (x86)\Sophos\Sophos Home\SophosHomeShellExtX64.dll [2018-01-04] (Sophos Limited)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers2: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll [2017-09-26] (IObit)
ContextMenuHandlers2: [SophosHomeShellExt] -> {2FE0F6D6-426A-4728-B435-7CF2FE926449} => C:\Program Files (x86)\Sophos\Sophos Home\SophosHomeShellExtX64.dll [2018-01-04] (Sophos Limited)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers4: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll [2017-09-26] (IObit)
ContextMenuHandlers4: [Incinerator] -> {E8215BEA-3290-4C73-964B-75502B9B41B2} => C:\Program Files (x86)\System Mechanic\Incinerator.dll [2017-05-03] (iolo technologies, LLC)
ContextMenuHandlers4: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2016-05-23] (IObit)
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers4: [SophosHomeShellExt] -> {2FE0F6D6-426A-4728-B435-7CF2FE926449} => C:\Program Files (x86)\Sophos\Sophos Home\SophosHomeShellExtX64.dll [2018-01-04] (Sophos Limited)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2015-06-01] (Intel Corporation)
ContextMenuHandlers6: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2017-06-30] ()
ContextMenuHandlers6: [IObitUnstaler] -> {B19ED566-D419-470b-B111-3C89040BC027} => C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallMenuRight.dll [2016-05-23] (IObit)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers6: [SophosHomeShellExt] -> {2FE0F6D6-426A-4728-B435-7CF2FE926449} => C:\Program Files (x86)\Sophos\Sophos Home\SophosHomeShellExtX64.dll [2018-01-04] (Sophos Limited)
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers1_S-1-5-21-105084621-2470936660-356980580-1001: [DropboxExt] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ContextMenuHandlers4_S-1-5-21-105084621-2470936660-356980580-1001: [DropboxExt] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ContextMenuHandlers5_S-1-5-21-105084621-2470936660-356980580-1001: [DropboxExt] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {01DEB208-5CB9-49CA-B9D4-2A66A30C21FE} - System32\Tasks\GoogleUpdateTaskMachineUA1d1aafe43a2359 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {02F1B9BA-B20C-4DFA-B682-BAF9AAE76D3C} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-02-07] (Piriform Ltd)
Task: {07195826-345C-4077-A132-AC65EF3FA597} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\5.2.0\Scheduler.exe
Task: {107DB48A-6A1A-43B9-A24C-D48DBBDA32E9} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {14BD9C5A-933E-452C-B2B8-BF4864F52004} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {16D79557-BF69-4E3A-BD2D-A456DBBFD293} - System32\Tasks\Uninstaller_SkipUac_Trevor => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-12-15] (IObit)
Task: {1E9C785D-F51A-4A7E-954F-97842CA733B1} - System32\Tasks\Avast TUNEUP Update => C:\Program Files (x86)\AVAST Software\Avast Cleanup\TUNEUpdate.exe [2018-02-02] (AVAST Software)
Task: {250BB11B-8B43-41D1-8869-786B7597FCE0} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-02-23] ()
Task: {26EBAD3E-22D4-4944-B017-86F68A0348B8} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe
Task: {2A98589C-4F61-425F-A105-80AAA4E85373} - System32\Tasks\JetCleanLoginCheckUpdate => C:\remote-service\jetclean\AutoUpdate.exe
Task: {2B269237-692F-4B67-A8FF-16A5C940BDDC} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {2CC4800F-E299-4B71-8837-659624A2CD47} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {2EAFD7A2-8207-48EF-8E05-6C069F9B01C3} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-02-23] (Microsoft Corporation)
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {34D88B88-DA37-4A08-9945-4E7BCA6E144C} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-02-23] ()
Task: {376C045B-D53B-40AC-BEB0-5FF70D02A8A5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {3DDEDC3A-B8DB-4E09-BDF1-4C2AE7F7F850} - System32\Tasks\{E9A8F2EA-E2E2-41FE-A089-80BCAE05F6BB} => C:\Windows\system32\pcalua.exe -a C:\Users\Trevor\Downloads\QuickBooksUK2010.exe -d C:\Users\Trevor\Desktop
Task: {48ECA183-57BA-4381-B8BC-F005B6F21338} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {5D7F99F3-A6A8-4B5D-9E6D-420343E0BC3D} - System32\Tasks\avastBCLRestartS-1-5-21-105084621-2470936660-356980580-1001 => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 
Task: {6086F0E6-C458-45B4-8933-92DE7CC3D4DA} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {63027AB7-85C0-478A-9D28-1DD6CC60BAE4} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-02-02] (Microsoft Corporation)
Task: {664E79EA-72A5-4BC1-ACB5-BCAB03D9A5B6} - System32\Tasks\Adobe online update program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {66A24790-9833-4727-B68B-24CADCFDF263} - System32\Tasks\WinZip Update Notifier => C:\Program Files\WinZip\WZUpdateNotifier.exe [2017-12-11] (WinZip)
Task: {7E266534-DF67-485C-BE13-A1E9DCE43DBE} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {7EE846D8-F3B6-4876-A71A-7A07D962E376} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {8A5F5366-E019-4D21-8D6A-60588126935C} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-02-23] (Microsoft Corporation)
Task: {8CA883E8-C31C-4281-A69E-BA7B2B99E43E} - System32\Tasks\ioloToaster => C:\Program Files (x86)\System Mechanic\ioloToaster.exe [2017-05-03] (iolo technologies, LLC)
Task: {8EBF0C94-411C-42A5-9948-8BBF95E570E8} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {8F7AA920-DCFC-470D-8E25-879AE28D4E99} - System32\Tasks\{1B447821-D9F5-415E-9BA3-336A32609963} => C:\Windows\system32\pcalua.exe -a "C:\Users\Trevor\Documents\duplicate_remover\Setup for Outlook 64-bit.exe" -d C:\Users\Trevor\Documents\duplicate_remover
Task: {9E9CC566-77ED-47C1-8416-365D9F26D56C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
Task: {AD652280-90A8-4DDC-809C-903DBC10FB68} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-02-23] (Microsoft Corporation)
Task: {B143D09F-6A96-4054-9409-0CD7D4F9E393} - System32\Tasks\ioloSmartUpdater => C:\Program Files (x86)\System Mechanic\ioloSmartUpdater.exe [2017-05-03] (iolo technologies, LLC)
Task: {BA4A92EB-FA00-41F6-8FF3-53B7EC34231B} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {C03EE229-DBC0-4642-85EA-02B8EA51E545} - System32\Tasks\{C981FBF5-AB04-4D95-A17E-54B7AA811FBA} => C:\Windows\system32\pcalua.exe -a "C:\Users\Trevor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F1PTW9UR\wlsetup-web.exe" -d C:\Users\Trevor\Desktop
Task: {C042916E-9061-4C47-A0B6-F421DE4B02D3} - System32\Tasks\Driver Booster SkipUAC (Trevor) => C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DriverBooster.exe
Task: {C57364C9-7241-495D-9FA2-1390EEFF7449} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
Task: {CF847419-9B89-4568-8EAF-70E779B9EC70} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-02-07] (Piriform Ltd)
Task: {DBCFE875-5657-486C-BFE8-931172755FD8} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-07-24] (Apple Inc.)
Task: {E9E02B38-FBF3-4BBA-9FD4-B39D2D2CCF99} - System32\Tasks\GoogleUpdateTaskMachineCore1d1aafe35676c3 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {F7A743ED-F02E-4799-940F-EECCBF1DC642} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-12-15] (IObit)
Task: {F7C1F809-3178-4E3D-B2BB-AA36F9C25206} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {F9BB9D61-0BC7-422D-A779-57FFA796FA6A} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-02-02] (Microsoft Corporation)
Task: {F9F71D54-5180-4DB0-8129-3293224B2AC0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-02-21] (Adobe Systems Incorporated)
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
Shortcut: C:\Users\Trevor\Old_Machine_Recovery\Trevor\NetHood\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.co
Shortcut: C:\Users\Trevor\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
 
==================== Loaded Modules (Whitelisted) ==============
 
2012-04-21 17:44 - 2011-10-04 21:43 - 000087552 _____ () C:\Windows\System32\custmon64i.dll
2018-02-23 15:53 - 2018-02-23 15:53 - 008929480 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2017-01-26 17:23 - 2017-01-26 17:23 - 000234336 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\http.plg
2017-01-26 17:23 - 2017-01-26 17:23 - 000141424 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\ip.plg
2017-01-26 17:23 - 2017-01-26 17:23 - 000120072 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\ipv6.plg
2017-01-26 17:23 - 2017-01-26 17:23 - 000077432 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\portmap.plg
2017-01-26 17:23 - 2017-01-26 17:23 - 000165728 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\tcp.plg
2017-01-26 17:23 - 2017-01-26 17:23 - 000149168 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\udp.plg
2017-06-30 16:26 - 2017-06-30 16:26 - 000105984 _____ () C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll
2018-02-23 12:32 - 2018-02-22 03:57 - 004433752 _____ () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.186\libglesv2.dll
2018-02-23 12:32 - 2018-02-22 03:57 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.186\libegl.dll
2018-02-23 15:58 - 2018-02-23 15:58 - 000094920 _____ () C:\Program Files (x86)\Microsoft Office\Root\Office16\officevoicemanager.dll
2018-02-23 15:49 - 2018-02-23 15:52 - 001754296 _____ () C:\Program Files (x86)\Microsoft Office\Root\Office16\tmpod.dll
2018-02-23 15:48 - 2018-02-23 15:48 - 001009832 _____ () C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
2018-02-23 15:58 - 2018-02-23 16:04 - 000537768 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\msfad.dll
2018-02-22 16:57 - 2018-02-22 16:57 - 024028656 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.dll
2018-02-11 22:53 - 2018-02-11 22:53 - 000392688 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\sqlite.dll
2017-07-31 22:31 - 2017-07-31 22:31 - 072940016 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\libcef.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [240]
AlternateDataStreams: C:\ProgramData\Temp:C23D5E4F [126]
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LMIRescue_ca296989-8fdc-826d-7ef3-8b1ae0d0b596 => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SAVService => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SntpService => ""="service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\dell.com -> dell.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\100sexlinks.com -> 100sexlinks.com
 
There are 5977 more sites.
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 02:34 - 2016-04-26 18:15 - 000000834 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-105084621-2470936660-356980580-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Trevor\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
HKU\S-1-5-21-105084621-2470936660-356980580-1022\Control Panel\Desktop\\Wallpaper -> C:\Users\Andy\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: avast! Firewall => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: IEEtwCollectorService => 3
MSCONFIG\Services: IJPLMSVC => 2
MSCONFIG\Services: IObitUnSvr => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: NOBU => 3
MSCONFIG\Services: RapportMgmtService => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk => C:\Windows\pss\QuickBooks Update Agent.lnk.CommonStartup
MSCONFIG\startupreg: AccuWeatherWidget => "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: btbb_McciTrayApp => "C:\Program Files\Plusnet Assist\btbb\PlusnetHelpNotifier.exe"
MSCONFIG\startupreg: CanonQuickMenu => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: Dell DataSafe Online => C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
MSCONFIG\startupreg: DellStage => "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup
MSCONFIG\startupreg: GoogleChromeAutoLaunch_06C6E514C4997929D7F8BD1032E95A69 => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
MSCONFIG\startupreg: GwxControlPanelMonitor => "C:\Program Files (x86)\UltimateOutsider\GWX Control Panel\GWX_control_panel.exe" /traymode                                                                                                                                                                              
MSCONFIG\startupreg: HP Officejet 6500 E710n-z (NET) => "c:\program files\hp\hp officejet 6500 e710n-z\bin\scantopcactivationapp.exe" -deviceid "cn18u3319z05jw:nw" -scfn "hp officejet 6500 e710n-z (net)" -autostart 1
MSCONFIG\startupreg: HP Software Update => c:\program files (x86)\hp\hp software update\hpwuschd2.exe
MSCONFIG\startupreg: Intuit SyncManager => c:\program files (x86)\common files\intuit\sync\intuitsyncmanager.exe  startup
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"                                                                                                                                                                                                                               
MSCONFIG\startupreg: LogMeIn GUI => "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RoxWatchTray => c:\program files (x86)\common files\roxio shared\oem\12.0\sharedcom\roxwatchtray12oem.exe
MSCONFIG\startupreg: SDTray => c:\program files (x86)\spybot - search & destroy 2\sdtray.exe
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun                                                                                                                                                                                                                    
MSCONFIG\startupreg: WinZip FAH => C:\Program Files\WinZip\FAHConsole.exe
MSCONFIG\startupreg: WinZip PreLoader => C:\Program Files\WinZip\WzPreloader.exe
MSCONFIG\startupreg: WinZip UN => C:\Program Files\WinZip\WZUpdateNotifier.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TelnetServer-Tlntadmn-RPC-In] => (Allow) %systemroot%\system32\tlntsvr.exe
FirewallRules: [TelnetServer-TlntSvr-TCP-In] => (Allow) %systemroot%\system32\tlntsvr.exe
FirewallRules: [{6AE8F0CA-5BC2-4F13-8FF5-1ADF7E745E31}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{D531A0D4-2184-4495-9C26-63315741FE12}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{9A5E0ED7-56AD-433D-9987-592987684F4C}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{6EF24EE9-DC0A-4595-A543-29AB9B87A1E9}] => (Block) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{A860E787-3653-4AFC-B0AB-2B32BCFE9D82}] => (Block) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{2540CF43-7440-474C-A83E-01F8B5107105}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{46026796-B4DC-45F1-B8E7-677968123C36}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2592959C-45E4-4390-8273-002F5FD0AC67}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{204822D7-38A5-4C20-897E-CF8B2C7F39B8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82083090-F011-4FB6-BE72-114D72921FBE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{9322FF4A-57B5-4B32-9115-18EEAD2E9203}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{7FCD6717-FD5B-43D9-994A-442A7DE04354}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe
FirewallRules: [{EAF68E5E-D65F-4A43-B8AD-AA5497D119CE}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe
FirewallRules: [{75C880C0-7692-432E-B894-66CB74C8C42C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{0DD60364-D127-4A98-B006-E57B72782427}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DriverBooster.exe
FirewallRules: [{C4D44CE0-83EB-46D4-B5A5-9842A82322BE}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DriverBooster.exe
FirewallRules: [{ED45108F-F5C5-4A7D-86D0-BFA4AE64F9F4}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DBDownloader.exe
FirewallRules: [{14DBAD59-DFA5-4695-B3E5-15FB2FAB16C1}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DBDownloader.exe
FirewallRules: [{EF1C3F6C-8D81-4890-A1D5-7952DA9EBB9D}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\AutoUpdate.exe
FirewallRules: [{6C118A70-EF67-44B2-A29A-1E61B5BEBDE8}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\AutoUpdate.exe
FirewallRules: [{C0C73CDD-F389-4AE6-ADCF-41342C9F92F1}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
FirewallRules: [{9510879D-2FB7-4F04-8364-3E237AC8DB5E}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{C07B845D-9A18-4CE4-AA29-091E6F1C106D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{E0989950-B885-4538-A3EC-0671C8ED7216}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{AF1017F7-3F02-40FB-B4F8-D0A0E1275E0A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{8D0174F1-0BD2-4692-97D0-915EC3DB3433}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{403CE75E-BF75-48DC-AAB4-A6E9FD6A2D2F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{8B4499F8-6E79-4699-9843-496D6F4F0ED3}C:\program files (x86)\teamviewer\teamviewer.exe] => (Block) C:\program files (x86)\teamviewer\teamviewer.exe
FirewallRules: [UDP Query User{3216B674-8744-43E9-A2B8-D87E2E717D11}C:\program files (x86)\teamviewer\teamviewer.exe] => (Block) C:\program files (x86)\teamviewer\teamviewer.exe
FirewallRules: [{7591DB91-F95A-4AFC-BDB2-0CEC1A5D936B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{48AC1BEB-B25B-4F76-BF94-FD7BB22A5B6B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{9051E6F9-2521-49E1-A05B-3005EA863935}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{A848A89E-A7D4-41A3-B771-0A1CC07EBDDF}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
 
==================== Restore Points =========================
 
23-02-2018 11:27:31 Removed Microsoft Office Professional Plus 2010
27-02-2018 03:25:09 Windows Update
 
==================== Faulty Device Manager Devices =============
 
Name: Officejet 6500 E710n-z
Description: Officejet 6500 E710n-z
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service: 
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/02/2018 03:48:20 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/02/2018 03:48:20 PM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/01/2018 11:23:37 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/01/2018 11:23:37 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/01/2018 03:13:32 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CompatTelRunner.exe, version: 10.0.17060.1019, time stamp: 0x0206ae46
Faulting module name: ntdll.dll, version: 6.1.7601.24024, time stamp: 0x5a58e571
Exception code: 0xc0000374
Fault offset: 0x00000000000bf6b2
Faulting process id: 0x2904
Faulting application start time: 0x01d3b10aa41cd61d
Faulting application path: C:\Windows\system32\CompatTelRunner.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 84cfb31d-1cfe-11e8-a8df-d067e527daa7
 
Error: (02/27/2018 03:50:43 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: CompatTelRunner.exe, version: 10.0.17060.1019, time stamp: 0x0206ae46
Faulting module name: ntdll.dll, version: 6.1.7601.24024, time stamp: 0x5a58e571
Exception code: 0xc0000374
Fault offset: 0x00000000000bf6b2
Faulting process id: 0x1b64
Faulting application start time: 0x01d3af7d8e188815
Faulting application path: C:\Windows\system32\CompatTelRunner.exe
Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report Id: 61fefe2b-1b71-11e8-a8df-d067e527daa7
 
Error: (02/26/2018 10:59:09 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (02/26/2018 10:59:09 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
 
System errors:
=============
Error: (02/27/2018 01:16:49 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 20.
 
Error: (02/24/2018 08:30:05 AM) (Source: DCOM) (EventID: 10016) (User: Trevor-PC)
Description: The machine-default permission settings do not grant Local Activation permission for the COM Server application with CLSID 
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
 and APPID 
{9BA05972-F6A8-11CF-A442-00A0C90A8F39}
 to the user Trevor-PC\Trevor SID (S-1-5-21-105084621-2470936660-356980580-1001) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool.
 
