Jump to content

Recommended Posts

Posted
BTW, the removal process seems to be hanging at a point which is showing "Removing product VS", if that should be stuck there for another, what else can I try? I had told the owner he may need to reinstall OS but he says has some softwares on there which he can;t get back the license info for.
Posted

Just let me have a new set of frst reports and we'll see if there's any leftovers.

Won't be able to write a fix (If needed) until I'm home from work though.... a couple of hours.

76c90dd0e79a714317a8daeecc1584d2.png

Posted

Sure thx but all is working fine.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-10-2017 01

Ran by Webb (administrator) on WEBB-PC (19-10-2017 11:07:13)

Running from E:\

Loaded Profiles: Webb (Available Profiles: Webb)

Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: IE)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

() C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

() C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe

() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

() C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE

(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe

(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe

() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe

(Microsoft Corporation) C:\Windows\splwow64.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe

(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe

(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe

(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe

(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)

HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)

HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)

HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-09-01] (Apple Inc.)

HKLM-x32\...\Run: [TrayServer] => C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_14\TrayServer.exe

HKLM-x32\...\Run: [iSUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [324976 2010-05-21] (Flexera Software, Inc.)

HKLM-x32\...\Run: [] => [X]

HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatchTray14.exe [294032 2012-07-18] (Corel Corporation)

HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)

HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1637496 2011-08-04] (CANON INC.)

HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296520 2014-11-03] (RealNetworks, Inc.)

HKLM-x32\...\Run: [RealDownloader] => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [551488 2014-09-23] ()

HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2131344 2016-06-20] (Wondershare)

HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\AllMyTube\DelayPluginI.exe [1960336 2015-08-11] ()

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Amazon Music] => C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe [5908968 2016-06-16] ()

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Chromium] => "c:\users\webb\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-09-09] (Apple Inc.)

HKU\S-1-5-18\...\RunOnce: [sPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-07-18] (Microsoft Corporation)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2014-11-03]

ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-10-18]

ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{1BE97A3D-A7FB-498E-9B5F-075F5A5C3C67}: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{7BAF68A2-5E5E-4630-A2D4-91496139CC0F}: [DhcpNameServer] 192.168.1.1

 

Internet Explorer:

==================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKU\S-1-5-21-207249110-600702845-166796750-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/en-us/?ocid=U221DHP&pc=U221

SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-09-26] (RealDownloader)

BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

BHO-x32: Wondershare AllMyTube 4.3.0 -> {067DF9EC-26B7-40DC-8DB8-CD8BE85AE367} -> C:\ProgramData\Wondershare\AllMyTube\WSBrowserAppMgr.dll [2015-08-11] (Wondershare)

BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-09-26] (RealDownloader)

BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14] (CANON INC.)

BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14] (CANON INC.)

DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File

 

FireFox:

========

FF ProfilePath: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default [2017-10-18]

FF NewTab: Mozilla\Firefox\Profiles\t8ym71sf.default -> about:newtab

FF DefaultSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\t8ym71sf.default -> Bing

FF SelectedSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF Homepage: Mozilla\Firefox\Profiles\t8ym71sf.default -> user_pref("browser.startup.homepage", "hxxps://www.malwarebytes.org/restorebrowser/

FF Extension: (Transit) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\@Transit.xpi [2017-09-12]

FF Extension: (Bing Extension) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\bingsearch.full@microsoft.com [2017-10-18] [not signed]

FF SearchPlugin: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\searchplugins\bing-.xml [2015-03-28]

FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-11-03] [not signed]

FF HKLM-x32\...\Firefox\Extensions: [{4642CD99-8FDF-4550-94E1-63360972C326}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF HKLM-x32\...\Firefox\Extensions: [AllMyTube@Wondershare.com] - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com

FF Extension: (Wondershare AllMyTube) - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com [2016-02-10] [not signed]

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-13] ()

FF Plugin: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-13] ()

FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-21] (CANON INC.)

FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-09] (Nero AG)

FF Plugin-x32: @real.com/nppl3260;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2014-11-03] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.14 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-09-26] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprpplugin;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2014-11-03] (RealPlayer Cloud)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)

FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)

FF Plugin ProgramFiles/Appdata: C:\Users\Webb\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2009-09-25] (Microsoft Corporation)

 

Chrome:

=======

CHR DefaultProfile: Default

CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US1134D20170817&p={searchTerms}

CHR DefaultSearchKeyword: Default -> mcafee

CHR Profile: C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default [2017-10-19]

CHR Extension: (Chrome Web Store Payments) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-28]

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19]

CHR HKU\S-1-5-21-207249110-600702845-166796750-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx

 

==================== Services (Whitelisted) ====================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [457360 2012-06-20] ()

R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-17] (Adobe Systems Incorporated)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)

R2 BOT4Service; C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe [22160 2012-07-11] ()

R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]

S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]

R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-21] (Malwarebytes)

R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-09-26] ()

R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-11-03] (RealNetworks, Inc.)

R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31344 2014-09-26] ()

S3 RoxMediaDB14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxMediaDB14.exe [1096848 2012-07-18] (Corel Corporation)

S2 RoxWatch14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatch14.exe [341136 2012-07-18] (Corel Corporation)

S3 UPnPService; C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [548864 2008-10-21] (Magix AG) [File not signed]

S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

 

===================== Drivers (Whitelisted) ======================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [253888 2017-10-19] (Malwarebytes)

R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-07-10] (Corel Corporation)

S3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3741960 2015-06-19] (Realtek Semiconductor Corporation )

S1 RxFilter; C:\Windows\SysWOW64\DRIVERS\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)

R0 Sahdad64; C:\Windows\System32\Drivers\Sahdad64.sys [28304 2012-06-20] (Corel Corporation)

R0 Saibad64; C:\Windows\System32\Drivers\Saibad64.sys [20112 2012-06-20] (Corel Corporation)

R1 SaibVdAd64; C:\Windows\System32\Drivers\SaibVdAd64.sys [27792 2012-06-20] (Corel Corporation)

R3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-09-03] (Wondershare)

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-18 19:30 - 2017-10-18 19:30 - 000000000 ____D C:\Users\Webb\AppData\Roaming\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:29 - 000000000 ____D C:\Program Files (x86)\TP-LINK

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 000030472 _____ (Windows ® Server 2003 DDK provider) C:\Windows\system32\rtlCoInst.dll

2017-10-18 19:28 - 2015-06-19 02:53 - 000028467 _____ C:\Windows\system32\netrtwlanu.cat

2017-10-18 19:28 - 2015-02-16 15:19 - 000008320 _____ C:\Windows\system32\rtlCoInst.dat

2017-10-18 19:27 - 2017-10-18 19:29 - 000000000 ____D C:\ProgramData\TP-LINK

2017-10-18 15:14 - 2017-10-18 15:14 - 000004034 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse

2017-10-18 12:23 - 2017-10-19 11:07 - 000000000 ____D C:\FRST

2017-10-18 11:54 - 2017-10-18 12:21 - 000000000 ____D C:\AdwCleaner

2017-10-18 11:09 - 2017-10-18 11:18 - 000000258 __RSH C:\ProgramData\ntuser.pol

2017-10-18 10:51 - 2017-10-19 07:34 - 000003860 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse

2017-10-18 10:36 - 2017-10-19 10:16 - 000253888 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

2017-10-18 10:36 - 2017-10-18 11:17 - 000002016 _____ C:\Users\Public\Desktop\Malwarebytes.lnk

2017-10-18 10:36 - 2017-10-18 10:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes

2017-10-18 10:36 - 2017-10-18 10:36 - 000000000 ____D C:\Program Files\Malwarebytes

2017-10-18 10:36 - 2017-08-21 07:20 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys

2017-10-09 16:03 - 2017-10-09 16:03 - 000000000 ____D C:\FixMeStick Quarantine

2017-10-09 15:02 - 2017-10-12 23:07 - 000000000 ____D C:\FixMeStick

2017-10-01 00:01 - 2017-10-01 00:01 - 000245712 _____ (Mozilla) C:\Users\Webb\Downloads\Firefox Installer (4).exe

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-19 11:06 - 2014-03-31 21:02 - 053736246 _____ C:\Windows\ntbtlog.txt

2017-10-19 10:23 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2017-10-19 10:23 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2017-10-19 10:15 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT

2017-10-19 10:14 - 2009-07-14 00:45 - 000658640 _____ C:\Windows\system32\FNTCACHE.DAT

2017-10-19 09:47 - 2017-05-17 21:06 - 000000000 ____D C:\Program Files\Common Files\McAfee

2017-10-19 08:52 - 2017-08-17 20:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee

2017-10-19 08:48 - 2017-08-17 20:16 - 000000000 __RSD C:\Users\Webb\Documents\McAfee Vaults

2017-10-19 08:35 - 2017-08-16 16:27 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

2017-10-19 08:35 - 2017-08-16 16:27 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk

2017-10-19 07:47 - 2013-07-17 00:37 - 000000000 ____D C:\Users\Webb\AppData\Local\Adobe

2017-10-18 19:29 - 2013-07-26 11:51 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2017-10-18 19:29 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf

2017-10-18 19:01 - 2013-07-16 23:39 - 000000000 ____D C:\Users\Webb\AppData\LocalLow\Temp

2017-10-18 12:41 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\NDF

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\ProgramData\iolo

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\Program Files (x86)\iolo

2017-10-18 10:39 - 2009-07-14 01:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI

2017-10-18 10:36 - 2013-08-29 14:46 - 000000000 ____D C:\ProgramData\Malwarebytes

2017-10-12 15:35 - 2017-09-12 09:37 - 000003482 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Webb

2017-10-12 15:34 - 2013-07-28 15:18 - 000000576 _____ C:\Users\Webb\Desktop\Wintm.lnk

2017-10-12 12:38 - 2017-09-12 09:37 - 000003488 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Webb

2017-10-09 09:37 - 2009-07-14 01:08 - 000032618 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2017-10-05 21:24 - 2013-07-20 19:08 - 000000000 ____D C:\Users\Webb\AppData\Local\CrashDumps

2017-10-05 21:21 - 2017-08-18 10:48 - 000000000 ____D C:\Program Files\Mozilla Firefox

2017-10-05 21:08 - 2015-01-24 20:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2017-09-23 17:17 - 2017-06-04 15:39 - 000033280 _____ C:\Users\Webb\Desktop\jeans schedule octoberdec.xls

2017-09-23 17:09 - 2017-06-03 23:12 - 000033280 _____ C:\Users\Webb\Desktop\field service october to decenber.xls

 

==================== Files in the root of some directories =======

 

2014-10-07 20:18 - 2016-05-02 13:41 - 000000098 _____ () C:\Users\Webb\AppData\Roaming\WB.CFG

2014-12-21 16:06 - 2014-12-21 16:06 - 000001456 _____ () C:\Users\Webb\AppData\Local\Adobe Save for Web 12.0 Prefs

2013-07-26 19:36 - 2017-09-14 20:55 - 001592448 _____ () C:\Users\Webb\AppData\Local\rx_audio.Cache

2013-07-22 20:33 - 2017-09-14 20:55 - 000054072 _____ () C:\Users\Webb\AppData\Local\rx_image32.Cache

2013-07-16 17:13 - 2013-07-16 17:13 - 000000021 ____H () C:\ProgramData\.24554863501262644635642126105

2014-08-20 22:25 - 2014-09-08 15:45 - 000000848 ___SH () C:\ProgramData\KGyGaAvL.sys

2014-12-10 21:02 - 2014-12-10 21:02 - 000000085 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

