Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Chuck's computer is moving folders around!


  • This topic is locked This topic is locked
62 replies to this topic

#1 AlaskaRick

AlaskaRick

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:09:42 AM

Posted 08 June 2018 - 11:49 AM

My elderly friend called me with this problem. "My file is gone". I remoted in (via TeamViewer) and showed him how to 'search' for the file instead. No surprise-- the file was there. 

But not in the proper folder. Of course I assumed that he moved them around via user error.

But-- when I went over to his home I realized that something very wrong was indeed going on! Entire folders had moved since I remoted in 2 hours before.

He is an architect and stores his project files in 2 folders --- Group1 and Group2. The reason Chuck could not find his file was because Group2 had moved, and was now inbedded in Group1. Formerly Group1 and Group2 were at the same hierarchal level. I could see how this could have been done via user error.

When I arrived at Chuck home things had changed again! Now Group1/Group2 folder was inbedded in a new folder, "MarcusWelby". The folder MarcusWelby was created minutes before. Chuck recognised the name --- it was the name of a word document-- but was not in any special folder-- was just in MyDocuments.

So-- His computer is not only moving files around but is also creating new folders and moving his older folders into the new!

I have been protecting Chuck with the same as my computers-- I use Malwarebytes and Microsoft's antivirus programs.

Any help is very much appreciated!! Thank you--- Rick

 

 

Chas' computer:

Is a Toshiba laptop running 64 bit Windows 7 .
Using MS Office 2010.
Autocad Lite ver 10.

Protected with Malwarebytes and Microsoft antivirus.

 

I also posted this issue on ------  



BC AdBot (Login to Remove)

 


#2 hamluis

hamluis

    Moderator


  • Moderator
  • 56,560 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:11:42 AM

Posted 08 June 2018 - 12:18 PM

Please...follow the guidance at https://www.bleepingcomputer.com/forums/t/34773/preparation-guide-for-use-before-using-malware-removal-tools-and-requesting-help/ .

 

Thanks ;)  .

 

Louis



#3 AlaskaRick

AlaskaRick
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:09:42 AM

Posted 09 June 2018 - 02:19 PM

Louis ---  Thank you ----  here is the first log----

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06.06.2018 01
Ran by Hawkes (administrator) on HAWKES-WIN7LAP (09-06-2018 10:56:26)
Running from C:\Users\Hawkes\Downloads
Loaded Profiles: Hawkes (Available Profiles: Hawkes & Rick Liotta)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Capital Intellect, Inc.) C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\befrgl.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
() C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
(GlavSoft LLC.) C:\Program Files (x86)\ShowMyPCService\tvnserver.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TBatmgrTrayicon.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
() C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\Teco.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4630 series\Bin\ScanToPCActivationApp.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4630 series\Bin\HPNetworkCommunicatorCom.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 7610 series\Bin\ScanToPCActivationApp.exe
(OLYMPUS IMAGING CORP.) C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\Monitor.exe
(Olympus Corporation) C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(EnTech Taiwan) C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(DTS, Inc.) C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\APO3GUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe
(Capital Intellect, Inc.) C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFHP.exe
() C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
(Carbonite, Inc.) C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\TscHelp.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagitEditor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_w32.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\tv_x64.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
() C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 7610 series\Bin\HPNetworkCommunicatorCom.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoHook.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [] => [X]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13535304 2013-05-07] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3014384 2013-02-06] (Synaptics Incorporated)
HKLM\...\Run: [BatteryManager] => C:\Program Files\TOSHIBA\Power Saver\TBatmgrTrayIcon.EXE [293760 2013-02-20] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [997216 2013-05-07] (TOSHIBA Corporation)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [595840 2012-03-02] ()
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1562032 2012-02-28] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297784 2017-09-11] (Apple Inc.)
HKLM-x32\...\Run: [DTS Sound] => C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\APO3GUI.exe [1471296 2013-05-31] (DTS, Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291280 2012-12-20] (Intel Corporation)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1298816 2011-07-11] (TOSHIBA Corporation)
HKLM-x32\...\Run: [ToshibaAppPlace] => C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe [552960 2010-09-23] (Toshiba)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [77824 2014-04-09] (Apple Computer, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3643712 2018-06-04] (Dropbox, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1183256 2018-02-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [OM_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\FirstStart.exe [40960 2006-05-16] (OLYMPUS IMAGING CORP.)
HKLM-x32\...\Run: [OV3_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe [40400 2017-07-26] (Olympus Corporation)
HKLM-x32\...\Run: [BFHP] => C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFHP.exe [415744 2015-05-21] (Capital Intellect, Inc.)
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [494064 2009-06-18] ()
HKLM-x32\...\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1278568 2018-02-02] (Carbonite, Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [HP Officejet 4630 series (NET)] => C:\Program Files\HP\HP Officejet 4630 series\Bin\ScanToPCActivationApp.exe [3487240 2014-03-06] (Hewlett-Packard Co.)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [EPSON WorkForce 1100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIFEA.EXE [223232 2009-01-06] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [HP Officejet 7610 series (NET)] => C:\Program Files\HP\HP Officejet 7610 series\Bin\ScanToPCActivationApp.exe [2631784 2012-10-21] (Hewlett-Packard Co.)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [OM_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\Monitor.exe [57344 2006-05-16] (OLYMPUS IMAGING CORP.)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [OV3_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe [415696 2017-07-26] (Olympus Corporation)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\MountPoints2: {763e31bb-075b-11e4-9b09-008cfaac16ea} - F:\EasySuite.exe
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\MountPoints2: {763e3206-075b-11e4-9b09-008cfaac16ea} - F:\EasySuite.exe
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\MountPoints2: {89cb0106-4a9a-11e4-814d-008cfaac16ea} - E:\EasySuite.exe
AppInit_DLLs-x32: C:\PROGRA~3\{74BF9~1\1170~1.1\sodi.dll => No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell Display Manager.lnk [2018-05-10]
ShortcutTarget: Dell Display Manager.lnk -> C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe (EnTech Taiwan)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 12.lnk [2015-11-28]
ShortcutTarget: Snagit 12.lnk -> C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe (TechSmith Corporation)
Startup: C:\Users\Hawkes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 7610 series (Network).lnk [2018-06-05]
ShortcutTarget: Monitor Ink Alerts - HP Officejet 7610 series (Network).lnk -> C:\Program Files\HP\HP Officejet 7610 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Rick Liotta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RicksTips.txt [2014-04-05] ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{5701235C-10EE-4FF4-9DC1-3168F65267C0}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{64C90373-4B61-4289-AEEF-D13EC2E23EF3}: [DhcpNameServer] 172.20.10.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131618721239150902&GUID=F590571E-92D7-42F5-AAB1-38EFF20AB6A0
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=befhp&type=iehp-3.19-1702
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=befhp&type=iehp-3.19-1702
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Software\Microsoft\Internet Explorer\Main,Old Start Page = hxxps://www.yahoo.com/
URLSearchHook: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 - (No Name) - {6d010537-9e99-400b-b652-b0d5a5757e5d} - C:\Program Files (x86)\OnlineMapFinder_9p\bar\1.bin\9pSrcAs.dll No File
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> DefaultScope {DAC91F0F-32A8-4E4E-AAB0-3AAD8754257C} URL = hxxp://home.packagesear.ch/search/?et=20170702-ie-s&q={searchTerms}
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {A1FBFE53-F23E-489F-B25D-F2C86D53463B} URL = hxxps://search.yahoo.com/search?p={searchTerms}&b={startPage?}&fr=ie8
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {B99FC9CF-5C6D-4E06-8136-09CEBB3EA2CF} URL = 
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = 
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {CE167512-14D1-42AC-AA95-0D52E094123C} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {DAC91F0F-32A8-4E4E-AAB0-3AAD8754257C} URL = hxxp://home.packagesear.ch/search/?et=20170702-ie-s&q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: BeFrugalIEHelper -> {2335A057-CBA6-40F6-A712-C6A7C98F7813} -> C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFTB.dll [2015-05-21] (Capital Intellect, Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Qualys BrowserCheck IE Helper -> {7D2FB79E-E58C-4DB5-A36F-AC1C73967FA5} -> C:\Windows\Downloaded Program Files\qbc_bho.dll [2016-08-31] (Qualys, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM-x32 - BeFrugal.com Shopping toolbar - {5BA2C4EE-42EF-4E2D-88BE-7271AE4E35B7} - C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFTB.dll [2015-05-21] (Capital Intellect, Inc.)
Toolbar: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D} hxxps://browsercheck.qualys.com/qbc_ax.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-07-18] (Skype Technologies)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-09-28] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-09-28] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-05-10] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-832600199-2139290072-1447759302-1000: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\Hawkes\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-23] (RocketLife, LLP)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default [2018-06-09]
CHR Extension: (Docs) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-03-24]
CHR Extension: (Google Drive) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-24]
CHR Extension: (YouTube) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-24]
CHR Extension: (Adblock Plus) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-05-18]
CHR Extension: (Google Search) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-25]
CHR Extension: (Adobe Acrobat) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-03-27]
CHR Extension: (Google Docs Offline) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-03-24]
CHR Extension: (Skype) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2018-03-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-30]
CHR Extension: (Gmail) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-25]
CHR Extension: (Chrome Media Router) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-09]
CHR HKU\S-1-5-21-832600199-2139290072-1447759302-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-09-07] (Apple Inc.)
R2 BeFrugal.com Service; C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\befrgl.exe [555520 2015-05-21] (Capital Intellect, Inc.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
S2 DbxSvc; C:\windows\system32\DbxSvc.exe [51024 2018-06-04] (Dropbox, Inc.)
R2 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [16720 2013-05-31] ()
S3 FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [1030600 2014-04-02] (Macrovision Europe Ltd.) [File not signed]
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [130592 2012-10-26] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [165488 2012-12-18] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7757552 2018-02-26] (TeamViewer GmbH)
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
R2 tvnserver; C:\Program Files (x86)\ShowMyPCService\tvnserver.exe [815704 2013-11-21] (GlavSoft LLC.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [152184 2018-06-09] (Malwarebytes)
R0 iaStorF; C:\windows\System32\DRIVERS\iaStorF.sys [28656 2013-03-11] (Intel Corporation)
R3 L1C; C:\windows\System32\DRIVERS\L1C62x64.sys [128200 2013-04-03] (Qualcomm Atheros Co., Ltd.)
R2 MBAMChameleon; C:\windows\System32\Drivers\MbamChameleon.sys [190696 2018-06-09] (Malwarebytes)
R3 MBAMFarflt; C:\windows\System32\DRIVERS\farflt.sys [112872 2018-06-09] (Malwarebytes)
R3 MBAMProtection; C:\windows\System32\DRIVERS\mbam.sys [44768 2018-06-09] (Malwarebytes)
R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [253664 2018-06-09] (Malwarebytes)
R3 MBAMWebProtection; C:\windows\System32\DRIVERS\mwac.sys [94840 2018-06-09] (Malwarebytes)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R1 MpKsl37450137; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{3E5CAD96-EBEB-4F65-B05A-F7CEC8F498C7}\MpKsl37450137.sys [58120 2018-06-09] (Microsoft Corporation)
R2 NisDrv; C:\windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R3 RTWlanE; C:\windows\System32\DRIVERS\rtwlane.sys [1480776 2013-02-08] (Realtek Semiconductor Corporation )
S1 RxFilter; C:\Windows\SysWOW64\DRIVERS\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)
R3 SmbDrvI; C:\windows\System32\DRIVERS\Smb_driver_Intel.sys [32496 2013-02-06] (Synaptics Incorporated)
S3 SWDUMon; C:\windows\System32\DRIVERS\SWDUMon.sys [13920 2016-05-22] ()
S3 dbx; system32\DRIVERS\dbx.sys [X]
S0 gufge; System32\drivers\spxncav.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-06-09 10:56 - 2018-06-09 10:58 - 000027185 _____ C:\Users\Hawkes\Downloads\FRST.txt
2018-06-09 10:52 - 2018-06-09 10:56 - 000000000 ____D C:\FRST
2018-06-09 10:50 - 2018-06-09 10:51 - 002413056 _____ (Farbar) C:\Users\Hawkes\Downloads\FRST64.exe
2018-06-09 09:02 - 2018-06-09 09:02 - 000253664 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
2018-06-09 09:02 - 2018-06-09 09:02 - 000190696 _____ (Malwarebytes) C:\windows\system32\Drivers\MbamChameleon.sys
2018-06-09 09:02 - 2018-06-09 09:02 - 000112872 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2018-06-09 09:02 - 2018-06-09 09:02 - 000094840 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2018-06-09 09:02 - 2018-06-09 09:02 - 000044768 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2018-06-07 12:32 - 2018-06-09 09:02 - 000152184 _____ (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys
2018-06-07 12:32 - 2018-06-07 12:32 - 000001878 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-06-07 12:32 - 2018-06-07 12:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-06-06 12:08 - 1997-06-02 12:32 - 000314880 _____ (InstallShield Software Corporation) C:\windows\IsUninst.exe
2018-06-06 10:34 - 2018-06-06 10:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-06-05 11:56 - 2018-06-05 13:00 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b16eafe
2018-06-04 16:41 - 2018-06-04 16:41 - 000002216 _____ C:\Users\Public\Desktop\DWG TrueView 2019 - English.lnk
2018-06-04 02:18 - 2018-06-04 02:18 - 000051024 _____ (Dropbox, Inc.) C:\windows\system32\DbxSvc.exe
2018-06-04 02:18 - 2018-06-04 02:18 - 000050232 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-dev.sys
2018-06-04 02:18 - 2018-06-04 02:18 - 000045672 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-canary.sys
2018-06-04 02:18 - 2018-06-04 02:18 - 000045640 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-stable.sys
2018-05-18 16:48 - 2018-05-18 16:48 - 000000904 _____ C:\windows\Tasks\DropboxUpdateTaskMachineCore1d3ef0b1b588d01.job
2018-05-14 16:56 - 2018-05-14 16:56 - 000002103 _____ C:\Users\Public\Desktop\Carbonite.lnk
2018-05-14 16:56 - 2018-05-14 16:56 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Carbonite
2018-05-11 18:31 - 2018-05-11 18:31 - 017266664 _____ (Carbonite, Inc.) C:\Users\Hawkes\Downloads\CarboniteSetup-personal-client (1).exe
2018-05-11 18:30 - 2018-05-11 18:31 - 017266664 _____ (Carbonite, Inc.) C:\Users\Hawkes\Downloads\CarboniteSetup-personal-client.exe
2018-05-10 09:24 - 2018-05-10 09:24 - 001131552 _____ (EnTech Taiwan ) C:\Users\Hawkes\Downloads\ddmsetup.exe
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-06-09 10:54 - 2009-07-13 20:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-06-09 10:54 - 2009-07-13 20:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-06-08 10:10 - 2014-04-05 17:13 - 000000000 ____D C:\Users\Hawkes\Documents\General Documents
2018-06-08 08:46 - 2014-10-15 16:01 - 000000000 ____D C:\Users\Hawkes\Documents\Outlookfiles2
2018-06-07 20:57 - 2016-01-13 15:43 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-06-07 19:52 - 2015-11-13 18:29 - 000001066 _____ C:\Users\Hawkes\Desktop\Drawings.lnk
2018-06-07 17:06 - 2015-11-13 18:10 - 000000000 ____D C:\Users\Hawkes\Documents\Drawings
2018-06-07 17:05 - 2017-12-21 23:44 - 000000000 ____D C:\Users\Hawkes\Documents\Misc
2018-06-07 14:30 - 2015-02-09 14:28 - 000000000 ____D C:\Users\Hawkes\Documents\ScannedFiles
2018-06-06 14:23 - 2018-03-24 17:48 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-06 14:23 - 2018-03-24 17:48 - 000002154 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-06-06 10:35 - 2015-07-07 20:35 - 000000000 ____D C:\Program Files (x86)\Dropbox
2018-06-05 13:10 - 2009-07-13 21:13 - 000785942 _____ C:\windows\system32\PerfStringBackup.INI
2018-06-05 13:10 - 2009-07-13 19:20 - 000000000 ____D C:\windows\inf
2018-06-05 13:00 - 2015-11-28 17:16 - 000000000 ____D C:\ProgramData\Package Cache
2018-06-05 13:00 - 2014-04-05 17:53 - 000000000 ____D C:\ProgramData\FLEXnet
2018-06-05 13:00 - 2014-04-02 18:36 - 000000000 ____D C:\Program Files\Common Files\Autodesk Shared
2018-06-05 13:00 - 2014-04-02 18:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2018-06-05 13:00 - 2010-11-20 23:16 - 000000000 ___RD C:\Users\Public\Recorded TV
2018-06-05 13:00 - 2009-07-13 19:20 - 000000000 ____D C:\windows\registration
2018-06-05 11:19 - 2015-04-21 18:18 - 000532144 _____ C:\windows\system32\FNTCACHE.DAT
2018-06-04 22:18 - 2015-04-21 17:25 - 000157576 _____ C:\Users\Hawkes\AppData\Local\GDIPFONTCACHEV1.DAT
2018-06-04 22:14 - 2014-04-05 17:13 - 000000000 ____D C:\Users\Hawkes\Documents\Faxes
2018-06-04 16:41 - 2014-04-02 18:36 - 000000000 ____D C:\Users\Hawkes\AppData\Roaming\Autodesk
2018-06-04 16:37 - 2016-10-17 14:47 - 000000000 ____D C:\Users\Public\Documents\Autodesk
2018-06-04 16:37 - 2016-10-17 14:44 - 000000000 ____D C:\Program Files\Autodesk
2018-06-04 16:37 - 2014-04-02 18:36 - 000000000 ____D C:\Users\Hawkes\AppData\Local\Autodesk
2018-06-04 16:37 - 2014-04-02 18:36 - 000000000 ____D C:\ProgramData\Autodesk
2018-05-31 22:20 - 2014-04-05 17:08 - 000000000 ____D C:\Users\Hawkes\Documents\Envelopes
2018-05-29 22:24 - 2016-01-22 12:59 - 000000000 ____D C:\Users\Hawkes\Documents\Project Documents
2018-05-29 20:08 - 2014-04-05 17:13 - 000000000 ____D C:\Users\Hawkes\Documents\Tyson Chang Projects
2018-05-25 02:26 - 2016-10-17 13:43 - 000000000 ____D C:\Autodesk
2018-05-20 12:24 - 2014-09-30 21:24 - 000000000 ____D C:\Users\Hawkes\Documents\Avery Templates
2018-05-15 07:30 - 2015-06-23 13:08 - 000000606 _____ C:\windows\Tasks\Adobe Acrobat Update Task.job
2018-05-15 07:26 - 2016-11-17 12:26 - 000002441 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Acrobat Reader DC.lnk
2018-05-14 16:56 - 2016-04-21 11:18 - 000004554 _____ C:\windows\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4}.job
2018-05-11 15:21 - 2014-04-05 17:08 - 000000000 ____D C:\Users\Hawkes\Documents\Word Documents-LT
2018-05-10 09:28 - 2017-10-07 16:48 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dell Display Manager
2018-05-10 04:05 - 2014-04-04 13:28 - 000000000 ____D C:\windows\system32\MRT
2018-05-10 03:14 - 2017-10-11 03:12 - 141696960 ____C (Microsoft Corporation) C:\windows\system32\MRT-KB890830.exe
2018-05-10 03:13 - 2014-04-06 03:10 - 141696960 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2018-05-10 03:04 - 2013-11-13 21:28 - 000778556 _____ C:\windows\SysWOW64\PerfStringBackup.INI
 
==================== Files in the root of some directories =======
 
2017-08-30 11:54 - 2017-09-30 12:21 - 000004096 ____H () C:\Users\Hawkes\AppData\Local\keyfile3.drm
 
Files to move or delete:
====================
C:\Windows\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4}.job
 
 
Some files in TEMP:
====================
2016-10-17 13:49 - 2018-01-11 00:42 - 000089432 _____ (Autodesk, Inc.) C:\Users\Hawkes\AppData\Local\Temp\AcDeltree.exe
2017-12-20 20:36 - 2017-12-20 20:36 - 000128857 ____T () C:\Users\Hawkes\AppData\Local\Temp\AEV33B0.exe
2017-08-25 20:47 - 2017-08-25 20:47 - 000131237 ____T () C:\Users\Hawkes\AppData\Local\Temp\AEV3CA6.exe
2015-12-08 12:41 - 2015-12-08 12:41 - 000071168 _____ () C:\Users\Hawkes\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp64knui.dll
2016-06-02 14:37 - 2017-06-04 22:16 - 010581280 _____ () C:\Users\Hawkes\AppData\Local\Temp\HPPSdr.exe
2015-07-24 01:58 - 2015-07-24 01:58 - 000000000 _____ () C:\Users\Hawkes\AppData\Local\Temp\ntc8hssa.dll
2016-05-22 14:15 - 2016-05-22 14:15 - 000205656 _____ (SlimWare Utilities, Inc.) C:\Users\Hawkes\AppData\Local\Temp\scp18F7.tmp.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2015-04-18 14:38
 