Error: (02/23/2018 10:18:58 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
 
Error: (02/23/2018 10:03:17 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
Description: The following fatal alert was received: 70.
 
Error: (02/23/2018 03:24:20 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The HP Network Devices Support service terminated with the following error: 
The system cannot find the file specified.
 
Error: (02/23/2018 01:26:51 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The HP Network Devices Support service terminated with the following error: 
The system cannot find the file specified.
 
Error: (02/23/2018 12:27:02 PM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The HP Network Devices Support service terminated with the following error: 
The system cannot find the file specified.
 
Error: (02/23/2018 12:26:38 PM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The aswbIDSAgent service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.
 
 
Windows Defender:
===================================
Date: 2016-02-16 19:19:44.075
Description: 
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
Name:Program:Win32/Hadsruda!bit
ID:213971
Severity:Medium
Category:Potentially Unwanted Software
Path Found:containerfile:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe;file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000005);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000098);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000103);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000104);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000110);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000111);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000118);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000128);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000130);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000142);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe-
Detection Type:Concrete
Detection Source:System
Status:Unknown
Process Name:
 
Date: 2016-02-15 11:41:12.220
Description: 
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
Name:Program:Win32/Hadsruda!bit
ID:213971
Severity:Medium
Category:Potentially Unwanted Software
Path Found:containerfile:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe;file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000005);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000098);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000103);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000104);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000110);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000111);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000118);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000128);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000130);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000142);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe-
Detection Type:Concrete
Detection Source:System
Status:Unknown
Process Name:
 
Date: 2016-04-30 05:37:07.134
Description: 
%1 engine has been terminated due to an unexpected error.
Failure Type:%5
Exception code:%6
Resource:%3
 
Date: 2016-04-26 16:58:36.527
Description: 
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified. 
Signature version:0.0.0.0
Engine version:0.0.0.0
 
Date: 2016-04-26 16:58:36.527
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source:Signature Update Folder
Signature Type:AntiSpyware
Update Type:Delta
Current Engine Version:
Previous Engine Version:
Error code:0x80070002
Error description:The system cannot find the file specified. 
 
CodeIntegrity:
===================================
 
Date: 2017-02-27 16:55:45.116
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:55:45.056
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:53:10.229
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:53:10.169
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:51:31.754
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:51:31.704
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:50:15.121
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:50:15.071
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 72%
Total physical RAM: 8104.63 MB
Available physical RAM: 2225.09 MB
Total Virtual: 20646.43 MB
Available Virtual: 4659.61 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:464.99 GB) (Free:276.16 GB) NTFS
 
\\?\Volume{b99bd4b9-e440-11e0-b8d3-806e6f6e6963}\ (RECOVERY) (Fixed) (Total:0.73 GB) (Free:0.11 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 6580F1A7)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=750 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=465 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================
 
 


BC AdBot (Login to Remove)

 


#2 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,780 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:17 PM

Posted 02 March 2018 - 11:18 AM

Greetings TJWIL and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met.
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. Please allow me just a bit of time to review what you have posted.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#3 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,780 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:17 PM

Posted 02 March 2018 - 11:43 AM

Greetings.

Let's start with this.

===================================================

Uninstalling Programs Using Revo Uninstaller Free

--------------------

I recommend uninstalling the below listed program(s) from your computer.
  • Please download and install Revo Uninstaller Free
  • Right click Revo Uninstaller and select Run as administrator
  • From the list of programs double click on the listed program(s), or anything similar, to remove it (if it exists)
Advanced SystemCare 11 
Avast Cleanup Premium
IObit Uninstaller 
Plusnet Assist
System Mechanic
  • Click Yes to any warning screen that may appear
  • If presented with the program uninstall option click Uninstall
  • If asked to restart now click No
  • Under Scanning Modes select Advanced then select Scan
  • On the Found leftover Registry items window click Select All, Delete, then Yes
  • If prompted click on Next
  • On the Found leftover files and folders window click on Select all, Delete, Yes, OK on any warning screen, then Finish
  • Reboot your computer
===================================================

Farbar's Recovery Scan Tool - Run Fix in Normal or Safe Mode

--------------------
  • Right click on the FRST icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time
Start::
CreateRestorePoint:
CloseProcesses:
IFEO\backup_central10.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\creator12oem.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\discimageloader12oem.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\fsui.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\itunes.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\moviemaker.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\msnmsgr.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\retrieve12oem.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\roxio burn.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\roxiocentralfx.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\softwareupdate.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\stax.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\systemmechanic.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\uninstaler_skipuac.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\windowslivewriter.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\winzip64.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\wlmail.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\wlxphotogallery.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-105084621-2470936660-356980580-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
SearchScopes: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = 
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit)
BHO-x32: No Name -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> No File
BHO-x32: IObit Ads Removal -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll [2016-06-23] (IObit)
Task: {07195826-345C-4077-A132-AC65EF3FA597} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\5.2.0\Scheduler.exe
Task: {16D79557-BF69-4E3A-BD2D-A456DBBFD293} - System32\Tasks\Uninstaller_SkipUac_Trevor => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-12-15] (IObit)
Task: {1E9C785D-F51A-4A7E-954F-97842CA733B1} - System32\Tasks\Avast TUNEUP Update => C:\Program Files (x86)\AVAST Software\Avast Cleanup\TUNEUpdate.exe [2018-02-02] (AVAST Software)
Task: {26EBAD3E-22D4-4944-B017-86F68A0348B8} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe
Task: {2A98589C-4F61-425F-A105-80AAA4E85373} - System32\Tasks\JetCleanLoginCheckUpdate => C:\remote-service\jetclean\AutoUpdate.exe
C:\remote-service\jetclean
Task: {8CA883E8-C31C-4281-A69E-BA7B2B99E43E} - System32\Tasks\ioloToaster => C:\Program Files (x86)\System Mechanic\ioloToaster.exe [2017-05-03] (iolo technologies, LLC)
C:\Program Files (x86)\System Mechanic
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent
Task: {B143D09F-6A96-4054-9409-0CD7D4F9E393} - System32\Tasks\ioloSmartUpdater => C:\Program Files (x86)\System Mechanic\ioloSmartUpdater.exe [2017-05-03] (iolo technologies, LLC)
Task: {C03EE229-DBC0-4642-85EA-02B8EA51E545} - System32\Tasks\{C981FBF5-AB04-4D95-A17E-54B7AA811FBA} => C:\Windows\system32\pcalua.exe -a "C:\Users\Trevor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F1PTW9UR\wlsetup-web.exe" -d C:\Users\Trevor\Desktop
Task: {C042916E-9061-4C47-A0B6-F421DE4B02D3} - System32\Tasks\Driver Booster SkipUAC (Trevor) => C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DriverBooster.exe
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector 
Task: {F7A743ED-F02E-4799-940F-EECCBF1DC642} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-12-15] (IObit)
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector
AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [240]
AlternateDataStreams: C:\ProgramData\Temp:C23D5E4F [126]
FirewallRules: [{7FCD6717-FD5B-43D9-994A-442A7DE04354}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe
FirewallRules: [{EAF68E5E-D65F-4A43-B8AD-AA5497D119CE}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe
FirewallRules: [{0DD60364-D127-4A98-B006-E57B72782427}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DriverBooster.exe
FirewallRules: [{C4D44CE0-83EB-46D4-B5A5-9842A82322BE}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DriverBooster.exe
FirewallRules: [{ED45108F-F5C5-4A7D-86D0-BFA4AE64F9F4}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DBDownloader.exe
FirewallRules: [{14DBAD59-DFA5-4695-B3E5-15FB2FAB16C1}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DBDownloader.exe
FirewallRules: [{EF1C3F6C-8D81-4890-A1D5-7952DA9EBB9D}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\AutoUpdate.exe
FirewallRules: [{6C118A70-EF67-44B2-A29A-1E61B5BEBDE8}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\AutoUpdate.exe
emptytemp:
End::
  • Click Fix
  • When completed he tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
  • After reboot check your computer performance
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Programs uninstall?
  • Fixlog
  • Update on computer performance

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#4 TJWIL

TJWIL
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:07:17 PM

Posted 02 March 2018 - 12:30 PM

Hi Gary . Thankyou for replying so quickly. I am not going to be at the pc until Monday. Hope that is ok. Trevor

#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,780 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:17 PM

Posted 02 March 2018 - 12:37 PM

Hi Trevor.

No problem at all. Thanks for letting me know, see you then.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#6 TJWIL

TJWIL
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:07:17 PM

Posted 07 March 2018 - 04:58 AM

Hi Gary , sorry for the delay. I have done the above and here is the attachment after the fix:

Fix result of Farbar Recovery Scan Tool (x64) Version: 04.03.2018
Ran by Trevor (07-03-2018 09:41:09) Run:1
Running from C:\Users\Trevor\Downloads
Loaded Profiles: Trevor (Available Profiles: Trevor & Andy)
Boot Mode: Normal
==============================================
 
fixlist content:
*****************
CreateRestorePoint:
CloseProcesses:
IFEO\backup_central10.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\creator12oem.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\discimageloader12oem.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\fsui.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\itunes.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\moviemaker.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\msnmsgr.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\retrieve12oem.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\roxio burn.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\roxiocentralfx.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\softwareupdate.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\stax.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\systemmechanic.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\unins000.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\uninstaler_skipuac.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\windowslivewriter.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\winzip64.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\wlmail.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
IFEO\wlxphotogallery.exe: [Debugger] "C:\Program Files (x86)\AVAST Software\Avast Cleanup\autoreactivator.exe"
CHR HKLM\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
CHR HKU\S-1-5-21-105084621-2470936660-356980580-1001\SOFTWARE\Policies\Google: Restriction <==== ATTENTION
SearchScopes: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = 
BHO: ExplorerWnd Helper -> {10921475-03CE-4E04-90CE-E2E7EF20C814} -> C:\Program Files (x86)\IObit\IObit Uninstaller\UninstallExplorer.dll [2016-05-23] (IObit)
BHO-x32: No Name -> {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} -> No File
BHO-x32: IObit Ads Removal -> {FFCB3198-32F3-4E8B-9539-4324694ED664} -> C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\Adblock\Adblock.dll [2016-06-23] (IObit)
Task: {07195826-345C-4077-A132-AC65EF3FA597} - System32\Tasks\Driver Booster Scheduler => C:\Program Files (x86)\IObit\Driver Booster\5.2.0\Scheduler.exe
Task: {16D79557-BF69-4E3A-BD2D-A456DBBFD293} - System32\Tasks\Uninstaller_SkipUac_Trevor => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-12-15] (IObit)
Task: {1E9C785D-F51A-4A7E-954F-97842CA733B1} - System32\Tasks\Avast TUNEUP Update => C:\Program Files (x86)\AVAST Software\Avast Cleanup\TUNEUpdate.exe [2018-02-02] (AVAST Software)
Task: {26EBAD3E-22D4-4944-B017-86F68A0348B8} - System32\Tasks\Game_Booster_AutoUpdate => C:\Program Files (x86)\IObit\Game Booster 3\AutoUpdate.exe
Task: {2A98589C-4F61-425F-A105-80AAA4E85373} - System32\Tasks\JetCleanLoginCheckUpdate => C:\remote-service\jetclean\AutoUpdate.exe
C:\remote-service\jetclean
Task: {8CA883E8-C31C-4281-A69E-BA7B2B99E43E} - System32\Tasks\ioloToaster => C:\Program Files (x86)\System Mechanic\ioloToaster.exe [2017-05-03] (iolo technologies, LLC)
C:\Program Files (x86)\System Mechanic
Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent
Task: {B143D09F-6A96-4054-9409-0CD7D4F9E393} - System32\Tasks\ioloSmartUpdater => C:\Program Files (x86)\System Mechanic\ioloSmartUpdater.exe [2017-05-03] (iolo technologies, LLC)
Task: {C03EE229-DBC0-4642-85EA-02B8EA51E545} - System32\Tasks\{C981FBF5-AB04-4D95-A17E-54B7AA811FBA} => C:\Windows\system32\pcalua.exe -a "C:\Users\Trevor\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\F1PTW9UR\wlsetup-web.exe" -d C:\Users\Trevor\Desktop
Task: {C042916E-9061-4C47-A0B6-F421DE4B02D3} - System32\Tasks\Driver Booster SkipUAC (Trevor) => C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DriverBooster.exe
Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector 
Task: {F7A743ED-F02E-4799-940F-EECCBF1DC642} - System32\Tasks\Uninstaller_SkipUac_Administrator => C:\Program Files (x86)\IObit\IObit Uninstaller\IObitUninstaler.exe [2016-12-15] (IObit)
Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector
AlternateDataStreams: C:\ProgramData\Temp:5C321E34 [240]
AlternateDataStreams: C:\ProgramData\Temp:C23D5E4F [126]
FirewallRules: [{7FCD6717-FD5B-43D9-994A-442A7DE04354}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe
FirewallRules: [{EAF68E5E-D65F-4A43-B8AD-AA5497D119CE}] => (Allow) C:\Program Files (x86)\IObit\Advanced SystemCare\Surfing Protection\FFNativeMessage.exe
FirewallRules: [{0DD60364-D127-4A98-B006-E57B72782427}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DriverBooster.exe
FirewallRules: [{C4D44CE0-83EB-46D4-B5A5-9842A82322BE}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DriverBooster.exe
FirewallRules: [{ED45108F-F5C5-4A7D-86D0-BFA4AE64F9F4}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DBDownloader.exe
FirewallRules: [{14DBAD59-DFA5-4695-B3E5-15FB2FAB16C1}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\DBDownloader.exe
FirewallRules: [{EF1C3F6C-8D81-4890-A1D5-7952DA9EBB9D}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\AutoUpdate.exe
FirewallRules: [{6C118A70-EF67-44B2-A29A-1E61B5BEBDE8}] => (Allow) C:\Program Files (x86)\IObit\Driver Booster\5.2.0\AutoUpdate.exe
emptytemp:
 
*****************
 
Restore point was successfully created.
Processes closed successfully.
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\backup_central10.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\creator12oem.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\discimageloader12oem.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\fsui.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\itunes.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\moviemaker.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\msnmsgr.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\retrieve12oem.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\roxio burn.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\roxiocentralfx.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\softwareupdate.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stax.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\systemmechanic.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\unins000.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\uninstaler_skipuac.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\windowslivewriter.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\winzip64.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wlmail.exe => not found
HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\wlxphotogallery.exe => not found
"HKLM\SOFTWARE\Policies\Google" => removed successfully
"HKU\S-1-5-21-105084621-2470936660-356980580-1001\SOFTWARE\Policies\Google" => removed successfully
"HKU\S-1-5-21-105084621-2470936660-356980580-1001\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{49606DC7-976D-4030-A74E-9FB5C842FA68}" => removed successfully
HKLM\Software\Classes\CLSID\{49606DC7-976D-4030-A74E-9FB5C842FA68} => not found
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{10921475-03CE-4E04-90CE-E2E7EF20C814} => not found
HKLM\Software\Classes\CLSID\{10921475-03CE-4E04-90CE-E2E7EF20C814} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} => not found
HKLM\Software\Wow6432Node\Classes\CLSID\{BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} => not found
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFCB3198-32F3-4E8B-9539-4324694ED664} => not found
HKLM\Software\Wow6432Node\Classes\CLSID\{FFCB3198-32F3-4E8B-9539-4324694ED664} => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{07195826-345C-4077-A132-AC65EF3FA597}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{07195826-345C-4077-A132-AC65EF3FA597}" => removed successfully
C:\Windows\System32\Tasks\Driver Booster Scheduler => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scheduler" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{16D79557-BF69-4E3A-BD2D-A456DBBFD293} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\Uninstaller_SkipUac_Trevor" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Trevor => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E9C785D-F51A-4A7E-954F-97842CA733B1} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\Avast TUNEUP Update" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast TUNEUP Update => could not remove. Access Denied.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{26EBAD3E-22D4-4944-B017-86F68A0348B8}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26EBAD3E-22D4-4944-B017-86F68A0348B8}" => removed successfully
C:\Windows\System32\Tasks\Game_Booster_AutoUpdate => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Game_Booster_AutoUpdate" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2A98589C-4F61-425F-A105-80AAA4E85373}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A98589C-4F61-425F-A105-80AAA4E85373}" => removed successfully
C:\Windows\System32\Tasks\JetCleanLoginCheckUpdate => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\JetCleanLoginCheckUpdate" => removed successfully
"C:\remote-service\jetclean" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8CA883E8-C31C-4281-A69E-BA7B2B99E43E} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\ioloToaster" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ioloToaster => could not remove. Access Denied.
"C:\Program Files (x86)\System Mechanic" => not found
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AC4E5ACF-89F7-4220-BA21-81EE183975E2}" => removed successfully
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B143D09F-6A96-4054-9409-0CD7D4F9E393} => could not remove. Access Denied.
"C:\Windows\System32\Tasks\ioloSmartUpdater" => not found
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ioloSmartUpdater => could not remove. Access Denied.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C03EE229-DBC0-4642-85EA-02B8EA51E545}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C03EE229-DBC0-4642-85EA-02B8EA51E545}" => removed successfully
C:\Windows\System32\Tasks\{C981FBF5-AB04-4D95-A17E-54B7AA811FBA} => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{C981FBF5-AB04-4D95-A17E-54B7AA811FBA}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{C042916E-9061-4C47-A0B6-F421DE4B02D3}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C042916E-9061-4C47-A0B6-F421DE4B02D3}" => removed successfully
C:\Windows\System32\Tasks\Driver Booster SkipUAC (Trevor) => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (Trevor)" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{CEE64558-E1A7-4D9D-80A7-2001912BE5B5}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{F7A743ED-F02E-4799-940F-EECCBF1DC642}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F7A743ED-F02E-4799-940F-EECCBF1DC642}" => removed successfully
C:\Windows\System32\Tasks\Uninstaller_SkipUac_Administrator => moved successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Administrator" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => removed successfully
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FA2BC0A6-8D4B-458A-85C8-2B8C72487513}" => removed successfully
C:\ProgramData\Temp => ":5C321E34" ADS removed successfully
C:\ProgramData\Temp => ":C23D5E4F" ADS removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{7FCD6717-FD5B-43D9-994A-442A7DE04354}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EAF68E5E-D65F-4A43-B8AD-AA5497D119CE}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{0DD60364-D127-4A98-B006-E57B72782427}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{C4D44CE0-83EB-46D4-B5A5-9842A82322BE}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{ED45108F-F5C5-4A7D-86D0-BFA4AE64F9F4}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{14DBAD59-DFA5-4695-B3E5-15FB2FAB16C1}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{EF1C3F6C-8D81-4890-A1D5-7952DA9EBB9D}" => removed successfully
"HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{6C118A70-EF67-44B2-A29A-1E61B5BEBDE8}" => removed successfully
 
=========== EmptyTemp: ==========
 
BITS transfer queue => 12582912 B
DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 8467384 B
Java, Flash, Steam htmlcache => 1290 B
Windows/system/drivers => 1769831939 B
Edge => 0 B
Chrome => 506494682 B
Firefox => 7133229 B
Opera => 0 B
 
Temp, IE cache, history, cookies, recent:
Users => 0 B
Default => 0 B
Public => 0 B
ProgramData => 0 B
systemprofile => 16674 B
systemprofile32 => 16802 B
LocalService => 159170 B
NetworkService => 37496 B
Trevor => 134397111 B
Andy => 27570955 B
 
RecycleBin => 180086396 B
EmptyTemp: => 2.5 GB temporary data Removed.
 