==================== End of FRST.txt ============================


#4 AlaskaRick

AlaskaRick
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:09:42 AM

Posted 09 June 2018 - 02:21 PM

And here is the second log ------

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06.06.2018 01
Ran by Hawkes (09-06-2018 10:59:25)
Running from C:\Users\Hawkes\Downloads
Windows 7 Home Premium Service Pack 1 (X64) (2014-03-29 15:48:06)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-832600199-2139290072-1447759302-500 - Administrator - Disabled)
Guest (S-1-5-21-832600199-2139290072-1447759302-501 - Limited - Disabled)
Hawkes (S-1-5-21-832600199-2139290072-1447759302-1000 - Administrator - Enabled) => C:\Users\Hawkes
HomeGroupUser$ (S-1-5-21-832600199-2139290072-1447759302-1002 - Limited - Enabled)
Rick Liotta (S-1-5-21-832600199-2139290072-1447759302-1003 - Administrator - Enabled) => C:\Users\Rick Liotta
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20040 - Adobe Systems Incorporated)
Adobe Flash Player 23 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 23.0.0.162 - Adobe Systems Incorporated)
Apple Application Support (32-bit) (HKLM-x32\...\{3D1290E6-1F77-46D5-A715-A56679C8D4E3}) (Version: 6.0.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{D0E45DEC-F4B9-4370-A9DF-66837789C2EF}) (Version: 6.0.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{E3C4B99B-BE71-4C27-8E3C-4FAE3C46E1D5}) (Version: 11.0.0.30 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.)
Audacity 2.0 (HKLM-x32\...\Audacity_is1) (Version:  - Audacity Team)
AutoCAD LT 2010 - English (HKLM\...\{5783F2D7-8009-0409-0102-0060B0CE6BBA}) (Version: 18.0.309.0 - Autodesk) Hidden
AutoCAD LT 2010 - English (HKLM\...\AutoCAD LT 2010 - English) (Version: 18.0.55.0 - Autodesk)
AutoCAD LT 2010 - English Version 3 (HKLM\...\AutoCAD LT 2010 - English Version 3) (Version: 1 - Autodesk)
Autodesk Design Review 2010 (HKLM-x32\...\{55D9E026-DCB0-46FF-B60A-68B972228CF6}) (Version: 10.0.0.108 - Autodesk, Inc.) Hidden
Autodesk Design Review 2010 (HKLM-x32\...\Autodesk Design Review 2010) (Version: 10.0.0.108 - Autodesk, Inc.)
Autodesk DWG TrueView 2017 - English (HKLM\...\DWG TrueView 2017 - English) (Version: 21.0.104.0 - Autodesk)
Autodesk DWG TrueView 2019 - English (HKLM\...\DWG TrueView 2019 - English) (Version: 23.0.46.0 - Autodesk)
BeFrugal.com Shopping toolbar (HKLM-x32\...\{6ADB86DC-7727-492F-865E-A7CAFFABAC72}_is1) (Version: 2013.3.19.3 - BeFrugal.com)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Carbonite (HKLM-x32\...\{ADD4D4D2-4489-43A7-A141-7EDF2C5FB68E}) (Version: 6.3.3 build 7602 (Feb-02-2018) - Carbonite)
Cash Back Assistant (HKLM-x32\...\{9CC676BB-4D00-4E54-9C8E-DE54A1710A80}_is1) (Version: 2013.3.19.3 - BeFrugal.com)
CCleaner (HKLM\...\CCleaner) (Version: 4.07 - Piriform)
CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version:  3.0 - Acro Software Inc.)
Dell Display Manager (HKLM-x32\...\{AC50C05D-9D57-40F5-B2EF-AC402F14312B}_is1) (Version:  - EnTech Taiwan)
DirectX 9 Runtime (HKLM-x32\...\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}) (Version: 1.00.0000 - Sonic Solutions) Hidden
Dropbox (HKLM-x32\...\Dropbox) (Version: 51.4.66 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.75.1 - Dropbox, Inc.) Hidden
DTS Sound (HKLM-x32\...\{791692AD-63B2-4A87-A097-4E8DD3CE4BC9}) (Version: 1.00.0079 - DTS, Inc.)
DWG TrueView 2017 - English (HKLM\...\{28B89EEF-0028-0409-0100-CF3F3A09B77D}) (Version: 21.0.104.0 - Autodesk) Hidden
DWG TrueView 2019 - English (HKLM\...\{28B89EEF-2028-0409-0100-CF3F3A09B77D}) (Version: 23.0.46.0 - Autodesk) Hidden
EMC 10 Content (HKLM-x32\...\{FDB46DE7-9045-47BB-970A-3E4ED5369E03}) (Version: 1.0.035 - Roxo, Inc.) Hidden
EMCGadgets64 (HKLM\...\{02AD9D20-03D2-4DE0-8793-E8253026AD86}) (Version: 1.0.302 - Sonic) Hidden
EPSON WorkForce 1100 Series Printer Uninstall (HKLM\...\EPSON WorkForce 1100 Series) (Version:  - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.79 - Google Inc.)
Google Earth Pro (HKLM-x32\...\{FA1BBF34-E994-4310-95D7-BE93092B8E61}) (Version: 7.3.1.4507 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.123 - Google Inc.) Hidden
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Officejet 4630 series Basic Device Software (HKLM\...\{1EEDD93E-B341-4353-92D6-9A009443C91A}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Officejet 4630 series Help (HKLM-x32\...\{9F79230F-EE1C-407E-94E1-D69021954C9B}) (Version: 31.0.0 - Hewlett Packard)
HP Officejet 7610 series Basic Device Software (HKLM\...\{3507BAF4-20F8-4AAC-8B4B-C61D67607728}) (Version: 29.1.971.39251 - Hewlett-Packard Co.)
HP Officejet 7610 series Help (HKLM-x32\...\{74C894CB-FDE5-4B38-BD3B-C9DE6EC6B698}) (Version: 29.0.0 - Hewlett Packard)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (HKLM-x32\...\{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}) (Version: 1.00.0001 - Microsoft) Hidden
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.30.1349 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3062 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.4.1001 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.7.248 - Intel Corporation)
iTunes (HKLM\...\{94E81D4F-FB5A-4B29-B385-33896CC9BE7E}) (Version: 12.7.0.166 - Apple Inc.)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
LUMIX Simple Viewer (HKLM-x32\...\{2CDCCE7E-55D5-40CC-AEA0-ABA54713501F}) (Version: 0.99.0000 - )
Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810 (HKLM-x32\...\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810 (HKLM-x32\...\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Nero BurnExpress (HKLM-x32\...\{052461A4-7170-40B4-AD39-04475387D1E9}) (Version: 12.5.00700 - Nero AG)
OLYMPUS CAMEDIA Master 4.1 (HKLM-x32\...\{30BB4D60-81DB-11D5-BB77-00400536ABAC}) (Version:  - )
OLYMPUS Digital Camera Updater (HKLM-x32\...\{962428F4-2E99-4AD2-B55D-B468C18A8A89}) (Version: 2.0.0 - Olympus Corporation)
OLYMPUS Master (HKLM-x32\...\{BA820A24-704B-428D-9904-71A10DAC1372}) (Version: 1.42.5000 - OLYMPUS IMAGING CORP.) Hidden
OLYMPUS Master (HKLM-x32\...\InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}) (Version: 1.42.5000 - OLYMPUS IMAGING CORP.)
OLYMPUS Viewer 3 (HKLM-x32\...\{AE1A1FF8-3BF6-444B-AF94-F75084D9AA31}) (Version: 2.1.1 - Olympus Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.1.12.73 - Electronic Arts, Inc.)
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Prerequisite installer (HKLM-x32\...\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0003 - Nero AG) Hidden
Product Improvement Study for HP Officejet 7610 series (HKLM\...\{5637E7AE-B399-4438-A5BA-46C17EB8FC0E}) (Version: 29.1.971.39251 - Hewlett-Packard Co.)
Qualcomm Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.16 - Qualcomm Atheros Communications Inc.)
QuickTime (HKLM-x32\...\QuickTime) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6899 - Realtek Semiconductor Corp.)
Realtek USB Card Reader (HKLM-x32\...\{1E496A68-4943-424E-829D-5C3C85B7B8F2}) (Version: 6.2.9200.39041 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0021 - REALTEK Semiconductor Corp.)
Roxio Easy CD and DVD Burning (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3 - Roxio)
Roxio File Backup (HKLM\...\{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}) (Version: 1.3.0 - Roxio) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
Snagit 12 (HKLM-x32\...\{4FC332FE-CBE3-4AE0-B531-35048FD81912}) (Version: 12.4.1 - TechSmith Corporation) Hidden
Snagit 12 (HKLM-x32\...\{ec29af82-9c9e-420e-ab18-53821c36ac3c}) (Version: 12.4.1.3036 - TechSmith Corporation)
Sonic CinePlayer Decoder Pack (HKLM-x32\...\{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}) (Version: 4.3.0 - Sonic Solutions) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.3.10.4 - Synaptics Incorporated)
TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.93231 - TeamViewer)
Toshiba App Place (HKLM-x32\...\{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}) (Version: 1.0.6.3 - Toshiba)
TOSHIBA Application Installer (HKLM\...\{21A63CA3-75C0-4E56-B602-B7CD2EF6B621}) (Version: 9.0.2.8 - Toshiba Corporation)
TOSHIBA Application Installer (HKLM-x32\...\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.1.2 - TOSHIBA)
TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.2.3.1 - TOSHIBA CORPORATION)
TOSHIBA Battery Check Utility (HKLM-x32\...\{5468E297-7EF8-4CB3-A091-F8714147793F}) (Version: 1.00.04.01 - Toshiba Client Solutions Co., Ltd.)
Toshiba Book Place (HKLM-x32\...\{11244D6B-9842-440F-8579-6A4D771A0D9B}) (Version: 3.3.9661 - K-NFB Reading Technology, Inc.)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.12 for x64 - TOSHIBA Corporation)
TOSHIBA eco Utility (HKLM\...\{F5AFF327-9B52-4E96-B5A0-BD2488A8EEC9}) (Version: 1.3.23.64 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\...\{6D622295-07A8-4CB3-8E0E-6E3D7C782A7B}) (Version: 3.1.0.10 - TOSHIBA Corporation)
TOSHIBA Quality Application (HKLM-x32\...\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.4 - TOSHIBA)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.7.52020010 - TOSHIBA CORPORATION)
TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.15.0 - TOSHIBA)
TOSHIBA Supervisor Password (HKLM-x32\...\{661C3409-C3CC-4869-A0AC-90EAB15F5E93}) (Version: 3.1.0.2 - TOSHIBA Corporation)
TOSHIBA User's Guide (HKLM-x32\...\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.6.0035.6406 - TOSHIBA Corporation)
TOSHIBARegistration (HKLM-x32\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.1.1 - TOSHIBA)
Windows Driver Package - OLYMPUS IMAGING CORP. Camera Communication Driver Package (09/09/2009 1.0.0.0) (HKLM\...\2C1C2F29FADF39F533CEEE67B90F07A5306A4BDB) (Version: 09/09/2009 1.0.0.0 - OLYMPUS IMAGING CORP.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{0C3BA0B1-BC14-4B55-98DC-F1E913C1DA10}\InprocServer32 -> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\ActiveX64.ocx (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\en-US\dwgviewrficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{6FFA7438-3E00-4176-9717-B3BBE2E704AB}\InprocServer32 -> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\ActiveX64.ocx (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\dwgviewr.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{74F5CC00-49A9-11CF-A2F9-444553540000}\InprocServer32 -> C:\Program Files\AutoCAD LT 2010\acadltficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\AutoCAD LT 2010\acadlt.exe (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [    Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [    Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [    Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\system32\AcSignIcon.dll [2018-01-29] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [    Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [    Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [    Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2018-01-29] (Autodesk)
ContextMenuHandlers1-x32: [Autodesk.DWF.ContextMenu] -> {6C18531F-CA85-45F7-8278-FF33CF0A5964} => C:\Program Files (x86)\Common Files\Autodesk Shared\DWF Common\DWFShellExtension.dll [2009-01-13] (Autodesk, Inc.)
ContextMenuHandlers1-x32: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers1-x32: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ContextMenuHandlers1-x32: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers1-x32: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll [2015-08-14] (TechSmith Corporation)
ContextMenuHandlers2: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers4: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers4: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll [2015-08-14] (TechSmith Corporation)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2013-03-08] (Intel Corporation)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0264BE93-D280-45CB-971A-7E31354713CF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-14] (Adobe Systems Incorporated)
Task: {0AD157B5-BC76-46FC-887F-11523B38249A} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.38\SymErr.exe
Task: {24143A82-347B-4C7D-8567-403EDE8F9222} - System32\Tasks\{D9B03117-C71B-4971-9717-DBC801D53489} => "c:\program files\internet explorer\iexplore.exe" hxxp://ui.skype.com/ui/0/6.21.0.104/en/abandoninstall?page=tsBing
Task: {3CEBE34D-B791-47A9-AAB8-2DD921148A31} - System32\Tasks\{165D6118-587D-443B-AAD8-7C049A881C39} => C:\windows\system32\pcalua.exe -a "C:\Users\Hawkes\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6PO75GX5\epson13165 (1).exe" -d C:\Users\Hawkes\Desktop
Task: {508CDD79-3374-468D-970E-2AEC9661A1E5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-21] (Google Inc.)
Task: {69287CB0-8F6A-4B44-9BFD-9C86237D903D} - System32\Tasks\{243D2FEE-8639-40EF-BD86-A0A99A67A997} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [2018-02-02] (Carbonite, Inc.)
Task: {69BF8FCC-500E-48C7-9649-6FD39A19F038} - System32\Tasks\{86CD6B5F-6199-4308-B329-B6449223B9F6} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [2018-02-02] (Carbonite, Inc.)
Task: {6CBEE6CD-C5C5-4C51-BFB8-D8BB9660ADFE} - System32\Tasks\Microsoft\Windows\Setup\gwx\rundetector => C:\windows\system32\GWX\GWXDetector.exe
Task: {7C67E785-E56B-41BB-ABC2-88896B419F48} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\windows\system32\GWX\GWX.exe
Task: {7E94FC44-54A1-4794-B3F8-B069952988E6} - System32\Tasks\{DF9A5375-A07D-49F4-B62A-523ED0737700} => C:\windows\system32\pcalua.exe -a C:\windows\unvise32qt.exe -c C:\windows\system32\QuickTime\Uninstall.log
Task: {8539D9BC-5607-4E45-949D-42B3653F332D} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.38\SymErr.exe
Task: {90683E55-A0B5-43F3-8BAC-EFCDEDB1331C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {977B015E-4952-4F3E-B2BC-7025E28B8E1B} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {9D21A963-3449-4446-BC46-CD4B4D1C77EC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-21] (Piriform Ltd)
Task: {A1CF5F5B-B251-405D-95B2-D4837FB1B100} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {A50D26AD-7504-44E4-8FEF-9510005F7F49} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\windows\system32\GWX\GWXConfigManager.exe
Task: {A6917D9F-C44C-4196-A75B-4914286E9E37} - System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} => C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe
Task: {BD9EF8BD-74FA-44E1-B4F7-6BC50FBA7854} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {BF5B7FF7-66A9-47A8-8F51-5F74B64B2B16} - System32\Tasks\HPCustParticipation HP Officejet 7610 series => C:\Program Files\HP\HP Officejet 7610 series\Bin\HPCustPartic.exe [2012-10-21] (Hewlett-Packard Co.)
Task: {C35535FB-AB09-404C-81B1-E0F017AC16FC} - System32\Tasks\{85772BBC-D792-4D46-ACCF-6A4DC7067956} => C:\windows\system32\pcalua.exe -a "C:\Users\Hawkes\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6PO75GX5\epson13165.exe" -d C:\Users\Hawkes\Desktop
Task: {C464523C-943F-44B9-998E-4334FE1E9E27} - System32\Tasks\{F9DE2CDE-E69A-4BE0-A141-207AE4B2D4C5} => "c:\program files\internet explorer\iexplore.exe" hxxp://ui.skype.com/ui/0/6.21.0.104/et/abandoninstall?page=tsMain
Task: {D8AECD38-57EF-4FA7-96C5-C88EA66B3D90} - System32\Tasks\Microsoft\Windows\Setup\EOONotify => C:\windows\EOONotify\EOONotify.exe
Task: {D9FF95C6-1BA7-48DE-AA47-875660B831E9} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {E0C994AE-F17F-4891-AD17-9133A139C3A6} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfigAndContent
Task: {E0C994AE-F17F-4891-AD17-9133A139C3A6} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(2): C:\windows\system32\GWX\GWXDetector.exe
Task: {E785CFD4-03B2-4CFA-8B6E-74699D9F08A7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\windows\system32\GWX\GWXConfigManager.exe
Task: {F2AF81B1-70C5-498F-87EE-C40C5066EA1A} - System32\Tasks\{7FD564CA-D11F-43F7-B5F3-EC2F12AD5B0E} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [2018-02-02] (Carbonite, Inc.)
Task: {F4946B0F-7618-4A94-95D8-FEAAE88BA7F7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {F4946B0F-7618-4A94-95D8-FEAAE88BA7F7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(2): C:\windows\system32\GWX\GWXDetector.exe
Task: {F93A9CCF-54A6-42F9-ABE9-D65E5E1AFBF7} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {FF339D3F-657D-498A-9AAE-A54FDC0E1263} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-21] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\Adobe Acrobat Update Task.job => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\BeFrugal.com Toolbar.job => C:\Users\Hawkes\AppData\Local\Programs\BeFrugal.com\Add-On\2013.3.19.3\BFHP.exe C:\Users\Hawkes\AppData\Local\Programs\BeFrugal.com\Add-On\2013.3.19.3BeFrugal.com
Task: C:\windows\Tasks\Carbonite Installer - Start Carbonite UI.job => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
Task: C:\windows\Tasks\DropboxUpdateTaskMachineCore1d3ef0b1b588d01.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d12498778f9a0e.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d12cab4234c555.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d15d98e723a1e9.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d1ab0f2d3b04ee.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d1e92df20b6857.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HP AR Program Upload - 27736493983845a3bd75f186d8862cb3b907ccf6bcaa47ea99cb5a5d61296bd8.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 27736493983845a3bd75f186d8862cb3b907ccf6bcaa47ea99cb5a5d61296bd8 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 288a60fccd9e45caaa6c191f699fcc14f9cd3f75b1864fd6b57b53ade8a34577.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 288a60fccd9e45caaa6c191f699fcc14f9cd3f75b1864fd6b57b53ade8a34577 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 288fe57b164c466199f2146b660e8d2752645e0b598f4754b6c2c3ae46e4713d.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 288fe57b164c466199f2146b660e8d2752645e0b598f4754b6c2c3ae46e4713d -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 383f041efd824504bb30bc1595885f2d47a62a47a0d64606b8dde3686841eea2.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 383f041efd824504bb30bc1595885f2d47a62a47a0d64606b8dde3686841eea2 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 4bed420b7c6d4592b5300295af77e4d316a4c156964e425ebb9ce627fa3fe22a.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 4bed420b7c6d4592b5300295af77e4d316a4c156964e425ebb9ce627fa3fe22a -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 9c09867638e1466486681f4201d2fc9c03056bfbeeb041ce93ea16442f54acb3.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 9c09867638e1466486681f4201d2fc9c03056bfbeeb041ce93ea16442f54acb3 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - a79dfbcc00c04a41ad79853178ed3d277881e027f7454645aef2662a8382d747.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N a79dfbcc00c04a41ad79853178ed3d277881e027f7454645aef2662a8382d747 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - abbccb9a521e4840a53914af05ad146bbd601fa958f44975b4ccbdd04b94f7de.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N abbccb9a521e4840a53914af05ad146bbd601fa958f44975b4ccbdd04b94f7de -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - c10ad8feea404f86949259d0615820cdd423f71b28c645e3b248bf4669bb00e1.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N c10ad8feea404f86949259d0615820cdd423f71b28c645e3b248bf4669bb00e1 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - ca517a7e7aec482f807d4d2552d8aca269e7ff6b2037414d8ab933c0cb4f43bc.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N ca517a7e7aec482f807d4d2552d8aca269e7ff6b2037414d8ab933c0cb4f43bc -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - d8c050373ec441009dd181e51c551416408d22ba35554eeaad46c007259a157f.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N d8c050373ec441009dd181e51c551416408d22ba35554eeaad46c007259a157f -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - d920090a1676405f9a759e2cac214230d2dac2c9fae74d6fa5b4f93fef65d00c.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N d920090a1676405f9a759e2cac214230d2dac2c9fae74d6fa5b4f93fef65d00c -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - e2200aa23c4b4d31bfbfe531b31ae1d65219cbde6dbd43a480eea9d8696848cc.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N e2200aa23c4b4d31bfbfe531b31ae1d65219cbde6dbd43a480eea9d8696848cc -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - e3f4e44d23cd4868bfcff04fd6d66f13c150df199dc5411d987a73304d5dda2f.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N e3f4e44d23cd4868bfcff04fd6d66f13c150df199dc5411d987a73304d5dda2f -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - fc7c17da35ec440f9150b71485d2d8b5d325724b3e7142f6bfafe9e654679784.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N fc7c17da35ec440f9150b71485d2d8b5d325724b3e7142f6bfafe9e654679784 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\TechSmith Updater.job => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe
Task: C:\windows\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4}.job => Powershell noexit command carbProgramDataPath env ProgramData \Carbonite Carbonite Backup\ upgradeExe CarboniteUpgrade exe upgradeFullPath carbProgramDataPath upgradeExe logFile CarboniteUpgrade log logFileFullPath carbProgramDataPath logFile psversion string psversiontable PSVersion major string psversiontable PSVersion minor string psversiontable PSVersion build string psversiontable PSVersion revision function LogMsg level message tab char date Get Date format yyyy MM dd HH mm ss ffzzz fullMessage date tab level message Add Content logFileFullPath fullMessage function LogError message write error message LogMsg message function LogWarning message write warning message LogMsg message function LogInfo message write host message LogMsg message LogInfo CarboniteUpgrade ps1 PS version psversion started at Get Date format LogInfo Input args args if test path path upgradeFullPath logStr No upgrade necessary upgradeFullPath not found LogInfo logStr exit expectedSubjectName Carbonite expectedSubjectName2018 Carbonite Inc codeSignStatus get authenticodesignature upgradeFullPath status if codeSignStatus ne Valid errorStr Invalid code signature status codeSignStatus LogError errorStr exit actualSubjectName get authenticodesignature upgradeFullPath signercertificate GetNameInfo SimpleName false if actualSubjectName ne expectedSubjectName and actualSubjectName ne expectedSubjectName2018 errorStr Unexpected certificate subject name actualSubjectName LogError errorStr exit LogInfo Starting upgradeFullPath args start process upgradeFullPath argumentlist args passthru wait verb runas if ExitCode ne errorStr Upgrade exited with error code ExitCode LogError errorStr exit ExitCode LogInfo Upgrade completed exit /silent Arg0 CarboniteBThis task checks for upgrades to Carbonite Please do not delete 08
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-04-11 07:58 - 2013-10-23 14:24 - 000087600 _____ () C:\windows\System32\cpwmon64.dll
2017-09-01 02:49 - 2017-09-01 02:49 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2017-09-01 02:49 - 2017-09-01 02:49 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-05-31 15:56 - 2013-05-31 15:56 - 000016720 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
2010-10-20 15:23 - 2010-10-20 15:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-03-08 19:06 - 2013-03-08 19:06 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-08-22 14:19 - 2011-08-22 14:19 - 011204992 _____ () C:\Program Files\Toshiba\FlashCards\BlackPng.dll
2012-03-02 15:08 - 2012-03-02 15:08 - 000595840 _____ () C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
2010-12-15 15:19 - 2010-12-15 15:19 - 000124320 _____ () C:\Program Files\Toshiba\TECO\MUIHelp.dll
2017-09-11 14:45 - 2017-09-11 14:45 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll
2017-09-11 14:45 - 2017-09-11 14:45 - 000092472 _____ () C:\Program Files\iTunes\zlib1.dll
2009-06-18 22:46 - 2009-06-18 22:46 - 000494064 _____ () C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
2018-06-07 12:32 - 2018-06-09 09:02 - 002297040 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-06-07 12:32 - 2018-06-09 09:02 - 002493648 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2009-06-22 12:36 - 2009-06-22 12:36 - 002677232 _____ () C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe
2018-06-06 14:23 - 2018-06-05 17:25 - 004608856 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.79\libglesv2.dll
2018-06-06 14:23 - 2018-06-05 17:25 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.79\libegl.dll
2017-01-19 10:50 - 2016-08-26 16:41 - 000014848 _____ () C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\Tracer.dll
2017-01-19 10:50 - 2016-05-31 10:41 - 000122880 _____ () C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OlyPalm.dll
2017-01-19 10:50 - 2011-08-09 15:22 - 000450560 _____ () C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OSLite.dll
2015-08-14 11:57 - 2015-08-14 11:57 - 002099200 _____ () C:\Program Files (x86)\TechSmith\Snagit 12\opencv_core249.dll
2015-08-14 11:57 - 2015-08-14 11:57 - 001914368 _____ () C:\Program Files (x86)\TechSmith\Snagit 12\opencv_imgproc249.dll
2014-03-01 22:28 - 2013-01-14 10:25 - 001200088 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\ACE.dll
2018-06-06 10:34 - 2018-06-04 02:18 - 001107272 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2018-06-06 10:34 - 2018-06-04 02:18 - 002079048 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2018-06-06 10:34 - 2018-06-04 02:20 - 000021328 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000022384 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000135656 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 001881448 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000111576 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes35.dll
2018-06-06 10:34 - 2018-06-04 02:18 - 000103392 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000065880 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000079688 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000399832 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom35.dll
2018-06-06 10:34 - 2018-06-04 02:18 - 000024544 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000043496 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000021472 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000124896 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000114664 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000392024 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000028520 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000024552 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000175584 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000024544 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000026080 _____ () C:\Program Files (x86)\Dropbox\Client\win32job.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000048616 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000057824 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000023904 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000022360 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000023392 _____ () C:\Program Files (x86)\Dropbox\Client\crashpad.compiled._Crashpad.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000069992 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 003865936 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000088904 _____ () C:\Program Files (x86)\Dropbox\Client\sip.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 001800528 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 001960272 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000028640 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000155480 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000521552 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000051032 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineCore.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000043352 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000130896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000220504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000205144 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000060896 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000056160 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000024040 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000024424 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000022376 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000028016 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000348128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000024432 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000026464 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000036312 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2018-06-06 10:34 - 2018-06-04 02:21 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.advapi32.compiled._winffi_advapi32.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000181064 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2018-06-06 10:34 - 2018-06-04 02:21 - 000031584 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000024384 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.DLL
2018-06-06 10:34 - 2018-06-04 02:19 - 001638208 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2018-06-06 10:34 - 2018-06-04 02:21 - 000026984 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000546640 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000359760 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.cp35-win32.pyd
2018-05-10 15:12 - 2018-05-10 15:12 - 024030704 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.dll
2018-02-11 14:53 - 2018-02-11 14:53 - 000392688 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\sqlite.dll
2017-07-31 14:31 - 2017-07-31 14:31 - 072940016 _____ () C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\libcef.dll
2009-06-22 12:39 - 2009-06-22 12:39 - 000449008 _____ () C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\MainrENU.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMPCHelper => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tvnserver => ""=""
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Software\Classes\.scr: AutoCADLTScriptFile => C:\windows\system32\notepad.exe "%1"
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 18:34 - 2009-06-10 13:00 - 000000824 _____ C:\windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Hawkes\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 172.20.10.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: SENS => 2
MSCONFIG\Services: Themes => 2
MSCONFIG\Services: WerSvc => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^LUMIX Simple Viewer.lnk => C:\windows\pss\LUMIX Simple Viewer.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Hawkes^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ChaliesTips.txt => C:\windows\pss\ChaliesTips.txt.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: BFHP => C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFHP.exe
MSCONFIG\startupreg: Carbonite Backup => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
MSCONFIG\startupreg: MyTransitGuide AppIntegrator 32-bit => C:\PROGRA~2\MYTRAN~1\bar\1.bin\AppIntegrator.exe
MSCONFIG\startupreg: MyTransitGuide AppIntegrator 64-bit => C:\PROGRA~2\MYTRAN~1\bar\1.bin\AppIntegrator64.exe
MSCONFIG\startupreg: MyTransitGuide EPM Support => "C:\PROGRA~2\MYTRAN~1\bar\1.bin\b7medint.exe" T8EPMSUP.DLL,S
MSCONFIG\startupreg: OnlineMapFinder AppIntegrator 32-bit => C:\PROGRA~2\ONLINE~2\bar\1.bin\AppIntegrator.exe
MSCONFIG\startupreg: OnlineMapFinder AppIntegrator 64-bit => C:\PROGRA~2\ONLINE~2\bar\1.bin\AppIntegrator64.exe
MSCONFIG\startupreg: OnlineMapFinder EPM Support => "C:\PROGRA~2\ONLINE~2\bar\1.bin\9pmedint.exe" T8EPMSUP.DLL,S
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: tvncontrol => "C:\Program Files (x86)\ShowMyPCService\tvnserver.exe" -controlservice -slave
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{D286209D-D47E-4FB2-990B-E5F083ECE2C0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{946D6113-2E42-4915-A9AF-748B5E95AA62}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\bin\FaxApplications.exe
FirewallRules: [{5F441D91-E139-4EE4-99CC-A3DE8A9E2026}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\bin\DigitalWizards.exe
FirewallRules: [{4AEF1F8E-6B65-44A9-8C21-00125FB3C499}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\bin\SendAFax.exe
FirewallRules: [{071924D8-FB41-459C-BAD7-8FC2191F04F4}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\Bin\DeviceSetup.exe
FirewallRules: [{B98F14D0-D6E0-41DC-817F-C8F91BF100D3}] => (Allow) LPort=5357
FirewallRules: [{7C02512E-A74E-49CE-BE18-6EE2537E501A}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{D485610C-2597-495F-963E-B107555D25B6}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\bin\FaxApplications.exe
FirewallRules: [{4E779424-ABBA-496B-9B91-8EF6BF90EF67}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\bin\DigitalWizards.exe
FirewallRules: [{BB47B70E-AFDA-427E-96EC-111CC9DCFCA0}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\bin\SendAFax.exe
FirewallRules: [{A0325101-C835-4182-B593-1CFAF451C694}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\Bin\DeviceSetup.exe
FirewallRules: [{EB25C5FF-1538-4D22-89B2-1573FB3D15E1}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{11EB5D6C-61A2-4ECD-A65B-47270BA64262}] => (Allow) LPort=5357
FirewallRules: [{0E995ABC-3867-4C29-BEBE-E3CB823147E6}] => (Allow) LPort=8298
FirewallRules: [{721FE470-A698-4217-90C6-E443CEB3ADD7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{89AB279E-108C-49A6-AC29-219E345FBF0F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{CF76B23B-0316-4DDB-A457-FA1E6093F24C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{A2F1F44A-F1DC-498E-A6D4-29FBBCEE7C5B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{DF8BB5E6-25CE-45BF-8385-10293BB4D45B}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS0938\HPDiagnosticCoreUI.exe
FirewallRules: [{9CC6951E-0F88-4326-8139-888CF5ED787B}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS0938\HPDiagnosticCoreUI.exe
FirewallRules: [{C4A82124-AA2C-4834-B75E-C87F4F6D4C37}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS09A0\HPDiagnosticCoreUI.exe
FirewallRules: [{45B6719E-3B1F-4944-AE1D-DF23E039676B}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS09A0\HPDiagnosticCoreUI.exe
FirewallRules: [{CD87450E-3D61-47DA-875E-B410F23B0C1E}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6B47\HPDiagnosticCoreUI.exe
FirewallRules: [{EB73A0BB-DFA5-451F-BC37-0018B8DA9BC4}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6B47\HPDiagnosticCoreUI.exe
FirewallRules: [{497DC7D4-A6F3-41E0-9796-02B5065FD6E3}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6BB3\HPDiagnosticCoreUI.exe
FirewallRules: [{94EB7634-7AB6-441F-8386-5174837B9A06}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6BB3\HPDiagnosticCoreUI.exe
FirewallRules: [TCP Query User{D3FD7FA5-EAB9-4BE7-8430-CB22469A7507}C:\program files\adventure pilot\ifly.exe] => (Allow) C:\program files\adventure pilot\ifly.exe
FirewallRules: [UDP Query User{CC1A72EB-D67F-4EF9-B84B-DC97A6553A8E}C:\program files\adventure pilot\ifly.exe] => (Allow) C:\program files\adventure pilot\ifly.exe
FirewallRules: [{D8A9DF54-8423-408A-818E-DD779D830BC5}] => (Block) C:\program files\adventure pilot\ifly.exe
FirewallRules: [{248CEB5B-1F8E-42FE-971D-CFD34214D96E}] => (Block) C:\program files\adventure pilot\ifly.exe
FirewallRules: [{25D49DFA-C110-4F58-89ED-A9511BA4C35B}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{676527A1-FC83-4624-A026-624905FAF165}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{6E747A63-C966-447F-B87D-6A62DEDBE771}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{252D9E02-6606-4899-8E57-E36CD2D56384}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{36CA8E8C-16F6-48E7-A504-DCC355027DE3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{0A20E917-2165-4A08-98BF-8D5D0701F326}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{E49C8126-E34F-48CC-9075-C8B3A559CC4F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
30-01-2018 12:28:35 Windows Update
31-01-2018 03:35:03 Microsoft Antimalware Checkpoint
03-02-2018 01:35:09 Windows Update
06-02-2018 02:19:14 Windows Update
09-02-2018 12:27:59 Windows Update
12-02-2018 12:29:16 Windows Update
14-02-2018 04:05:28 Windows Update
18-02-2018 02:03:32 Windows Update
22-02-2018 02:08:37 Windows Update
25-02-2018 05:00:28 Windows Update
01-03-2018 01:53:56 Windows Update
04-03-2018 02:22:16 Windows Update
07-03-2018 05:01:31 Windows Update
11-03-2018 02:24:42 Windows Update
14-03-2018 03:00:17 Windows Update
17-03-2018 04:01:02 Windows Update
20-03-2018 05:08:10 Microsoft Antimalware Checkpoint
21-03-2018 01:04:44 Windows Update
24-03-2018 01:15:31 Windows Update
28-03-2018 00:36:46 Windows Update
31-03-2018 01:10:51 Windows Update
31-03-2018 03:00:13 Windows Update
04-04-2018 01:13:38 Windows Update
06-04-2018 03:00:13 Windows Update
09-04-2018 03:33:26 Windows Update
12-04-2018 03:00:16 Windows Update
15-04-2018 03:31:36 Windows Update
19-04-2018 01:05:21 Windows Update
22-04-2018 01:26:14 Windows Update
25-04-2018 03:30:42 Windows Update
29-04-2018 01:08:06 Windows Update
02-05-2018 03:31:23 Windows Update
06-05-2018 01:17:38 Windows Update
09-05-2018 03:31:15 Windows Update
10-05-2018 03:00:13 Windows Update
13-05-2018 04:50:49 Windows Update
17-05-2018 00:37:23 Windows Update
20-05-2018 01:08:31 Windows Update
21-05-2018 19:19:05 Microsoft Antimalware Checkpoint
23-05-2018 04:51:00 Windows Update
27-05-2018 00:58:18 Windows Update
30-05-2018 01:03:23 Windows Update
02-06-2018 01:23:47 Windows Update
04-06-2018 16:28:09 Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810
04-06-2018 16:29:24 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026
04-06-2018 16:30:22 Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810
04-06-2018 16:31:38 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026
04-06-2018 16:32:23 Installed DirectX
05-06-2018 12:49:07 Restore Operation
06-06-2018 00:53:42 Windows Update
09-06-2018 10:53:54 About to run BleepingComputer scan
 
==================== Faulty Device Manager Devices =============
 
Name: MpKslc7980628
Description: MpKslc7980628
Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
Manufacturer: 
Service: MpKslc7980628
Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
Devices stay in this state if they have been prepared for removal.
After you remove the device, this error disappears.Remove the device, and this error should be resolved.
 
 
==================== Event log errors: =========================
 
Application errors:
==================
 
System errors:
=============
Error: (03/11/2018 10:12:32 PM) (Source: Service Control Manager) (EventID: 7026) (User: )
Description: The following boot-start or system-start driver(s) failed to load: 
gufge
RxFilter
 
Error: (03/11/2018 10:12:28 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The DbxSvc service failed to start due to the following error: 
The service did not respond to the start or control request in a timely fashion.
 
Error: (03/11/2018 10:12:28 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the DbxSvc service to connect.
 
Error: (03/11/2018 10:12:27 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The Task Scheduler service depends on the Windows Event Log service which failed to start because of the following error: 
The service cannot be started, either because it is disabled or because it has no enabled devices associated with it.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i3-3110M CPU @ 2.40GHz
Percentage of memory in use: 66%
Total physical RAM: 6026.36 MB
Available physical RAM: 2037.14 MB
Total Virtual: 15063.52 MB
Available Virtual: 10983.54 MB
 
==================== Drives ================================
 
Drive c: (TI10668700I) (Fixed) (Total:919.09 GB) (Free:715.42 GB) NTFS ==>[system with boot components (obtained from drive)]
 
\\?\Volume{75ee4344-a1d2-11e3-a5c4-806e6f6e6963}\ (System) (Fixed) (Total:1.46 GB) (Free:1.24 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 624B2B4D)
Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Not Active) - (Size=919.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=11 GB) - (Type=17)
 
==================== End of Addition.txt ============================


#5 HelpBot

HelpBot

    Bleepin' Binary Bot


  • Bots
  • 12,769 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:01:42 PM

Posted 13 June 2018 - 11:50 AM

Hello and welcome to Bleeping Computer!

I am HelpBot: an automated program designed to help the Bleeping Computer Staff better assist you! This message contains very important information, so please read through all of it before doing anything.

We apologize for the delay in responding to your request for help. Here at Bleeping Computer we get overwhelmed at times, and we are trying our best to keep up. Please note that your topic was not intentionally overlooked. Our mission is to help everyone in need, but sometimes it takes just a little longer to get to every request for help. No one is ignored here.

To help Bleeping Computer better assist you please perform the following steps:

***************************************************

step1.gif In order to continue receiving help at BleepingComputer.com, YOU MUST tell me if you still need help or if your issue has already been resolved on your own or through another resource! To tell me this, please click on the following link and follow the instructions there.

CLICK THIS LINK >>> https://www.bleepingcomputer.com/logreply/678785 <<< CLICK THIS LINK



If you no longer need help, then all you needed to do was the previous instructions of telling me so. You can skip the rest of this post. If you do need help please continue with Step 2 below.

***************************************************

step2.gifIf you still need help, I would like you to post a Reply to this topic (click the "Add Reply" button in the lower right hand of this page). In that reply, please include the following information:

  • If you have not done so already, include a clear description of the problems you're having, along with any steps you may have performed so far.
  • A new FRST log. For your convenience, you will find the instructions for generating these logs repeated at the bottom of this post.
    • Please do this even if you have previously posted logs for us.
    • If you were unable to produce the logs originally please try once more.
    • If you are unable to create a log please provide detailed information about your installed Windows Operating System including the Version, Edition and if it is a 32bit or a 64bit system.
    • If you are unsure about any of these characteristics just post what you can and we will guide you.
  • Please tell us if you have your original Windows CD/DVD available.
  • Upon completing the above steps and posting a reply, another staff member will review your topic and do their best to resolve your issues.

Thank you for your patience, and again sorry for the delay.

***************************************************

We need to see some information about what is happening in your machine. Please perform the following scan again:

  • Download FRST by Farbar from the following link if you no longer have it available and save it to your destop.

    FRST Download Link

  • When you go to the above page, there will be 32-bit and 64-bit downloads available. Please click on the appropriate one for your version of Windows. If you are unsure as to whether your Windows is 32-bit or 64-bit, please see this tutorial.
  • Double click on the FRST icon and allow it to run.
  • Agree to the usage agreement and FRST will open. Do not make any changes and click on the Scan button.
  • Notepad will open with the results.
  • Post the new logs as explained in the prep guide.
  • Close the program window, and delete the program from your desktop.


As I am just a silly little program running on the BleepingComputer.com servers, please do not send me private messages as I do not know how to read and reply to them! Thanks!

#6 AlaskaRick

AlaskaRick
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:09:42 AM

Posted 13 June 2018 - 02:06 PM

Yes we still need help!

 

I am unable to run your scans again-- im in the middle of Resurrection Bay, Alaska.  Will be home tomorrow and will run scans on Chuck's laptop then.

 

Thank you!  Rick



#7 AlaskaRick

AlaskaRick
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:09:42 AM

Posted 15 June 2018 - 05:23 PM

I am back at Chuck's laptop and here is first scan-----

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 06.06.2018 01
Ran by Hawkes (administrator) on HAWKES-WIN7LAP (15-06-2018 14:07:12)
Running from C:\Users\Hawkes\Desktop\ricksfolder\BleepingComputer\FRST
Loaded Profiles: Hawkes (Available Profiles: Hawkes & Rick Liotta)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Capital Intellect, Inc.) C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\befrgl.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
() C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TBatmgrTrayicon.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
() C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\Teco.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(GlavSoft LLC.) C:\Program Files (x86)\ShowMyPCService\tvnserver.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoService.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4630 series\Bin\ScanToPCActivationApp.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 7610 series\Bin\ScanToPCActivationApp.exe
(OLYMPUS IMAGING CORP.) C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\Monitor.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 7610 series\Bin\HPNetworkCommunicatorCom.exe
(Olympus Corporation) C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe
(EnTech Taiwan) C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(DTS, Inc.) C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\APO3GUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Capital Intellect, Inc.) C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFHP.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe
() C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
(Carbonite, Inc.) C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\TscHelp.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagitEditor.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroRd32.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AcroCEF\RdrCEF.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4630 series\Bin\HPNetworkCommunicatorCom.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoHook.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [] => [X]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13535304 2013-05-07] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3014384 2013-02-06] (Synaptics Incorporated)
HKLM\...\Run: [BatteryManager] => C:\Program Files\TOSHIBA\Power Saver\TBatmgrTrayIcon.EXE [293760 2013-02-20] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [997216 2013-05-07] (TOSHIBA Corporation)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [595840 2012-03-02] ()
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1562032 2012-02-28] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297784 2017-09-11] (Apple Inc.)
HKLM-x32\...\Run: [DTS Sound] => C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\APO3GUI.exe [1471296 2013-05-31] (DTS, Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291280 2012-12-20] (Intel Corporation)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1298816 2011-07-11] (TOSHIBA Corporation)
HKLM-x32\...\Run: [ToshibaAppPlace] => C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe [552960 2010-09-23] (Toshiba)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [77824 2014-04-09] (Apple Computer, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3643712 2018-06-04] (Dropbox, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1183256 2018-02-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [OM_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\FirstStart.exe [40960 2006-05-16] (OLYMPUS IMAGING CORP.)
HKLM-x32\...\Run: [OV3_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe [40400 2017-07-26] (Olympus Corporation)
HKLM-x32\...\Run: [BFHP] => C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFHP.exe [415744 2015-05-21] (Capital Intellect, Inc.)
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [494064 2009-06-18] ()
HKLM-x32\...\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1278568 2018-02-02] (Carbonite, Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [HP Officejet 4630 series (NET)] => C:\Program Files\HP\HP Officejet 4630 series\Bin\ScanToPCActivationApp.exe [3487240 2014-03-06] (Hewlett-Packard Co.)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [EPSON WorkForce 1100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIFEA.EXE [223232 2009-01-06] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [HP Officejet 7610 series (NET)] => C:\Program Files\HP\HP Officejet 7610 series\Bin\ScanToPCActivationApp.exe [2631784 2012-10-21] (Hewlett-Packard Co.)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [OM_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\Monitor.exe [57344 2006-05-16] (OLYMPUS IMAGING CORP.)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [OV3_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe [415696 2017-07-26] (Olympus Corporation)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\MountPoints2: {763e31bb-075b-11e4-9b09-008cfaac16ea} - F:\EasySuite.exe
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\MountPoints2: {763e3206-075b-11e4-9b09-008cfaac16ea} - F:\EasySuite.exe
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\MountPoints2: {89cb0106-4a9a-11e4-814d-008cfaac16ea} - E:\EasySuite.exe
AppInit_DLLs-x32: C:\PROGRA~3\{74BF9~1\1170~1.1\sodi.dll => No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell Display Manager.lnk [2018-05-10]
ShortcutTarget: Dell Display Manager.lnk -> C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe (EnTech Taiwan)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 12.lnk [2015-11-28]
ShortcutTarget: Snagit 12.lnk -> C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe (TechSmith Corporation)
Startup: C:\Users\Hawkes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 7610 series (Network).lnk [2018-06-14]
ShortcutTarget: Monitor Ink Alerts - HP Officejet 7610 series (Network).lnk -> C:\Program Files\HP\HP Officejet 7610 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Rick Liotta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RicksTips.txt [2014-04-05] ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{5701235C-10EE-4FF4-9DC1-3168F65267C0}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{64C90373-4B61-4289-AEEF-D13EC2E23EF3}: [DhcpNameServer] 172.20.10.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131618721239150902&GUID=F590571E-92D7-42F5-AAB1-38EFF20AB6A0
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=befhp&type=iehp-3.19-1702
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=befhp&type=iehp-3.19-1702
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Software\Microsoft\Internet Explorer\Main,Old Start Page = hxxps://www.yahoo.com/
URLSearchHook: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 - (No Name) - {6d010537-9e99-400b-b652-b0d5a5757e5d} - C:\Program Files (x86)\OnlineMapFinder_9p\bar\1.bin\9pSrcAs.dll No File
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> DefaultScope {DAC91F0F-32A8-4E4E-AAB0-3AAD8754257C} URL = hxxp://home.packagesear.ch/search/?et=20170702-ie-s&q={searchTerms}
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {A1FBFE53-F23E-489F-B25D-F2C86D53463B} URL = hxxps://search.yahoo.com/search?p={searchTerms}&b={startPage?}&fr=ie8
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {B99FC9CF-5C6D-4E06-8136-09CEBB3EA2CF} URL = 
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = 
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {CE167512-14D1-42AC-AA95-0D52E094123C} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {DAC91F0F-32A8-4E4E-AAB0-3AAD8754257C} URL = hxxp://home.packagesear.ch/search/?et=20170702-ie-s&q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: BeFrugalIEHelper -> {2335A057-CBA6-40F6-A712-C6A7C98F7813} -> C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFTB.dll [2015-05-21] (Capital Intellect, Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Qualys BrowserCheck IE Helper -> {7D2FB79E-E58C-4DB5-A36F-AC1C73967FA5} -> C:\Windows\Downloaded Program Files\qbc_bho.dll [2016-08-31] (Qualys, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM-x32 - BeFrugal.com Shopping toolbar - {5BA2C4EE-42EF-4E2D-88BE-7271AE4E35B7} - C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFTB.dll [2015-05-21] (Capital Intellect, Inc.)
Toolbar: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D} hxxps://browsercheck.qualys.com/qbc_ax.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-07-18] (Skype Technologies)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-09-28] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-09-28] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-05-10] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-832600199-2139290072-1447759302-1000: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\Hawkes\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-23] (RocketLife, LLP)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default [2018-06-15]
CHR Extension: (Docs) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-03-24]
CHR Extension: (Google Drive) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-24]
CHR Extension: (YouTube) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-24]
CHR Extension: (Adblock Plus) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-05-18]
CHR Extension: (Google Search) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-25]
CHR Extension: (Adobe Acrobat) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-03-27]
CHR Extension: (Google Docs Offline) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-03-24]
CHR Extension: (Skype) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2018-03-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-30]
CHR Extension: (Gmail) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-25]
CHR Extension: (Chrome Media Router) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-09]
CHR HKU\S-1-5-21-832600199-2139290072-1447759302-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-09-07] (Apple Inc.)
R2 BeFrugal.com Service; C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\befrgl.exe [555520 2015-05-21] (Capital Intellect, Inc.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
R2 DbxSvc; C:\windows\system32\DbxSvc.exe [51024 2018-06-04] (Dropbox, Inc.)
R2 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [16720 2013-05-31] ()
S3 FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [1030600 2014-04-02] (Macrovision Europe Ltd.) [File not signed]
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [130592 2012-10-26] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [165488 2012-12-18] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7757552 2018-02-26] (TeamViewer GmbH)
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
R2 tvnserver; C:\Program Files (x86)\ShowMyPCService\tvnserver.exe [815704 2013-11-21] (GlavSoft LLC.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [152184 2018-06-09] (Malwarebytes)
R0 iaStorF; C:\windows\System32\DRIVERS\iaStorF.sys [28656 2013-03-11] (Intel Corporation)
R3 L1C; C:\windows\System32\DRIVERS\L1C62x64.sys [128200 2013-04-03] (Qualcomm Atheros Co., Ltd.)
R2 MBAMChameleon; C:\windows\System32\Drivers\MbamChameleon.sys [190696 2018-06-09] (Malwarebytes)
R3 MBAMFarflt; C:\windows\System32\DRIVERS\farflt.sys [112872 2018-06-14] (Malwarebytes)
R3 MBAMProtection; C:\windows\System32\DRIVERS\mbam.sys [44768 2018-06-14] (Malwarebytes)
R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [253664 2018-06-14] (Malwarebytes)
R3 MBAMWebProtection; C:\windows\System32\DRIVERS\mwac.sys [94840 2018-06-15] (Malwarebytes)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R2 NisDrv; C:\windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R3 RTWlanE; C:\windows\System32\DRIVERS\rtwlane.sys [1480776 2013-02-08] (Realtek Semiconductor Corporation )
S1 RxFilter; C:\Windows\SysWOW64\DRIVERS\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)
R3 SmbDrvI; C:\windows\System32\DRIVERS\Smb_driver_Intel.sys [32496 2013-02-06] (Synaptics Incorporated)
S3 SWDUMon; C:\windows\System32\DRIVERS\SWDUMon.sys [13920 2016-05-22] ()
S3 dbx; system32\DRIVERS\dbx.sys [X]
S0 gufge; System32\drivers\spxncav.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-06-15 08:46 - 2018-06-15 08:46 - 000000000 ____D C:\Users\Hawkes\Documents\Book Place
2018-06-09 10:52 - 2018-06-15 14:07 - 000000000 ____D C:\FRST
2018-06-09 09:02 - 2018-06-15 10:35 - 000094840 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2018-06-09 09:02 - 2018-06-14 20:02 - 000253664 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
2018-06-09 09:02 - 2018-06-14 20:02 - 000112872 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2018-06-09 09:02 - 2018-06-14 20:02 - 000044768 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2018-06-09 09:02 - 2018-06-09 09:02 - 000190696 _____ (Malwarebytes) C:\windows\system32\Drivers\MbamChameleon.sys
2018-06-07 12:32 - 2018-06-09 09:02 - 000152184 _____ (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys
2018-06-07 12:32 - 2018-06-07 12:32 - 000001878 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-06-07 12:32 - 2018-06-07 12:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-06-06 12:08 - 1997-06-02 12:32 - 000314880 _____ (InstallShield Software Corporation) C:\windows\IsUninst.exe
2018-06-06 10:34 - 2018-06-06 10:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-06-05 11:56 - 2018-06-05 13:00 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b16eafe
2018-06-04 16:41 - 2018-06-04 16:41 - 000002216 _____ C:\Users\Public\Desktop\DWG TrueView 2019 - English.lnk
2018-06-04 02:18 - 2018-06-04 02:18 - 000051024 _____ (Dropbox, Inc.) C:\windows\system32\DbxSvc.exe
2018-06-04 02:18 - 2018-06-04 02:18 - 000050232 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-dev.sys
2018-06-04 02:18 - 2018-06-04 02:18 - 000045672 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-canary.sys
2018-06-04 02:18 - 2018-06-04 02:18 - 000045640 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-stable.sys
2018-05-18 16:48 - 2018-05-18 16:48 - 000000904 _____ C:\windows\Tasks\DropboxUpdateTaskMachineCore1d3ef0b1b588d01.job
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-06-15 14:05 - 2016-01-13 16:00 - 000000000 ____D C:\Users\Hawkes\Desktop\ricksfolder
2018-06-15 14:04 - 2014-10-15 16:01 - 000000000 ____D C:\Users\Hawkes\Documents\Outlookfiles2
2018-06-15 13:51 - 2013-11-13 22:56 - 000000830 _____ C:\windows\Tasks\Adobe Flash Player Updater.job
2018-06-15 11:07 - 2018-03-24 17:48 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-15 11:07 - 2018-03-24 17:48 - 000002154 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-06-15 10:23 - 2009-07-13 20:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-06-15 10:23 - 2009-07-13 20:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-06-14 21:55 - 2009-07-13 19:20 - 000000000 ____D C:\windows\rescache
2018-06-14 21:54 - 2015-07-24 01:26 - 000000000 ____D C:\Users\Hawkes\AppData\Local\ElevatedDiagnostics
2018-06-14 20:07 - 2009-07-13 21:13 - 000785942 _____ C:\windows\system32\PerfStringBackup.INI
2018-06-14 20:07 - 2009-07-13 19:20 - 000000000 ____D C:\windows\inf
2018-06-14 20:02 - 2015-11-21 12:09 - 000000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2018-06-14 20:01 - 2009-07-13 21:09 - 000000000 ____D C:\windows\System32\Tasks\WPD
2018-06-14 20:00 - 2009-07-13 21:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
2018-06-08 10:10 - 2014-04-05 17:13 - 000000000 ____D C:\Users\Hawkes\Documents\General Documents
2018-06-07 20:57 - 2016-01-13 15:43 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-06-07 19:52 - 2015-11-13 18:29 - 000001066 _____ C:\Users\Hawkes\Desktop\Drawings.lnk
2018-06-07 17:06 - 2015-11-13 18:10 - 000000000 ____D C:\Users\Hawkes\Documents\Drawings
2018-06-07 17:05 - 2017-12-21 23:44 - 000000000 ____D C:\Users\Hawkes\Documents\Misc
2018-06-07 14:30 - 2015-02-09 14:28 - 000000000 ____D C:\Users\Hawkes\Documents\ScannedFiles
2018-06-06 10:35 - 2015-07-07 20:35 - 000000000 ____D C:\Program Files (x86)\Dropbox
2018-06-05 13:00 - 2015-11-28 17:16 - 000000000 ____D C:\ProgramData\Package Cache
2018-06-05 13:00 - 2014-04-05 17:53 - 000000000 ____D C:\ProgramData\FLEXnet
2018-06-05 13:00 - 2014-04-02 18:36 - 000000000 ____D C:\Program Files\Common Files\Autodesk Shared
2018-06-05 13:00 - 2014-04-02 18:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2018-06-05 13:00 - 2010-11-20 23:16 - 000000000 ___RD C:\Users\Public\Recorded TV
2018-06-05 13:00 - 2009-07-13 19:20 - 000000000 ____D C:\windows\registration
2018-06-05 11:19 - 2015-04-21 18:18 - 000532144 _____ C:\windows\system32\FNTCACHE.DAT
2018-06-04 22:18 - 2015-04-21 17:25 - 000157576 _____ C:\Users\Hawkes\AppData\Local\GDIPFONTCACHEV1.DAT
2018-06-04 22:14 - 2014-04-05 17:13 - 000000000 ____D C:\Users\Hawkes\Documents\Faxes
2018-06-04 16:41 - 2014-04-02 18:36 - 000000000 ____D C:\Users\Hawkes\AppData\Roaming\Autodesk
2018-06-04 16:37 - 2016-10-17 14:47 - 000000000 ____D C:\Users\Public\Documents\Autodesk
2018-06-04 16:37 - 2016-10-17 14:44 - 000000000 ____D C:\Program Files\Autodesk
2018-06-04 16:37 - 2014-04-02 18:36 - 000000000 ____D C:\Users\Hawkes\AppData\Local\Autodesk
2018-06-04 16:37 - 2014-04-02 18:36 - 000000000 ____D C:\ProgramData\Autodesk
2018-05-31 22:20 - 2014-04-05 17:08 - 000000000 ____D C:\Users\Hawkes\Documents\Envelopes
2018-05-29 22:24 - 2016-01-22 12:59 - 000000000 ____D C:\Users\Hawkes\Documents\Project Documents
2018-05-29 20:08 - 2014-04-05 17:13 - 000000000 ____D C:\Users\Hawkes\Documents\Tyson Chang Projects
2018-05-25 02:26 - 2016-10-17 13:43 - 000000000 ____D C:\Autodesk
2018-05-20 12:24 - 2014-09-30 21:24 - 000000000 ____D C:\Users\Hawkes\Documents\Avery Templates
 