================================
 
Result of scheduled files to move (Boot Mode: Normal) (Date&Time: 07-03-2018 09:48:07)
 
 
Result of scheduled keys to remove after reboot:
 
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{16D79557-BF69-4E3A-BD2D-A456DBBFD293} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Uninstaller_SkipUac_Trevor => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E9C785D-F51A-4A7E-954F-97842CA733B1} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Avast TUNEUP Update => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8CA883E8-C31C-4281-A69E-BA7B2B99E43E} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ioloToaster => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B143D09F-6A96-4054-9409-0CD7D4F9E393} => could not remove. Access Denied.
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ioloSmartUpdater => could not remove. Access Denied.
 
==== End of Fixlog 09:48:07 ====


#7 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,780 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:17 PM

Posted 07 March 2018 - 10:51 AM

Thank you.

Is it possible you needed to run the Fixlist twice?

Can you update me on the state of your computer?
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#8 TJWIL

TJWIL
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:07:17 PM

Posted 07 March 2018 - 11:41 AM

Hi Gary. It seems to be running fine although the original problem of the emptied folders is still  there and it will not recognise things plugged into the USB ports other than mouse and printer. This has been the case since the original problem though. Speedwise it seems better but tbh I have been out all day. I haven't knowingly run it twice although Google did some sort of update and shut the browser down earlier requiring a restart and that was after the fix but before sending it to you.



#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,780 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:17 PM

Posted 07 March 2018 - 08:41 PM

Thank you Trevor.

Regarding the folders, were they shortcuts (you mention quick access) pointing to a folder that was not actually on the Desktop or did you actually save the files inside the Desktop folders?

Please do the following.

===================================================

Unhide

--------------------
  • Please download Unhide to your desktop
  • Double click the icon
  • Once the program has completed a Windows alert will be displayed stating your files have been restored
  • Please reboot your computer
  • If the issues is not resolved please run the program a second time
  • Please copy and paste the contents of the Unhide.txt document which will be created on your desktop
  • Check for your files
===================================================

RogueKiller Anti-Malware

--------------------
  • Download RogueKiller and save it to your desktop
  • Close all running programs
  • Right click on the setup.exe icon and select Run as Administrator
  • Click OK on English
  • Select Install 32 and 64 bits versions (Recommended for Technicians), then continually click Next until you click Install
  • Click Finish
  • Click Accept
  • Under # Software Version if it does not indicate up to date click Check for updates >>
  • Click Start Scan twice
  • When completed click Open Report
  • Click Export Text and save the file on your Desktop as RK.txt
  • Close all open RogueKiller windows
  • Copy and paste the contents of the report in your reply
===================================================

Installing Everything Search Engine

--------------------

Note: Complete this step only if you know some of the names of the missing files
  • Download Everything Search for 64 bit computers and save it to your desktop
  • Double click the icon and select Run, then I Agree
  • Click Next, then Next
  • Click Install, then Finish
  • In the pop up screen that appears type some missing file names and see if the program locates them
===================================================

Please run another FRST scan and copy/paste both reports in your reply.

===================================================

System Summary Information

--------------------
  • Press the Windows Key + R at the same time
  • Type msinfo32 and press Enter
  • Left click on System Summary
  • Click File, Save, and name the file Summary
  • Zip and upload the file here
===================================================
Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Shortcuts?
  • Unhide.txt
  • RogueKiller report
  • Everything Search
  • FRST.txt
  • Addition.txt
  • Attached System Summary report

Edited by Oh My!, 07 March 2018 - 08:42 PM.

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#10 TJWIL

TJWIL
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:07:17 PM

Posted 08 March 2018 - 02:13 AM

Thanks Gary. I am out all day today so will do all this tomorrow. There was a mixture of shortcuts and files saved in the folders I had created on the desktop. They were various formats ie Pdf, doc, docx , jpeg etc. Really appreciate this.

#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 36,780 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:12:17 PM

Posted 08 March 2018 - 10:22 AM

Thanks for letting me know. When you are ready we will carry on.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"Lord, to whom would we go? You have the words that give eternal life. We believe, and we know you are the Holy One of God."

#12 TJWIL

TJWIL
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:07:17 PM

Posted 08 March 2018 - 11:17 AM

Unhide by Lawrence Abrams (Grinler)
Copyright 2008-2018 BleepingComputer.com
More Information about Unhide.exe can be found at this link:
 
Program started at: 03/08/2018 09:18:21 AM
Windows Version: Windows 7
 
Please be patient while your files are made visible again.
 
Processing the C:\ drive
Finished processing the C:\ drive. 405040 files processed.
 
The C:\Users\Trevor\AppData\Local\Temp\smtmp\ folder does not exist!!
Unhide cannot restore your missing shortcuts!!
Please see this topic in order to learn how to restore default
 
Searching for Windows Registry changes made by FakeHDD rogues.
 - Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
 - Checking HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
 - Checking HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System
 - Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
No registry changes detected.
 
Program finished at: 03/08/2018 09:30:58 AM
Execution time: 0 hours(s), 12 minute(s), and 37 seconds(s)


#13 TJWIL

TJWIL
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:07:17 PM

Posted 09 March 2018 - 05:57 AM

RogueKiller V12.12.7.0 (x64) [Mar  5 2018] (Free) by Adlice Software
 
Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User : Trevor [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 03/08/2018 16:26:48 (Duration : 01:00:43)
Switches : -refid
 
¤¤¤ Processes : 0 ¤¤¤
 
¤¤¤ Registry : 5 ¤¤¤
[PUP.Gen0] (X64) HKEY_CLASSES_ROOT\CLSID\{03EB0E9C-7A91-4381-A220-9B52B641CDB1} -> Found
[PUM.Proxy] (X64) HKEY_USERS\S-1-5-21-105084621-2470936660-356980580-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : localhost:8080  -> Found
[PUM.Proxy] (X86) HKEY_USERS\S-1-5-21-105084621-2470936660-356980580-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings | ProxyServer : localhost:8080  -> Found
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-105084621-2470936660-356980580-1001\Software\Microsoft\Internet Explorer\Main | Start Page :
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-105084621-2470936660-356980580-1001\Software\Microsoft\Internet Explorer\Main | Start Page :
 
¤¤¤ Tasks : 0 ¤¤¤
 
¤¤¤ Files : 0 ¤¤¤
 
¤¤¤ WMI : 0 ¤¤¤
 
¤¤¤ Hosts File : 0 ¤¤¤
 
¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤
 
¤¤¤ Web browsers : 3 ¤¤¤
[PUM.HomePage][Firefox:Config] o2recolz.default : user_pref("browser.startup.homepage", "http://www.bbc.co.uk/"); -> Found
[PUM.HomePage][Chrome:Config] Default [SecurePrefs] : session.startup_urls [http://www.bbc.co.uk/] -> Found
[PUM.SearchPage][Chrome:Config] Default [SecurePrefs] : default_search_provider_data.template_url_data.keyword [google.co.uk] -> Found
 
¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST3500413AS ATA Device +++++
--- User ---
[MBR] f7ca1e5cd5e2536f79d3f02df0fe2373
[BSP] 9a899b8240ce0043757d878ad374b9e8 : HP|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] DELL-UTIL (0xde) [VISIBLE] Offset (sectors): 63 | Size: 39 MB
1 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 81920 | Size: 750 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
2 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 1617920 | Size: 476149 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
User = LL1 ... OK
User = LL2 ... OK


#14 TJWIL

TJWIL
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:07:17 PM

Posted 09 March 2018 - 08:21 AM

Hi Gary. I have been looking through "Everything". It seems the files that were shortcuts are still in their original locations but the ones that were actually stored in the folders on the desktop have gone. All those files were modified on 2/2/18. I cannot find those.

As requested here are the FRST logs

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 04.03.2018
Ran by Trevor (administrator) on TREVOR-PC (09-03-2018 12:58:41)
Running from C:\Users\Trevor\Downloads
Loaded Profiles: Trevor (Available Profiles: Trevor & Andy)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Chrome)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe
(Dell, Inc.) C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuAgent.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Network Threat Protection\bin\SntpService.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsAgent.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsClient.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos Data Recorder\SDRService.exe
(Sophos Limited) C:\Program Files\Sophos\Sophos System Protection\ssp.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.7\GoogleCrashHandler64.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\root\Office16\OUTLOOK.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
() C:\Program Files\Everything\Everything.exe
() C:\Program Files\Everything\Everything.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Everything] => C:\Program Files\Everything\Everything.exe [2199656 2018-02-09] ()
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587800 2017-12-19] (Oracle Corporation)
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] => C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [1516096 2018-02-24] (Sophos Limited)
HKLM-x32\...\Run: [Dell DataSafe Online] => C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe [1117528 2010-08-26] (Dell, Inc.)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-09-14] (Apple Inc.)
HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\RunOnce: [Uninstall C:\Users\Trevor\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Trevor\AppData\Local\Microsoft\OneDrive\17.3.6390.0509_1\amd64"
HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\RunOnce: [Uninstall 17.005.0107.0008_1\amd64] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Trevor\AppData\Local\Microsoft\OneDrive\17.005.0107.0008_1\amd64"
HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\RunOnce: [Uninstall 17.005.0107.0008_1] => C:\Windows\system32\cmd.exe /q /c rmdir /s /q "C:\Users\Trevor\AppData\Local\Microsoft\OneDrive\17.005.0107.0008_1"
HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\Policies\Explorer: [NolowDiskSpaceChecks] 1
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
ProxyServer: [S-1-5-21-105084621-2470936660-356980580-1001] => localhost:8080
Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [141424 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Winsock: Catalog9-x64 19 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [201656 2017-09-27] (Sophos Limited)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{4203D66C-69BE-429D-AE78-2193EA9AA5EF}: [DhcpNameServer] 192.168.1.254
Tcpip\..\Interfaces\{F9419E88-BAD8-4C2E-A8A2-461912EFF709}: [NameServer] 8.8.8.8
Tcpip\..\Interfaces\{F9419E88-BAD8-4C2E-A8A2-461912EFF709}: [DhcpNameServer] 192.168.1.254
 
Internet Explorer:
==================
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/?trackid=sp-006
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = 
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Local Page = 
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
HKU\S-1-5-21-105084621-2470936660-356980580-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKU\S-1-5-21-105084621-2470936660-356980580-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bbc.co.uk/
SearchScopes: HKLM -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {49606DC7-976D-4030-A74E-9FB5C842FA68} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
SearchScopes: HKLM-x32 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKLM-x32 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = hxxps://www.google.com/search?q={searchTerms}
SearchScopes: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> {E9410C70-B6AE-41FF-AB71-32F4B279EA5F} URL = hxxps://www.google.com/search?trackid=sp-006&q={searchTerms}
SearchScopes: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = hxxps://www.google.com/search?q={searchTerms}
BHO: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\OCHelper.dll [2018-02-23] (Microsoft Corporation)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-06-06] (Google Inc.)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\URLREDIR.DLL [2018-02-23] (Microsoft Corporation)
BHO: Microsoft OneDrive for Business Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\GROOVEEX.DLL [2018-02-23] (Microsoft Corporation)
BHO: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2011-09-21] (Sun Microsystems, Inc.)
BHO-x32: Lync Browser Helper -> {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} -> C:\Program Files (x86)\Microsoft Office\root\Office16\OCHelper.dll [2018-02-23] (Microsoft Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_162\bin\ssv.dll [2018-01-25] (Oracle Corporation)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-06-06] (Google Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\root\Office16\URLREDIR.DLL [2018-02-23] (Microsoft Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_162\bin\jp2ssv.dll [2018-01-25] (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-06-06] (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2017-06-06] (Google Inc.)
Toolbar: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2017-06-06] (Google Inc.)
Toolbar: HKU\S-1-5-21-105084621-2470936660-356980580-1001 -> Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll [2014-07-07] (CANON INC.)
DPF: HKLM-x32 {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} hxxp://h20614.www2.hp.com/ediags/gmd/Install/Cab/hpdetect121.cab
DPF: HKLM-x32 {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} hxxps://secure.logmein.com/activex/RACtrl.cab
Handler: intu-help-qb2 - No CLSID Value
Handler-x32: mso-minsb-roaming.16 - {83C25742-A9F7-49FB-9138-434302C88D07} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-23] (Microsoft Corporation)
Handler-x32: mso-minsb.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-23] (Microsoft Corporation)
Handler-x32: osf-roaming.16 - {42089D2D-912D-4018-9087-2B87803E93FB} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-23] (Microsoft Corporation)
Handler-x32: osf.16 - {5504BE45-A83B-4808-900A-3A5C36E7F77A} - C:\Program Files (x86)\Microsoft Office\root\Office16\MSOSB.DLL [2018-02-23] (Microsoft Corporation)
Filter: application/x-mfe-ipt - No CLSID Value
 