==================== Files in the root of some directories =======
 
2017-08-30 11:54 - 2017-09-30 12:21 - 000004096 ____H () C:\Users\Hawkes\AppData\Local\keyfile3.drm
 
Files to move or delete:
====================
C:\Windows\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4}.job
 
 
Some files in TEMP:
====================
2016-10-17 13:49 - 2018-01-11 00:42 - 000089432 _____ (Autodesk, Inc.) C:\Users\Hawkes\AppData\Local\Temp\AcDeltree.exe
2017-12-20 20:36 - 2017-12-20 20:36 - 000128857 ____T () C:\Users\Hawkes\AppData\Local\Temp\AEV33B0.exe
2017-08-25 20:47 - 2017-08-25 20:47 - 000131237 ____T () C:\Users\Hawkes\AppData\Local\Temp\AEV3CA6.exe
2015-12-08 12:41 - 2015-12-08 12:41 - 000071168 _____ () C:\Users\Hawkes\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp64knui.dll
2016-06-02 14:37 - 2017-06-04 22:16 - 010581280 _____ () C:\Users\Hawkes\AppData\Local\Temp\HPPSdr.exe
2015-07-24 01:58 - 2015-07-24 01:58 - 000000000 _____ () C:\Users\Hawkes\AppData\Local\Temp\ntc8hssa.dll
2016-05-22 14:15 - 2016-05-22 14:15 - 000205656 _____ (SlimWare Utilities, Inc.) C:\Users\Hawkes\AppData\Local\Temp\scp18F7.tmp.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-06-14 21:47
 
==================== End of FRST.txt ============================


#8 AlaskaRick

AlaskaRick
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:09:42 AM

Posted 15 June 2018 - 05:24 PM

and here is second scan------

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 06.06.2018 01
Ran by Hawkes (15-06-2018 14:08:31)
Running from C:\Users\Hawkes\Desktop\ricksfolder\BleepingComputer\FRST
Windows 7 Home Premium Service Pack 1 (X64) (2014-03-29 15:48:06)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-832600199-2139290072-1447759302-500 - Administrator - Disabled)
Guest (S-1-5-21-832600199-2139290072-1447759302-501 - Limited - Disabled)
Hawkes (S-1-5-21-832600199-2139290072-1447759302-1000 - Administrator - Enabled) => C:\Users\Hawkes
HomeGroupUser$ (S-1-5-21-832600199-2139290072-1447759302-1002 - Limited - Enabled)
Rick Liotta (S-1-5-21-832600199-2139290072-1447759302-1003 - Administrator - Enabled) => C:\Users\Rick Liotta
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20040 - Adobe Systems Incorporated)
Adobe Flash Player 23 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 23.0.0.162 - Adobe Systems Incorporated)
Apple Application Support (32-bit) (HKLM-x32\...\{3D1290E6-1F77-46D5-A715-A56679C8D4E3}) (Version: 6.0.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{D0E45DEC-F4B9-4370-A9DF-66837789C2EF}) (Version: 6.0.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{E3C4B99B-BE71-4C27-8E3C-4FAE3C46E1D5}) (Version: 11.0.0.30 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.)
Audacity 2.0 (HKLM-x32\...\Audacity_is1) (Version:  - Audacity Team)
AutoCAD LT 2010 - English (HKLM\...\{5783F2D7-8009-0409-0102-0060B0CE6BBA}) (Version: 18.0.309.0 - Autodesk) Hidden
AutoCAD LT 2010 - English (HKLM\...\AutoCAD LT 2010 - English) (Version: 18.0.55.0 - Autodesk)
AutoCAD LT 2010 - English Version 3 (HKLM\...\AutoCAD LT 2010 - English Version 3) (Version: 1 - Autodesk)
Autodesk Design Review 2010 (HKLM-x32\...\{55D9E026-DCB0-46FF-B60A-68B972228CF6}) (Version: 10.0.0.108 - Autodesk, Inc.) Hidden
Autodesk Design Review 2010 (HKLM-x32\...\Autodesk Design Review 2010) (Version: 10.0.0.108 - Autodesk, Inc.)
Autodesk DWG TrueView 2017 - English (HKLM\...\DWG TrueView 2017 - English) (Version: 21.0.104.0 - Autodesk)
Autodesk DWG TrueView 2019 - English (HKLM\...\DWG TrueView 2019 - English) (Version: 23.0.46.0 - Autodesk)
BeFrugal.com Shopping toolbar (HKLM-x32\...\{6ADB86DC-7727-492F-865E-A7CAFFABAC72}_is1) (Version: 2013.3.19.3 - BeFrugal.com)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Carbonite (HKLM-x32\...\{ADD4D4D2-4489-43A7-A141-7EDF2C5FB68E}) (Version: 6.3.3 build 7602 (Feb-02-2018) - Carbonite)
Cash Back Assistant (HKLM-x32\...\{9CC676BB-4D00-4E54-9C8E-DE54A1710A80}_is1) (Version: 2013.3.19.3 - BeFrugal.com)
CCleaner (HKLM\...\CCleaner) (Version: 4.07 - Piriform)
CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version:  3.0 - Acro Software Inc.)
Dell Display Manager (HKLM-x32\...\{AC50C05D-9D57-40F5-B2EF-AC402F14312B}_is1) (Version:  - EnTech Taiwan)
DirectX 9 Runtime (HKLM-x32\...\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}) (Version: 1.00.0000 - Sonic Solutions) Hidden
Dropbox (HKLM-x32\...\Dropbox) (Version: 51.4.66 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.75.1 - Dropbox, Inc.) Hidden
DTS Sound (HKLM-x32\...\{791692AD-63B2-4A87-A097-4E8DD3CE4BC9}) (Version: 1.00.0079 - DTS, Inc.)
DWG TrueView 2017 - English (HKLM\...\{28B89EEF-0028-0409-0100-CF3F3A09B77D}) (Version: 21.0.104.0 - Autodesk) Hidden
DWG TrueView 2019 - English (HKLM\...\{28B89EEF-2028-0409-0100-CF3F3A09B77D}) (Version: 23.0.46.0 - Autodesk) Hidden
EMC 10 Content (HKLM-x32\...\{FDB46DE7-9045-47BB-970A-3E4ED5369E03}) (Version: 1.0.035 - Roxo, Inc.) Hidden
EMCGadgets64 (HKLM\...\{02AD9D20-03D2-4DE0-8793-E8253026AD86}) (Version: 1.0.302 - Sonic) Hidden
EPSON WorkForce 1100 Series Printer Uninstall (HKLM\...\EPSON WorkForce 1100 Series) (Version:  - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.87 - Google Inc.)
Google Earth Pro (HKLM-x32\...\{FA1BBF34-E994-4310-95D7-BE93092B8E61}) (Version: 7.3.1.4507 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.123 - Google Inc.) Hidden
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Officejet 4630 series Basic Device Software (HKLM\...\{1EEDD93E-B341-4353-92D6-9A009443C91A}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Officejet 4630 series Help (HKLM-x32\...\{9F79230F-EE1C-407E-94E1-D69021954C9B}) (Version: 31.0.0 - Hewlett Packard)
HP Officejet 7610 series Basic Device Software (HKLM\...\{3507BAF4-20F8-4AAC-8B4B-C61D67607728}) (Version: 29.1.971.39251 - Hewlett-Packard Co.)
HP Officejet 7610 series Help (HKLM-x32\...\{74C894CB-FDE5-4B38-BD3B-C9DE6EC6B698}) (Version: 29.0.0 - Hewlett Packard)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (HKLM-x32\...\{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}) (Version: 1.00.0001 - Microsoft) Hidden
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.30.1349 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3062 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.4.1001 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.7.248 - Intel Corporation)
iTunes (HKLM\...\{94E81D4F-FB5A-4B29-B385-33896CC9BE7E}) (Version: 12.7.0.166 - Apple Inc.)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
LUMIX Simple Viewer (HKLM-x32\...\{2CDCCE7E-55D5-40CC-AEA0-ABA54713501F}) (Version: 0.99.0000 - )
Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810 (HKLM-x32\...\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810 (HKLM-x32\...\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Nero BurnExpress (HKLM-x32\...\{052461A4-7170-40B4-AD39-04475387D1E9}) (Version: 12.5.00700 - Nero AG)
OLYMPUS CAMEDIA Master 4.1 (HKLM-x32\...\{30BB4D60-81DB-11D5-BB77-00400536ABAC}) (Version:  - )
OLYMPUS Digital Camera Updater (HKLM-x32\...\{962428F4-2E99-4AD2-B55D-B468C18A8A89}) (Version: 2.0.0 - Olympus Corporation)
OLYMPUS Master (HKLM-x32\...\{BA820A24-704B-428D-9904-71A10DAC1372}) (Version: 1.42.5000 - OLYMPUS IMAGING CORP.) Hidden
OLYMPUS Master (HKLM-x32\...\InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}) (Version: 1.42.5000 - OLYMPUS IMAGING CORP.)
OLYMPUS Viewer 3 (HKLM-x32\...\{AE1A1FF8-3BF6-444B-AF94-F75084D9AA31}) (Version: 2.1.1 - Olympus Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.1.12.73 - Electronic Arts, Inc.)
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Prerequisite installer (HKLM-x32\...\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0003 - Nero AG) Hidden
Product Improvement Study for HP Officejet 7610 series (HKLM\...\{5637E7AE-B399-4438-A5BA-46C17EB8FC0E}) (Version: 29.1.971.39251 - Hewlett-Packard Co.)
Qualcomm Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.16 - Qualcomm Atheros Communications Inc.)
QuickTime (HKLM-x32\...\QuickTime) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6899 - Realtek Semiconductor Corp.)
Realtek USB Card Reader (HKLM-x32\...\{1E496A68-4943-424E-829D-5C3C85B7B8F2}) (Version: 6.2.9200.39041 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0021 - REALTEK Semiconductor Corp.)
Roxio Easy CD and DVD Burning (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3 - Roxio)
Roxio File Backup (HKLM\...\{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}) (Version: 1.3.0 - Roxio) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
Snagit 12 (HKLM-x32\...\{4FC332FE-CBE3-4AE0-B531-35048FD81912}) (Version: 12.4.1 - TechSmith Corporation) Hidden
Snagit 12 (HKLM-x32\...\{ec29af82-9c9e-420e-ab18-53821c36ac3c}) (Version: 12.4.1.3036 - TechSmith Corporation)
Sonic CinePlayer Decoder Pack (HKLM-x32\...\{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}) (Version: 4.3.0 - Sonic Solutions) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.3.10.4 - Synaptics Incorporated)
TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.93231 - TeamViewer)
Toshiba App Place (HKLM-x32\...\{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}) (Version: 1.0.6.3 - Toshiba)
TOSHIBA Application Installer (HKLM\...\{21A63CA3-75C0-4E56-B602-B7CD2EF6B621}) (Version: 9.0.2.8 - Toshiba Corporation)
TOSHIBA Application Installer (HKLM-x32\...\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.1.2 - TOSHIBA)
TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.2.3.1 - TOSHIBA CORPORATION)
TOSHIBA Battery Check Utility (HKLM-x32\...\{5468E297-7EF8-4CB3-A091-F8714147793F}) (Version: 1.00.04.01 - Toshiba Client Solutions Co., Ltd.)
Toshiba Book Place (HKLM-x32\...\{11244D6B-9842-440F-8579-6A4D771A0D9B}) (Version: 3.3.9661 - K-NFB Reading Technology, Inc.)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.12 for x64 - TOSHIBA Corporation)
TOSHIBA eco Utility (HKLM\...\{F5AFF327-9B52-4E96-B5A0-BD2488A8EEC9}) (Version: 1.3.23.64 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\...\{6D622295-07A8-4CB3-8E0E-6E3D7C782A7B}) (Version: 3.1.0.10 - TOSHIBA Corporation)
TOSHIBA Quality Application (HKLM-x32\...\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.4 - TOSHIBA)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.7.52020010 - TOSHIBA CORPORATION)
TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.15.0 - TOSHIBA)
TOSHIBA Supervisor Password (HKLM-x32\...\{661C3409-C3CC-4869-A0AC-90EAB15F5E93}) (Version: 3.1.0.2 - TOSHIBA Corporation)
TOSHIBA User's Guide (HKLM-x32\...\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.6.0035.6406 - TOSHIBA Corporation)
TOSHIBARegistration (HKLM-x32\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.1.1 - TOSHIBA)
Windows Driver Package - OLYMPUS IMAGING CORP. Camera Communication Driver Package (09/09/2009 1.0.0.0) (HKLM\...\2C1C2F29FADF39F533CEEE67B90F07A5306A4BDB) (Version: 09/09/2009 1.0.0.0 - OLYMPUS IMAGING CORP.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{0C3BA0B1-BC14-4B55-98DC-F1E913C1DA10}\InprocServer32 -> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\ActiveX64.ocx (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\en-US\dwgviewrficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{6FFA7438-3E00-4176-9717-B3BBE2E704AB}\InprocServer32 -> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\ActiveX64.ocx (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\dwgviewr.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{74F5CC00-49A9-11CF-A2F9-444553540000}\InprocServer32 -> C:\Program Files\AutoCAD LT 2010\acadltficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\AutoCAD LT 2010\acadlt.exe (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [    Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [    Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [    Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\system32\AcSignIcon.dll [2018-01-29] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [    Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [    Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [    Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2018-01-29] (Autodesk)
ContextMenuHandlers1-x32: [Autodesk.DWF.ContextMenu] -> {6C18531F-CA85-45F7-8278-FF33CF0A5964} => C:\Program Files (x86)\Common Files\Autodesk Shared\DWF Common\DWFShellExtension.dll [2009-01-13] (Autodesk, Inc.)
ContextMenuHandlers1-x32: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers1-x32: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ContextMenuHandlers1-x32: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers1-x32: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll [2015-08-14] (TechSmith Corporation)
ContextMenuHandlers2: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers4: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers4: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll [2015-08-14] (TechSmith Corporation)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-04] (Dropbox, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2013-03-08] (Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0264BE93-D280-45CB-971A-7E31354713CF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-09-14] (Adobe Systems Incorporated)
Task: {0AD157B5-BC76-46FC-887F-11523B38249A} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.38\SymErr.exe
Task: {24143A82-347B-4C7D-8567-403EDE8F9222} - System32\Tasks\{D9B03117-C71B-4971-9717-DBC801D53489} => "c:\program files\internet explorer\iexplore.exe" hxxp://ui.skype.com/ui/0/6.21.0.104/en/abandoninstall?page=tsBing
Task: {3CEBE34D-B791-47A9-AAB8-2DD921148A31} - System32\Tasks\{165D6118-587D-443B-AAD8-7C049A881C39} => C:\windows\system32\pcalua.exe -a "C:\Users\Hawkes\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6PO75GX5\epson13165 (1).exe" -d C:\Users\Hawkes\Desktop
Task: {508CDD79-3374-468D-970E-2AEC9661A1E5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-21] (Google Inc.)
Task: {69287CB0-8F6A-4B44-9BFD-9C86237D903D} - System32\Tasks\{243D2FEE-8639-40EF-BD86-A0A99A67A997} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [2018-02-02] (Carbonite, Inc.)
Task: {69BF8FCC-500E-48C7-9649-6FD39A19F038} - System32\Tasks\{86CD6B5F-6199-4308-B329-B6449223B9F6} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [2018-02-02] (Carbonite, Inc.)
Task: {6CBEE6CD-C5C5-4C51-BFB8-D8BB9660ADFE} - System32\Tasks\Microsoft\Windows\Setup\gwx\rundetector => C:\windows\system32\GWX\GWXDetector.exe
Task: {7C67E785-E56B-41BB-ABC2-88896B419F48} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\windows\system32\GWX\GWX.exe
Task: {7E94FC44-54A1-4794-B3F8-B069952988E6} - System32\Tasks\{DF9A5375-A07D-49F4-B62A-523ED0737700} => C:\windows\system32\pcalua.exe -a C:\windows\unvise32qt.exe -c C:\windows\system32\QuickTime\Uninstall.log
Task: {8539D9BC-5607-4E45-949D-42B3653F332D} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.38\SymErr.exe
Task: {90683E55-A0B5-43F3-8BAC-EFCDEDB1331C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {977B015E-4952-4F3E-B2BC-7025E28B8E1B} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {9D21A963-3449-4446-BC46-CD4B4D1C77EC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-21] (Piriform Ltd)
Task: {A1CF5F5B-B251-405D-95B2-D4837FB1B100} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {A50D26AD-7504-44E4-8FEF-9510005F7F49} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\windows\system32\GWX\GWXConfigManager.exe
Task: {A6917D9F-C44C-4196-A75B-4914286E9E37} - System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} => C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe
Task: {BD9EF8BD-74FA-44E1-B4F7-6BC50FBA7854} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {BF5B7FF7-66A9-47A8-8F51-5F74B64B2B16} - System32\Tasks\HPCustParticipation HP Officejet 7610 series => C:\Program Files\HP\HP Officejet 7610 series\Bin\HPCustPartic.exe [2012-10-21] (Hewlett-Packard Co.)
Task: {C35535FB-AB09-404C-81B1-E0F017AC16FC} - System32\Tasks\{85772BBC-D792-4D46-ACCF-6A4DC7067956} => C:\windows\system32\pcalua.exe -a "C:\Users\Hawkes\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6PO75GX5\epson13165.exe" -d C:\Users\Hawkes\Desktop
Task: {C464523C-943F-44B9-998E-4334FE1E9E27} - System32\Tasks\{F9DE2CDE-E69A-4BE0-A141-207AE4B2D4C5} => "c:\program files\internet explorer\iexplore.exe" hxxp://ui.skype.com/ui/0/6.21.0.104/et/abandoninstall?page=tsMain
Task: {D9FF95C6-1BA7-48DE-AA47-875660B831E9} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {E0C994AE-F17F-4891-AD17-9133A139C3A6} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfigAndContent
Task: {E0C994AE-F17F-4891-AD17-9133A139C3A6} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(2): C:\windows\system32\GWX\GWXDetector.exe
Task: {E785CFD4-03B2-4CFA-8B6E-74699D9F08A7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\windows\system32\GWX\GWXConfigManager.exe
Task: {F2AF81B1-70C5-498F-87EE-C40C5066EA1A} - System32\Tasks\{7FD564CA-D11F-43F7-B5F3-EC2F12AD5B0E} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [2018-02-02] (Carbonite, Inc.)
Task: {F4946B0F-7618-4A94-95D8-FEAAE88BA7F7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {F4946B0F-7618-4A94-95D8-FEAAE88BA7F7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(2): C:\windows\system32\GWX\GWXDetector.exe
Task: {F93A9CCF-54A6-42F9-ABE9-D65E5E1AFBF7} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {FF339D3F-657D-498A-9AAE-A54FDC0E1263} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-21] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\Adobe Acrobat Update Task.job => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\windows\Tasks\BeFrugal.com Toolbar.job => C:\Users\Hawkes\AppData\Local\Programs\BeFrugal.com\Add-On\2013.3.19.3\BFHP.exe C:\Users\Hawkes\AppData\Local\Programs\BeFrugal.com\Add-On\2013.3.19.3BeFrugal.com
Task: C:\windows\Tasks\Carbonite Installer - Start Carbonite UI.job => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
Task: C:\windows\Tasks\DropboxUpdateTaskMachineCore1d3ef0b1b588d01.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d12498778f9a0e.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d12cab4234c555.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d15d98e723a1e9.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d1ab0f2d3b04ee.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d1e92df20b6857.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HP AR Program Upload - 27736493983845a3bd75f186d8862cb3b907ccf6bcaa47ea99cb5a5d61296bd8.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 27736493983845a3bd75f186d8862cb3b907ccf6bcaa47ea99cb5a5d61296bd8 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 288a60fccd9e45caaa6c191f699fcc14f9cd3f75b1864fd6b57b53ade8a34577.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 288a60fccd9e45caaa6c191f699fcc14f9cd3f75b1864fd6b57b53ade8a34577 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 288fe57b164c466199f2146b660e8d2752645e0b598f4754b6c2c3ae46e4713d.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 288fe57b164c466199f2146b660e8d2752645e0b598f4754b6c2c3ae46e4713d -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 383f041efd824504bb30bc1595885f2d47a62a47a0d64606b8dde3686841eea2.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 383f041efd824504bb30bc1595885f2d47a62a47a0d64606b8dde3686841eea2 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 4bed420b7c6d4592b5300295af77e4d316a4c156964e425ebb9ce627fa3fe22a.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 4bed420b7c6d4592b5300295af77e4d316a4c156964e425ebb9ce627fa3fe22a -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 9c09867638e1466486681f4201d2fc9c03056bfbeeb041ce93ea16442f54acb3.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 9c09867638e1466486681f4201d2fc9c03056bfbeeb041ce93ea16442f54acb3 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - a79dfbcc00c04a41ad79853178ed3d277881e027f7454645aef2662a8382d747.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N a79dfbcc00c04a41ad79853178ed3d277881e027f7454645aef2662a8382d747 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - abbccb9a521e4840a53914af05ad146bbd601fa958f44975b4ccbdd04b94f7de.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N abbccb9a521e4840a53914af05ad146bbd601fa958f44975b4ccbdd04b94f7de -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - c10ad8feea404f86949259d0615820cdd423f71b28c645e3b248bf4669bb00e1.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N c10ad8feea404f86949259d0615820cdd423f71b28c645e3b248bf4669bb00e1 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - ca517a7e7aec482f807d4d2552d8aca269e7ff6b2037414d8ab933c0cb4f43bc.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N ca517a7e7aec482f807d4d2552d8aca269e7ff6b2037414d8ab933c0cb4f43bc -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - d8c050373ec441009dd181e51c551416408d22ba35554eeaad46c007259a157f.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N d8c050373ec441009dd181e51c551416408d22ba35554eeaad46c007259a157f -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - d920090a1676405f9a759e2cac214230d2dac2c9fae74d6fa5b4f93fef65d00c.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N d920090a1676405f9a759e2cac214230d2dac2c9fae74d6fa5b4f93fef65d00c -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - e2200aa23c4b4d31bfbfe531b31ae1d65219cbde6dbd43a480eea9d8696848cc.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N e2200aa23c4b4d31bfbfe531b31ae1d65219cbde6dbd43a480eea9d8696848cc -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - e3f4e44d23cd4868bfcff04fd6d66f13c150df199dc5411d987a73304d5dda2f.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N e3f4e44d23cd4868bfcff04fd6d66f13c150df199dc5411d987a73304d5dda2f -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - fc7c17da35ec440f9150b71485d2d8b5d325724b3e7142f6bfafe9e654679784.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N fc7c17da35ec440f9150b71485d2d8b5d325724b3e7142f6bfafe9e654679784 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\TechSmith Updater.job => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe
Task: C:\windows\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4}.job => Powershell noexit command carbProgramDataPath env ProgramData \Carbonite Carbonite Backup\ upgradeExe CarboniteUpgrade exe upgradeFullPath carbProgramDataPath upgradeExe logFile CarboniteUpgrade log logFileFullPath carbProgramDataPath logFile psversion string psversiontable PSVersion major string psversiontable PSVersion minor string psversiontable PSVersion build string psversiontable PSVersion revision function LogMsg level message tab char date Get Date format yyyy MM dd HH mm ss ffzzz fullMessage date tab level message Add Content logFileFullPath fullMessage function LogError message write error message LogMsg message function LogWarning message write warning message LogMsg message function LogInfo message write host message LogMsg message LogInfo CarboniteUpgrade ps1 PS version psversion started at Get Date format LogInfo Input args args if test path path upgradeFullPath logStr No upgrade necessary upgradeFullPath not found LogInfo logStr exit expectedSubjectName Carbonite expectedSubjectName2018 Carbonite Inc codeSignStatus get authenticodesignature upgradeFullPath status if codeSignStatus ne Valid errorStr Invalid code signature status codeSignStatus LogError errorStr exit actualSubjectName get authenticodesignature upgradeFullPath signercertificate GetNameInfo SimpleName false if actualSubjectName ne expectedSubjectName and actualSubjectName ne expectedSubjectName2018 errorStr Unexpected certificate subject name actualSubjectName LogError errorStr exit LogInfo Starting upgradeFullPath args start process upgradeFullPath argumentlist args passthru wait verb runas if ExitCode ne errorStr Upgrade exited with error code ExitCode LogError errorStr exit ExitCode LogInfo Upgrade completed exit /silent Arg0 CarboniteBThis task checks for upgrades to Carbonite Please do not delete 08
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-04-11 07:58 - 2013-10-23 14:24 - 000087600 _____ () C:\windows\System32\cpwmon64.dll
2017-09-01 02:49 - 2017-09-01 02:49 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2017-09-01 02:49 - 2017-09-01 02:49 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-05-31 15:56 - 2013-05-31 15:56 - 000016720 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
2010-10-20 15:23 - 2010-10-20 15:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-03-08 19:06 - 2013-03-08 19:06 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-08-22 14:19 - 2011-08-22 14:19 - 011204992 _____ () C:\Program Files\Toshiba\FlashCards\BlackPng.dll
2012-03-02 15:08 - 2012-03-02 15:08 - 000595840 _____ () C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
2010-12-15 15:19 - 2010-12-15 15:19 - 000124320 _____ () C:\Program Files\Toshiba\TECO\MUIHelp.dll
2018-06-07 12:32 - 2018-06-09 09:02 - 002297040 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-06-07 12:32 - 2018-06-09 09:02 - 002493648 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2017-09-11 14:45 - 2017-09-11 14:45 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll
2017-09-11 14:45 - 2017-09-11 14:45 - 000092472 _____ () C:\Program Files\iTunes\zlib1.dll
2009-06-18 22:46 - 2009-06-18 22:46 - 000494064 _____ () C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
2018-06-06 14:23 - 2018-06-05 17:25 - 004608856 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.79\libglesv2.dll
2018-06-06 14:23 - 2018-06-05 17:25 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.79\libegl.dll
2017-01-19 10:50 - 2016-08-26 16:41 - 000014848 _____ () C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\Tracer.dll
2017-01-19 10:50 - 2016-05-31 10:41 - 000122880 _____ () C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OlyPalm.dll
2017-01-19 10:50 - 2011-08-09 15:22 - 000450560 _____ () C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OSLite.dll
2015-08-14 11:57 - 2015-08-14 11:57 - 002099200 _____ () C:\Program Files (x86)\TechSmith\Snagit 12\opencv_core249.dll
2015-08-14 11:57 - 2015-08-14 11:57 - 001914368 _____ () C:\Program Files (x86)\TechSmith\Snagit 12\opencv_imgproc249.dll
2018-06-06 10:34 - 2018-06-04 02:18 - 001107272 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2018-06-06 10:34 - 2018-06-04 02:18 - 002079048 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2018-06-06 10:34 - 2018-06-04 02:20 - 000021328 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000022384 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000135656 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 001881448 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000111576 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes35.dll
2018-06-06 10:34 - 2018-06-04 02:18 - 000103392 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000065880 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000079688 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000399832 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom35.dll
2018-06-06 10:34 - 2018-06-04 02:18 - 000024544 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000043496 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000021472 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000124896 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000114664 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000392024 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000028520 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000024552 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000175584 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000024544 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000026080 _____ () C:\Program Files (x86)\Dropbox\Client\win32job.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000048616 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000057824 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000023904 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000022360 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000023392 _____ () C:\Program Files (x86)\Dropbox\Client\crashpad.compiled._Crashpad.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000069992 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 003865936 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000088904 _____ () C:\Program Files (x86)\Dropbox\Client\sip.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 001800528 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 001960272 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000028640 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000155480 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000521552 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000051032 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineCore.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000043352 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000130896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000220504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000205144 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000060896 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000056160 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000024040 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000024424 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000022376 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000028016 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000348128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:21 - 000024432 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000026464 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:18 - 000036312 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2018-06-06 10:34 - 2018-06-04 02:21 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.advapi32.compiled._winffi_advapi32.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000181064 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2018-06-06 10:34 - 2018-06-04 02:21 - 000031584 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:19 - 000024384 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.DLL
2018-06-06 10:34 - 2018-06-04 02:19 - 001638208 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2018-06-06 10:34 - 2018-06-04 02:21 - 000026984 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000546640 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.cp35-win32.pyd
2018-06-06 10:34 - 2018-06-04 02:20 - 000359760 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.cp35-win32.pyd
2014-03-01 22:28 - 2013-01-14 10:25 - 001200088 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\ACE.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 004300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-02-14 15:46 - 2013-02-14 15:46 - 001044048 _____ () C:\Program Files (x86)\Microsoft Office\Office14\ADDINS\UmOutlookAddin.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMPCHelper => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tvnserver => ""=""
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Software\Classes\.scr: AutoCADLTScriptFile => C:\windows\system32\notepad.exe "%1"
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 18:34 - 2009-06-10 13:00 - 000000824 _____ C:\windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Hawkes\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 172.20.10.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: SENS => 2
MSCONFIG\Services: Themes => 2
MSCONFIG\Services: WerSvc => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^LUMIX Simple Viewer.lnk => C:\windows\pss\LUMIX Simple Viewer.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Hawkes^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ChaliesTips.txt => C:\windows\pss\ChaliesTips.txt.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: BFHP => C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFHP.exe
MSCONFIG\startupreg: Carbonite Backup => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
MSCONFIG\startupreg: MyTransitGuide AppIntegrator 32-bit => C:\PROGRA~2\MYTRAN~1\bar\1.bin\AppIntegrator.exe
MSCONFIG\startupreg: MyTransitGuide AppIntegrator 64-bit => C:\PROGRA~2\MYTRAN~1\bar\1.bin\AppIntegrator64.exe
MSCONFIG\startupreg: MyTransitGuide EPM Support => "C:\PROGRA~2\MYTRAN~1\bar\1.bin\b7medint.exe" T8EPMSUP.DLL,S
MSCONFIG\startupreg: OnlineMapFinder AppIntegrator 32-bit => C:\PROGRA~2\ONLINE~2\bar\1.bin\AppIntegrator.exe
MSCONFIG\startupreg: OnlineMapFinder AppIntegrator 64-bit => C:\PROGRA~2\ONLINE~2\bar\1.bin\AppIntegrator64.exe
MSCONFIG\startupreg: OnlineMapFinder EPM Support => "C:\PROGRA~2\ONLINE~2\bar\1.bin\9pmedint.exe" T8EPMSUP.DLL,S
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: tvncontrol => "C:\Program Files (x86)\ShowMyPCService\tvnserver.exe" -controlservice -slave
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{D286209D-D47E-4FB2-990B-E5F083ECE2C0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{946D6113-2E42-4915-A9AF-748B5E95AA62}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\bin\FaxApplications.exe
FirewallRules: [{5F441D91-E139-4EE4-99CC-A3DE8A9E2026}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\bin\DigitalWizards.exe
FirewallRules: [{4AEF1F8E-6B65-44A9-8C21-00125FB3C499}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\bin\SendAFax.exe
FirewallRules: [{071924D8-FB41-459C-BAD7-8FC2191F04F4}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\Bin\DeviceSetup.exe
FirewallRules: [{B98F14D0-D6E0-41DC-817F-C8F91BF100D3}] => (Allow) LPort=5357
FirewallRules: [{7C02512E-A74E-49CE-BE18-6EE2537E501A}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{D485610C-2597-495F-963E-B107555D25B6}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\bin\FaxApplications.exe
FirewallRules: [{4E779424-ABBA-496B-9B91-8EF6BF90EF67}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\bin\DigitalWizards.exe
FirewallRules: [{BB47B70E-AFDA-427E-96EC-111CC9DCFCA0}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\bin\SendAFax.exe
FirewallRules: [{A0325101-C835-4182-B593-1CFAF451C694}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\Bin\DeviceSetup.exe
FirewallRules: [{EB25C5FF-1538-4D22-89B2-1573FB3D15E1}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{11EB5D6C-61A2-4ECD-A65B-47270BA64262}] => (Allow) LPort=5357
FirewallRules: [{0E995ABC-3867-4C29-BEBE-E3CB823147E6}] => (Allow) LPort=8298
FirewallRules: [{721FE470-A698-4217-90C6-E443CEB3ADD7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{89AB279E-108C-49A6-AC29-219E345FBF0F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{CF76B23B-0316-4DDB-A457-FA1E6093F24C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{A2F1F44A-F1DC-498E-A6D4-29FBBCEE7C5B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{DF8BB5E6-25CE-45BF-8385-10293BB4D45B}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS0938\HPDiagnosticCoreUI.exe
FirewallRules: [{9CC6951E-0F88-4326-8139-888CF5ED787B}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS0938\HPDiagnosticCoreUI.exe
FirewallRules: [{C4A82124-AA2C-4834-B75E-C87F4F6D4C37}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS09A0\HPDiagnosticCoreUI.exe
FirewallRules: [{45B6719E-3B1F-4944-AE1D-DF23E039676B}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS09A0\HPDiagnosticCoreUI.exe
FirewallRules: [{CD87450E-3D61-47DA-875E-B410F23B0C1E}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6B47\HPDiagnosticCoreUI.exe
FirewallRules: [{EB73A0BB-DFA5-451F-BC37-0018B8DA9BC4}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6B47\HPDiagnosticCoreUI.exe
FirewallRules: [{497DC7D4-A6F3-41E0-9796-02B5065FD6E3}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6BB3\HPDiagnosticCoreUI.exe
FirewallRules: [{94EB7634-7AB6-441F-8386-5174837B9A06}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6BB3\HPDiagnosticCoreUI.exe
FirewallRules: [TCP Query User{D3FD7FA5-EAB9-4BE7-8430-CB22469A7507}C:\program files\adventure pilot\ifly.exe] => (Allow) C:\program files\adventure pilot\ifly.exe
FirewallRules: [UDP Query User{CC1A72EB-D67F-4EF9-B84B-DC97A6553A8E}C:\program files\adventure pilot\ifly.exe] => (Allow) C:\program files\adventure pilot\ifly.exe
FirewallRules: [{D8A9DF54-8423-408A-818E-DD779D830BC5}] => (Block) C:\program files\adventure pilot\ifly.exe
FirewallRules: [{248CEB5B-1F8E-42FE-971D-CFD34214D96E}] => (Block) C:\program files\adventure pilot\ifly.exe
FirewallRules: [{25D49DFA-C110-4F58-89ED-A9511BA4C35B}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{676527A1-FC83-4624-A026-624905FAF165}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{6E747A63-C966-447F-B87D-6A62DEDBE771}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{252D9E02-6606-4899-8E57-E36CD2D56384}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{36CA8E8C-16F6-48E7-A504-DCC355027DE3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{0A20E917-2165-4A08-98BF-8D5D0701F326}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{8CA549B8-1E1A-480F-BE2B-B3B6EA25CC9F}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
 
==================== Restore Points =========================
 
30-01-2018 12:28:35 Windows Update
31-01-2018 03:35:03 Microsoft Antimalware Checkpoint
03-02-2018 01:35:09 Windows Update
06-02-2018 02:19:14 Windows Update
09-02-2018 12:27:59 Windows Update
12-02-2018 12:29:16 Windows Update
14-02-2018 04:05:28 Windows Update
18-02-2018 02:03:32 Windows Update
22-02-2018 02:08:37 Windows Update
25-02-2018 05:00:28 Windows Update
01-03-2018 01:53:56 Windows Update
04-03-2018 02:22:16 Windows Update
07-03-2018 05:01:31 Windows Update
11-03-2018 02:24:42 Windows Update
14-03-2018 03:00:17 Windows Update
17-03-2018 04:01:02 Windows Update
20-03-2018 05:08:10 Microsoft Antimalware Checkpoint
21-03-2018 01:04:44 Windows Update
24-03-2018 01:15:31 Windows Update
28-03-2018 00:36:46 Windows Update
31-03-2018 01:10:51 Windows Update
31-03-2018 03:00:13 Windows Update
04-04-2018 01:13:38 Windows Update
06-04-2018 03:00:13 Windows Update
09-04-2018 03:33:26 Windows Update
12-04-2018 03:00:16 Windows Update
15-04-2018 03:31:36 Windows Update
19-04-2018 01:05:21 Windows Update
22-04-2018 01:26:14 Windows Update
25-04-2018 03:30:42 Windows Update
29-04-2018 01:08:06 Windows Update
02-05-2018 03:31:23 Windows Update
06-05-2018 01:17:38 Windows Update
09-05-2018 03:31:15 Windows Update
10-05-2018 03:00:13 Windows Update
13-05-2018 04:50:49 Windows Update
17-05-2018 00:37:23 Windows Update
20-05-2018 01:08:31 Windows Update
21-05-2018 19:19:05 Microsoft Antimalware Checkpoint
23-05-2018 04:51:00 Windows Update
27-05-2018 00:58:18 Windows Update
30-05-2018 01:03:23 Windows Update
02-06-2018 01:23:47 Windows Update
04-06-2018 16:28:09 Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810
04-06-2018 16:29:24 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026
04-06-2018 16:30:22 Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810
04-06-2018 16:31:38 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026
04-06-2018 16:32:23 Installed DirectX
05-06-2018 12:49:07 Restore Operation
06-06-2018 00:53:42 Windows Update
09-06-2018 10:53:54 About to run BleepingComputer scan
15-06-2018 11:51:13 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/15/2018 01:47:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5693709
 
Error: (06/15/2018 01:47:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5693709
 
Error: (06/15/2018 01:47:32 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (06/15/2018 01:47:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 5692695
 
Error: (06/15/2018 01:47:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 5692695
 
Error: (06/15/2018 01:47:31 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (06/15/2018 12:12:39 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 1014
 
Error: (06/15/2018 12:12:39 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 1014
 
 
System errors:
=============
Error: (06/15/2018 09:39:55 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 119.0.0.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: Network Inspection System
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 2.1.14600.4
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/15/2018 09:39:55 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.269.945.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: AntiSpyware
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 1.1.14901.4
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/15/2018 09:39:55 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.269.945.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: AntiVirus
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 1.1.14901.4
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/15/2018 09:39:55 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.269.945.0
 
Update Source: Microsoft Update Server
 
Update Stage: Search
 
 
Signature Type: AntiVirus
 
Update Type: Full
 
User: NT AUTHORITY\SYSTEM
 
Current Engine Version: 
 
Previous Engine Version: 1.1.14901.4
 
Error code: 0x8024402c
 
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
 
Error: (06/15/2018 01:23:47 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 119.0.0.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: Network Inspection System
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 2.1.14600.4
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/15/2018 01:23:47 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.269.945.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: AntiSpyware
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 1.1.14901.4
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/15/2018 01:23:47 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.269.945.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: AntiVirus
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 1.1.14901.4
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/15/2018 01:23:47 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.269.945.0
 
Update Source: Microsoft Update Server
 
Update Stage: Search
 
 
Signature Type: AntiVirus
 
Update Type: Full
 
User: NT AUTHORITY\SYSTEM
 
Current Engine Version: 
 
Previous Engine Version: 1.1.14901.4
 
Error code: 0x8024402c
 
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i3-3110M CPU @ 2.40GHz
Percentage of memory in use: 59%
Total physical RAM: 6026.36 MB
Available physical RAM: 2440.65 MB
Total Virtual: 15063.52 MB
Available Virtual: 11673.89 MB
 
==================== Drives ================================
 
Drive c: (TI10668700I) (Fixed) (Total:919.09 GB) (Free:706.18 GB) NTFS ==>[system with boot components (obtained from drive)]
 
\\?\Volume{75ee4344-a1d2-11e3-a5c4-806e6f6e6963}\ (System) (Fixed) (Total:1.46 GB) (Free:1.24 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 624B2B4D)
Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Not Active) - (Size=919.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=11 GB) - (Type=17)
 
==================== End of Addition.txt ============================


#9 Jo*

Jo*

  • Malware Response Team
  • 3,460 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:06:42 PM

Posted 20 June 2018 - 05:00 PM

:welcome: to BleepingComputer.

Hi there,

sorry for this late response, not sure if the problem is malware related...

my name is Jo and I will help you with your computer problems.


Please follow these guidelines:
  • Read and follow the instructions in the sequence they are posted.
  • print or copy & save instructions.
  • back up all your private data / music / important files on another (external) drive before using our tools.
  • Do not install / uninstall any applications, unless otherwise instructed.
  • Use only that tools you have been instructed to use.
  • Copy and Paste the log files inside your post, unless otherwise instructed.
  • Ask for clarification, if you have any questions.
  • Stay with this topic til you get the all clean post.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

***


:step1: Please download Security Analysis by Rocket Grannie from here
  • Save it to your Desktop.
  • Close your security software to avoid potential conflicts.
  • Double click RGSA.exe
  • Click OK on the copyright-disclaimer
  • When finished, a Notepad window will open with the results of the scan.
  • The log named SALog.txt can also be found on the Desktop or in the same folder from where the tool is run if installed elsewhere.
  • Please copy and paste the contents of that log in this topic.
  • Note:
If you get a Warning from Windows about running the program, click on More info and then click Run Anyway to run it even though Windows says it might put your PC at risk.
 

***


:step2: Please download Malwarebytes Anti-Rootkit and save it to your desktop.
  • Be sure to print out and follow the instructions provided on that same page.
  • Caution: This is a beta version so please be sure to read the disclaimer and back up all your data before using.
  • Double click on downloaded file. OK self extracting prompt.
  • MBAR will start. Click in the introduction screen "next" to continue.
  • Click in the following screen "Update" to obtain the latest malware definitions.
  • Once the update is complete select "Next" and click "Scan".
With some infections, you may see two messages boxes.
  • 'Could not load protection driver'. Click 'OK'.
  • 'Could not load DDA driver'. Click 'Yes' to this message, to allow the driver to load after a restart. Allow the computer to restart. Continue with the rest of these instructions.
  • If malware is found - do not press the Clean up button, please go to the MBAR folder and then copy/paste the contents of the MBAR-log-***.txt file to your next reply.
  • If there is no malware found, please let me know as well.

***


:step3: Please download AdwCleaner by Xplode and save to your Desktop.
Double-click AdwCleaner.exe
Vista / Windows 7/8/10 users right-click and select Run As Administrator.
  • Click on the Scan button.
  • AdwCleaner will begin...be patient as the scan may take some time to complete.
  • After the scan has finished, click on the Logfile button...a logfile (AdwCleaner[R0].txt) will open in Notepad for review.
  • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it.
    If you see an entry you want to keep, let me know about it.
  • Copy and paste the contents of that logfile in your next reply.
  • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.

***


Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#10 AlaskaRick

AlaskaRick
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:09:42 AM

Posted 21 June 2018 - 03:00 PM

Jo--  if problems are not malware related, then what is your next guess??



#11 Jo*

Jo*

  • Malware Response Team
  • 3,460 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:06:42 PM

Posted 21 June 2018 - 03:39 PM

Please run the scans as instructed with post #9 and post the logs here.

First we have to clean the pc and then we can see, if I can help you with the moving Folder issue or if you should ask for help at another Forum section later.

Edited by Jo*, 21 June 2018 - 03:39 PM.

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#12 Jo*

Jo*

  • Malware Response Team
  • 3,460 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Germany
  • Local time:06:42 PM

Posted 25 June 2018 - 05:19 PM


Hi,

it has been several days since I sent my last set of instructions to help with your computer problem.

Please let me know if you are having problems and still need help.

Note: Thread will be closed if no response within 3 days.

Graduate of the WTT Classroom
Cheers,
Jo
If I have been helping you, and I have not replied to your latest post in 36 hours please send me a PM.


#13 AlaskaRick

AlaskaRick
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:09:42 AM

Posted 27 June 2018 - 12:40 PM

Please don't close this thread.  Chuck needed to use his computer for a few days.

 

It is now back in my possession and I will run Malwarebytes scan and antivirus scan again, then the FRST scans again and then run the scans you sent me last week.

 

Thank you for your patience.

 

Rick



#14 AlaskaRick

AlaskaRick
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:09:42 AM

Posted 27 June 2018 - 04:35 PM

OK---  I have run FRST and here are contents of the first file-----

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 20.06.2018
Ran by Hawkes (administrator) on HAWKES-WIN7LAP (27-06-2018 13:28:31)
Running from C:\Users\Hawkes\Desktop\ricksfolder\BleepingComputer\FRST
Loaded Profiles: Hawkes (Available Profiles: Hawkes & Rick Liotta)
Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Microsoft Corporation) C:\Windows\System32\alg.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Capital Intellect, Inc.) C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\befrgl.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Carbonite, Inc. (www.carbonite.com)) C:\Program Files\Carbonite\Carbonite Backup\CarboniteService.exe
() C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40STB.EXE
(SEIKO EPSON CORPORATION) C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RPB.EXE
(Intel® Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
(TechSmith Corporation) C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe
(TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
(GlavSoft LLC.) C:\Program Files (x86)\ShowMyPCService\tvnserver.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoService.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe
(Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® Integrated Clock Controller Service\ICCProxy.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TBatmgrTrayicon.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
() C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\Teco.exe
(Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4630 series\Bin\ScanToPCActivationApp.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 7610 series\Bin\ScanToPCActivationApp.exe
(OLYMPUS IMAGING CORP.) C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\Monitor.exe
(Olympus Corporation) C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 7610 series\Bin\HPNetworkCommunicatorCom.exe
(EnTech Taiwan) C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(DTS, Inc.) C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\APO3GUI.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe
(Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Capital Intellect, Inc.) C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFHP.exe
() C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Carbonite, Inc.) C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagPriv.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\TscHelp.exe
(TechSmith Corporation) C:\Program Files (x86)\TechSmith\Snagit 12\SnagitEditor.exe
(TOSHIBA Corporation) C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Hewlett-Packard Co.) C:\Program Files\HP\HP Officejet 4630 series\Bin\HPNetworkCommunicatorCom.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoHook.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
 
==================== Registry (Whitelisted) ===========================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [] => [X]
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13535304 2013-05-07] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [3014384 2013-02-06] (Synaptics Incorporated)
HKLM\...\Run: [BatteryManager] => C:\Program Files\TOSHIBA\Power Saver\TBatmgrTrayIcon.EXE [293760 2013-02-20] (TOSHIBA Corporation)
HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [997216 2013-05-07] (TOSHIBA Corporation)
HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [595840 2012-03-02] ()
HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1562032 2012-02-28] (TOSHIBA Corporation)
HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1337000 2015-04-30] (Microsoft Corporation)
HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [297784 2017-09-11] (Apple Inc.)
HKLM-x32\...\Run: [DTS Sound] => C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\APO3GUI.exe [1471296 2013-05-31] (DTS, Inc.)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel® USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291280 2012-12-20] (Intel Corporation)
HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1298816 2011-07-11] (TOSHIBA Corporation)
HKLM-x32\...\Run: [ToshibaAppPlace] => C:\Program Files (x86)\Toshiba\Toshiba App Place\ToshibaAppPlace.exe [552960 2010-09-23] (Toshiba)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [77824 2014-04-09] (Apple Computer, Inc.)
HKLM-x32\...\Run: [HP Software Update] => C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [96056 2013-05-30] (Hewlett-Packard)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3752768 2018-06-25] (Dropbox, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [1183256 2018-02-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [OM_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\FirstStart.exe [40960 2006-05-16] (OLYMPUS IMAGING CORP.)
HKLM-x32\...\Run: [OV3_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\FirstStart.exe [40400 2017-07-26] (Olympus Corporation)
HKLM-x32\...\Run: [BFHP] => C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFHP.exe [415744 2015-05-21] (Capital Intellect, Inc.)
HKLM-x32\...\Run: [Desktop Disc Tool] => C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe [494064 2009-06-18] ()
HKLM-x32\...\Run: [Carbonite Backup] => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [1278568 2018-02-02] (Carbonite, Inc.)
Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [HP Officejet 4630 series (NET)] => C:\Program Files\HP\HP Officejet 4630 series\Bin\ScanToPCActivationApp.exe [3487240 2014-03-06] (Hewlett-Packard Co.)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [EPSON WorkForce 1100 Series] => C:\windows\system32\spool\DRIVERS\x64\3\E_IATIFEA.EXE [223232 2009-01-06] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [HP Officejet 7610 series (NET)] => C:\Program Files\HP\HP Officejet 7610 series\Bin\ScanToPCActivationApp.exe [2631784 2012-10-21] (Hewlett-Packard Co.)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [OM_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Master\Monitor.exe [57344 2006-05-16] (OLYMPUS IMAGING CORP.)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\Run: [OV3_Monitor] => C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OV3Monitor.exe [415696 2017-07-26] (Olympus Corporation)
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\MountPoints2: {763e31bb-075b-11e4-9b09-008cfaac16ea} - F:\EasySuite.exe
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\MountPoints2: {763e3206-075b-11e4-9b09-008cfaac16ea} - F:\EasySuite.exe
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\...\MountPoints2: {89cb0106-4a9a-11e4-814d-008cfaac16ea} - E:\EasySuite.exe
AppInit_DLLs-x32: C:\PROGRA~3\{74BF9~1\1170~1.1\sodi.dll => No File
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Dell Display Manager.lnk [2018-05-10]
ShortcutTarget: Dell Display Manager.lnk -> C:\Program Files (x86)\Dell\Dell Display Manager\ddm.exe (EnTech Taiwan)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Snagit 12.lnk [2015-11-28]
ShortcutTarget: Snagit 12.lnk -> C:\Program Files (x86)\TechSmith\Snagit 12\Snagit32.exe (TechSmith Corporation)
Startup: C:\Users\Hawkes\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 7610 series (Network).lnk [2018-06-19]
ShortcutTarget: Monitor Ink Alerts - HP Officejet 7610 series (Network).lnk -> C:\Program Files\HP\HP Officejet 7610 series\Bin\HPStatusBL.dll (Hewlett-Packard Co.)
Startup: C:\Users\Rick Liotta\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\RicksTips.txt [2014-04-05] ()
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{5701235C-10EE-4FF4-9DC1-3168F65267C0}: [DhcpNameServer] 172.20.10.1
Tcpip\..\Interfaces\{64C90373-4B61-4289-AEEF-D13EC2E23EF3}: [DhcpNameServer] 172.20.10.1
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkID=617911&ResetID=131618721239150902&GUID=F590571E-92D7-42F5-AAB1-38EFF20AB6A0
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=befhp&type=iehp-3.19-1702
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://toshiba13.msn.com
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.yahoo.com/?fr=befhp&type=iehp-3.19-1702
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Software\Microsoft\Internet Explorer\Main,Old Start Page = hxxps://www.yahoo.com/
URLSearchHook: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 - (No Name) - {6d010537-9e99-400b-b652-b0d5a5757e5d} - C:\Program Files (x86)\OnlineMapFinder_9p\bar\1.bin\9pSrcAs.dll No File
SearchScopes: HKLM -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = 
SearchScopes: HKLM-x32 -> DefaultScope {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM-x32 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSSEDF&pc=MSSE
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> DefaultScope {DAC91F0F-32A8-4E4E-AAB0-3AAD8754257C} URL = hxxp://home.packagesear.ch/search/?et=20170702-ie-s&q={searchTerms}
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = 
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {A1FBFE53-F23E-489F-B25D-F2C86D53463B} URL = hxxps://search.yahoo.com/search?p={searchTerms}&b={startPage?}&fr=ie8
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {B99FC9CF-5C6D-4E06-8136-09CEBB3EA2CF} URL = 
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {c9ab6446-7efc-47fe-966c-dc54324eff9f} URL = 
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {CE167512-14D1-42AC-AA95-0D52E094123C} URL = hxxps://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:{language}:{referrer:source}&ie={inputEncoding?}&oe={outputEncoding?}
SearchScopes: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> {DAC91F0F-32A8-4E4E-AAB0-3AAD8754257C} URL = hxxp://home.packagesear.ch/search/?et=20170702-ie-s&q={searchTerms}
BHO: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: BeFrugalIEHelper -> {2335A057-CBA6-40F6-A712-C6A7C98F7813} -> C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFTB.dll [2015-05-21] (Capital Intellect, Inc.)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL [2013-12-19] (Microsoft Corporation)
BHO-x32: Qualys BrowserCheck IE Helper -> {7D2FB79E-E58C-4DB5-A36F-AC1C73967FA5} -> C:\Windows\Downloaded Program Files\qbc_bho.dll [2016-08-31] (Qualys, Inc.)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
Toolbar: HKLM-x32 - BeFrugal.com Shopping toolbar - {5BA2C4EE-42EF-4E2D-88BE-7271AE4E35B7} - C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFTB.dll [2015-05-21] (Capital Intellect, Inc.)
Toolbar: HKU\S-1-5-21-832600199-2139290072-1447759302-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {7D2FB79E-E58C-4DB5-A36F-AC1C73967F4D} hxxps://browsercheck.qualys.com/qbc_ax.cab
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2017-07-18] (Skype Technologies)
StartMenuInternet: IEXPLORE.EXE - iexplore.exe
 