FireFox:
========
FF DefaultProfile: o2recolz.default
FF ProfilePath: C:\Users\Trevor\AppData\Roaming\Mozilla\Firefox\Profiles\o2recolz.default [2018-03-07]
FF user.js: detected! => C:\Users\Trevor\AppData\Roaming\Mozilla\Firefox\Profiles\o2recolz.default\user.js [2016-12-08]
FF Homepage: Mozilla\Firefox\Profiles\o2recolz.default -> hxxp://www.bbc.co.uk/
FF Extension: (IBM Security Rapport) - C:\Users\Trevor\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\rapportext@trusteer.com.xpi [2018-01-22]
FF Extension: (No Name) - C:\Users\Trevor\AppData\Roaming\Mozilla\Firefox\Profiles\o2recolz.default\extensions\ascsurfingprotectionnew@iobit.com.xpi [not found]
FF HKLM-x32\...\Firefox\Extensions: [{D19CA586-DD6C-4a0a-96F8-14644F340D60}] - C:\Program Files (x86)\Common Files\McAfee\SystemCore => not found
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_28_0_0_161.dll [2018-02-21] ()
FF Plugin: @mcafee.com/MSC,version=10 -> c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL [No File]
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_28_0_0_161.dll [2018-02-21] ()
FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\My Image Garden\AddOn\CIG\npmigfpi.dll [2011-11-30] (CANON INC.)
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll [2014-01-06] (Google, Inc.)
FF Plugin-x32: @java.com/DTPlugin,version=11.162.2 -> C:\Program Files (x86)\Java\jre1.8.0_162\bin\dtplugin\npDeployJava1.dll [2018-01-25] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.162.2 -> C:\Program Files (x86)\Java\jre1.8.0_162\bin\plugin2\npjp2.dll [2018-01-25] (Oracle Corporation)
FF Plugin-x32: @mcafee.com/MSC,version=10 -> c:\progra~2\mcafee\msc\npmcsn~1.dll [No File]
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/Lync,version=15.0 -> C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX86\Mozilla Firefox\plugins\npmeetingjoinpluginoc.dll [2018-02-23] (Microsoft Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\Program Files (x86)\Microsoft Office\root\Office16\NPSPWRAP.DLL [2018-02-23] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3508.0205 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2013-02-05] (Microsoft Corporation)
FF Plugin-x32: @Motive.com/NpMotive,version=1.0 -> C:\Program Files (x86)\Common Files\Motive\npMotive.dll [2011-09-07] (Motive, Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2017-11-15] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-02-11] (Adobe Systems Inc.)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR HomePage: Default -> hxxps://uk.search.yahoo.com/?type=715483&fr=yo-yhp-ch
CHR StartupUrls: Default -> "hxxp://www.bbc.co.uk/"
CHR DefaultSearchKeyword: Default -> google.co.uk
CHR Profile: C:\Users\Trevor\AppData\Local\Google\Chrome\User Data\Default [2018-03-09]
CHR Extension: (Adobe Acrobat) - C:\Users\Trevor\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2017-03-10]
CHR Extension: (Avast Passwords) - C:\Users\Trevor\AppData\Local\Google\Chrome\User Data\Default\Extensions\emhginjpijfggbofeediiojmdlmlkoik [2018-03-02]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Trevor\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-08-29]
CHR Extension: (Chrome Media Router) - C:\Users\Trevor\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-02-12]
CHR HKU\S-1-5-21-105084621-2470936660-356980580-1001\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bbjllphbppobebmjpjcijfbakobcheof] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [173472 2017-11-27] (SUPERAntiSpyware.com)
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-11-27] (Apple Inc.)
R2 ClickToRunSvc; C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe [7761576 2018-02-02] (Microsoft Corporation)
R2 Everything; C:\Program Files\Everything\Everything.exe [2199656 2018-02-09] ()
S4 Freemake Improver; C:\ProgramData\Freemake\FreemakeUtilsService\FreemakeUtilsService.exe [100864 2013-02-21] (Freemake) [File not signed]
S2 HPSLPSVC; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S2 HPSLPSVC; C:\Windows\SysWOW64\svchost.exe [20992 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S4 LMIGuardianSvc; C:\Program Files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [376144 2014-04-11] (LogMeIn, Inc.)
S4 LMIMaint; C:\Program Files (x86)\LogMeIn\x64\RaMaint.exe [226640 2014-04-11] (LogMeIn, Inc.)
S4 LMIRescue_ca296989-8fdc-826d-7ef3-8b1ae0d0b596; C:\Program Files (x86)\LogMeIn Rescue Applet\LMIR0002.tmp\LMI_Rescue_srv.exe [3775960 2018-02-21] (LogMeIn, Inc.)
S4 LogMeIn; C:\Program Files (x86)\LogMeIn\x64\LogMeIn.exe [407424 2011-09-16] (LogMeIn, Inc.)
S4 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6234056 2017-11-01] (Malwarebytes)
S4 McciCMService; C:\Program Files (x86)\Common Files\Motive\McciCMService.exe [319488 2011-03-29] (Alcatel-Lucent) [File not signed]
S4 McciCMService64; C:\Program Files\Common Files\Motive\McciCMService.exe [517632 2011-03-29] (Alcatel-Lucent) [File not signed]
S3 QBCFMonitorService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [24576 2011-03-08] (Intuit) [File not signed]
S3 QBFCService; C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [61440 2008-11-18] (Intuit Inc.) [File not signed]
S4 RapportMgmtService; C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [5249008 2018-01-24] (IBM Corp.)
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [235872 2017-09-27] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [200064 2017-09-27] (Sophos Limited)
R2 SntpService; C:\Program Files\Sophos\Sophos Network Threat Protection\bin\SntpService.exe [925824 2017-01-26] (Sophos Limited)
R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [773080 2018-02-24] (Sophos Limited)
R2 Sophos MCS Agent; C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsAgent.exe [1301976 2018-02-24] (Sophos Limited)
R2 Sophos MCS Client; C:\Program Files (x86)\Sophos\Management Communications System\Endpoint\McsClient.exe [1715464 2018-02-24] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [360040 2017-09-27] (Sophos Limited)
R2 SophosDataRecorderService; C:\Program Files\Sophos\Sophos Data Recorder\SDRService.exe [996240 2016-09-12] (Sophos Limited)
R2 sophossps; C:\Program Files\Sophos\Sophos System Protection\ssp.exe [5366040 2016-09-12] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [3596088 2017-09-27] (Sophos Limited)
S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2121216 2017-09-27] (Sophos Limited)
S4 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [10945776 2017-12-15] (TeamViewer GmbH)
S4 TlntSvr; C:\Windows\System32\tlntsvr.exe [81920 2009-07-14] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
S4 WinZip Compression Smart Monitor Service; C:\Program Files\WinZip\WinZip Smart Monitor\WinZip Compression Smart Monitor Service.exe [495872 2017-09-01] ()
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) <==== ATTENTION (no ServiceDLL)
S3 catchme; no ImagePath
R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77432 2017-11-29] ()
S3 hitmanpro37; C:\Windows\system32\drivers\hitmanpro37.sys [49584 2016-04-26] ()
R1 HWiNFO32; C:\Windows\SysWOW64\drivers\HWiNFO64A.SYS [27552 2017-01-04] (REALiX™)
R2 LMIInfo; C:\Program Files (x86)\LogMeIn\x64\RaInfo.sys [16056 2013-05-29] (LogMeIn, Inc.)
S4 LMIRfsClientNP; no ImagePath
R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [193968 2018-02-23] (Malwarebytes)
S3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2018-02-23] (Malwarebytes)
S3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [46008 2018-02-23] (Malwarebytes)
R0 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [253880 2018-02-23] (Malwarebytes)
S3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2018-02-23] (Malwarebytes)
R3 MEIx64; C:\Windows\System32\DRIVERS\TeeDriverx64.sys [100312 2014-05-19] (Intel Corporation)
S3 MREMP50; C:\Program Files (x86)\Common Files\Motive\MREMP50.sys [21248 2012-06-25] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MREMPR5; no ImagePath
S3 MRENDIS5; no ImagePath
S3 MRESP50; C:\Program Files (x86)\Common Files\Motive\MRESP50.sys [20096 2012-06-25] (Printing Communications Assoc., Inc. (PCAUSA)) [File not signed]
S3 MRESP50a64; no ImagePath
R1 RapportAegle64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportAegle64.sys [489616 2018-01-24] (IBM Corp.)
R1 RapportCerberus_1908103; C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\baseline\RapportCerberus64_1908103.sys [1635344 2018-02-20] (IBM Corp.)
R1 RapportEI64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [703056 2018-01-24] (IBM Corp.)
R0 RapportHades64; C:\Windows\System32\Drivers\RapportHades64.sys [338384 2018-01-24] (IBM Corp.)
S3 RapportKE64; C:\Windows\System32\Drivers\RapportKE64.sys [597976 2018-01-24] (IBM Corp.)
R1 RapportPG64; C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [743568 2018-01-24] (IBM Corp.)
R1 RawDisk3; C:\Windows\system32\drivers\rawdsk3.sys [41576 2016-02-19] (EldoS Corporation)
S3 RTSUER; C:\Windows\System32\Drivers\RtsUer.sys [420832 2017-11-09] (Realsil Semiconductor Corporation)
R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com)
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [204328 2017-09-27] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [38144 2017-09-27] (Sophos Limited)
R2 sntp; C:\Windows\System32\DRIVERS\sntp.sys [123848 2017-01-26] (Sophos Limited)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [45840 2017-09-27] (Sophos Limited)
S3 cpuz143; \??\C:\Windows\temp\cpuz143\cpuz143_x64.sys [X]
S3 WinRing0_1_2_0; \??\C:\Program Files (x86)\IObit\Game Booster 3\Driver\WinRing0x64.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-03-09 12:53 - 2018-03-09 12:53 - 002102686 _____ C:\Users\Trevor\Desktop\summary.nfo
2018-03-09 11:01 - 2018-03-09 12:49 - 000000000 ____D C:\Users\Trevor\AppData\Roaming\Everything
2018-03-09 11:00 - 2018-03-09 11:01 - 000000000 ____D C:\Program Files\Everything
2018-03-09 11:00 - 2018-03-09 11:00 - 000000955 _____ C:\Users\Trevor\Desktop\Search Everything.lnk
2018-03-09 11:00 - 2018-03-09 11:00 - 000000000 ____D C:\Users\Trevor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Everything
2018-03-09 10:56 - 2018-03-09 10:56 - 000004930 _____ C:\Users\Trevor\Desktop\RK2.txt
2018-03-09 09:50 - 2018-03-09 09:50 - 000000000 ___HD C:\OneDriveTemp
2018-03-08 16:26 - 2018-03-08 16:26 - 000028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2018-03-08 16:25 - 2018-03-09 12:30 - 000000000 ____D C:\ProgramData\RogueKiller
2018-03-08 16:25 - 2018-03-09 10:55 - 000000000 ____D C:\Program Files\RogueKiller
2018-03-08 16:25 - 2018-03-08 16:25 - 000000826 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2018-03-08 16:25 - 2018-03-08 16:25 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2018-03-08 16:20 - 2018-03-08 16:20 - 000326484 _____ C:\Users\Trevor\Downloads\win7-x64-sm-reset.exe
2018-03-08 09:32 - 2018-03-08 09:25 - 036467456 _____ (Adlice Software ) C:\Users\Trevor\Desktop\RogueKiller_setup_ref3.exe
2018-03-08 09:32 - 2018-03-08 09:25 - 001478240 _____ () C:\Users\Trevor\Desktop\Everything-1.4.1.895.x64-Setup.exe
2018-03-08 09:25 - 2018-03-08 09:25 - 001478240 _____ () C:\Users\Trevor\Downloads\Everything-1.4.1.895.x64-Setup.exe
2018-03-08 09:24 - 2018-03-08 09:25 - 036467456 _____ (Adlice Software ) C:\Users\Trevor\Downloads\RogueKiller_setup_ref3.exe
2018-03-08 09:18 - 2018-03-08 09:30 - 000002476 _____ C:\Users\Trevor\Desktop\unhide.txt
2018-03-08 09:18 - 2018-03-08 09:18 - 000398752 _____ (Bleeping Computer, LLC) C:\Users\Trevor\Downloads\unhide.exe
2018-03-07 10:53 - 2018-03-07 10:53 - 000110356 _____ C:\Users\Trevor\Downloads\Copy of RIDESUREBIKES06032018.xlsb
2018-03-07 09:41 - 2018-03-07 09:48 - 000018433 _____ C:\Users\Trevor\Downloads\Fixlog.txt
2018-03-07 09:40 - 2018-03-07 09:40 - 000000000 ____D C:\Users\Trevor\Downloads\FRST-OlderVersion
2018-03-06 09:00 - 2018-03-06 09:00 - 004632872 _____ (Microsoft Corporation) C:\Users\Trevor\Downloads\Setup.X86.en-US_O365HomePremRetail_07fab5b5-62db-4ff5-a899-614bc0cc70b9_TX_DB_.exe
2018-03-05 17:48 - 2018-03-05 17:48 - 000001008 _____ C:\Users\Public\Desktop\Revo Uninstaller.lnk
2018-03-05 17:48 - 2018-03-05 17:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Revo Uninstaller
2018-03-05 17:48 - 2018-03-05 17:48 - 000000000 ____D C:\Program Files\VS Revo Group
2018-03-05 17:47 - 2018-03-05 17:47 - 007189760 _____ (VS Revo Group ) C:\Users\Trevor\Downloads\revosetup.exe
2018-03-05 08:48 - 2018-03-05 08:48 - 000032265 _____ C:\Users\Trevor\Documents\IMG_20180305_0001.pdf
2018-03-04 15:36 - 2018-03-04 15:36 - 000059904 _____ C:\Users\Trevor\Desktop\New Microsoft Publisher Document.pub
2018-03-04 12:00 - 2018-03-04 12:00 - 000032278 _____ C:\Users\Trevor\Documents\IMG_20180304_0001.pdf
2018-03-01 11:59 - 2018-03-02 15:57 - 000067570 _____ C:\Users\Trevor\Downloads\Addition.txt
2018-03-01 11:55 - 2018-03-09 12:59 - 000026724 _____ C:\Users\Trevor\Downloads\FRST.txt
2018-03-01 11:53 - 2018-03-09 12:58 - 000000000 ____D C:\FRST
2018-03-01 11:53 - 2018-03-07 09:40 - 002403328 _____ (Farbar) C:\Users\Trevor\Downloads\FRST64.exe
2018-03-01 11:24 - 2018-03-01 11:24 - 000671719 _____ C:\Users\Trevor\Documents\IMG_20180301_0001.pdf
2018-02-28 14:03 - 2018-02-28 14:04 - 000109609 _____ C:\Users\Trevor\Downloads\Copy of RIDESUREBIKES17022018.xlsb
2018-02-26 10:50 - 2018-02-26 10:49 - 000166833 _____ C:\Users\Trevor\Documents\Ridesure Motorcycle Training Payment Policy (006).pdf
2018-02-26 10:50 - 2018-02-26 10:49 - 000095440 _____ C:\Users\Trevor\Documents\Ridesuredisclaimer (005).pdf
2018-02-26 10:50 - 2018-02-26 10:49 - 000084283 _____ C:\Users\Trevor\Documents\DASinfo (003).pdf
2018-02-26 10:50 - 2018-02-26 10:48 - 000012824 _____ C:\Users\Trevor\Documents\CBT info for students (005).pdf
2018-02-26 10:50 - 2012-03-16 18:01 - 000001967 _____ C:\Users\Trevor\Documents\course info1.pdf
2018-02-26 10:50 - 2011-09-30 12:03 - 001113184 _____ C:\Users\Trevor\Documents\dsa-dt1-standard-operating-procedure.pdf
2018-02-26 10:49 - 2018-02-26 10:49 - 000166833 _____ C:\Users\Trevor\Desktop\Ridesure Motorcycle Training Payment Policy (006).pdf
2018-02-26 10:49 - 2018-02-26 10:49 - 000095440 _____ C:\Users\Trevor\Desktop\Ridesuredisclaimer (005).pdf
2018-02-26 10:49 - 2018-02-26 10:49 - 000084283 _____ C:\Users\Trevor\Desktop\DASinfo (003).pdf
2018-02-26 10:48 - 2018-02-26 10:48 - 000012824 _____ C:\Users\Trevor\Desktop\CBT info for students (005).pdf
2018-02-24 08:38 - 2018-02-24 08:38 - 000003172 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-105084621-2470936660-356980580-1022
2018-02-24 08:14 - 2017-09-27 20:57 - 000044304 _____ (Sophos Limited) C:\Windows\system32\SophosBootTasks.exe
2018-02-24 08:13 - 2018-02-24 08:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Sophos
2018-02-24 08:13 - 2017-01-26 17:23 - 000123848 _____ (Sophos Limited) C:\Windows\system32\Drivers\sntp.sys
2018-02-24 08:12 - 2018-02-24 08:13 - 000000000 ____D C:\Program Files\Sophos
2018-02-24 08:11 - 2017-09-27 20:57 - 000204328 _____ (Sophos Limited) C:\Windows\system32\Drivers\savonaccess.sys
2018-02-24 08:11 - 2017-09-27 20:57 - 000176120 _____ (Sophos Limited) C:\Windows\system32\sdccoinstaller.dll
2018-02-24 08:11 - 2017-09-27 20:57 - 000045840 _____ (Sophos Limited) C:\Windows\system32\Drivers\SophosBootDriver.sys
2018-02-24 08:11 - 2017-09-27 20:57 - 000038144 _____ (Sophos Limited) C:\Windows\system32\Drivers\sdcfilter.sys
2018-02-24 08:04 - 2018-02-24 08:17 - 000000000 ____D C:\ProgramData\Sophos
2018-02-24 08:04 - 2018-02-24 08:17 - 000000000 ____D C:\Program Files (x86)\Sophos
2018-02-24 07:54 - 2018-02-24 07:58 - 267508920 _____ (Sophos Limited) C:\Users\Andy\Downloads\SophosInstall.exe
2018-02-23 16:13 - 2018-02-24 08:37 - 000000000 ___RD C:\Users\Andy\OneDrive
2018-02-23 16:13 - 2018-02-23 16:13 - 000000000 ____D C:\Users\Andy\AppData\Roaming\Skype
2018-02-23 16:08 - 2018-02-23 16:08 - 000002423 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype for Business 2016.lnk
2018-02-23 16:08 - 2018-02-23 16:08 - 000002418 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Word 2016.lnk
2018-02-23 16:08 - 2018-02-23 16:08 - 000002417 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PowerPoint 2016.lnk
2018-02-23 16:08 - 2018-02-23 16:08 - 000002381 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Access 2016.lnk
2018-02-23 16:08 - 2018-02-23 16:08 - 000002380 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Excel 2016.lnk
2018-02-23 16:08 - 2018-02-23 16:08 - 000002374 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Outlook 2016.lnk
2018-02-23 16:08 - 2018-02-23 16:08 - 000002368 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Publisher 2016.lnk
2018-02-23 16:08 - 2018-02-23 16:08 - 000002360 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OneNote 2016.lnk
2018-02-23 16:08 - 2018-02-23 16:08 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2016 Tools
2018-02-23 15:46 - 2018-02-23 15:46 - 000000000 ____D C:\Program Files\Microsoft Office 15
2018-02-23 15:45 - 2018-02-23 15:45 - 004500256 _____ (Microsoft Corporation) C:\Users\Andy\Downloads\Setup.X86.en-us_O365ProPlusRetail_05583e78-e65c-4372-a367-db8d0707efba_TX_DB_b_64_.exe
2018-02-23 14:57 - 2018-02-23 14:57 - 000092993 _____ C:\Users\Andy\Downloads\o15-ctrremove (1).diagcab
2018-02-23 14:52 - 2018-02-23 14:52 - 000000000 ____D C:\Users\Andy\AppData\Local\ElevatedDiagnostics
2018-02-23 14:09 - 2018-02-23 14:09 - 000092993 _____ C:\Users\Andy\Downloads\o15-ctrremove.diagcab
2018-02-23 14:07 - 2018-02-23 14:07 - 000136296 _____ C:\Users\Andy\AppData\Local\GDIPFONTCACHEV1.DAT
2018-02-23 14:07 - 2018-02-23 14:07 - 000009700 _____ C:\Users\Andy\Downloads\UninstallO16.zip
2018-02-23 14:06 - 2018-02-23 14:06 - 000000000 ____D C:\Users\Andy\AppData\Local\TeamViewer
2018-02-23 13:56 - 2018-02-23 16:16 - 000000000 ____D C:\Users\Andy\AppData\Roaming\TeamViewer
2018-02-23 13:44 - 2018-02-23 14:15 - 000000000 ____D C:\Users\Andy\AppData\Local\Google
2018-02-23 13:44 - 2018-02-23 13:44 - 000001375 _____ C:\Users\Andy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-02-23 13:44 - 2018-02-23 13:44 - 000000000 ____D C:\Users\Andy\AppData\Roaming\IObit
2018-02-23 13:44 - 2018-02-23 13:44 - 000000000 ____D C:\Users\Andy\AppData\Roaming\Adobe
2018-02-23 13:22 - 2018-03-07 09:46 - 000508840 _____ C:\Windows\system32\FNTCACHE.DAT
2018-02-23 13:20 - 2018-02-23 13:20 - 000092993 _____ C:\Users\Trevor\Downloads\o15-ctrremove (1).diagcab
2018-02-23 12:49 - 2018-02-23 12:49 - 000000000 ____D C:\Users\Trevor\AppData\Local\TeamViewer
2018-02-23 12:46 - 2018-02-23 12:46 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys
2018-02-23 12:37 - 2018-02-23 12:37 - 000001049 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 13.lnk
2018-02-23 12:37 - 2018-02-23 12:37 - 000001037 _____ C:\Users\Public\Desktop\TeamViewer 13.lnk
2018-02-23 12:37 - 2018-02-23 12:37 - 000000000 ____D C:\Users\Trevor\AppData\Roaming\TeamViewer
2018-02-23 12:36 - 2018-02-23 12:50 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-02-23 12:36 - 2018-02-23 12:37 - 004500256 _____ (Microsoft Corporation) C:\Users\Trevor\Downloads\Setup.X86.en-us_O365ProPlusRetail_05583e78-e65c-4372-a367-db8d0707efba_TX_DB_b_64_.exe
2018-02-23 12:33 - 2018-02-23 12:33 - 019315456 _____ (TeamViewer GmbH) C:\Users\Trevor\Downloads\TeamViewer_Setup.exe
2018-02-23 12:32 - 2018-02-23 12:32 - 000002300 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-02-23 12:32 - 2018-02-23 12:32 - 000002259 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-02-23 12:30 - 2018-02-23 13:21 - 007649280 _____ C:\Program Files (x86)\GUT7639.tmp
2018-02-23 12:30 - 2018-02-23 12:30 - 000000000 ____D C:\Program Files (x86)\GUM7638.tmp
2018-02-23 12:02 - 2018-02-23 12:02 - 000000000 ____D C:\Users\Andy\AppData\Local\VirtualStore
2018-02-23 12:01 - 2018-02-24 08:37 - 000002158 _____ C:\Users\Andy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2018-02-23 12:01 - 2018-02-23 16:13 - 000000000 ____D C:\Users\Andy
2018-02-23 12:01 - 2018-02-23 12:01 - 000000020 ___SH C:\Users\Andy\ntuser.ini
2018-02-23 12:01 - 2017-07-21 14:28 - 000000000 ____D C:\Users\Andy\AppData\Roaming\Mozilla
2018-02-23 12:01 - 2013-12-06 15:43 - 000000000 ____D C:\Users\Andy\AppData\Local\Trusteer
2018-02-23 12:01 - 2011-09-21 09:50 - 000000000 ____D C:\Users\Andy\AppData\Roaming\Macromedia
2018-02-23 12:01 - 2010-11-21 07:16 - 000000000 ____D C:\Users\Andy\AppData\Roaming\Media Center Programs
2018-02-23 11:59 - 2018-02-23 12:46 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys
2018-02-23 11:41 - 2018-02-23 11:41 - 000006091 _____ C:\Users\Trevor\Desktop\threats found 23.02.18.txt
2018-02-23 11:25 - 2018-02-23 12:46 - 000046008 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys
2018-02-23 11:25 - 2018-02-23 11:25 - 000253880 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys
2018-02-23 11:25 - 2018-02-23 11:25 - 000193968 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys
2018-02-23 11:24 - 2018-02-23 11:24 - 000001837 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-02-23 11:24 - 2018-02-23 11:24 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-02-23 11:24 - 2018-02-23 11:24 - 000000000 ____D C:\ProgramData\MB2Migration
2018-02-23 11:24 - 2018-02-23 11:24 - 000000000 ____D C:\Program Files\Malwarebytes
2018-02-23 11:24 - 2017-11-29 09:11 - 000077432 _____ C:\Windows\system32\Drivers\mbae64.sys
2018-02-23 11:13 - 2018-02-23 11:13 - 000000000 ____D C:\Users\Trevor\AppData\Roaming\JAM Software
2018-02-23 11:13 - 2018-02-23 11:13 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TreeSize Free
2018-02-23 11:13 - 2018-02-23 11:13 - 000000000 ____D C:\Program Files (x86)\JAM Software
2018-02-23 11:02 - 2018-02-23 11:02 - 000001620 _____ C:\Users\Public\Desktop\Recuva.lnk
2018-02-21 15:54 - 2018-03-05 17:57 - 000003410 _____ C:\Windows\System32\Tasks\WinZip Update Notifier
2018-02-21 15:54 - 2018-02-21 15:54 - 000001883 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip.lnk
2018-02-21 15:54 - 2018-02-21 15:54 - 000001783 _____ C:\Users\Public\Desktop\WinZip.lnk
2018-02-21 15:54 - 2018-02-21 15:54 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinZip 22.0
2018-02-21 15:54 - 2018-02-21 15:54 - 000000000 ____D C:\Program Files\WinZip
2018-02-21 15:53 - 2018-02-21 15:53 - 000000000 ____D C:\Users\Trevor\Documents\Add-in Express
2018-02-21 15:47 - 2018-02-21 15:47 - 000001709 _____ C:\Users\Public\Desktop\iTunes.lnk
2018-02-21 15:47 - 2018-02-21 15:47 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2018-02-21 15:46 - 2018-02-21 15:47 - 000000000 ____D C:\Program Files\iTunes
2018-02-21 11:19 - 2018-02-21 11:19 - 000000784 _____ C:\Users\Public\Desktop\CCleaner.lnk
2018-02-21 10:15 - 2018-02-21 10:15 - 000092993 _____ C:\Users\Trevor\Downloads\o15-ctrremove.diagcab
2018-02-21 09:10 - 2018-02-21 11:39 - 000000000 ____D C:\Program Files (x86)\LogMeIn Rescue Applet
2018-02-21 09:10 - 2018-02-21 10:33 - 000000000 ____D C:\Users\Trevor\AppData\Local\LogMeIn Rescue Applet