FireFox:
========
FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll [2012-09-28] (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-09-28] (Intel Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-05-17] (Google Inc.)
FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\1\NP_wtapp.dll [No File]
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2018-05-10] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-832600199-2139290072-1447759302-1000: @rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5 -> C:\Users\Hawkes\AppData\Roaming\Visan\plugins\npRLSecurePluginLayer.dll [2011-05-23] (RocketLife, LLP)
 
Chrome: 
=======
CHR DefaultProfile: Default
CHR Profile: C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default [2018-06-27]
CHR Extension: (Docs) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-03-24]
CHR Extension: (Google Drive) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-03-24]
CHR Extension: (YouTube) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-03-24]
CHR Extension: (Adblock Plus) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2018-05-18]
CHR Extension: (Google Search) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-25]
CHR Extension: (Adobe Acrobat) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\efaidnbmnnnibpcajpcglclefindmkaj [2018-03-27]
CHR Extension: (Google Docs Offline) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-03-24]
CHR Extension: (Skype) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2018-03-24]
CHR Extension: (Chrome Web Store Payments) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-04-30]
CHR Extension: (Gmail) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-25]
CHR Extension: (Chrome Media Router) - C:\Users\Hawkes\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-06-09]
CHR HKU\S-1-5-21-832600199-2139290072-1447759302-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [efaidnbmnnnibpcajpcglclefindmkaj] - hxxps://clients2.google.com/service/update2/crx
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - hxxps://clients2.google.com/service/update2/crx
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2017-09-07] (Apple Inc.)
R2 BeFrugal.com Service; C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\befrgl.exe [555520 2015-05-21] (Capital Intellect, Inc.)
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-11-04] (Dropbox, Inc.)
R2 DbxSvc; C:\windows\system32\DbxSvc.exe [51024 2018-06-25] (Dropbox, Inc.)
R2 dts_apo_service; C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe [16720 2013-05-31] ()
S3 FLEXnet Licensing Service 64; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [1030600 2014-04-02] (Macrovision Europe Ltd.) [File not signed]
R2 Intel® Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel® Corporation) [File not signed]
S3 Intel® Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel® Corporation)
R2 Intel® ME Service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe [130592 2012-10-26] (Intel Corporation)
R2 jhi_service; C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe [165488 2012-12-18] (Intel Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23816 2015-04-30] (Microsoft Corporation)
R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [366544 2015-04-30] (Microsoft Corporation)
R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [7757552 2018-02-26] (TeamViewer GmbH)
R2 TechSmith Uploader Service; C:\Program Files (x86)\Common Files\TechSmith Shared\Uploader\UploaderService.exe [3408384 2015-01-26] (TechSmith Corporation) [File not signed]
R2 tvnserver; C:\Program Files (x86)\ShowMyPCService\tvnserver.exe [815704 2013-11-21] (GlavSoft LLC.)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R1 ESProtectionDriver; C:\windows\system32\drivers\mbae64.sys [152184 2018-06-09] (Malwarebytes)
R0 iaStorF; C:\windows\System32\DRIVERS\iaStorF.sys [28656 2013-03-11] (Intel Corporation)
R3 L1C; C:\windows\System32\DRIVERS\L1C62x64.sys [128200 2013-04-03] (Qualcomm Atheros Co., Ltd.)
R2 MBAMChameleon; C:\windows\System32\Drivers\MbamChameleon.sys [190696 2018-06-09] (Malwarebytes)
R3 MBAMFarflt; C:\windows\System32\DRIVERS\farflt.sys [112872 2018-06-19] (Malwarebytes)
R3 MBAMProtection; C:\windows\System32\DRIVERS\mbam.sys [44768 2018-06-19] (Malwarebytes)
R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [253664 2018-06-19] (Malwarebytes)
R3 MBAMWebProtection; C:\windows\System32\DRIVERS\mwac.sys [94840 2018-06-27] (Malwarebytes)
R0 MpFilter; C:\windows\System32\DRIVERS\MpFilter.sys [280376 2015-03-04] (Microsoft Corporation)
R1 MpKsl1e1d69b7; c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{E9100CE6-76AD-4F0D-BD42-14254CDEA82D}\MpKsl1e1d69b7.sys [58120 2018-06-26] (Microsoft Corporation)
R2 NisDrv; C:\windows\System32\DRIVERS\NisDrvWFP.sys [124568 2015-03-04] (Microsoft Corporation)
R3 RTWlanE; C:\windows\System32\DRIVERS\rtwlane.sys [1480776 2013-02-08] (Realtek Semiconductor Corporation )
S1 RxFilter; C:\Windows\SysWOW64\DRIVERS\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)
R3 SmbDrvI; C:\windows\System32\DRIVERS\Smb_driver_Intel.sys [32496 2013-02-06] (Synaptics Incorporated)
S3 SWDUMon; C:\windows\System32\DRIVERS\SWDUMon.sys [13920 2016-05-22] ()
S3 dbx; system32\DRIVERS\dbx.sys [X]
S0 gufge; System32\drivers\spxncav.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-06-26 12:55 - 2018-06-26 12:55 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2018-06-25 09:24 - 2018-06-25 09:24 - 000051024 _____ (Dropbox, Inc.) C:\windows\system32\DbxSvc.exe
2018-06-25 09:24 - 2018-06-25 09:24 - 000050232 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-dev.sys
2018-06-25 09:24 - 2018-06-25 09:24 - 000045672 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-canary.sys
2018-06-25 09:24 - 2018-06-25 09:24 - 000045640 _____ (Dropbox, Inc.) C:\windows\system32\Drivers\dbx-stable.sys
2018-06-19 11:14 - 2018-06-22 17:57 - 000000000 ____D C:\Users\Hawkes\Documents\- New files since June 15
2018-06-18 11:05 - 2018-05-29 12:36 - 000396960 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
2018-06-18 11:05 - 2018-05-29 11:40 - 000348824 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
2018-06-18 11:05 - 2018-05-28 18:43 - 000631640 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
2018-06-18 11:05 - 2018-05-28 18:41 - 005577408 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
2018-06-18 11:05 - 2018-05-28 18:41 - 000708288 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
2018-06-18 11:05 - 2018-05-28 18:41 - 000262336 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
2018-06-18 11:05 - 2018-05-28 18:41 - 000154816 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
2018-06-18 11:05 - 2018-05-28 18:41 - 000095424 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
2018-06-18 11:05 - 2018-05-28 18:35 - 001665336 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 004050624 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
2018-06-18 11:05 - 2018-05-28 18:32 - 003962048 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
2018-06-18 11:05 - 2018-05-28 18:32 - 001461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 001211904 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 001163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000731648 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000361984 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000094208 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000007168 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:32 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:25 - 001314064 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 001114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000554496 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000070144 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:22 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 18:03 - 000148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
2018-06-18 11:05 - 2018-05-28 18:03 - 000064512 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
2018-06-18 11:05 - 2018-05-28 18:03 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
2018-06-18 11:05 - 2018-05-28 18:03 - 000050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
2018-06-18 11:05 - 2018-05-28 18:03 - 000017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
2018-06-18 11:05 - 2018-05-28 17:59 - 000338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
2018-06-18 11:05 - 2018-05-28 17:59 - 000296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
2018-06-18 11:05 - 2018-05-28 17:59 - 000129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\videoprt.sys
2018-06-18 11:05 - 2018-05-28 17:59 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
2018-06-18 11:05 - 2018-05-28 17:59 - 000014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
2018-06-18 11:05 - 2018-05-28 17:59 - 000007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
2018-06-18 11:05 - 2018-05-28 17:59 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
2018-06-18 11:05 - 2018-05-28 17:58 - 000036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
2018-06-18 11:05 - 2018-05-28 17:58 - 000006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 17:58 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 17:58 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 17:58 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
2018-06-18 11:05 - 2018-05-28 17:56 - 000160256 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
2018-06-18 11:05 - 2018-05-28 17:55 - 000291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
2018-06-18 11:05 - 2018-05-28 17:55 - 000129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
2018-06-18 11:05 - 2018-05-28 17:54 - 000112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
2018-06-18 11:05 - 2018-05-28 17:54 - 000030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
2018-06-18 11:05 - 2018-05-28 16:04 - 000634272 _____ (Microsoft Corporation) C:\windows\system32\winload.exe
2018-06-18 11:05 - 2018-05-24 21:10 - 025742848 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2018-06-18 11:05 - 2018-05-24 20:59 - 002724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2018-06-18 11:05 - 2018-05-24 20:59 - 000004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2018-06-18 11:05 - 2018-05-24 20:46 - 002902016 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2018-06-18 11:05 - 2018-05-24 20:45 - 000066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2018-06-18 11:05 - 2018-05-24 20:44 - 000578048 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
2018-06-18 11:05 - 2018-05-24 20:44 - 000417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
2018-06-18 11:05 - 2018-05-24 20:44 - 000048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2018-06-18 11:05 - 2018-05-24 20:43 - 000088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
2018-06-18 11:05 - 2018-05-24 20:38 - 005779968 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2018-06-18 11:05 - 2018-05-24 20:37 - 000054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2018-06-18 11:05 - 2018-05-24 20:36 - 000034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2018-06-18 11:05 - 2018-05-24 20:34 - 020286976 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
2018-06-18 11:05 - 2018-05-24 20:33 - 000615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2018-06-18 11:05 - 2018-05-24 20:32 - 000814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2018-06-18 11:05 - 2018-05-24 20:32 - 000794624 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
2018-06-18 11:05 - 2018-05-24 20:32 - 000144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2018-06-18 11:05 - 2018-05-24 20:32 - 000116224 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2018-06-18 11:05 - 2018-05-24 20:28 - 002724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
2018-06-18 11:05 - 2018-05-24 20:24 - 000969216 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2018-06-18 11:05 - 2018-05-24 20:21 - 000489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
2018-06-18 11:05 - 2018-05-24 20:16 - 000499712 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
2018-06-18 11:05 - 2018-05-24 20:16 - 000062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
2018-06-18 11:05 - 2018-05-24 20:15 - 000341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
2018-06-18 11:05 - 2018-05-24 20:15 - 000047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
2018-06-18 11:05 - 2018-05-24 20:14 - 000087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
2018-06-18 11:05 - 2018-05-24 20:14 - 000077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
2018-06-18 11:05 - 2018-05-24 20:14 - 000064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
2018-06-18 11:05 - 2018-05-24 20:13 - 000107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
2018-06-18 11:05 - 2018-05-24 20:12 - 002295296 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
2018-06-18 11:05 - 2018-05-24 20:10 - 000199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2018-06-18 11:05 - 2018-05-24 20:10 - 000092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
2018-06-18 11:05 - 2018-05-24 20:09 - 000047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
2018-06-18 11:05 - 2018-05-24 20:08 - 000315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
2018-06-18 11:05 - 2018-05-24 20:08 - 000030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
2018-06-18 11:05 - 2018-05-24 20:07 - 000476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
2018-06-18 11:05 - 2018-05-24 20:06 - 000662016 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
2018-06-18 11:05 - 2018-05-24 20:06 - 000152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
2018-06-18 11:05 - 2018-05-24 20:05 - 000620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
2018-06-18 11:05 - 2018-05-24 20:05 - 000115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
2018-06-18 11:05 - 2018-05-24 19:57 - 000416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
2018-06-18 11:05 - 2018-05-24 19:57 - 000262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
2018-06-18 11:05 - 2018-05-24 19:55 - 000809472 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2018-06-18 11:05 - 2018-05-24 19:55 - 000728064 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2018-06-18 11:05 - 2018-05-24 19:53 - 015283200 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2018-06-18 11:05 - 2018-05-24 19:53 - 002135552 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2018-06-18 11:05 - 2018-05-24 19:53 - 001359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
2018-06-18 11:05 - 2018-05-24 19:52 - 000073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
2018-06-18 11:05 - 2018-05-24 19:52 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
2018-06-18 11:05 - 2018-05-24 19:51 - 000091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
2018-06-18 11:05 - 2018-05-24 19:49 - 000168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
2018-06-18 11:05 - 2018-05-24 19:48 - 000076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
2018-06-18 11:05 - 2018-05-24 19:47 - 000279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
2018-06-18 11:05 - 2018-05-24 19:45 - 000130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
2018-06-18 11:05 - 2018-05-24 19:42 - 004496896 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
2018-06-18 11:05 - 2018-05-24 19:40 - 000230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
2018-06-18 11:05 - 2018-05-24 19:39 - 003241472 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2018-06-18 11:05 - 2018-05-24 19:39 - 000696320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
2018-06-18 11:05 - 2018-05-24 19:38 - 013679616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
2018-06-18 11:05 - 2018-05-24 19:38 - 002060288 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
2018-06-18 11:05 - 2018-05-24 19:37 - 001155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
2018-06-18 11:05 - 2018-05-24 19:29 - 001546240 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2018-06-18 11:05 - 2018-05-24 19:19 - 002767872 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
2018-06-18 11:05 - 2018-05-24 19:17 - 000800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2018-06-18 11:05 - 2018-05-24 19:15 - 001314304 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
2018-06-18 11:05 - 2018-05-24 19:14 - 000710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
2018-06-18 11:05 - 2018-05-14 20:16 - 001681088 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ntfs.sys
2018-06-18 11:05 - 2018-05-14 19:44 - 004120576 _____ (Microsoft Corporation) C:\windows\system32\mf.dll
2018-06-18 11:05 - 2018-05-14 19:44 - 001159680 _____ (Microsoft Corporation) C:\windows\system32\webservices.dll
2018-06-18 11:05 - 2018-05-14 19:44 - 000206848 _____ (Microsoft Corporation) C:\windows\system32\mfps.dll
2018-06-18 11:05 - 2018-05-14 19:44 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\mferror.dll
2018-06-18 11:05 - 2018-05-14 19:24 - 000055808 _____ (Microsoft Corporation) C:\windows\system32\rrinstaller.exe
2018-06-18 11:05 - 2018-05-14 19:23 - 000024576 _____ (Microsoft Corporation) C:\windows\system32\mfpmp.exe
2018-06-18 11:05 - 2018-05-14 19:13 - 003207168 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf.dll
2018-06-18 11:05 - 2018-05-14 19:13 - 000782848 _____ (Microsoft Corporation) C:\windows\SysWOW64\webservices.dll
2018-06-18 11:05 - 2018-05-14 19:13 - 000103424 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfps.dll
2018-06-18 11:05 - 2018-05-14 19:13 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\mferror.dll
2018-06-18 11:05 - 2018-05-14 19:01 - 000050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\rrinstaller.exe
2018-06-18 11:05 - 2018-05-14 19:01 - 000023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\mfpmp.exe
2018-06-18 11:05 - 2018-05-14 17:20 - 000467856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\cng.sys
2018-06-18 11:05 - 2018-05-14 17:20 - 000459632 _____ (Microsoft Corporation) C:\windows\system32\ci.dll
2018-06-18 11:05 - 2018-05-11 18:07 - 000076800 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidclass.sys
2018-06-18 11:05 - 2018-05-11 18:07 - 000033152 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidparse.sys
2018-06-18 11:05 - 2018-05-11 18:07 - 000030208 _____ (Microsoft Corporation) C:\windows\system32\Drivers\hidusb.sys
2018-06-18 11:05 - 2018-05-11 13:19 - 000977408 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
2018-06-18 11:05 - 2018-05-11 13:19 - 000109568 _____ (Microsoft Corporation) C:\windows\system32\hlink.dll
2018-06-18 11:05 - 2018-05-11 13:19 - 000084480 _____ (Microsoft Corporation) C:\windows\system32\INETRES.dll
2018-06-18 11:05 - 2018-05-10 16:40 - 000741888 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
2018-06-18 11:05 - 2018-05-10 16:40 - 000084480 _____ (Microsoft Corporation) C:\windows\SysWOW64\INETRES.dll
2018-06-18 11:05 - 2018-05-10 16:39 - 000084992 _____ (Microsoft Corporation) C:\windows\SysWOW64\hlink.dll
2018-06-18 11:05 - 2018-04-06 08:39 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
2018-06-18 11:05 - 2018-04-06 08:38 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
2018-06-15 08:46 - 2018-06-15 08:46 - 000000000 ____D C:\Users\Hawkes\Documents\Book Place
2018-06-09 10:52 - 2018-06-27 13:28 - 000000000 ____D C:\FRST
2018-06-09 09:02 - 2018-06-27 13:15 - 000094840 _____ (Malwarebytes) C:\windows\system32\Drivers\mwac.sys
2018-06-09 09:02 - 2018-06-19 03:49 - 000253664 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
2018-06-09 09:02 - 2018-06-19 03:49 - 000112872 _____ (Malwarebytes) C:\windows\system32\Drivers\farflt.sys
2018-06-09 09:02 - 2018-06-19 03:49 - 000044768 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
2018-06-09 09:02 - 2018-06-09 09:02 - 000190696 _____ (Malwarebytes) C:\windows\system32\Drivers\MbamChameleon.sys
2018-06-07 12:32 - 2018-06-09 09:02 - 000152184 _____ (Malwarebytes) C:\windows\system32\Drivers\mbae64.sys
2018-06-07 12:32 - 2018-06-07 12:32 - 000001878 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2018-06-07 12:32 - 2018-06-07 12:32 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2018-06-06 12:08 - 1997-06-02 12:32 - 000314880 _____ (InstallShield Software Corporation) C:\windows\IsUninst.exe
2018-06-05 11:56 - 2018-06-05 13:00 - 000000000 ____D C:\ProgramData\bomgar-scc-0x5b16eafe
2018-06-04 16:41 - 2018-06-04 16:41 - 000002216 _____ C:\Users\Public\Desktop\DWG TrueView 2019 - English.lnk
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2018-06-27 10:22 - 2014-10-15 16:01 - 000000000 ____D C:\Users\Hawkes\Documents\Outlookfiles2
2018-06-26 19:04 - 2015-11-21 12:09 - 000000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore.job
2018-06-26 16:39 - 2014-06-10 20:35 - 000000000 ____D C:\Users\Hawkes\AppData\Local\CutePDF Writer
2018-06-26 12:56 - 2015-07-07 20:35 - 000000000 ____D C:\Program Files (x86)\Dropbox
2018-06-26 03:15 - 2009-07-13 20:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-06-26 03:15 - 2009-07-13 20:45 - 000024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-06-25 14:06 - 2018-03-24 17:48 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-06-25 14:06 - 2018-03-24 17:48 - 000002154 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-06-22 21:34 - 2015-02-09 14:28 - 000000000 ____D C:\Users\Hawkes\Documents\ScannedFiles
2018-06-20 19:28 - 2014-04-05 17:13 - 000000000 ____D C:\Users\Hawkes\Documents\General Documents
2018-06-19 04:37 - 2009-07-13 19:20 - 000000000 ____D C:\windows\rescache
2018-06-19 03:56 - 2009-07-13 21:13 - 000785942 _____ C:\windows\system32\PerfStringBackup.INI
2018-06-19 03:56 - 2009-07-13 19:20 - 000000000 ____D C:\windows\inf
2018-06-19 03:48 - 2009-07-13 21:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
2018-06-19 03:28 - 2014-04-04 13:28 - 000000000 ____D C:\windows\system32\MRT
2018-06-19 03:06 - 2017-10-11 03:12 - 133315992 ____C (Microsoft Corporation) C:\windows\system32\MRT-KB890830.exe
2018-06-19 03:05 - 2014-04-06 03:10 - 133315992 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
2018-06-18 09:53 - 2013-11-13 22:56 - 000842240 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerApp.exe
2018-06-18 09:53 - 2013-11-13 22:56 - 000175104 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\FlashPlayerCPLApp.cpl
2018-06-18 09:53 - 2013-11-13 22:56 - 000004312 _____ C:\windows\System32\Tasks\Adobe Flash Player Updater
2018-06-18 09:53 - 2013-11-13 22:56 - 000000000 ____D C:\windows\SysWOW64\Macromed
2018-06-18 09:53 - 2013-11-13 22:56 - 000000000 ____D C:\windows\system32\Macromed
2018-06-15 14:05 - 2016-01-13 16:00 - 000000000 ____D C:\Users\Hawkes\Desktop\ricksfolder
2018-06-14 21:54 - 2015-07-24 01:26 - 000000000 ____D C:\Users\Hawkes\AppData\Local\ElevatedDiagnostics
2018-06-14 20:01 - 2009-07-13 21:09 - 000000000 ____D C:\windows\System32\Tasks\WPD
2018-06-07 20:57 - 2016-01-13 15:43 - 000000000 ____D C:\Program Files (x86)\TeamViewer
2018-06-07 19:52 - 2015-11-13 18:29 - 000001066 _____ C:\Users\Hawkes\Desktop\Drawings.lnk
2018-06-07 17:06 - 2015-11-13 18:10 - 000000000 ____D C:\Users\Hawkes\Documents\Drawings
2018-06-07 17:05 - 2017-12-21 23:44 - 000000000 ____D C:\Users\Hawkes\Documents\Misc
2018-06-05 13:00 - 2015-11-28 17:16 - 000000000 ____D C:\ProgramData\Package Cache
2018-06-05 13:00 - 2014-04-05 17:53 - 000000000 ____D C:\ProgramData\FLEXnet
2018-06-05 13:00 - 2014-04-02 18:36 - 000000000 ____D C:\Program Files\Common Files\Autodesk Shared
2018-06-05 13:00 - 2014-04-02 18:34 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Autodesk
2018-06-05 13:00 - 2010-11-20 23:16 - 000000000 ___RD C:\Users\Public\Recorded TV
2018-06-05 13:00 - 2009-07-13 19:20 - 000000000 ____D C:\windows\registration
2018-06-05 11:19 - 2015-04-21 18:18 - 000532144 _____ C:\windows\system32\FNTCACHE.DAT
2018-06-04 22:18 - 2015-04-21 17:25 - 000157576 _____ C:\Users\Hawkes\AppData\Local\GDIPFONTCACHEV1.DAT
2018-06-04 22:14 - 2014-04-05 17:13 - 000000000 ____D C:\Users\Hawkes\Documents\Faxes
2018-06-04 16:41 - 2014-04-02 18:36 - 000000000 ____D C:\Users\Hawkes\AppData\Roaming\Autodesk
2018-06-04 16:37 - 2016-10-17 14:47 - 000000000 ____D C:\Users\Public\Documents\Autodesk
2018-06-04 16:37 - 2016-10-17 14:44 - 000000000 ____D C:\Program Files\Autodesk
2018-06-04 16:37 - 2014-04-02 18:36 - 000000000 ____D C:\Users\Hawkes\AppData\Local\Autodesk
2018-06-04 16:37 - 2014-04-02 18:36 - 000000000 ____D C:\ProgramData\Autodesk
2018-05-31 22:20 - 2014-04-05 17:08 - 000000000 ____D C:\Users\Hawkes\Documents\Envelopes
2018-05-29 22:24 - 2016-01-22 12:59 - 000000000 ____D C:\Users\Hawkes\Documents\Project Documents
2018-05-29 20:08 - 2014-04-05 17:13 - 000000000 ____D C:\Users\Hawkes\Documents\Tyson Chang Projects
 