2018-02-21 08:51 - 2018-02-10 19:52 - 000395928 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2018-02-21 08:51 - 2018-02-10 19:03 - 000347296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2018-02-21 08:51 - 2018-02-10 08:44 - 025740288 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2018-02-21 08:51 - 2018-02-10 07:30 - 002724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2018-02-21 08:51 - 2018-02-10 07:29 - 000004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2018-02-21 08:51 - 2018-02-10 07:19 - 002900480 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2018-02-21 08:51 - 2018-02-10 07:17 - 000417280 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2018-02-21 08:51 - 2018-02-10 07:17 - 000066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2018-02-21 08:51 - 2018-02-10 07:17 - 000048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2018-02-21 08:51 - 2018-02-10 07:16 - 000577536 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2018-02-21 08:51 - 2018-02-10 07:16 - 000088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2018-02-21 08:51 - 2018-02-10 07:10 - 000054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2018-02-21 08:51 - 2018-02-10 07:10 - 000034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2018-02-21 08:51 - 2018-02-10 07:09 - 005782016 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2018-02-21 08:51 - 2018-02-10 07:07 - 000615936 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2018-02-21 08:51 - 2018-02-10 07:06 - 000816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2018-02-21 08:51 - 2018-02-10 07:06 - 000814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2018-02-21 08:51 - 2018-02-10 07:06 - 000144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2018-02-21 08:51 - 2018-02-10 07:06 - 000116224 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2018-02-21 08:51 - 2018-02-10 07:01 - 000969216 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2018-02-21 08:51 - 2018-02-10 06:58 - 000489984 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2018-02-21 08:51 - 2018-02-10 06:52 - 000087552 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2018-02-21 08:51 - 2018-02-10 06:52 - 000077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2018-02-21 08:51 - 2018-02-10 06:51 - 000107520 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2018-02-21 08:51 - 2018-02-10 06:49 - 000199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2018-02-21 08:51 - 2018-02-10 06:48 - 000092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2018-02-21 08:51 - 2018-02-10 06:46 - 000315392 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2018-02-21 08:51 - 2018-02-10 06:45 - 000152064 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2018-02-21 08:51 - 2018-02-10 06:36 - 015283712 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2018-02-21 08:51 - 2018-02-10 06:36 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2018-02-21 08:51 - 2018-02-10 06:34 - 000807936 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2018-02-21 08:51 - 2018-02-10 06:34 - 000726528 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2018-02-21 08:51 - 2018-02-10 06:33 - 001359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2018-02-21 08:51 - 2018-02-10 06:32 - 002134528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2018-02-21 08:51 - 2018-02-10 06:27 - 003241472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2018-02-21 08:51 - 2018-02-10 06:20 - 020274176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2018-02-21 08:51 - 2018-02-10 06:14 - 001546240 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2018-02-21 08:51 - 2018-02-10 06:08 - 002724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2018-02-21 08:51 - 2018-02-10 06:02 - 000800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2018-02-21 08:51 - 2018-02-10 05:57 - 000499712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2018-02-21 08:51 - 2018-02-10 05:57 - 000341504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2018-02-21 08:51 - 2018-02-10 05:57 - 000062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2018-02-21 08:51 - 2018-02-10 05:57 - 000047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2018-02-21 08:51 - 2018-02-10 05:56 - 000064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2018-02-21 08:51 - 2018-02-10 05:54 - 002294272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2018-02-21 08:51 - 2018-02-10 05:52 - 000047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2018-02-21 08:51 - 2018-02-10 05:51 - 000030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2018-02-21 08:51 - 2018-02-10 05:50 - 000476160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2018-02-21 08:51 - 2018-02-10 05:49 - 000662528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2018-02-21 08:51 - 2018-02-10 05:49 - 000620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2018-02-21 08:51 - 2018-02-10 05:49 - 000115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2018-02-21 08:51 - 2018-02-10 05:42 - 000416256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2018-02-21 08:51 - 2018-02-10 05:39 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-02-21 08:51 - 2018-02-10 05:38 - 000091136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll
2018-02-21 08:51 - 2018-02-10 05:38 - 000073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx
2018-02-21 08:51 - 2018-02-10 05:36 - 000168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2018-02-21 08:51 - 2018-02-10 05:35 - 004498944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2018-02-21 08:51 - 2018-02-10 05:35 - 000279040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2018-02-21 08:51 - 2018-02-10 05:35 - 000076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2018-02-21 08:51 - 2018-02-10 05:34 - 000130048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll
2018-02-21 08:51 - 2018-02-10 05:33 - 013680640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2018-02-21 08:51 - 2018-02-10 05:29 - 000230400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll
2018-02-21 08:51 - 2018-02-10 05:27 - 002058752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2018-02-21 08:51 - 2018-02-10 05:27 - 000694784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2018-02-21 08:51 - 2018-02-10 05:26 - 001155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2018-02-21 08:51 - 2018-02-10 05:14 - 002767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2018-02-21 08:51 - 2018-02-10 05:10 - 001314304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2018-02-21 08:51 - 2018-02-10 05:08 - 000710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2018-02-21 08:51 - 2018-01-12 16:46 - 000631680 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2018-02-21 08:51 - 2018-01-12 16:44 - 005581544 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2018-02-21 08:51 - 2018-01-12 16:44 - 001894120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2018-02-21 08:51 - 2018-01-12 16:44 - 000708328 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2018-02-21 08:51 - 2018-01-12 16:44 - 000377064 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2018-02-21 08:51 - 2018-01-12 16:44 - 000371432 _____ (Microsoft Corporation) C:\Windows\system32\clfs.sys
2018-02-21 08:51 - 2018-01-12 16:44 - 000287976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\FWPKCLNT.SYS
2018-02-21 08:51 - 2018-01-12 16:44 - 000262376 _____ (Microsoft Corporation) C:\Windows\system32\hal.dll
2018-02-21 08:51 - 2018-01-12 16:44 - 000154856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys
2018-02-21 08:51 - 2018-01-12 16:44 - 000095464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2018-02-21 08:51 - 2018-01-12 16:40 - 001460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 001212928 _____ (Microsoft Corporation) C:\Windows\system32\rpcrt4.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 001163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000880640 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000731648 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000690688 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000484864 _____ (Microsoft Corporation) C:\Windows\system32\StructuredQuery.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000463872 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000419840 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000361984 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000345600 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000316928 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000312320 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000215552 _____ (Microsoft Corporation) C:\Windows\system32\winsrv.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000210432 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000190464 _____ (Microsoft Corporation) C:\Windows\system32\rpchttp.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000123904 _____ (Microsoft Corporation) C:\Windows\system32\bcrypt.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000059904 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000044032 _____ (Microsoft Corporation) C:\Windows\system32\csrsrv.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000043520 _____ (Microsoft Corporation) C:\Windows\system32\cryptbase.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000034816 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000006656 _____ (Microsoft Corporation) C:\Windows\system32\apisetschema.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000006144 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000005120 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000004608 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000004096 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003584 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:40 - 000003072 ____H (Microsoft Corporation) C:\Windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:33 - 001665384 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2018-02-21 08:51 - 2018-01-12 16:29 - 004014312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2018-02-21 08:51 - 2018-01-12 16:29 - 003959016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2018-02-21 08:51 - 2018-01-12 16:27 - 004834816 _____ (Microsoft Corporation) C:\Windows\system32\xpsrchvw.exe
2018-02-21 08:51 - 2018-01-12 16:27 - 001314112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 001114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000666112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000644096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000554496 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000363520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\StructuredQuery.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000342528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000275456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000261120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000254464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000141312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpchttp.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000082944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\bcrypt.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\apisetschema.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000005120 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000004096 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:26 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 16:16 - 003405824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\xpsrchvw.exe
2018-02-21 08:51 - 2018-01-12 16:16 - 000076288 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidclass.sys
2018-02-21 08:51 - 2018-01-12 16:16 - 000030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidusb.sys
2018-02-21 08:51 - 2018-01-12 16:15 - 000032896 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\hidparse.sys
2018-02-21 08:51 - 2018-01-12 16:11 - 000148480 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2018-02-21 08:51 - 2018-01-12 16:11 - 000062464 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2018-02-21 08:51 - 2018-01-12 16:11 - 000017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2018-02-21 08:51 - 2018-01-12 16:10 - 000064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe
2018-02-21 08:51 - 2018-01-12 16:07 - 000338432 _____ (Microsoft Corporation) C:\Windows\system32\conhost.exe
2018-02-21 08:51 - 2018-01-12 16:06 - 000296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2018-02-21 08:51 - 2018-01-12 16:03 - 000159744 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2018-02-21 08:51 - 2018-01-12 16:02 - 000291328 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2018-02-21 08:51 - 2018-01-12 16:02 - 000129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2018-02-21 08:51 - 2018-01-12 16:02 - 000050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe
2018-02-21 08:51 - 2018-01-12 16:01 - 000112640 _____ (Microsoft Corporation) C:\Windows\system32\smss.exe
2018-02-21 08:51 - 2018-01-12 16:01 - 000030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe
2018-02-21 08:51 - 2018-01-12 15:57 - 000036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptbase.dll
2018-02-21 08:51 - 2018-01-12 15:57 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2018-02-21 08:51 - 2018-01-12 15:57 - 000014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2018-02-21 08:51 - 2018-01-12 15:57 - 000007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2018-02-21 08:51 - 2018-01-12 15:57 - 000002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2018-02-21 08:51 - 2018-01-12 15:56 - 000006144 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 15:56 - 000004608 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 15:56 - 000003584 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-02-21 08:51 - 2018-01-12 15:56 - 000003072 ____H (Microsoft Corporation) C:\Windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-02-21 08:51 - 2018-01-11 16:41 - 001133568 _____ (Microsoft Corporation) C:\Windows\system32\cdosys.dll
2018-02-21 08:51 - 2018-01-11 16:22 - 000805376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cdosys.dll
2018-02-21 08:51 - 2018-01-11 16:09 - 003224064 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2018-02-21 08:51 - 2018-01-05 16:31 - 000151552 _____ (Microsoft Corporation) C:\Windows\system32\t2embed.dll
2018-02-21 08:51 - 2018-01-05 16:31 - 000041472 _____ (Microsoft Corporation) C:\Windows\system32\lpk.dll
2018-02-21 08:51 - 2018-01-05 16:30 - 000100864 _____ (Microsoft Corporation) C:\Windows\system32\fontsub.dll
2018-02-21 08:51 - 2018-01-05 16:30 - 000046080 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2018-02-21 08:51 - 2018-01-05 16:30 - 000014336 _____ (Microsoft Corporation) C:\Windows\system32\dciman32.dll
2018-02-21 08:51 - 2018-01-05 16:25 - 000383720 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2018-02-21 08:51 - 2018-01-05 16:14 - 000309480 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2018-02-21 08:51 - 2018-01-05 16:11 - 000111104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\t2embed.dll
2018-02-21 08:51 - 2018-01-05 16:11 - 000071168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\fontsub.dll
2018-02-21 08:51 - 2018-01-05 16:11 - 000025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\lpk.dll
2018-02-21 08:51 - 2018-01-05 16:11 - 000010240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dciman32.dll
2018-02-21 08:51 - 2018-01-05 15:50 - 000034304 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2018-02-21 08:36 - 2018-01-21 23:50 - 000136424 _____ (Microsoft Corporation) C:\Windows\system32\CompatTelRunner.exe
2018-02-21 08:36 - 2018-01-21 23:40 - 000654336 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2018-02-21 08:36 - 2018-01-19 14:05 - 001994752 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe
2018-02-21 08:36 - 2018-01-19 14:05 - 001569280 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll
2018-02-21 08:36 - 2018-01-19 14:05 - 000749568 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2018-02-21 08:36 - 2018-01-19 14:05 - 000604672 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll
2018-02-21 08:36 - 2018-01-19 14:05 - 000450048 _____ (Microsoft Corporation) C:\Windows\system32\centel.dll
2018-02-21 08:36 - 2018-01-19 14:05 - 000378880 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll
2018-02-21 08:36 - 2018-01-19 14:05 - 000262144 _____ (Microsoft Corporation) C:\Windows\system32\acmigration.dll
2018-02-21 08:36 - 2018-01-19 14:05 - 000236544 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll
2018-02-21 07:36 - 2018-02-21 07:36 - 000000000 ____D C:\Users\Trevor\AppData\Local\SaraResults
2018-02-21 07:28 - 2018-02-21 07:28 - 000000458 _____ C:\Users\Trevor\Desktop\Microsoft Support and Recovery Assistant for Office 365.appref-ms
2018-02-21 07:28 - 2018-02-21 07:28 - 000000000 ____D C:\Users\Trevor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft Corporation
2018-02-20 16:52 - 2018-01-24 17:13 - 000338384 _____ (IBM Corp.) C:\Windows\system32\Drivers\RapportHades64.sys
2018-02-20 16:02 - 2018-02-20 16:02 - 000000000 ____D C:\ProgramData\SWCUTemp
2018-02-20 15:49 - 2018-02-20 15:49 - 000397630 _____ C:\unp306489301672468634.mdmp
2018-02-20 15:43 - 2018-03-09 09:50 - 000003176 _____ C:\Windows\System32\Tasks\OneDrive Standalone Update Task-S-1-5-21-105084621-2470936660-356980580-1001
2018-02-20 15:27 - 2018-02-20 15:27 - 000000000 _____ C:\asc_rdflag
2018-02-09 18:08 - 2018-02-09 18:08 - 000625826 _____ C:\Users\Trevor\Downloads\Surrey_Day_Conference_leaflet.pdf
2018-02-09 18:08 - 2018-02-09 18:08 - 000625826 _____ C:\Users\Trevor\Downloads\Surrey_Day_Conference_leaflet (1).pdf
2018-02-08 12:22 - 2018-02-08 12:22 - 000072018 _____ C:\Users\Trevor\Desktop\spire
2018-02-07 05:29 - 2018-02-07 05:29 - 000002222 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth Pro.lnk
2018-02-07 05:29 - 2018-02-07 05:29 - 000002184 _____ C:\Users\Public\Desktop\Google Earth Pro.lnk
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2021-10-31 18:57 - 2012-08-20 18:04 - 000689664 _____ (AdminSystem Software Limited) C:\Windows\system32\ANPOP.dll
2018-03-09 12:44 - 2016-01-22 18:51 - 000000000 ____D C:\Users\Trevor\Desktop\William Tunley - Facts_files
2018-03-09 12:42 - 2014-01-28 16:48 - 000000000 ____D C:\Users\Trevor\Desktop\Ridesure docs
2018-03-09 10:52 - 2011-12-06 18:55 - 000000000 ____D C:\Users\Trevor\Documents\Outlook Files
2018-03-09 09:50 - 2016-08-15 16:03 - 000002164 _____ C:\Users\Trevor\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Microsoft OneDrive.lnk
2018-03-09 09:27 - 2016-04-29 12:01 - 000000000 ____D C:\Users\Trevor\AppData\Local\F6C5EA55-120D-42F5-A668-B2E152643ACC.aplzod
2018-03-09 04:31 - 2009-07-14 04:45 - 000028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-03-09 04:31 - 2009-07-14 04:45 - 000028352 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-03-08 09:35 - 2009-07-14 05:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-03-07 10:01 - 2011-12-23 16:56 - 000007620 _____ C:\Users\Trevor\AppData\Local\resmon.resmoncfg
2018-03-07 09:59 - 2011-12-19 19:07 - 000000000 ____D C:\Users\Trevor\AppData\Local\Deployment
2018-03-07 09:44 - 2012-06-25 16:17 - 000000000 ____D C:\Users\Trevor\AppData\LocalLow\Temp
2018-03-06 09:26 - 2011-09-21 09:20 - 000000000 ____D C:\Program Files (x86)\Microsoft Office
2018-03-05 18:25 - 2012-01-03 11:15 - 000000000 ____D C:\Program Files\Plusnet Assist
2018-03-05 18:25 - 2011-12-15 17:18 - 000000000 ____D C:\Program Files (x86)\IObit
2018-03-05 18:15 - 2011-09-21 09:24 - 000000000 ____D C:\Program Files (x86)\InstallShield Installation Information
2018-03-05 18:15 - 2009-07-14 05:09 - 000000000 ____D C:\Windows\System32\Tasks\WPD
2018-03-05 18:12 - 2011-12-15 17:20 - 000000000 ____D C:\ProgramData\IObit
2018-03-05 18:12 - 2011-12-15 17:18 - 000000000 ____D C:\Users\Trevor\AppData\Roaming\IObit
2018-03-05 18:10 - 2014-10-28 08:56 - 000000000 ____D C:\Program Files (x86)\Canon
2018-03-05 18:05 - 2014-10-28 09:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX720 series Manual
2018-03-05 18:01 - 2014-10-28 16:06 - 000000000 ____D C:\ProgramData\CanonIJScan
2018-03-05 18:01 - 2014-10-28 09:43 - 000000000 ____D C:\Users\Trevor\AppData\Roaming\Canon
2018-03-05 18:01 - 2014-10-28 08:52 - 000000000 ____D C:\ProgramData\CanonIJFAX
2018-03-05 18:01 - 2009-07-14 03:20 - 000000000 ____D C:\Windows\inf
2018-03-05 17:58 - 2015-06-17 16:29 - 000000000 ____D C:\ProgramData\AVAST Software
2018-03-01 11:58 - 2014-12-28 08:44 - 000004476 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
2018-03-01 11:57 - 2015-11-13 09:50 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-03-01 11:57 - 2015-11-13 09:50 - 000002049 _____ C:\Users\Public\Desktop\Acrobat Reader DC.lnk
2018-03-01 11:50 - 2012-02-28 17:40 - 000000000 ____D C:\Users\Trevor\AppData\Local\ElevatedDiagnostics
2018-02-27 16:44 - 2011-09-21 09:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell DataSafe Online
2018-02-26 10:55 - 2012-08-20 18:06 - 000000000 ____D C:\Program Files\Recuva
2018-02-26 10:53 - 2011-12-03 10:04 - 000000000 ___RD C:\Users\Trevor\Desktop\cbt joining info
2018-02-24 08:28 - 2018-01-05 17:08 - 000003148 _____ C:\Windows\System32\Tasks\SidebarExecute
2018-02-23 16:24 - 2017-06-01 13:34 - 000136296 _____ C:\Users\Trevor\AppData\Local\GDIPFONTCACHEV1.DAT
2018-02-23 16:12 - 2017-05-20 13:13 - 000000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2018-02-23 16:08 - 2009-07-14 03:20 - 000000000 ____D C:\Program Files\Common Files\Microsoft Shared
2018-02-23 12:35 - 2018-01-31 14:05 - 000000000 ____D C:\Users\Trevor\Desktop\word docs
2018-02-23 12:35 - 2017-01-17 10:17 - 000000000 ____D C:\Users\Trevor\Desktop\ridesurereceipts
2018-02-23 12:31 - 2011-12-06 18:25 - 000000000 ____D C:\Program Files (x86)\Google
2018-02-23 12:19 - 2016-04-26 18:28 - 000000000 ____D C:\ProgramData\ProductData
2018-02-23 11:44 - 2011-09-21 09:32 - 000000000 ____D C:\Program Files (x86)\Microsoft SQL Server Compact Edition
2018-02-23 11:43 - 2009-07-14 05:32 - 000000000 ____D C:\Program Files (x86)\MSBuild
2018-02-23 11:42 - 2016-04-26 18:33 - 000000000 ____D C:\Users\Trevor\AppData\Roaming\BlueSprig
2018-02-23 11:42 - 2010-11-21 07:16 - 000000000 ____D C:\Windows\ShellNew
2018-02-23 11:29 - 2011-11-30 16:47 - 000000000 ____D C:\Users\Trevor
2018-02-23 11:24 - 2013-03-07 13:33 - 000000000 ____D C:\ProgramData\Malwarebytes
2018-02-23 11:02 - 2012-08-20 18:14 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2018-02-22 17:48 - 2011-02-10 16:10 - 000770488 _____ C:\Windows\SysWOW64\PerfStringBackup.INI
2018-02-22 17:48 - 2009-07-14 05:13 - 000770488 _____ C:\Windows\system32\PerfStringBackup.INI
2018-02-21 15:55 - 2017-04-04 09:38 - 000000000 ____D C:\ProgramData\WinZip
2018-02-21 15:48 - 2016-10-21 13:12 - 000000000 ____D C:\Program Files (x86)\Mozilla Firefox
2018-02-21 15:47 - 2015-02-23 09:09 - 000000000 ____D C:\Program Files\iPod
2018-02-21 12:37 - 2009-07-14 03:20 - 000000000 ____D C:\Windows\rescache
2018-02-21 11:20 - 2012-07-11 15:20 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2018-02-21 11:20 - 2012-03-15 06:43 - 000000000 ____D C:\Windows\system32\Macromed
2018-02-21 11:20 - 2011-09-21 09:12 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-02-21 11:20 - 2011-09-21 09:12 - 000000000 ____D C:\Windows\SysWOW64\Macromed
2018-02-21 11:19 - 2018-01-09 10:50 - 000003870 _____ C:\Windows\System32\Tasks\CCleaner Update
2018-02-21 09:22 - 2014-12-10 03:26 - 000000000 ____D C:\Windows\system32\appraiser
2018-02-21 09:22 - 2013-07-26 18:12 - 000000000 ____D C:\Windows\system32\MRT
2018-02-21 09:08 - 2017-11-09 16:48 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT-KB890830.exe
2018-02-21 09:08 - 2011-12-01 12:14 - 130067560 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2018-02-20 16:47 - 2016-02-26 09:37 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Trusteer Endpoint Protection
2018-02-20 15:56 - 2012-10-24 16:22 - 000000000 ____D C:\Users\Trevor\AppData\LocalLow\IObit
2018-02-20 15:56 - 2009-07-14 03:20 - 000000000 ____D C:\Windows\registration
2018-02-20 15:49 - 2017-05-03 07:44 - 000000000 _____ C:\Windows\SysWOW64\last.dump
2018-02-20 15:27 - 2014-01-06 14:21 - 140505088 _____ C:\Windows\system32\config\SOFTWARE.iodefrag.bak
2018-02-20 15:27 - 2014-01-06 14:21 - 001642496 _____ C:\Windows\system32\config\DEFAULT.iodefrag.bak
2018-02-20 15:27 - 2014-01-06 14:21 - 000057344 _____ C:\Windows\system32\config\SAM.iodefrag.bak
2018-02-20 15:27 - 2014-01-06 14:21 - 000024576 _____ C:\Windows\system32\config\SECURITY.iodefrag.bak
 