==================== Files in the root of some directories =======
 
2017-08-30 11:54 - 2017-09-30 12:21 - 000004096 ____H () C:\Users\Hawkes\AppData\Local\keyfile3.drm
 
Files to move or delete:
====================
C:\Windows\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4}.job
 
 
Some files in TEMP:
====================
2016-10-17 13:49 - 2018-01-11 00:42 - 000089432 _____ (Autodesk, Inc.) C:\Users\Hawkes\AppData\Local\Temp\AcDeltree.exe
2017-12-20 20:36 - 2017-12-20 20:36 - 000128857 ____T () C:\Users\Hawkes\AppData\Local\Temp\AEV33B0.exe
2017-08-25 20:47 - 2017-08-25 20:47 - 000131237 ____T () C:\Users\Hawkes\AppData\Local\Temp\AEV3CA6.exe
2015-12-08 12:41 - 2015-12-08 12:41 - 000071168 _____ () C:\Users\Hawkes\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmp64knui.dll
2016-06-02 14:37 - 2017-06-04 22:16 - 010581280 _____ () C:\Users\Hawkes\AppData\Local\Temp\HPPSdr.exe
2015-07-24 01:58 - 2015-07-24 01:58 - 000000000 _____ () C:\Users\Hawkes\AppData\Local\Temp\ntc8hssa.dll
2016-05-22 14:15 - 2016-05-22 14:15 - 000205656 _____ (SlimWare Utilities, Inc.) C:\Users\Hawkes\AppData\Local\Temp\scp18F7.tmp.exe
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\windows\system32\winlogon.exe => File is digitally signed
C:\windows\system32\wininit.exe => File is digitally signed
C:\windows\SysWOW64\wininit.exe => File is digitally signed
C:\windows\explorer.exe => File is digitally signed
C:\windows\SysWOW64\explorer.exe => File is digitally signed
C:\windows\system32\svchost.exe => File is digitally signed
C:\windows\SysWOW64\svchost.exe => File is digitally signed
C:\windows\system32\services.exe => File is digitally signed
C:\windows\system32\User32.dll => File is digitally signed
C:\windows\SysWOW64\User32.dll => File is digitally signed
C:\windows\system32\userinit.exe => File is digitally signed
C:\windows\SysWOW64\userinit.exe => File is digitally signed
C:\windows\system32\rpcss.dll => File is digitally signed
C:\windows\system32\dnsapi.dll => File is digitally signed
C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\windows\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2018-06-27 00:27
 
==================== End of FRST.txt ============================


#15 AlaskaRick

AlaskaRick
  • Topic Starter

  • Members
  • 43 posts
  • OFFLINE
  •  
  • Local time:09:42 AM

Posted 27 June 2018 - 04:38 PM

And here is contents of addition.txt-----

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 20.06.2018
Ran by Hawkes (27-06-2018 13:29:07)
Running from C:\Users\Hawkes\Desktop\ricksfolder\BleepingComputer\FRST
Windows 7 Home Premium Service Pack 1 (X64) (2014-03-29 15:48:06)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-832600199-2139290072-1447759302-500 - Administrator - Disabled)
Guest (S-1-5-21-832600199-2139290072-1447759302-501 - Limited - Disabled)
Hawkes (S-1-5-21-832600199-2139290072-1447759302-1000 - Administrator - Enabled) => C:\Users\Hawkes
HomeGroupUser$ (S-1-5-21-832600199-2139290072-1447759302-1002 - Limited - Enabled)
Rick Liotta (S-1-5-21-832600199-2139290072-1447759302-1003 - Administrator - Enabled) => C:\Users\Rick Liotta
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Microsoft Security Essentials (Enabled - Up to date) {B7ECF8CD-0188-6703-DBA4-AA65C6ACFB0A}
AS: Microsoft Security Essentials (Enabled - Up to date) {0C8D1929-27B2-688D-E114-9117BD2BB1B7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 18.011.20040 - Adobe Systems Incorporated)
Adobe Flash Player 30 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 30.0.0.113 - Adobe Systems Incorporated)
Apple Application Support (32-bit) (HKLM-x32\...\{3D1290E6-1F77-46D5-A715-A56679C8D4E3}) (Version: 6.0.2 - Apple Inc.)
Apple Application Support (64-bit) (HKLM\...\{D0E45DEC-F4B9-4370-A9DF-66837789C2EF}) (Version: 6.0.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{E3C4B99B-BE71-4C27-8E3C-4FAE3C46E1D5}) (Version: 11.0.0.30 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{C1BBFD2A-BCDD-45B3-8C0B-66BD434970A8}) (Version: 2.4.8.1 - Apple Inc.)
Audacity 2.0 (HKLM-x32\...\Audacity_is1) (Version:  - Audacity Team)
AutoCAD LT 2010 - English (HKLM\...\{5783F2D7-8009-0409-0102-0060B0CE6BBA}) (Version: 18.0.309.0 - Autodesk) Hidden
AutoCAD LT 2010 - English (HKLM\...\AutoCAD LT 2010 - English) (Version: 18.0.55.0 - Autodesk)
AutoCAD LT 2010 - English Version 3 (HKLM\...\AutoCAD LT 2010 - English Version 3) (Version: 1 - Autodesk)
Autodesk Design Review 2010 (HKLM-x32\...\{55D9E026-DCB0-46FF-B60A-68B972228CF6}) (Version: 10.0.0.108 - Autodesk, Inc.) Hidden
Autodesk Design Review 2010 (HKLM-x32\...\Autodesk Design Review 2010) (Version: 10.0.0.108 - Autodesk, Inc.)
Autodesk DWG TrueView 2017 - English (HKLM\...\DWG TrueView 2017 - English) (Version: 21.0.104.0 - Autodesk)
Autodesk DWG TrueView 2019 - English (HKLM\...\DWG TrueView 2019 - English) (Version: 23.0.46.0 - Autodesk)
BeFrugal.com Shopping toolbar (HKLM-x32\...\{6ADB86DC-7727-492F-865E-A7CAFFABAC72}_is1) (Version: 2013.3.19.3 - BeFrugal.com)
Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
Carbonite (HKLM-x32\...\{ADD4D4D2-4489-43A7-A141-7EDF2C5FB68E}) (Version: 6.3.3 build 7602 (Feb-02-2018) - Carbonite)
Cash Back Assistant (HKLM-x32\...\{9CC676BB-4D00-4E54-9C8E-DE54A1710A80}_is1) (Version: 2013.3.19.3 - BeFrugal.com)
CCleaner (HKLM\...\CCleaner) (Version: 4.07 - Piriform)
CutePDF Writer 3.0 (HKLM\...\CutePDF Writer Installation) (Version:  3.0 - Acro Software Inc.)
Dell Display Manager (HKLM-x32\...\{AC50C05D-9D57-40F5-B2EF-AC402F14312B}_is1) (Version:  - EnTech Taiwan)
DirectX 9 Runtime (HKLM-x32\...\{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}) (Version: 1.00.0000 - Sonic Solutions) Hidden
Dropbox (HKLM-x32\...\Dropbox) (Version: 52.4.60 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.75.1 - Dropbox, Inc.) Hidden
DTS Sound (HKLM-x32\...\{791692AD-63B2-4A87-A097-4E8DD3CE4BC9}) (Version: 1.00.0079 - DTS, Inc.)
DWG TrueView 2017 - English (HKLM\...\{28B89EEF-0028-0409-0100-CF3F3A09B77D}) (Version: 21.0.104.0 - Autodesk) Hidden
DWG TrueView 2019 - English (HKLM\...\{28B89EEF-2028-0409-0100-CF3F3A09B77D}) (Version: 23.0.46.0 - Autodesk) Hidden
EMC 10 Content (HKLM-x32\...\{FDB46DE7-9045-47BB-970A-3E4ED5369E03}) (Version: 1.0.035 - Roxo, Inc.) Hidden
EMCGadgets64 (HKLM\...\{02AD9D20-03D2-4DE0-8793-E8253026AD86}) (Version: 1.0.302 - Sonic) Hidden
EPSON WorkForce 1100 Series Printer Uninstall (HKLM\...\EPSON WorkForce 1100 Series) (Version:  - SEIKO EPSON Corporation)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 67.0.3396.99 - Google Inc.)
Google Earth Pro (HKLM-x32\...\{FA1BBF34-E994-4310-95D7-BE93092B8E61}) (Version: 7.3.1.4507 - Google)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.21.123 - Google Inc.) Hidden
HP FWUpdateEDO2 (HKLM-x32\...\{415FA9AD-DA10-4ABE-97B6-5051D4795C90}) (Version: 1.2.0.0 - Hewlett-Packard)
HP Officejet 4630 series Basic Device Software (HKLM\...\{1EEDD93E-B341-4353-92D6-9A009443C91A}) (Version: 32.2.188.47710 - Hewlett-Packard Co.)
HP Officejet 4630 series Help (HKLM-x32\...\{9F79230F-EE1C-407E-94E1-D69021954C9B}) (Version: 31.0.0 - Hewlett Packard)
HP Officejet 7610 series Basic Device Software (HKLM\...\{3507BAF4-20F8-4AAC-8B4B-C61D67607728}) (Version: 29.1.971.39251 - Hewlett-Packard Co.)
HP Officejet 7610 series Help (HKLM-x32\...\{74C894CB-FDE5-4B38-BD3B-C9DE6EC6B698}) (Version: 29.0.0 - Hewlett Packard)
HP Update (HKLM-x32\...\{912D30CF-F39E-4B31-AD9A-123C6B794EE2}) (Version: 5.005.002.002 - Hewlett-Packard)
HPDiagnosticAlert (HKLM-x32\...\{B6465A32-8BE9-4B38-ADC5-4B4BDDC10B0D}) (Version: 1.00.0001 - Microsoft) Hidden
I.R.I.S. OCR (HKLM-x32\...\{CA6BCA2F-EDEB-408F-850B-31404BE16A61}) (Version: 12.3.4.0 - HP)
Intel® Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.1.30.1349 - Intel Corporation)
Intel® Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 9.17.10.3062 - Intel Corporation)
Intel® Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.0.4.1001 - Intel Corporation)
Intel® SDK for OpenCL - CPU Only Runtime Package (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: 2.0.0.37149 - Intel Corporation)
Intel® USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.7.248 - Intel Corporation)
iTunes (HKLM\...\{94E81D4F-FB5A-4B29-B385-33896CC9BE7E}) (Version: 12.7.0.166 - Apple Inc.)
LAME v3.99.3 (for Windows) (HKLM-x32\...\LAME_is1) (Version:  - )
LUMIX Simple Viewer (HKLM-x32\...\{2CDCCE7E-55D5-40CC-AEA0-ABA54713501F}) (Version: 0.99.0000 - )
Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
Microsoft .NET Framework 4.7.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.7.02558 - Microsoft Corporation)
Microsoft Mouse and Keyboard Center (HKLM\...\Microsoft Mouse and Keyboard Center) (Version: 2.3.188.0 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (HKLM-x32\...\Office14.PROPLUSR) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.8.204.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6E8E85E8-CE4B-4FF5-91F7-04999C9FAE6A}) (Version: 8.0.50727.42 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810 (HKLM-x32\...\{e2ee15e2-a480-4bc5-bfb7-e9803d1d9823}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810 (HKLM-x32\...\{56e11d69-7cc9-40a5-a4f9-8f6190c4d84d}) (Version: 14.12.25810.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 4.0 (HKLM-x32\...\{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}) (Version: 4.0.20823.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
MSXML 4.0 SP2 Parser and SDK (HKLM-x32\...\{716E0306-8318-4364-8B8F-0CC4E9376BAC}) (Version: 4.20.9818.0 - Microsoft Corporation)
Nero BurnExpress (HKLM-x32\...\{052461A4-7170-40B4-AD39-04475387D1E9}) (Version: 12.5.00700 - Nero AG)
OLYMPUS CAMEDIA Master 4.1 (HKLM-x32\...\{30BB4D60-81DB-11D5-BB77-00400536ABAC}) (Version:  - )
OLYMPUS Digital Camera Updater (HKLM-x32\...\{962428F4-2E99-4AD2-B55D-B468C18A8A89}) (Version: 2.0.0 - Olympus Corporation)
OLYMPUS Master (HKLM-x32\...\{BA820A24-704B-428D-9904-71A10DAC1372}) (Version: 1.42.5000 - OLYMPUS IMAGING CORP.) Hidden
OLYMPUS Master (HKLM-x32\...\InstallShield_{BA820A24-704B-428D-9904-71A10DAC1372}) (Version: 1.42.5000 - OLYMPUS IMAGING CORP.)
OLYMPUS Viewer 3 (HKLM-x32\...\{AE1A1FF8-3BF6-444B-AF94-F75084D9AA31}) (Version: 2.1.1 - Olympus Corporation)
Origin (HKLM-x32\...\Origin) (Version: 9.1.12.73 - Electronic Arts, Inc.)
PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
Prerequisite installer (HKLM-x32\...\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0003 - Nero AG) Hidden
Product Improvement Study for HP Officejet 7610 series (HKLM\...\{5637E7AE-B399-4438-A5BA-46C17EB8FC0E}) (Version: 29.1.971.39251 - Hewlett-Packard Co.)
Qualcomm Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.16 - Qualcomm Atheros Communications Inc.)
QuickTime (HKLM-x32\...\QuickTime) (Version:  - )
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6899 - Realtek Semiconductor Corp.)
Realtek USB Card Reader (HKLM-x32\...\{1E496A68-4943-424E-829D-5C3C85B7B8F2}) (Version: 6.2.9200.39041 - Realtek Semiconductor Corp.)
Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0021 - REALTEK Semiconductor Corp.)
Roxio Easy CD and DVD Burning (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3 - Roxio)
Roxio File Backup (HKLM\...\{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}) (Version: 1.3.0 - Roxio) Hidden
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Skype Click to Call (HKLM-x32\...\{873F8E7C-10E6-449F-BD7E-5FBA7C8E1C9B}) (Version: 8.5.0.9167 - Microsoft Corporation)
Skype™ 7.40 (HKLM-x32\...\{3B7E914A-93D5-4A29-92BB-AF8C3F66C431}) (Version: 7.40.103 - Skype Technologies S.A.)
Snagit 12 (HKLM-x32\...\{4FC332FE-CBE3-4AE0-B531-35048FD81912}) (Version: 12.4.1 - TechSmith Corporation) Hidden
Snagit 12 (HKLM-x32\...\{ec29af82-9c9e-420e-ab18-53821c36ac3c}) (Version: 12.4.1.3036 - TechSmith Corporation)
Sonic CinePlayer Decoder Pack (HKLM-x32\...\{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}) (Version: 4.3.0 - Sonic Solutions) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 16.3.10.4 - Synaptics Incorporated)
TeamViewer 11 (HKLM-x32\...\TeamViewer) (Version: 11.0.93231 - TeamViewer)
Toshiba App Place (HKLM-x32\...\{ED3CBA78-488F-4E8C-B33F-8E3BF4DDB4D2}) (Version: 1.0.6.3 - Toshiba)
TOSHIBA Application Installer (HKLM\...\{21A63CA3-75C0-4E56-B602-B7CD2EF6B621}) (Version: 9.0.2.8 - Toshiba Corporation)
TOSHIBA Application Installer (HKLM-x32\...\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.1.2 - TOSHIBA)
TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.2.3.1 - TOSHIBA CORPORATION)
TOSHIBA Battery Check Utility (HKLM-x32\...\{5468E297-7EF8-4CB3-A091-F8714147793F}) (Version: 1.00.04.01 - Toshiba Client Solutions Co., Ltd.)
Toshiba Book Place (HKLM-x32\...\{11244D6B-9842-440F-8579-6A4D771A0D9B}) (Version: 3.3.9661 - K-NFB Reading Technology, Inc.)
TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.12 for x64 - TOSHIBA Corporation)
TOSHIBA eco Utility (HKLM\...\{F5AFF327-9B52-4E96-B5A0-BD2488A8EEC9}) (Version: 1.3.23.64 - TOSHIBA Corporation)
TOSHIBA Hardware Setup (HKLM-x32\...\{6D622295-07A8-4CB3-8E0E-6E3D7C782A7B}) (Version: 3.1.0.10 - TOSHIBA Corporation)
TOSHIBA Quality Application (HKLM-x32\...\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.4 - TOSHIBA)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.7.52020010 - TOSHIBA CORPORATION)
TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.15.0 - TOSHIBA)
TOSHIBA Supervisor Password (HKLM-x32\...\{661C3409-C3CC-4869-A0AC-90EAB15F5E93}) (Version: 3.1.0.2 - TOSHIBA Corporation)
TOSHIBA User's Guide (HKLM-x32\...\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.6.0035.6406 - TOSHIBA Corporation)
TOSHIBARegistration (HKLM-x32\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.1.1 - TOSHIBA)
Windows Driver Package - OLYMPUS IMAGING CORP. Camera Communication Driver Package (09/09/2009 1.0.0.0) (HKLM\...\2C1C2F29FADF39F533CEEE67B90F07A5306A4BDB) (Version: 09/09/2009 1.0.0.0 - OLYMPUS IMAGING CORP.)
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{0C3BA0B1-BC14-4B55-98DC-F1E913C1DA10}\InprocServer32 -> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\ActiveX64.ocx (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{3faa4380-a399-11cf-a466-00805fe418f6}\InprocServer32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\en-US\dwgviewrficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{6FFA7438-3E00-4176-9717-B3BBE2E704AB}\InprocServer32 -> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\ActiveX64.ocx (TODO: <Company name>)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{720DB9AF-D62C-4ED0-A377-429C22312852}\localserver32 -> C:\Program Files\Autodesk\DWG TrueView 2017 - English\dwgviewr.exe (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{74F5CC00-49A9-11CF-A2F9-444553540000}\InprocServer32 -> C:\Program Files\AutoCAD LT 2010\acadltficn.dll (Autodesk, Inc.)
CustomCLSID: HKU\S-1-5-21-832600199-2139290072-1447759302-1000_Classes\CLSID\{D70E31AD-2614-49F2-B0FC-ACA781D81F3E}\localserver32 -> C:\Program Files\AutoCAD LT 2010\acadlt.exe (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [    Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [    Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [    Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [AutoCAD Digital Signatures Icon Overlay Handler] -> {36A21736-36C2-4C11-8ACB-D4136F2B57BD} => C:\windows\system32\AcSignIcon.dll [2018-01-29] (Autodesk, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [    Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [    Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [    Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [ Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Green] -> {95A27763-F62A-4114-9072-E81D87DE3B68} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Partial] -> {E300CD91-100F-4E67-9AF3-1384A6124015} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ShellIconOverlayIdentifiers-x32: [Carbonite.Yellow] -> {5E529433-B50E-4bef-A63B-16A6B71B071A} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers1: [AcShellExtension.AcContextMenuHandler] -> {2E7A2C6C-B938-40a4-BA1C-C7EC982DC202} => C:\Program Files\Common Files\Autodesk Shared\AcShellEx\AcShellExtension.dll [2018-01-29] (Autodesk)
ContextMenuHandlers1-x32: [Autodesk.DWF.ContextMenu] -> {6C18531F-CA85-45F7-8278-FF33CF0A5964} => C:\Program Files (x86)\Common Files\Autodesk Shared\DWF Common\DWFShellExtension.dll [2009-01-13] (Autodesk, Inc.)
ContextMenuHandlers1-x32: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers1-x32: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ContextMenuHandlers1-x32: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers1-x32: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll [2015-08-14] (TechSmith Corporation)
ContextMenuHandlers2: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers2: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
ContextMenuHandlers4: [Carbonite] -> {FE8BD682-9A64-4740-A92B-EE7E5F7FA0A5} => C:\Program Files\Carbonite\Carbonite Backup\CarboniteNSE.dll [2018-02-02] (Carbonite, Inc.)
ContextMenuHandlers4: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ContextMenuHandlers4: [EPP] -> {09A47860-11B0-4DA5-AFA5-26D86198A780} => c:\Program Files\Microsoft Security Client\shellext.dll [2015-04-30] (Microsoft Corporation)
ContextMenuHandlers4: [SnagItMainShellExt] -> {CF74B903-3389-469c-B3B6-0204D204FCBD} => C:\Program Files (x86)\TechSmith\Snagit 12\DLLx64\SnagitShellExt64.dll [2015-08-14] (TechSmith Corporation)
ContextMenuHandlers5: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.22.0.dll [2018-06-25] (Dropbox, Inc.)
ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2013-03-08] (Intel Corporation)
ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {0264BE93-D280-45CB-971A-7E31354713CF} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2018-06-18] (Adobe Systems Incorporated)
Task: {0AD157B5-BC76-46FC-887F-11523B38249A} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.38\SymErr.exe
Task: {24143A82-347B-4C7D-8567-403EDE8F9222} - System32\Tasks\{D9B03117-C71B-4971-9717-DBC801D53489} => "c:\program files\internet explorer\iexplore.exe" hxxp://ui.skype.com/ui/0/6.21.0.104/en/abandoninstall?page=tsBing
Task: {3CEBE34D-B791-47A9-AAB8-2DD921148A31} - System32\Tasks\{165D6118-587D-443B-AAD8-7C049A881C39} => C:\windows\system32\pcalua.exe -a "C:\Users\Hawkes\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6PO75GX5\epson13165 (1).exe" -d C:\Users\Hawkes\Desktop
Task: {508CDD79-3374-468D-970E-2AEC9661A1E5} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-21] (Google Inc.)
Task: {69287CB0-8F6A-4B44-9BFD-9C86237D903D} - System32\Tasks\{243D2FEE-8639-40EF-BD86-A0A99A67A997} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [2018-02-02] (Carbonite, Inc.)
Task: {69BF8FCC-500E-48C7-9649-6FD39A19F038} - System32\Tasks\{86CD6B5F-6199-4308-B329-B6449223B9F6} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [2018-02-02] (Carbonite, Inc.)
Task: {6CBEE6CD-C5C5-4C51-BFB8-D8BB9660ADFE} - System32\Tasks\Microsoft\Windows\Setup\gwx\rundetector => C:\windows\system32\GWX\GWXDetector.exe
Task: {7C67E785-E56B-41BB-ABC2-88896B419F48} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\windows\system32\GWX\GWX.exe
Task: {7E94FC44-54A1-4794-B3F8-B069952988E6} - System32\Tasks\{DF9A5375-A07D-49F4-B62A-523ED0737700} => C:\windows\system32\pcalua.exe -a C:\windows\unvise32qt.exe -c C:\windows\system32\QuickTime\Uninstall.log
Task: {8539D9BC-5607-4E45-949D-42B3653F332D} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.5.0.38\SymErr.exe
Task: {90683E55-A0B5-43F3-8BAC-EFCDEDB1331C} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2018-02-09] (Adobe Systems Incorporated)
Task: {977B015E-4952-4F3E-B2BC-7025E28B8E1B} - System32\Tasks\Microsoft_Hardware_Launch_mousekeyboardcenter_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\mousekeyboardcenter.exe [2014-03-19] (Microsoft)
Task: {9D21A963-3449-4446-BC46-CD4B4D1C77EC} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-10-21] (Piriform Ltd)
Task: {A1CF5F5B-B251-405D-95B2-D4837FB1B100} - System32\Tasks\Microsoft_MKC_Logon_Task_itype.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {A50D26AD-7504-44E4-8FEF-9510005F7F49} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\windows\system32\GWX\GWXConfigManager.exe
Task: {A6917D9F-C44C-4196-A75B-4914286E9E37} - System32\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4} => C:\ProgramData\Carbonite\Carbonite Backup\CarboniteUpgrade.exe
Task: {BD9EF8BD-74FA-44E1-B4F7-6BC50FBA7854} - System32\Tasks\Microsoft_Hardware_Launch_ipoint_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {BF5B7FF7-66A9-47A8-8F51-5F74B64B2B16} - System32\Tasks\HPCustParticipation HP Officejet 7610 series => C:\Program Files\HP\HP Officejet 7610 series\Bin\HPCustPartic.exe [2012-10-21] (Hewlett-Packard Co.)
Task: {C35535FB-AB09-404C-81B1-E0F017AC16FC} - System32\Tasks\{85772BBC-D792-4D46-ACCF-6A4DC7067956} => C:\windows\system32\pcalua.exe -a "C:\Users\Hawkes\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6PO75GX5\epson13165.exe" -d C:\Users\Hawkes\Desktop
Task: {C464523C-943F-44B9-998E-4334FE1E9E27} - System32\Tasks\{F9DE2CDE-E69A-4BE0-A141-207AE4B2D4C5} => "c:\program files\internet explorer\iexplore.exe" hxxp://ui.skype.com/ui/0/6.21.0.104/et/abandoninstall?page=tsMain
Task: {D9FF95C6-1BA7-48DE-AA47-875660B831E9} - System32\Tasks\Microsoft_MKC_Logon_Task_ipoint.exe => c:\Program Files\Microsoft Mouse and Keyboard Center\ipoint.exe [2014-03-19] (Microsoft Corporation)
Task: {E0C994AE-F17F-4891-AD17-9133A139C3A6} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfigAndContent
Task: {E0C994AE-F17F-4891-AD17-9133A139C3A6} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(2): C:\windows\system32\GWX\GWXDetector.exe
Task: {E785CFD4-03B2-4CFA-8B6E-74699D9F08A7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\windows\system32\GWX\GWXConfigManager.exe
Task: {F2AF81B1-70C5-498F-87EE-C40C5066EA1A} - System32\Tasks\{7FD564CA-D11F-43F7-B5F3-EC2F12AD5B0E} => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe [2018-02-02] (Carbonite, Inc.)
Task: {F4946B0F-7618-4A94-95D8-FEAAE88BA7F7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig
Task: {F4946B0F-7618-4A94-95D8-FEAAE88BA7F7} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(2): C:\windows\system32\GWX\GWXDetector.exe
Task: {F93A9CCF-54A6-42F9-ABE9-D65E5E1AFBF7} - System32\Tasks\Microsoft_Hardware_Launch_itype_exe => c:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe [2014-03-19] (Microsoft Corporation)
Task: {FF339D3F-657D-498A-9AAE-A54FDC0E1263} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-21] (Google Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\windows\Tasks\Adobe Acrobat Update Task.job => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
Task: C:\windows\Tasks\BeFrugal.com Toolbar.job => C:\Users\Hawkes\AppData\Local\Programs\BeFrugal.com\Add-On\2013.3.19.3\BFHP.exe C:\Users\Hawkes\AppData\Local\Programs\BeFrugal.com\Add-On\2013.3.19.3BeFrugal.com
Task: C:\windows\Tasks\Carbonite Installer - Start Carbonite UI.job => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
Task: C:\windows\Tasks\DropboxUpdateTaskMachineCore1d3ef0b1b588d01.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d12498778f9a0e.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d12cab4234c555.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d15d98e723a1e9.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d1ab0f2d3b04ee.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d1e92df20b6857.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\windows\Tasks\HP AR Program Upload - 27736493983845a3bd75f186d8862cb3b907ccf6bcaa47ea99cb5a5d61296bd8.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 27736493983845a3bd75f186d8862cb3b907ccf6bcaa47ea99cb5a5d61296bd8 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 288a60fccd9e45caaa6c191f699fcc14f9cd3f75b1864fd6b57b53ade8a34577.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 288a60fccd9e45caaa6c191f699fcc14f9cd3f75b1864fd6b57b53ade8a34577 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 288fe57b164c466199f2146b660e8d2752645e0b598f4754b6c2c3ae46e4713d.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 288fe57b164c466199f2146b660e8d2752645e0b598f4754b6c2c3ae46e4713d -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 383f041efd824504bb30bc1595885f2d47a62a47a0d64606b8dde3686841eea2.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 383f041efd824504bb30bc1595885f2d47a62a47a0d64606b8dde3686841eea2 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 4bed420b7c6d4592b5300295af77e4d316a4c156964e425ebb9ce627fa3fe22a.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 4bed420b7c6d4592b5300295af77e4d316a4c156964e425ebb9ce627fa3fe22a -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - 9c09867638e1466486681f4201d2fc9c03056bfbeeb041ce93ea16442f54acb3.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N 9c09867638e1466486681f4201d2fc9c03056bfbeeb041ce93ea16442f54acb3 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - a79dfbcc00c04a41ad79853178ed3d277881e027f7454645aef2662a8382d747.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N a79dfbcc00c04a41ad79853178ed3d277881e027f7454645aef2662a8382d747 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - abbccb9a521e4840a53914af05ad146bbd601fa958f44975b4ccbdd04b94f7de.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N abbccb9a521e4840a53914af05ad146bbd601fa958f44975b4ccbdd04b94f7de -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - c10ad8feea404f86949259d0615820cdd423f71b28c645e3b248bf4669bb00e1.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N c10ad8feea404f86949259d0615820cdd423f71b28c645e3b248bf4669bb00e1 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - ca517a7e7aec482f807d4d2552d8aca269e7ff6b2037414d8ab933c0cb4f43bc.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N ca517a7e7aec482f807d4d2552d8aca269e7ff6b2037414d8ab933c0cb4f43bc -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - d8c050373ec441009dd181e51c551416408d22ba35554eeaad46c007259a157f.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N d8c050373ec441009dd181e51c551416408d22ba35554eeaad46c007259a157f -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - d920090a1676405f9a759e2cac214230d2dac2c9fae74d6fa5b4f93fef65d00c.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N d920090a1676405f9a759e2cac214230d2dac2c9fae74d6fa5b4f93fef65d00c -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - e2200aa23c4b4d31bfbfe531b31ae1d65219cbde6dbd43a480eea9d8696848cc.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N e2200aa23c4b4d31bfbfe531b31ae1d65219cbde6dbd43a480eea9d8696848cc -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - e3f4e44d23cd4868bfcff04fd6d66f13c150df199dc5411d987a73304d5dda2f.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N e3f4e44d23cd4868bfcff04fd6d66f13c150df199dc5411d987a73304d5dda2f -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\HP AR Program Upload - fc7c17da35ec440f9150b71485d2d8b5d325724b3e7142f6bfafe9e654679784.job => C:\Program Files\HP\HP Officejet 4630 series\bin\HPRewards.exeT-N fc7c17da35ec440f9150b71485d2d8b5d325724b3e7142f6bfafe9e654679784 -mode ScheduledRunDLL32.exe
Task: C:\windows\Tasks\TechSmith Updater.job => C:\Program Files (x86)\Common Files\TechSmith Shared\Updater\TSCUpdClt.exe
Task: C:\windows\Tasks\{5F6010C8-60E5-41f3-BF5B-C3AF5DBE12D4}.job => Powershell noexit command carbProgramDataPath env ProgramData \Carbonite Carbonite Backup\ upgradeExe CarboniteUpgrade exe upgradeFullPath carbProgramDataPath upgradeExe logFile CarboniteUpgrade log logFileFullPath carbProgramDataPath logFile psversion string psversiontable PSVersion major string psversiontable PSVersion minor string psversiontable PSVersion build string psversiontable PSVersion revision function LogMsg level message tab char date Get Date format yyyy MM dd HH mm ss ffzzz fullMessage date tab level message Add Content logFileFullPath fullMessage function LogError message write error message LogMsg message function LogWarning message write warning message LogMsg message function LogInfo message write host message LogMsg message LogInfo CarboniteUpgrade ps1 PS version psversion started at Get Date format LogInfo Input args args if test path path upgradeFullPath logStr No upgrade necessary upgradeFullPath not found LogInfo logStr exit expectedSubjectName Carbonite expectedSubjectName2018 Carbonite Inc codeSignStatus get authenticodesignature upgradeFullPath status if codeSignStatus ne Valid errorStr Invalid code signature status codeSignStatus LogError errorStr exit actualSubjectName get authenticodesignature upgradeFullPath signercertificate GetNameInfo SimpleName false if actualSubjectName ne expectedSubjectName and actualSubjectName ne expectedSubjectName2018 errorStr Unexpected certificate subject name actualSubjectName LogError errorStr exit LogInfo Starting upgradeFullPath args start process upgradeFullPath argumentlist args passthru wait verb runas if ExitCode ne errorStr Upgrade exited with error code ExitCode LogError errorStr exit ExitCode LogInfo Upgrade completed exit /silent Arg0 CarboniteBThis task checks for upgrades to Carbonite Please do not delete 08
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-04-11 07:58 - 2013-10-23 14:24 - 000087600 _____ () C:\windows\System32\cpwmon64.dll
2017-09-01 02:49 - 2017-09-01 02:49 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2017-09-01 02:49 - 2017-09-01 02:49 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-05-31 15:56 - 2013-05-31 15:56 - 000016720 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
2018-06-07 12:32 - 2018-06-09 09:02 - 002297040 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
2018-06-07 12:32 - 2018-06-09 09:02 - 002493648 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll
2010-10-20 15:23 - 2010-10-20 15:23 - 008801632 _____ () C:\Program Files\Microsoft Office\Office14\1033\GrooveIntlResource.dll
2013-03-08 19:06 - 2013-03-08 19:06 - 000094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-08-22 14:19 - 2011-08-22 14:19 - 011204992 _____ () C:\Program Files\Toshiba\FlashCards\BlackPng.dll
2012-03-02 15:08 - 2012-03-02 15:08 - 000595840 _____ () C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
2010-12-15 15:19 - 2010-12-15 15:19 - 000124320 _____ () C:\Program Files\Toshiba\TECO\MUIHelp.dll
2017-09-11 14:45 - 2017-09-11 14:45 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll
2017-09-11 14:45 - 2017-09-11 14:45 - 000092472 _____ () C:\Program Files\iTunes\zlib1.dll
2009-06-18 22:46 - 2009-06-18 22:46 - 000494064 _____ () C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe
2018-06-25 14:06 - 2018-06-22 11:15 - 004608856 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.99\libglesv2.dll
2018-06-25 14:06 - 2018-06-22 11:15 - 000099672 _____ () C:\Program Files (x86)\Google\Chrome\Application\67.0.3396.99\libegl.dll
2014-03-01 22:28 - 2013-01-14 10:25 - 001200088 _____ () C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\ACE.dll
2017-01-19 10:50 - 2016-08-26 16:41 - 000014848 _____ () C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\Tracer.dll
2017-01-19 10:50 - 2016-05-31 10:41 - 000122880 _____ () C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OlyPalm.dll
2017-01-19 10:50 - 2011-08-09 15:22 - 000450560 _____ () C:\Program Files (x86)\OLYMPUS\OLYMPUS Viewer 3\OSLite.dll
2015-08-14 11:57 - 2015-08-14 11:57 - 002099200 _____ () C:\Program Files (x86)\TechSmith\Snagit 12\opencv_core249.dll
2015-08-14 11:57 - 2015-08-14 11:57 - 001914368 _____ () C:\Program Files (x86)\TechSmith\Snagit 12\opencv_imgproc249.dll
2018-06-26 12:54 - 2018-06-25 09:24 - 001107272 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2018-06-26 12:54 - 2018-06-25 09:24 - 002079048 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2018-06-26 12:55 - 2018-06-25 09:29 - 000021328 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000022384 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000135656 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 001881448 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:24 - 000111576 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes35.dll
2018-06-26 12:55 - 2018-06-25 09:24 - 000103392 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000068952 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000079688 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:24 - 000399832 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom35.dll
2018-06-26 12:55 - 2018-06-25 09:24 - 000024544 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000043496 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:24 - 000021472 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000124896 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000114664 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000392024 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000028520 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000024552 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000175584 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000024544 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000026080 _____ () C:\Program Files (x86)\Dropbox\Client\win32job.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000023904 _____ () C:\Program Files (x86)\Dropbox\Client\winshell.compiled._winshell.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000048616 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000057824 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000022360 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000023392 _____ () C:\Program Files (x86)\Dropbox\Client\crashpad.compiled._Crashpad.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000069992 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000025960 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:27 - 003865936 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000088904 _____ () C:\Program Files (x86)\Dropbox\Client\sip.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 001800528 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 001960272 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000028640 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:27 - 000155480 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000521552 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:27 - 000051032 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineCore.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000043352 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:27 - 000130896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:27 - 000220504 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000205144 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000060896 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000056160 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000024040 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000024424 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000022376 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000028016 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:24 - 000348128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.cp35-win32.pyd
2018-06-26 12:55 - 2018-06-25 09:29 - 000024432 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000026464 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:24 - 000036312 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2018-06-26 12:55 - 2018-06-25 09:29 - 000023400 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.advapi32.compiled._winffi_advapi32.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000181064 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2018-06-26 12:55 - 2018-06-25 09:29 - 000031584 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000024384 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.DLL
2018-06-26 12:54 - 2018-06-25 09:26 - 001638208 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2018-06-26 12:55 - 2018-06-25 09:29 - 000026984 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000546640 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.cp35-win32.pyd
2018-06-26 12:54 - 2018-06-25 09:26 - 000359760 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.cp35-win32.pyd
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMPCHelper => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tvnserver => ""=""
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Software\Classes\.scr: AutoCADLTScriptFile => C:\windows\system32\notepad.exe "%1"
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2009-07-13 18:34 - 2009-06-10 13:00 - 000000824 _____ C:\windows\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-832600199-2139290072-1447759302-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Hawkes\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 172.20.10.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: SENS => 2
MSCONFIG\Services: Themes => 2
MSCONFIG\Services: WerSvc => 3
MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^LUMIX Simple Viewer.lnk => C:\windows\pss\LUMIX Simple Viewer.lnk.CommonStartup
MSCONFIG\startupfolder: C:^Users^Hawkes^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^ChaliesTips.txt => C:\windows\pss\ChaliesTips.txt.Startup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: BCSSync => "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
MSCONFIG\startupreg: BFHP => C:\Program Files (x86)\Common Files\BeFrugal.com\Toolbar\BFHP.exe
MSCONFIG\startupreg: Carbonite Backup => C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR
MSCONFIG\startupreg: Dropbox => "C:\Program Files (x86)\Dropbox\Client\Dropbox.exe" /systemstartup
MSCONFIG\startupreg: MyTransitGuide AppIntegrator 32-bit => C:\PROGRA~2\MYTRAN~1\bar\1.bin\AppIntegrator.exe
MSCONFIG\startupreg: MyTransitGuide AppIntegrator 64-bit => C:\PROGRA~2\MYTRAN~1\bar\1.bin\AppIntegrator64.exe
MSCONFIG\startupreg: MyTransitGuide EPM Support => "C:\PROGRA~2\MYTRAN~1\bar\1.bin\b7medint.exe" T8EPMSUP.DLL,S
MSCONFIG\startupreg: OnlineMapFinder AppIntegrator 32-bit => C:\PROGRA~2\ONLINE~2\bar\1.bin\AppIntegrator.exe
MSCONFIG\startupreg: OnlineMapFinder AppIntegrator 64-bit => C:\PROGRA~2\ONLINE~2\bar\1.bin\AppIntegrator64.exe
MSCONFIG\startupreg: OnlineMapFinder EPM Support => "C:\PROGRA~2\ONLINE~2\bar\1.bin\9pmedint.exe" T8EPMSUP.DLL,S
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: tvncontrol => "C:\Program Files (x86)\ShowMyPCService\tvnserver.exe" -controlservice -slave
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{D286209D-D47E-4FB2-990B-E5F083ECE2C0}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{946D6113-2E42-4915-A9AF-748B5E95AA62}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\bin\FaxApplications.exe
FirewallRules: [{5F441D91-E139-4EE4-99CC-A3DE8A9E2026}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\bin\DigitalWizards.exe
FirewallRules: [{4AEF1F8E-6B65-44A9-8C21-00125FB3C499}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\bin\SendAFax.exe
FirewallRules: [{071924D8-FB41-459C-BAD7-8FC2191F04F4}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\Bin\DeviceSetup.exe
FirewallRules: [{B98F14D0-D6E0-41DC-817F-C8F91BF100D3}] => (Allow) LPort=5357
FirewallRules: [{7C02512E-A74E-49CE-BE18-6EE2537E501A}] => (Allow) C:\Program Files\HP\HP Officejet 4630 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{D485610C-2597-495F-963E-B107555D25B6}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\bin\FaxApplications.exe
FirewallRules: [{4E779424-ABBA-496B-9B91-8EF6BF90EF67}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\bin\DigitalWizards.exe
FirewallRules: [{BB47B70E-AFDA-427E-96EC-111CC9DCFCA0}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\bin\SendAFax.exe
FirewallRules: [{A0325101-C835-4182-B593-1CFAF451C694}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\Bin\DeviceSetup.exe
FirewallRules: [{EB25C5FF-1538-4D22-89B2-1573FB3D15E1}] => (Allow) C:\Program Files\HP\HP Officejet 7610 series\Bin\HPNetworkCommunicatorCom.exe
FirewallRules: [{11EB5D6C-61A2-4ECD-A65B-47270BA64262}] => (Allow) LPort=5357
FirewallRules: [{0E995ABC-3867-4C29-BEBE-E3CB823147E6}] => (Allow) LPort=8298
FirewallRules: [{721FE470-A698-4217-90C6-E443CEB3ADD7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{89AB279E-108C-49A6-AC29-219E345FBF0F}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{CF76B23B-0316-4DDB-A457-FA1E6093F24C}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{A2F1F44A-F1DC-498E-A6D4-29FBBCEE7C5B}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{DF8BB5E6-25CE-45BF-8385-10293BB4D45B}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS0938\HPDiagnosticCoreUI.exe
FirewallRules: [{9CC6951E-0F88-4326-8139-888CF5ED787B}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS0938\HPDiagnosticCoreUI.exe
FirewallRules: [{C4A82124-AA2C-4834-B75E-C87F4F6D4C37}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS09A0\HPDiagnosticCoreUI.exe
FirewallRules: [{45B6719E-3B1F-4944-AE1D-DF23E039676B}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS09A0\HPDiagnosticCoreUI.exe
FirewallRules: [{CD87450E-3D61-47DA-875E-B410F23B0C1E}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6B47\HPDiagnosticCoreUI.exe
FirewallRules: [{EB73A0BB-DFA5-451F-BC37-0018B8DA9BC4}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6B47\HPDiagnosticCoreUI.exe
FirewallRules: [{497DC7D4-A6F3-41E0-9796-02B5065FD6E3}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6BB3\HPDiagnosticCoreUI.exe
FirewallRules: [{94EB7634-7AB6-441F-8386-5174837B9A06}] => (Allow) C:\Users\Hawkes\AppData\Local\Temp\7zS6BB3\HPDiagnosticCoreUI.exe
FirewallRules: [TCP Query User{D3FD7FA5-EAB9-4BE7-8430-CB22469A7507}C:\program files\adventure pilot\ifly.exe] => (Allow) C:\program files\adventure pilot\ifly.exe
FirewallRules: [UDP Query User{CC1A72EB-D67F-4EF9-B84B-DC97A6553A8E}C:\program files\adventure pilot\ifly.exe] => (Allow) C:\program files\adventure pilot\ifly.exe
FirewallRules: [{D8A9DF54-8423-408A-818E-DD779D830BC5}] => (Block) C:\program files\adventure pilot\ifly.exe
FirewallRules: [{248CEB5B-1F8E-42FE-971D-CFD34214D96E}] => (Block) C:\program files\adventure pilot\ifly.exe
FirewallRules: [{25D49DFA-C110-4F58-89ED-A9511BA4C35B}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{676527A1-FC83-4624-A026-624905FAF165}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{6E747A63-C966-447F-B87D-6A62DEDBE771}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer.exe
FirewallRules: [{252D9E02-6606-4899-8E57-E36CD2D56384}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{36CA8E8C-16F6-48E7-A504-DCC355027DE3}] => (Allow) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe
FirewallRules: [{FC0C23DB-B064-4C41-9C52-6D3B6E40B928}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [{58428A2F-10FF-47E2-B471-B0B68FC3DDD7}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
 