==================== Files in the root of some directories =======
 
2018-02-23 12:30 - 2018-02-23 13:21 - 007649280 _____ () C:\Program Files (x86)\GUT7639.tmp
2012-08-29 07:36 - 2013-02-11 13:37 - 000000754 _____ () C:\Users\Trevor\AppData\Roaming\AtomicAlarmClock.ini
2012-12-11 17:47 - 2012-12-11 17:47 - 000012288 _____ (Archlink Technology Corporation) C:\Users\Trevor\AppData\Roaming\CheckOSandLaunch.exe
2012-12-12 14:14 - 2012-12-12 14:14 - 000001855 _____ () C:\Users\Trevor\AppData\Roaming\CheckOSandLaunch.exe.config
2011-12-08 13:17 - 2014-02-21 19:02 - 000022236 _____ () C:\Users\Trevor\AppData\Roaming\Comma Separated Values (Windows).ADR
2014-05-20 10:17 - 2016-04-26 19:40 - 000000600 _____ () C:\Users\Trevor\AppData\Roaming\winscp.rnd
2011-12-23 16:56 - 2018-03-07 10:01 - 000007620 _____ () C:\Users\Trevor\AppData\Local\resmon.resmoncfg
 
Some files in TEMP:
====================
2018-03-08 16:25 - 2018-01-12 16:33 - 001665384 _____ (Microsoft Corporation) C:\Users\Trevor\AppData\Local\Temp\dllnt_dump.dll
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-03-09 00:36
 