==================== Restore Points =========================
 
30-01-2018 12:28:35 Windows Update
31-01-2018 03:35:03 Microsoft Antimalware Checkpoint
03-02-2018 01:35:09 Windows Update
06-02-2018 02:19:14 Windows Update
09-02-2018 12:27:59 Windows Update
12-02-2018 12:29:16 Windows Update
14-02-2018 04:05:28 Windows Update
18-02-2018 02:03:32 Windows Update
22-02-2018 02:08:37 Windows Update
25-02-2018 05:00:28 Windows Update
01-03-2018 01:53:56 Windows Update
04-03-2018 02:22:16 Windows Update
07-03-2018 05:01:31 Windows Update
11-03-2018 02:24:42 Windows Update
14-03-2018 03:00:17 Windows Update
17-03-2018 04:01:02 Windows Update
20-03-2018 05:08:10 Microsoft Antimalware Checkpoint
21-03-2018 01:04:44 Windows Update
24-03-2018 01:15:31 Windows Update
28-03-2018 00:36:46 Windows Update
31-03-2018 01:10:51 Windows Update
31-03-2018 03:00:13 Windows Update
04-04-2018 01:13:38 Windows Update
06-04-2018 03:00:13 Windows Update
09-04-2018 03:33:26 Windows Update
12-04-2018 03:00:16 Windows Update
15-04-2018 03:31:36 Windows Update
19-04-2018 01:05:21 Windows Update
22-04-2018 01:26:14 Windows Update
25-04-2018 03:30:42 Windows Update
29-04-2018 01:08:06 Windows Update
02-05-2018 03:31:23 Windows Update
06-05-2018 01:17:38 Windows Update
09-05-2018 03:31:15 Windows Update
10-05-2018 03:00:13 Windows Update
13-05-2018 04:50:49 Windows Update
17-05-2018 00:37:23 Windows Update
20-05-2018 01:08:31 Windows Update
21-05-2018 19:19:05 Microsoft Antimalware Checkpoint
23-05-2018 04:51:00 Windows Update
27-05-2018 00:58:18 Windows Update
30-05-2018 01:03:23 Windows Update
02-06-2018 01:23:47 Windows Update
04-06-2018 16:28:09 Microsoft Visual C++ 2017 Redistributable (x86) - 14.12.25810
04-06-2018 16:29:24 Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23026
04-06-2018 16:30:22 Microsoft Visual C++ 2017 Redistributable (x64) - 14.12.25810
04-06-2018 16:31:38 Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026
04-06-2018 16:32:23 Installed DirectX
05-06-2018 12:49:07 Restore Operation
06-06-2018 00:53:42 Windows Update
09-06-2018 10:53:54 About to run BleepingComputer scan
15-06-2018 11:51:13 Windows Update
19-06-2018 03:00:29 Windows Update
22-06-2018 09:55:50 Windows Update
25-06-2018 16:48:37 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (06/26/2018 03:09:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 13696
 
Error: (06/26/2018 03:09:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 13696
 
Error: (06/26/2018 03:09:36 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (06/26/2018 03:09:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 12589
 
Error: (06/26/2018 03:09:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 12589
 
Error: (06/26/2018 03:09:35 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
 
Error: (06/26/2018 03:09:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 11419
 
Error: (06/26/2018 03:09:33 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 11419
 
 
System errors:
=============
Error: (06/27/2018 12:59:33 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 119.0.0.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: Network Inspection System
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 2.1.14600.4
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/27/2018 12:59:33 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.271.22.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: AntiSpyware
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 1.1.15000.2
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/27/2018 12:59:33 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.271.22.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: AntiVirus
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 1.1.15000.2
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/27/2018 12:59:33 AM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.271.22.0
 
Update Source: Microsoft Update Server
 
Update Stage: Search
 
 
Signature Type: AntiVirus
 
Update Type: Full
 
User: NT AUTHORITY\SYSTEM
 
Current Engine Version: 
 
Previous Engine Version: 1.1.15000.2
 
Error code: 0x8024402c
 
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
 
Error: (06/26/2018 04:47:36 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 119.0.0.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: Network Inspection System
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 2.1.14600.4
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/26/2018 04:47:36 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.271.22.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: AntiSpyware
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 1.1.15000.2
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/26/2018 04:47:36 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.271.22.0
 
Update Source: Microsoft Malware Protection Center
 
Update Stage: Search
 
 
Signature Type: AntiVirus
 
Update Type: Full
 
User: NT AUTHORITY\NETWORK SERVICE
 
Current Engine Version: 
 
Previous Engine Version: 1.1.15000.2
 
Error code: 0x80072ee7
 
Error description: The server name or address could not be resolved
 
Error: (06/26/2018 04:47:36 PM) (Source: Microsoft Antimalware) (EventID: 2001) (User: )
Description: Microsoft Antimalware has encountered an error trying to update signatures.
 
New Signature Version: 
 
Previous Signature Version: 1.271.22.0
 
Update Source: Microsoft Update Server
 
Update Stage: Search
 
 
Signature Type: AntiVirus
 
Update Type: Full
 
User: NT AUTHORITY\SYSTEM
 
Current Engine Version: 
 
Previous Engine Version: 1.1.15000.2
 
Error code: 0x8024402c
 
Error description: An unexpected problem occurred while checking for updates. For information on installing or troubleshooting updates, see Help and Support.
 
 
==================== Memory info =========================== 
 
Processor: Intel® Core™ i3-3110M CPU @ 2.40GHz
Percentage of memory in use: 70%
Total physical RAM: 6026.36 MB
Available physical RAM: 1755.84 MB
Total Virtual: 15063.52 MB
Available Virtual: 11118.01 MB
 
==================== Drives ================================
 
Drive c: (TI10668700I) (Fixed) (Total:919.09 GB) (Free:682.06 GB) NTFS ==>[system with boot components (obtained from drive)]
 
\\?\Volume{75ee4344-a1d2-11e3-a5c4-806e6f6e6963}\ (System) (Fixed) (Total:1.46 GB) (Free:1.24 GB) NTFS
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 931.5 GB) (Disk ID: 624B2B4D)
Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
Partition 2: (Not Active) - (Size=919.1 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=11 GB) - (Type=17)
 
==================== End of Addition.txt ============================





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users