==================== End of FRST.txt ============================
 
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04.03.2018
Ran by Trevor (09-03-2018 13:00:23)
Running from C:\Users\Trevor\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2011-11-30 16:47:28)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-105084621-2470936660-356980580-500 - Administrator - Disabled)
Andy (S-1-5-21-105084621-2470936660-356980580-1022 - Administrator - Enabled) => C:\Users\Andy
Guest (S-1-5-21-105084621-2470936660-356980580-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-105084621-2470936660-356980580-1002 - Limited - Enabled)
SophosSAUTREVOR-Paaa (S-1-5-21-105084621-2470936660-356980580-1023 - Limited - Enabled)
Trevor (S-1-5-21-105084621-2470936660-356980580-1001 - Administrator - Enabled) => C:\Users\Trevor
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Sophos Home (Enabled - Up to date) {FFADE7EA-DC92-4602-D6B2-626CD3450A0F}
AV: Malwarebytes (Disabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}
AS: Sophos Home (Enabled - Up to date) {44CC060E-FAA8-498C-EC02-591EA8C240B2}
AS: Malwarebytes (Disabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20038 - Adobe Systems Incorporated)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 28.0.0.127 - Adobe Systems Incorporated)
Adobe Flash Player 28 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 28.0.0.161 - Adobe Systems Incorporated)
Adobe Flash Player 28 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 28.0.0.161 - Adobe Systems Incorporated)
Aid4Mail MBOX Converter (Remove only) (HKLM-x32\...\Aid4Mail MBOX Converter_is1) (Version: 1.0.0.0 - Fookes Holding Ltd)
Apple Application Support (32-bit) (HKLM-x32\...\{F1D83CEA-2855-4224-9935-D981785AA75D}) (Version: 6.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{E2A6344A-45BF-47A0-9AE1-848325E7FD88}) (Version: 6.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BD6778C5-6FA5-492A-ADD6-E706339C2A7B}) (Version: 11.0.2.4 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.)
Bitser (HKLM-x32\...\{9BD25977-657C-421E-8E1B-71773690BE64}) (Version: 1.4.0 - Bitser)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.5.0.0 - Canon Inc.)
Canon IJ Scan Utility (HKLM-x32\...\Canon_IJ_Scan_Utility) (Version:  - Canon Inc.)
Canon MX720 series On-screen Manual (HKLM-x32\...\Canon MX720 series On-screen Manual) (Version: 7.6.0 - Canon Inc.)
Canon MX720 series User Registration (HKLM-x32\...\Canon MX720 series User Registration) (Version:  - ‭Canon Inc.)
Canon MX920 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX920_series) (Version: 1.00 - Canon Inc.)
Canon MX920 series On-screen Manual (HKLM-x32\...\Canon MX920 series On-screen Manual) (Version: 7.6.0 - Canon Inc.)
Canon MX920 series User Registration (HKLM-x32\...\Canon MX920 series User Registration) (Version:  - ‭Canon Inc.)
Canon My Image Garden (HKLM-x32\...\Canon My Image Garden) (Version: 1.1.2 - Canon Inc.)
Canon My Image Garden Design Files (HKLM-x32\...\Canon My Image Garden Design Files) (Version: 1.0.1 - Canon Inc.)
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: 3.1.0 - Canon Inc.)
Canon Quick Menu (HKLM-x32\...\CanonQuickMenu) (Version: 2.1.0 - Canon Inc.)
Canon Speed Dial Utility (HKLM-x32\...\Speed Dial Utility) (Version: 1.3.0 - Canon Inc.)
CCleaner (HKLM\...\CCleaner) (Version: 5.40 - Piriform)
Clone My DVD (HKLM-x32\...\{F27B8353-1F12-4814-B9F2-82A87C438315}) (Version: 1.7.1 - Streamware Development)
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 8.50.4.0 - Conexant)
CyberLink PowerDVD 9.5 (HKLM-x32\...\InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}) (Version: 9.5.1.4418 - CyberLink Corp.)
D3DX10 (HKLM-x32\...\{E09C4DB7-630C-4F06-A631-8EA7239923AF}) (Version: 15.4.2368.0902 - Microsoft) Hidden
Dell DataSafe Online (HKLM-x32\...\{7EC66A95-AC2D-4127-940B-0445A526AB2F}) (Version: 2.1.19634 - Dell)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell MusicStage (HKLM-x32\...\{91AF2672-F5BC-42CF-8037-A9D2F92BBCC0}) (Version: 1.5.201.0 - Fingertapps)
Dell PhotoStage (HKLM-x32\...\{E4335E82-17B3-460F-9E70-39D9BC269DB3}) (Version: 1.5.0.65 - ArcSoft)
Dell Stage (HKLM-x32\...\{39901B4C-E954-4471-ADAB-E786AEE326D1}) (Version: 1.5.420.0 - Fingertapps)
Dell System Detect - 1  (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\73f463568823ebbe) (Version: 6.0.0.14 - Dell)
Dell System Detect (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\9204f5692a8faf3b) (Version: 5.8.1.1 - Dell)
Dell VideoStage  (HKLM-x32\...\{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.) Hidden
Dell VideoStage  (HKLM-x32\...\InstallShield_{DCE0E79A-B9AC-41AC-98C1-7EF0538BCA7F}) (Version: 1.2.0.1712 - CyberLink Corp.)
DirectX 9 Runtime (HKLM-x32\...\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}) (Version: 1.00.0000 - Sonic Solutions) Hidden
Driving Recorder Player (HKLM-x32\...\{4B214065-5C62-4ECA-B99F-D31924006F31}) (Version: 1.0.4989.27635 - Archlink Technology Corporation)
Driving Test Success 2003-2004 (HKLM-x32\...\{27A4C502-AAD6-402F-8A36-63ECB26B67D6}) (Version: 7.01.0001 - Focus Multimedia Ltd)
Dropbox (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\Dropbox) (Version: 2.6.24 - Dropbox, Inc.)
Duplicate Email Remover (HKLM-x32\...\{7AA36634-4324-4EF4-8C0C-D8EF1FC2BEA4}) (Version: 3.1.0 - MAPILab Ltd.)
Easy Duplicate Finder 4 (HKLM\...\{DA060B99-6B87-4D85-8B1A-29BCF6DF2B06}_is1) (Version:  - WebMinds, Inc.)
Everything 1.4.1.895 (x64) (HKLM\...\Everything) (Version: 1.4.1.895 - David Carpenter)
Express Zip File Compression (HKLM-x32\...\ExpressZip) (Version: 3.03 - NCH Software)
Extended Asian Language font pack for Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-2530-0000-AC0F074E4100}) (Version: 15.007.20033 - Adobe Systems Incorporated)
FastStone Image Viewer 4.6 (HKLM-x32\...\FastStone Image Viewer) (Version: 4.6 - FastStone Soft)
Free Opener (HKLM\...\{A1F2C608-32D6-467D-B035-BBEF509042BA}_is1) (Version: 1.0 - EZ Freeware)
Freemake Video Converter version 3.2.1 (HKLM-x32\...\Freemake Video Converter_is1) (Version: 3.2.1 - Ellora Assets Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 64.0.3282.186 - Google Inc.)
Google Earth Pro (HKLM-x32\...\{FA1BBF34-E994-4310-95D7-BE93092B8E61}) (Version: 7.3.1.4507 - Google)
Google Toolbar for Internet Explorer (HKLM-x32\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Google+ Auto Backup (HKLM-x32\...\{A50DE037-B5C0-4C8A-8049-B0C576B313D1}) (Version: 1.0.21.81 - Google)
GWX Control Panel (HKLM-x32\...\UltimateOutsider_GwxControlPanel) (Version:  - UltimateOutsider)
Hazard Perception Training 2003-2004 (HKLM-x32\...\{6112DD9A-2A3B-4487-8271-ADBA4A390287}) (Version: 3.02.00.00 - Focus Multimedia Ltd)
HP450 (HKLM-x32\...\ST6UNST #1) (Version:  - )
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
iCloud (HKLM\...\{EAFB2AD8-D92B-464C-8D97-B9CB94703C4A}) (Version: 3.0.2.163 - Apple Inc.)
InstallConverter bundle uninstaller (HKLM-x32\...\InstallConverter bundle uninstaller) (Version: 2.0.0.5 - InstallConverter)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.4229 - Intel Corporation)
Internet Explorer (Enable DEP) (HKLM\...\{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb) (Version:  - )
iTunes (HKLM\...\{C9355099-E68D-4802-ABB2-03757A1AB4BD}) (Version: 12.7.2.58 - Apple Inc.)
Java 8 Update 151 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180151F0}) (Version: 8.0.1510.12 - Oracle Corporation)
Java 8 Update 162 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180162F0}) (Version: 8.0.1620.12 - Oracle Corporation)
Junk Mail filter update (HKLM-x32\...\{F6F30C28-38AA-4DBA-AE0B-7E30238E61BB}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
K-Lite Codec Pack 7.0.0 (Standard) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 7.0.0 - )
Kodi (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\Kodi) (Version:  - XBMC-Foundation)
LogMeIn (HKLM-x32\...\{976475B8-63E9-4559-BE2C-D26086BE4C40}) (Version: 4.1.2126 - LogMeIn, Inc.)
Malwarebytes version 3.3.1.2183 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.3.1.2183 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft Office 365 - en-us (HKLM\...\O365HomePremRetail - en-us) (Version: 16.0.8431.2215 - Microsoft Corporation)
Microsoft Office 365 ProPlus - en-us (HKLM\...\O365ProPlusRetail - en-us) (Version: 16.0.8431.2215 - Microsoft Corporation)
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-0081-0409-0000-0000000FF1CE}) (Version: 14.0.6123.5001 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\OneDriveSetup.exe) (Version: 18.025.0204.0009 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Support and Recovery Assistant for Office 365 (HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\dacae1bed46e81d5) (Version: 16.0.2146.9 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.40660 (HKLM-x32\...\{ef6b00ec-13e1-4c25-9064-b2f383cb8412}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.40660 (HKLM-x32\...\{61087a79-ac85-455c-934d-1fa22cc64f36}) (Version: 12.0.40660.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.10.25017 (HKLM-x32\...\{d6f233bd-3f8c-43f6-878b-07bd0568d595}) (Version: 14.10.25017.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.10.25017 (HKLM-x32\...\{cb7c3049-21de-415b-bd85-b65c14e547df}) (Version: 14.10.25017.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.0 (HKLM-x32\...\{3898934B-05AE-41CD-96BE-70DA9BFBCE1F}) (Version: 3.0.11010.0 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
MiVue Manager (HKLM-x32\...\{123BDDDC-D02F-4C6E-A011-9CB265E2483E}) (Version: 1.0.30.4 - Mio Technology Corporation)
Movie Maker (HKLM-x32\...\{3C5F91EF-5C0B-4D13-BCBE-0FC6FC3ED7F9}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{45898170-E68C-4F02-AA35-C2186BF347A3}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Movie Maker (HKLM-x32\...\{B39A6825-EA20-43EA-AB2D-A6BC0298D9A1}) (Version: 16.4.3508.0205 - Microsoft Corporation) Hidden
Mozilla Firefox 56.0 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 56.0 (x86 en-GB)) (Version: 56.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 49.0.2 - Mozilla)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Office 16 Click-to-Run Extensibility Component (HKLM-x32\...\{90160000-008C-0000-0000-0000000FF1CE}) (Version: 16.0.8431.2215 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Extensibility Component 64-bit Registration (HKLM\...\{90160000-00DD-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2215 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Licensing Component (HKLM\...\{90160000-008F-0000-1000-0000000FF1CE}) (Version: 16.0.8431.2215 - Microsoft Corporation) Hidden
Office 16 Click-to-Run Localization Component (HKLM-x32\...\{90160000-008C-0409-0000-0000000FF1CE}) (Version: 16.0.8326.2076 - Microsoft Corporation) Hidden
Open Contacts v6 (HKLM-x32\...\{A592374A-82CB-4BB3-A7CB-58D8FABA031F}_is1) (Version: 6 - Fonlow IT)
OutlookTools 2 (HKLM-x32\...\{E69BB189-4B20-46AE-93CF-59099F05FC3F}) (Version: 2.3.0 - HowTo-Outlook)
PDF Creator (HKLM\...\PDF Creator) (Version:  - )
PhotoShowExpress (HKLM-x32\...\{3250260C-7A95-4632-893B-89657EB5545B}) (Version: 2.0.063 - Sonic Solutions) Hidden
Picasa 3 (HKLM-x32\...\Picasa 3) (Version: 3.9 - Google, Inc.)
PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
QuickBooks (HKLM-x32\...\{1D972553-29C8-442F-97F1-136B7F15E7E6}) (Version: 19.0.4004.1100 - Intuit Limited) Hidden
QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)
Rapport (HKLM-x32\...\{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}) (Version: 3.5.1908.137 - Trusteer) Hidden
RBVirtualFolder64Inst (HKLM\...\{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}) (Version: 1.00.0000 - Roxio, Inc.) Hidden
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.14393.31233 - Realtek Semiconductor Corp.)
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Revo Uninstaller 2.0.4 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.4 - VS Revo Group, Ltd.)
RogueKiller version 12.12.7.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.12.7.0 - Adlice Software)
Roxio Creator Starter (HKLM-x32\...\{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}) (Version: 12.1.77.0 - Roxio)
Roxio File Backup (HKLM\...\{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}) (Version: 1.3.2 - Roxio) Hidden
Safari (HKLM-x32\...\{C779648B-410E-4BBA-B75B-5815BCEFE71D}) (Version: 5.34.57.2 - Apple Inc.)
Shockwave (HKLM-x32\...\Shockwave) (Version:  - )
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.151 - Skype Technologies S.A.)
SmoothDraw version 4.0.5 (HKLM-x32\...\SmoothDraw_is1) (Version: 4.0.5 - )
Sonic CinePlayer Decoder Pack (HKLM-x32\...\{9A00EC4E-27E1-42C4-98DD-662F32AC8870}) (Version: 4.3.0 - Sonic Solutions) Hidden
Sophos Anti-Virus (HKLM-x32\...\{2519A41E-5D7C-429B-B2DB-1E943927CB3D}) (Version: 10.7.6.117 - Sophos Limited) Hidden
Sophos AutoUpdate (HKLM-x32\...\{AFBCA1B9-496C-4AE6-98AE-3EA1CFF65C54}) (Version: 5.8.335 - Sophos Limited) Hidden
Sophos Diagnostic Utility (HKLM-x32\...\{4627F5A1-E85A-4394-9DB3-875DF83AF6C2}) (Version: 1.20.0.4 - Sophos Limited) Hidden
Sophos Home (HKLM\...\Sophos Endpoint Agent) (Version: 1.2.11 - Sophos Ltd)
Sophos Home (HKLM-x32\...\{65174B13-CB1D-45A8-8B65-69F87AAAAFEB}) (Version: 2.1.137 - Sophos Limited) Hidden
Sophos Management Communications System (HKLM-x32\...\{2C14E1A2-C4EB-466E-8374-81286D723D3A}) (Version: 4.7.15 - Sophos Limited) Hidden
Sophos Network Threat Protection (HKLM\...\{66967E5F-43E8-4402-87A4-04685EE5C2CB}) (Version: 1.3.2.40 - Sophos Limited) Hidden
Sophos System Protection (HKLM\...\{934BEF80-B9D1-4A86-8B42-D8A6716A8D27}) (Version: 2.6.0.71 - Sophos Limited) Hidden
Sperry Software - Add Email Address (HKLM-x32\...\{D6479B35-26C4-42C1-B5AE-344CF6B53E0F}) (Version: 6.0 - Sperry Software)
Sperry Software - Duplicate Email Eliminator (HKLM-x32\...\{6FB099B2-8981-484A-8161-FF64880B5386}) (Version: 6.0 - Sperry Software)
SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 5.0.1142 - SUPERAntiSpyware.com)
TeamViewer 13 (HKLM-x32\...\TeamViewer) (Version: 13.0.6447 - TeamViewer)
TreeSize Free V4.1.2 (HKLM-x32\...\TreeSize Free_is1) (Version: 4.1.2 - JAM Software)
Trusteer Endpoint Protection (HKLM-x32\...\Rapport_msi) (Version: 3.5.1908.137 - Trusteer)
VideoPad Video Editor (HKLM-x32\...\VideoPad) (Version: 5.03 - NCH Software)
VSDC Free Video Editor version 3.3.0.394 (HKLM-x32\...\VSDC Free Video Editor_is1) (Version: 3.3.0.394 - Flash-Integro LLC)
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 16.4.3508.0205 - Microsoft Corporation)
Windows Mail Recovery v.3.4.0 (HKLM\...\Windows Mail Recovery_is1) (Version:  - Email Adept, Ltd.)
WinZip 22.0 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C24119}) (Version: 22.0.12706 - Corel Corporation)
YouTube2DVD Burner v1.17.0.92 (HKLM-x32\...\{1ADE23D7-7A1E-4AEC-BA5D-EB8A21B1D943}) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-105084621-2470936660-356980580-1001_Classes\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-105084621-2470936660-356980580-1001_Classes\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-105084621-2470936660-356980580-1001_Classes\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
CustomCLSID: HKU\S-1-5-21-105084621-2470936660-356980580-1001_Classes\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 -> C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} =>  -> No File
ContextMenuHandlers1: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll -> No File
ContextMenuHandlers1: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2017-06-30] ()
ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2013-09-15] (Apple Inc.)
ContextMenuHandlers1: [Roxio Burn] -> {E8CB9D53-A47A-42B5-9F5B-96B037C9DD4C} => C:\Program Files\Roxio\Roxio Burn\RB_ContextMenu64.dll [2010-11-11] (TODO: <Company name>)
ContextMenuHandlers1: [SophosHomeShellExt] -> {2FE0F6D6-426A-4728-B435-7CF2FE926449} => C:\Program Files (x86)\Sophos\Sophos Home\SophosHomeShellExtX64.dll [2018-01-04] (Sophos Limited)
ContextMenuHandlers1: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers2: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll -> No File
ContextMenuHandlers2: [SophosHomeShellExt] -> {2FE0F6D6-426A-4728-B435-7CF2FE926449} => C:\Program Files (x86)\Sophos\Sophos Home\SophosHomeShellExtX64.dll [2018-01-04] (Sophos Limited)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers4: [Advanced SystemCare] -> {2803063F-4B8D-4dc6-8874-D1802487FE2D} => C:\Program Files (x86)\IObit\Advanced SystemCare\ASCExtMenu_64.dll -> No File
ContextMenuHandlers4: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers4: [SophosHomeShellExt] -> {2FE0F6D6-426A-4728-B435-7CF2FE926449} => C:\Program Files (x86)\Sophos\Sophos Home\SophosHomeShellExtX64.dll [2018-01-04] (Sophos Limited)
ContextMenuHandlers4: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2015-06-01] (Intel Corporation)
ContextMenuHandlers6: [ExpressZip] -> {8EEA165E-0B8B-4BA7-9796-50214C767171} => C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll [2017-06-30] ()
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-11-01] (Malwarebytes)
ContextMenuHandlers6: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers6: [SophosHomeShellExt] -> {2FE0F6D6-426A-4728-B435-7CF2FE926449} => C:\Program Files (x86)\Sophos\Sophos Home\SophosHomeShellExtX64.dll [2018-01-04] (Sophos Limited)
ContextMenuHandlers6: [WinZip] -> {E0D79304-84BE-11CE-9641-444553540000} => C:\Program Files\WinZip\wzshls64.dll [2017-12-11] (WinZip Computing, S.L.)
ContextMenuHandlers1_S-1-5-21-105084621-2470936660-356980580-1001: [DropboxExt] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ContextMenuHandlers4_S-1-5-21-105084621-2470936660-356980580-1001: [DropboxExt] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
ContextMenuHandlers5_S-1-5-21-105084621-2470936660-356980580-1001: [DropboxExt] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Users\Trevor\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll [2013-09-11] (Dropbox, Inc.)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {01DEB208-5CB9-49CA-B9D4-2A66A30C21FE} - System32\Tasks\GoogleUpdateTaskMachineUA1d1aafe43a2359 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {02F1B9BA-B20C-4DFA-B682-BAF9AAE76D3C} - System32\Tasks\CCleaner Update => C:\Program Files\CCleaner\CCUpdate.exe [2018-02-07] (Piriform Ltd)
Task: {107DB48A-6A1A-43B9-A24C-D48DBBDA32E9} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {14BD9C5A-933E-452C-B2B8-BF4864F52004} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeTime -> No File <==== ATTENTION
Task: {2B269237-692F-4B67-A8FF-16A5C940BDDC} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {2CC4800F-E299-4B71-8837-659624A2CD47} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
Task: {359C111E-5A5F-4351-9D8B-43CC2FA7F016} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-02-23] (Microsoft Corporation)
Task: {376C045B-D53B-40AC-BEB0-5FF70D02A8A5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {38228C4B-631A-4560-BA4D-CA20932D2D8D} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack2016 => C:\Program Files (x86)\Microsoft Office\root\Office16\msoia.exe [2018-02-23] (Microsoft Corporation)
Task: {3DDEDC3A-B8DB-4E09-BDF1-4C2AE7F7F850} - System32\Tasks\{E9A8F2EA-E2E2-41FE-A089-80BCAE05F6BB} => C:\Windows\system32\pcalua.exe -a C:\Users\Trevor\Downloads\QuickBooksUK2010.exe -d C:\Users\Trevor\Desktop
Task: {48ECA183-57BA-4381-B8BC-F005B6F21338} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {50994D35-8AE1-4A0F-BB98-3EF24BC53032} - System32\Tasks\Microsoft\Office\Office ClickToRun Service Monitor => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-02-02] (Microsoft Corporation)
Task: {5D7F99F3-A6A8-4B5D-9E6D-420343E0BC3D} - System32\Tasks\avastBCLRestartS-1-5-21-105084621-2470936660-356980580-1001 => C:\Program Files (x86)\Google\Chrome\Application\chrome.exe 
Task: {6086F0E6-C458-45B4-8933-92DE7CC3D4DA} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {664E79EA-72A5-4BC1-ACB5-BCAB03D9A5B6} - System32\Tasks\Adobe online update program => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {66A24790-9833-4727-B68B-24CADCFDF263} - System32\Tasks\WinZip Update Notifier => C:\Program Files\WinZip\WZUpdateNotifier.exe [2017-12-11] (WinZip)
Task: {7C48027A-1318-4466-97F6-34D8E24131DE} - System32\Tasks\Microsoft\Office\Office Automatic Updates => C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe [2018-02-02] (Microsoft Corporation)
Task: {7E266534-DF67-485C-BE13-A1E9DCE43DBE} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
Task: {7EE846D8-F3B6-4876-A71A-7A07D962E376} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {8A5F5366-E019-4D21-8D6A-60588126935C} - System32\Tasks\Microsoft\Office\Office Subscription Maintenance => C:\Program Files (x86)\Microsoft Office\root\vfs\ProgramFilesCommonx86\Microsoft Shared\Office16\OLicenseHeartbeat.exe [2018-02-23] (Microsoft Corporation)
Task: {8C00DD2D-1500-4E9C-A943-6005D57FC86E} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerRegistration => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-02-23] ()
Task: {8EBF0C94-411C-42A5-9948-8BBF95E570E8} - \Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime -> No File <==== ATTENTION
Task: {8F7AA920-DCFC-470D-8E25-879AE28D4E99} - System32\Tasks\{1B447821-D9F5-415E-9BA3-336A32609963} => C:\Windows\system32\pcalua.exe -a "C:\Users\Trevor\Documents\duplicate_remover\Setup for Outlook 64-bit.exe" -d C:\Users\Trevor\Documents\duplicate_remover
Task: {9D8C629F-582A-4351-8945-8C1F806595C7} - System32\Tasks\Microsoft\Office\OfficeBackgroundTaskHandlerLogon => C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe [2018-02-23] ()
Task: {9E9CC566-77ED-47C1-8416-365D9F26D56C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {BA4A92EB-FA00-41F6-8FF3-53B7EC34231B} - \Microsoft\Windows\Setup\GWXTriggers\OnIdle-5d -> No File <==== ATTENTION
Task: {C57364C9-7241-495D-9FA2-1390EEFF7449} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
Task: {CF847419-9B89-4568-8EAF-70E779B9EC70} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2018-02-07] (Piriform Ltd)
Task: {DBCFE875-5657-486C-BFE8-931172755FD8} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2017-07-24] (Apple Inc.)
Task: {E9E02B38-FBF3-4BBA-9FD4-B39D2D2CCF99} - System32\Tasks\GoogleUpdateTaskMachineCore1d1aafe35676c3 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {F7C1F809-3178-4E3D-B2BB-AA36F9C25206} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {F9F71D54-5180-4DB0-8129-3293224B2AC0} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-02-21] (Adobe Systems Incorporated)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
Shortcut: C:\Users\Trevor\Old_Machine_Recovery\Trevor\NetHood\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.co
Shortcut: C:\Users\Trevor\Favorites\NCH Software Download Site.lnk -> hxxp://www.nchsoftware.com/index.htm
 
==================== Loaded Modules (Whitelisted) ==============
 
2012-04-21 17:44 - 2011-10-04 21:43 - 000087552 _____ () C:\Windows\System32\custmon64i.dll
2017-11-30 18:54 - 2017-11-30 18:54 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2017-11-30 18:54 - 2017-11-30 18:54 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2018-02-23 15:53 - 2018-02-23 15:53 - 008929480 _____ () C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesX64\Microsoft Office\Office16\1033\GrooveIntlResource.dll
2017-06-30 16:26 - 2017-06-30 16:26 - 000105984 _____ () C:\Program Files (x86)\NCH Software\ExpressZip\ezcm64.dll
2017-01-26 17:23 - 2017-01-26 17:23 - 000234336 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\http.plg
2017-01-26 17:23 - 2017-01-26 17:23 - 000141424 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\ip.plg
2017-01-26 17:23 - 2017-01-26 17:23 - 000120072 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\ipv6.plg
2017-01-26 17:23 - 2017-01-26 17:23 - 000077432 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\portmap.plg
2017-01-26 17:23 - 2017-01-26 17:23 - 000165728 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\tcp.plg
2017-01-26 17:23 - 2017-01-26 17:23 - 000149168 _____ () C:\Program Files\Sophos\Sophos Network Threat Protection\bin\plugins\udp.plg
2018-02-23 12:32 - 2018-02-22 03:57 - 004433752 _____ () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.186\libglesv2.dll
2018-02-23 12:32 - 2018-02-22 03:57 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\64.0.3282.186\libegl.dll
2018-03-09 11:00 - 2018-02-09 04:11 - 002199656 _____ () C:\Program Files\Everything\Everything.exe
2013-09-14 01:51 - 2013-09-14 01:51 - 000087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll
2013-09-14 01:50 - 2013-09-14 01:50 - 001242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll
2018-02-23 15:49 - 2018-02-23 15:52 - 001754296 _____ () C:\Program Files (x86)\Microsoft Office\Root\Office16\tmpod.dll
2018-02-23 15:48 - 2018-02-23 15:48 - 001009832 _____ () C:\Program Files (x86)\Microsoft Office\Root\Office16\ADDINS\UmOutlookAddin.dll
2018-02-23 15:58 - 2018-02-23 16:04 - 000537768 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\msfad.dll
2018-02-23 15:58 - 2018-02-23 15:58 - 000094920 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\officevoicemanager.dll
2018-02-23 15:50 - 2018-02-23 15:50 - 000164528 _____ () C:\Program Files (x86)\Microsoft Office\root\Office16\JitV.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SAVService => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LMIRescue_ca296989-8fdc-826d-7ef3-8b1ae0d0b596 => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\PEVSystemStart => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SAVService => ""="service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SntpService => ""="service"
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
IE trusted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\dell.com -> dell.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\008i.com -> 008i.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\008k.com -> 008k.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\00hq.com -> 00hq.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\0190-dialers.com -> 0190-dialers.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\01i.info -> 01i.info
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\02pmnzy5eo29bfk4.com -> 02pmnzy5eo29bfk4.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\05p.com -> 05p.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\07ic5do2myz3vzpk.com -> 07ic5do2myz3vzpk.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\08nigbmwk43i01y6.com -> 08nigbmwk43i01y6.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\093qpeuqpmz6ebfa.com -> 093qpeuqpmz6ebfa.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\0calories.net -> 0calories.net
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\0cj.net -> 0cj.net
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\0scan.com -> 0scan.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\1-britney-spears-nude.com -> 1-britney-spears-nude.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\1-domains-registrations.com -> 1-domains-registrations.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\1-se.com -> 1-se.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\1001movie.com -> 1001movie.com
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\1001night.biz -> 1001night.biz
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\100gal.net -> 100gal.net
IE restricted site: HKU\S-1-5-21-105084621-2470936660-356980580-1001\...\100sexlinks.com -> 100sexlinks.com
 
There are 5977 more sites.
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-14 02:34 - 2016-04-26 18:15 - 000000834 _____ C:\Windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-105084621-2470936660-356980580-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Trevor\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 8.8.8.8 - 192.168.1.254
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: AdobeARMservice => 2
MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3
MSCONFIG\Services: avast! Firewall => 2
MSCONFIG\Services: gupdate => 2
MSCONFIG\Services: gupdatem => 3
MSCONFIG\Services: IEEtwCollectorService => 3
MSCONFIG\Services: IJPLMSVC => 2
MSCONFIG\Services: IObitUnSvr => 2
MSCONFIG\Services: MozillaMaintenance => 3
MSCONFIG\Services: NOBU => 3
MSCONFIG\Services: RapportMgmtService => 2
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk => C:\Windows\pss\QuickBooks Update Agent.lnk.CommonStartup
MSCONFIG\startupreg: AccuWeatherWidget => "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\accuweather.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\AccuWeather\start.umj" --startup
MSCONFIG\startupreg: ApplePhotoStreams => C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: btbb_McciTrayApp => "C:\Program Files\Plusnet Assist\btbb\PlusnetHelpNotifier.exe"
MSCONFIG\startupreg: CanonQuickMenu => C:\Program Files (x86)\Canon\Quick Menu\CNQMMAIN.EXE /logon
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: Dell DataSafe Online => C:\Program Files (x86)\Dell\Dell Datasafe Online\NOBuClient.exe
MSCONFIG\startupreg: DellStage => "C:\Program Files (x86)\Dell Stage\Dell Stage\stage_primary.exe" "C:\Program Files (x86)\Dell Stage\Dell Stage\start.umj" --startup
MSCONFIG\startupreg: GoogleChromeAutoLaunch_06C6E514C4997929D7F8BD1032E95A69 => "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" --no-startup-window /prefetch:5
MSCONFIG\startupreg: GwxControlPanelMonitor => "C:\Program Files (x86)\UltimateOutsider\GWX Control Panel\GWX_control_panel.exe" /traymode                                                                                                                                                                              
MSCONFIG\startupreg: HP Officejet 6500 E710n-z (NET) => "c:\program files\hp\hp officejet 6500 e710n-z\bin\scantopcactivationapp.exe" -deviceid "cn18u3319z05jw:nw" -scfn "hp officejet 6500 e710n-z (net)" -autostart 1
MSCONFIG\startupreg: HP Software Update => c:\program files (x86)\hp\hp software update\hpwuschd2.exe
MSCONFIG\startupreg: Intuit SyncManager => c:\program files (x86)\common files\intuit\sync\intuitsyncmanager.exe  startup
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files\iTunes\iTunesHelper.exe"                                                                                                                                                                                                                               
MSCONFIG\startupreg: LogMeIn GUI => "C:\Program Files (x86)\LogMeIn\x64\LogMeInSystray.exe"
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: RoxWatchTray => c:\program files (x86)\common files\roxio shared\oem\12.0\sharedcom\roxwatchtray12oem.exe
MSCONFIG\startupreg: SDTray => c:\program files (x86)\spybot - search & destroy 2\sdtray.exe
MSCONFIG\startupreg: Sidebar => C:\Program Files\Windows Sidebar\sidebar.exe /autoRun                                                                                                                                                                                                                    
MSCONFIG\startupreg: WinZip FAH => C:\Program Files\WinZip\FAHConsole.exe
MSCONFIG\startupreg: WinZip PreLoader => C:\Program Files\WinZip\WzPreloader.exe
MSCONFIG\startupreg: WinZip UN => C:\Program Files\WinZip\WZUpdateNotifier.exe
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [TelnetServer-Tlntadmn-RPC-In] => (Allow) %systemroot%\system32\tlntsvr.exe
FirewallRules: [TelnetServer-TlntSvr-TCP-In] => (Allow) %systemroot%\system32\tlntsvr.exe
FirewallRules: [{6AE8F0CA-5BC2-4F13-8FF5-1ADF7E745E31}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [TCP Query User{D531A0D4-2184-4495-9C26-63315741FE12}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [UDP Query User{9A5E0ED7-56AD-433D-9987-592987684F4C}C:\program files (x86)\kodi\kodi.exe] => (Allow) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{6EF24EE9-DC0A-4595-A543-29AB9B87A1E9}] => (Block) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{A860E787-3653-4AFC-B0AB-2B32BCFE9D82}] => (Block) C:\program files (x86)\kodi\kodi.exe
FirewallRules: [{2540CF43-7440-474C-A83E-01F8B5107105}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{46026796-B4DC-45F1-B8E7-677968123C36}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{2592959C-45E4-4390-8273-002F5FD0AC67}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{204822D7-38A5-4C20-897E-CF8B2C7F39B8}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{82083090-F011-4FB6-BE72-114D72921FBE}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{9322FF4A-57B5-4B32-9115-18EEAD2E9203}] => (Allow) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
FirewallRules: [{75C880C0-7692-432E-B894-66CB74C8C42C}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\outlook.exe
FirewallRules: [{C0C73CDD-F389-4AE6-ADCF-41342C9F92F1}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
FirewallRules: [{9510879D-2FB7-4F04-8364-3E237AC8DB5E}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{C07B845D-9A18-4CE4-AA29-091E6F1C106D}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{E0989950-B885-4538-A3EC-0671C8ED7216}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{AF1017F7-3F02-40FB-B4F8-D0A0E1275E0A}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{8D0174F1-0BD2-4692-97D0-915EC3DB3433}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{403CE75E-BF75-48DC-AAB4-A6E9FD6A2D2F}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [TCP Query User{8B4499F8-6E79-4699-9843-496D6F4F0ED3}C:\program files (x86)\teamviewer\teamviewer.exe] => (Block) C:\program files (x86)\teamviewer\teamviewer.exe
FirewallRules: [UDP Query User{3216B674-8744-43E9-A2B8-D87E2E717D11}C:\program files (x86)\teamviewer\teamviewer.exe] => (Block) C:\program files (x86)\teamviewer\teamviewer.exe
FirewallRules: [{7591DB91-F95A-4AFC-BDB2-0CEC1A5D936B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{48AC1BEB-B25B-4F76-BF94-FD7BB22A5B6B}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\Lync.exe
FirewallRules: [{9051E6F9-2521-49E1-A05B-3005EA863935}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
FirewallRules: [{A848A89E-A7D4-41A3-B771-0A1CC07EBDDF}] => (Allow) C:\Program Files (x86)\Microsoft Office\root\Office16\UcMapi.exe
 
==================== Restore Points =========================
 
23-02-2018 11:27:31 Removed Microsoft Office Professional Plus 2010
27-02-2018 03:25:09 Windows Update
05-03-2018 17:49:04 Revo Uninstaller's restore point - Advanced SystemCare 11
05-03-2018 17:56:01 Revo Uninstaller's restore point - Avast Cleanup Premium
05-03-2018 17:59:49 Revo Uninstaller's restore point - Canon MX720 series MP Drivers
05-03-2018 18:02:32 Revo Uninstaller's restore point - Canon MX720 series On-screen Manual
05-03-2018 18:06:47 Revo Uninstaller's restore point - Canon Inkjet Printer/Scanner/Fax Extended Survey Program
05-03-2018 18:10:27 Revo Uninstaller's restore point - IObit Uninstaller
05-03-2018 18:13:08 Revo Uninstaller's restore point - System Mechanic
05-03-2018 18:14:21 Removed System Mechanic
05-03-2018 18:17:03 Revo Uninstaller's restore point - Plusnet Assist
06-03-2018 04:11:18 Windows Update
07-03-2018 09:41:11 Restore Point Created by FRST
 
==================== Faulty Device Manager Devices =============
 
Name: Officejet 6500 E710n-z
Description: Officejet 6500 E710n-z
Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318}
Manufacturer: HP
Service: 
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
 
Name: 
Description: 
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (03/08/2018 09:37:41 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (03/07/2018 09:58:51 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/07/2018 09:58:51 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/07/2018 09:47:10 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
 
Error: (03/07/2018 09:39:16 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/07/2018 09:39:16 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
Error: (03/07/2018 12:40:16 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: chrome.exe, version: 64.0.3282.186, time stamp: 0x5a8e38d5
Faulting module name: swi_ifslsp_64.dll_unloaded, version: 0.0.0.0, time stamp: 0x59c8c73f
Exception code: 0xc0000005
Fault offset: 0x000007fefc9a822a
Faulting process id: 0xe28
Faulting application start time: 0x01d3b52833dd8dfc
Faulting application path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
Faulting module path: swi_ifslsp_64.dll
Report Id: 1a092b1c-21a0-11e8-a27c-d067e527daa7
 
Error: (03/06/2018 08:49:36 AM) (Source: SideBySide) (EventID: 35) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\root\Office16\lync.exe.Manifest".Error in manifest or policy file "C:\Program Files (x86)\Microsoft Office\root\Office16\UccApi.DLL" on line 1.
Component identity found in manifest does not match the identity of the component requested.
Reference is UccApi,processorArchitecture="AMD64",type="win32",version="16.0.0.0".
Definition is UccApi,processorArchitecture="x86",type="win32",version="16.0.0.0".
Please use sxstrace.exe for detailed diagnosis.
 
 
System errors:
=============
Error: (03/08/2018 09:39:43 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The HP Network Devices Support service terminated with the following error: 
The system cannot find the file specified.
 
Error: (03/07/2018 09:50:00 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The HP Network Devices Support service terminated with the following error: 
The system cannot find the file specified.
 
Error: (03/07/2018 09:42:12 AM) (Source: Service Control Manager) (EventID: 7032) (User: )
Description: The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Search service, but this action failed with the following error: 
An instance of the service is already running.
 
Error: (03/07/2018 09:41:56 AM) (Source: SAVOnAccess) (EventID: 85) (User: )
Description: File [...\Device\HarddiskVolume3\Windows\SYSTEM32\sechost.dll]'s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process SearchIndexer., (start check timestamp [ 1d3b5f888322b06]).
 
Error: (03/07/2018 09:41:56 AM) (Source: SAVOnAccess) (EventID: 85) (User: )
Description: File [...\Device\HarddiskVolume3\Windows\system32\SearchIndexer.exe]'s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process services.exe, (start check timestamp [ 1d3b5f888264425]).
 
Error: (03/07/2018 09:41:56 AM) (Source: SAVOnAccess) (EventID: 85) (User: )
Description: File [...\Device\HarddiskVolume3\Windows\system32\slc.dll]'s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process FRST64.exe, (start check timestamp [ 1d3b5f888218164]).
 
Error: (03/07/2018 09:41:56 AM) (Source: SAVOnAccess) (EventID: 85) (User: )
Description: File [...\Device\HarddiskVolume3\Windows\system32\cscapi.dll]'s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process FRST64.exe, (start check timestamp [ 1d3b5f888218164]).
 
Error: (03/07/2018 09:41:56 AM) (Source: SAVOnAccess) (EventID: 85) (User: )
Description: File [...\Device\HarddiskVolume3\Windows\system32\srvcli.dll]'s scan succeeded following a timeout/busy condition - it is being logged in case it contributed to that condition. Process FRST64.exe, (start check timestamp [ 1d3b5f8881f2004]).
 
 
Windows Defender:
===================================
Date: 2016-02-16 19:19:44.075
Description: 
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
Name:Program:Win32/Hadsruda!bit
ID:213971
Severity:Medium
Category:Potentially Unwanted Software
Path Found:containerfile:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe;file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000005);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000098);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000103);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000104);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000110);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000111);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000118);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000128);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000130);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000142);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe-
Detection Type:Concrete
Detection Source:System
Status:Unknown
Process Name:
 
Date: 2016-02-15 11:41:12.220
Description: 
Windows Defender has detected spyware or other potentially unwanted software.
For more information please see the following:
Name:Program:Win32/Hadsruda!bit
ID:213971
Severity:Medium
Category:Potentially Unwanted Software
Path Found:containerfile:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe;file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000005);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000098);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000103);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000104);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000110);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000111);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000118);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000128);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000130);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe->(inno#000142);file:C:\Program Files (x86)\IObit\Advanced SystemCare\PatchSetup_A9.exe-
Detection Type:Concrete
Detection Source:System
Status:Unknown
Process Name:
 
Date: 2016-04-30 05:37:07.134
Description: 
%1 engine has been terminated due to an unexpected error.
Failure Type:%5
Exception code:%6
Resource:%3
 
Date: 2016-04-26 16:58:36.527
Description: 
Windows Defender has encountered an error trying to load signatures and will attempt reverting back to a known-good set of signatures.
Signatures Attempted:Current
Error Code:0x80070002
Error description:The system cannot find the file specified. 
Signature version:0.0.0.0
Engine version:0.0.0.0
 
Date: 2016-04-26 16:58:36.527
Description: 
Windows Defender has encountered an error trying to update signatures.
New Signature Version:
Previous Signature Version:
Update Source:Signature Update Folder
Signature Type:AntiSpyware
Update Type:Delta
Current Engine Version:
Previous Engine Version:
Error code:0x80070002
Error description:The system cannot find the file specified. 
 
CodeIntegrity:
===================================
 
Date: 2017-02-27 16:55:45.116
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:55:45.056
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:53:10.229
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:53:10.169
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:51:31.754
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:51:31.704
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:50:15.121
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
Date: 2017-02-27 16:50:15.071
Description: 
Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i3-2120 CPU @ 3.30GHz
Percentage of memory in use: 50%
Total physical RAM: 8104.63 MB
Available physical RAM: 3971.71 MB
Total Virtual: 16207.43 MB
Available Virtual: 12660.32 MB
 
==================== Drives ================================
 
Drive c: (OS) (Fixed) (Total:464.99 GB) (Free:269.53 GB) NTFS
 
\\?\Volume{b99bd4b9-e440-11e0-b8d3-806e6f6e6963}\ (RECOVERY) (Fixed) (Total:0.73 GB) (Free:0.11 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 465.8 GB) (Disk ID: 6580F1A7)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=750 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=465 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================


#15 TJWIL

TJWIL
  • Topic Starter

  • Members
  • 24 posts
  • OFFLINE
  •  
  • Local time:07:17 PM

Posted 09 March 2018 - 08:25 AM

Summary file attached

Attached Files






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users