2012-07-30 20:51 - 2012-07-30 20:51 - 000002454 _____ () C:\ProgramData\regid.2012-08.com.Corel,Roxio_76C7858E-078C-4C49-AB1A-2A7072664935.swidtag

 

==================== Bamital & volsnap ======================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

LastRegBack: 2016-05-20 20:45

 

==================== End of FRST.txt ============================

Posted

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-10-2017 01

Ran by Webb (administrator) on WEBB-PC (19-10-2017 11:07:13)

Running from E:\

Loaded Profiles: Webb (Available Profiles: Webb)

Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: IE)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

() C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

() C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe

() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

() C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE

(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe

(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe

() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe

(Microsoft Corporation) C:\Windows\splwow64.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe

(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe

(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe

(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe

(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)

HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)

HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)

HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-09-01] (Apple Inc.)

HKLM-x32\...\Run: [TrayServer] => C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_14\TrayServer.exe

HKLM-x32\...\Run: [iSUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [324976 2010-05-21] (Flexera Software, Inc.)

HKLM-x32\...\Run: [] => [X]

HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatchTray14.exe [294032 2012-07-18] (Corel Corporation)

HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)

HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1637496 2011-08-04] (CANON INC.)

HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296520 2014-11-03] (RealNetworks, Inc.)

HKLM-x32\...\Run: [RealDownloader] => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [551488 2014-09-23] ()

HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2131344 2016-06-20] (Wondershare)

HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\AllMyTube\DelayPluginI.exe [1960336 2015-08-11] ()

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Amazon Music] => C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe [5908968 2016-06-16] ()

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Chromium] => "c:\users\webb\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-09-09] (Apple Inc.)

HKU\S-1-5-18\...\RunOnce: [sPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-07-18] (Microsoft Corporation)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2014-11-03]

ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-10-18]

ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{1BE97A3D-A7FB-498E-9B5F-075F5A5C3C67}: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{7BAF68A2-5E5E-4630-A2D4-91496139CC0F}: [DhcpNameServer] 192.168.1.1

 

Internet Explorer:

==================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKU\S-1-5-21-207249110-600702845-166796750-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/en-us/?ocid=U221DHP&pc=U221

SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-09-26] (RealDownloader)

BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

BHO-x32: Wondershare AllMyTube 4.3.0 -> {067DF9EC-26B7-40DC-8DB8-CD8BE85AE367} -> C:\ProgramData\Wondershare\AllMyTube\WSBrowserAppMgr.dll [2015-08-11] (Wondershare)

BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-09-26] (RealDownloader)

BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14] (CANON INC.)

BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14] (CANON INC.)

DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File

 

FireFox:

========

FF ProfilePath: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default [2017-10-18]

FF NewTab: Mozilla\Firefox\Profiles\t8ym71sf.default -> about:newtab

FF DefaultSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\t8ym71sf.default -> Bing

FF SelectedSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF Homepage: Mozilla\Firefox\Profiles\t8ym71sf.default -> user_pref("browser.startup.homepage", "hxxps://www.malwarebytes.org/restorebrowser/

FF Extension: (Transit) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\@Transit.xpi [2017-09-12]

FF Extension: (Bing Extension) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\bingsearch.full@microsoft.com [2017-10-18] [not signed]

FF SearchPlugin: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\searchplugins\bing-.xml [2015-03-28]

FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-11-03] [not signed]

FF HKLM-x32\...\Firefox\Extensions: [{4642CD99-8FDF-4550-94E1-63360972C326}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF HKLM-x32\...\Firefox\Extensions: [AllMyTube@Wondershare.com] - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com

FF Extension: (Wondershare AllMyTube) - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com [2016-02-10] [not signed]

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-13] ()

FF Plugin: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-13] ()

FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-21] (CANON INC.)

FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-09] (Nero AG)

FF Plugin-x32: @real.com/nppl3260;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2014-11-03] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.14 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-09-26] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprpplugin;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2014-11-03] (RealPlayer Cloud)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)

FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)

FF Plugin ProgramFiles/Appdata: C:\Users\Webb\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2009-09-25] (Microsoft Corporation)

 

Chrome:

=======

CHR DefaultProfile: Default

CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US1134D20170817&p={searchTerms}

CHR DefaultSearchKeyword: Default -> mcafee

CHR Profile: C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default [2017-10-19]

CHR Extension: (Chrome Web Store Payments) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-28]

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19]

CHR HKU\S-1-5-21-207249110-600702845-166796750-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx

 

==================== Services (Whitelisted) ====================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [457360 2012-06-20] ()

R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-17] (Adobe Systems Incorporated)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)

R2 BOT4Service; C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe [22160 2012-07-11] ()

R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]

S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]

R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-21] (Malwarebytes)

R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-09-26] ()

R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-11-03] (RealNetworks, Inc.)

R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31344 2014-09-26] ()

S3 RoxMediaDB14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxMediaDB14.exe [1096848 2012-07-18] (Corel Corporation)

S2 RoxWatch14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatch14.exe [341136 2012-07-18] (Corel Corporation)

S3 UPnPService; C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [548864 2008-10-21] (Magix AG) [File not signed]

S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

 

===================== Drivers (Whitelisted) ======================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [253888 2017-10-19] (Malwarebytes)

R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-07-10] (Corel Corporation)

S3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3741960 2015-06-19] (Realtek Semiconductor Corporation )

S1 RxFilter; C:\Windows\SysWOW64\DRIVERS\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)

R0 Sahdad64; C:\Windows\System32\Drivers\Sahdad64.sys [28304 2012-06-20] (Corel Corporation)

R0 Saibad64; C:\Windows\System32\Drivers\Saibad64.sys [20112 2012-06-20] (Corel Corporation)

R1 SaibVdAd64; C:\Windows\System32\Drivers\SaibVdAd64.sys [27792 2012-06-20] (Corel Corporation)

R3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-09-03] (Wondershare)

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-18 19:30 - 2017-10-18 19:30 - 000000000 ____D C:\Users\Webb\AppData\Roaming\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:29 - 000000000 ____D C:\Program Files (x86)\TP-LINK

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 000030472 _____ (Windows ® Server 2003 DDK provider) C:\Windows\system32\rtlCoInst.dll

2017-10-18 19:28 - 2015-06-19 02:53 - 000028467 _____ C:\Windows\system32\netrtwlanu.cat

2017-10-18 19:28 - 2015-02-16 15:19 - 000008320 _____ C:\Windows\system32\rtlCoInst.dat

2017-10-18 19:27 - 2017-10-18 19:29 - 000000000 ____D C:\ProgramData\TP-LINK

2017-10-18 15:14 - 2017-10-18 15:14 - 000004034 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse

2017-10-18 12:23 - 2017-10-19 11:07 - 000000000 ____D C:\FRST

2017-10-18 11:54 - 2017-10-18 12:21 - 000000000 ____D C:\AdwCleaner

2017-10-18 11:09 - 2017-10-18 11:18 - 000000258 __RSH C:\ProgramData\ntuser.pol

2017-10-18 10:51 - 2017-10-19 07:34 - 000003860 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse

2017-10-18 10:36 - 2017-10-19 10:16 - 000253888 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

2017-10-18 10:36 - 2017-10-18 11:17 - 000002016 _____ C:\Users\Public\Desktop\Malwarebytes.lnk

2017-10-18 10:36 - 2017-10-18 10:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes

2017-10-18 10:36 - 2017-10-18 10:36 - 000000000 ____D C:\Program Files\Malwarebytes

2017-10-18 10:36 - 2017-08-21 07:20 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys

2017-10-09 16:03 - 2017-10-09 16:03 - 000000000 ____D C:\FixMeStick Quarantine

2017-10-09 15:02 - 2017-10-12 23:07 - 000000000 ____D C:\FixMeStick

2017-10-01 00:01 - 2017-10-01 00:01 - 000245712 _____ (Mozilla) C:\Users\Webb\Downloads\Firefox Installer (4).exe

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-19 11:06 - 2014-03-31 21:02 - 053736246 _____ C:\Windows\ntbtlog.txt

2017-10-19 10:23 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2017-10-19 10:23 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2017-10-19 10:15 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT

2017-10-19 10:14 - 2009-07-14 00:45 - 000658640 _____ C:\Windows\system32\FNTCACHE.DAT

2017-10-19 09:47 - 2017-05-17 21:06 - 000000000 ____D C:\Program Files\Common Files\McAfee

2017-10-19 08:52 - 2017-08-17 20:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee

2017-10-19 08:48 - 2017-08-17 20:16 - 000000000 __RSD C:\Users\Webb\Documents\McAfee Vaults

2017-10-19 08:35 - 2017-08-16 16:27 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

2017-10-19 08:35 - 2017-08-16 16:27 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk

2017-10-19 07:47 - 2013-07-17 00:37 - 000000000 ____D C:\Users\Webb\AppData\Local\Adobe

2017-10-18 19:29 - 2013-07-26 11:51 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2017-10-18 19:29 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf

2017-10-18 19:01 - 2013-07-16 23:39 - 000000000 ____D C:\Users\Webb\AppData\LocalLow\Temp

2017-10-18 12:41 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\NDF

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\ProgramData\iolo

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\Program Files (x86)\iolo

2017-10-18 10:39 - 2009-07-14 01:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI

2017-10-18 10:36 - 2013-08-29 14:46 - 000000000 ____D C:\ProgramData\Malwarebytes

2017-10-12 15:35 - 2017-09-12 09:37 - 000003482 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Webb

2017-10-12 15:34 - 2013-07-28 15:18 - 000000576 _____ C:\Users\Webb\Desktop\Wintm.lnk

2017-10-12 12:38 - 2017-09-12 09:37 - 000003488 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Webb

2017-10-09 09:37 - 2009-07-14 01:08 - 000032618 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2017-10-05 21:24 - 2013-07-20 19:08 - 000000000 ____D C:\Users\Webb\AppData\Local\CrashDumps

2017-10-05 21:21 - 2017-08-18 10:48 - 000000000 ____D C:\Program Files\Mozilla Firefox

2017-10-05 21:08 - 2015-01-24 20:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2017-09-23 17:17 - 2017-06-04 15:39 - 000033280 _____ C:\Users\Webb\Desktop\jeans schedule octoberdec.xls

2017-09-23 17:09 - 2017-06-03 23:12 - 000033280 _____ C:\Users\Webb\Desktop\field service october to decenber.xls

 

==================== Files in the root of some directories =======

 

2014-10-07 20:18 - 2016-05-02 13:41 - 000000098 _____ () C:\Users\Webb\AppData\Roaming\WB.CFG

2014-12-21 16:06 - 2014-12-21 16:06 - 000001456 _____ () C:\Users\Webb\AppData\Local\Adobe Save for Web 12.0 Prefs

2013-07-26 19:36 - 2017-09-14 20:55 - 001592448 _____ () C:\Users\Webb\AppData\Local\rx_audio.Cache

2013-07-22 20:33 - 2017-09-14 20:55 - 000054072 _____ () C:\Users\Webb\AppData\Local\rx_image32.Cache

2013-07-16 17:13 - 2013-07-16 17:13 - 000000021 ____H () C:\ProgramData\.24554863501262644635642126105

2014-08-20 22:25 - 2014-09-08 15:45 - 000000848 ___SH () C:\ProgramData\KGyGaAvL.sys

2014-12-10 21:02 - 2014-12-10 21:02 - 000000085 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

2012-07-30 20:51 - 2012-07-30 20:51 - 000002454 _____ () C:\ProgramData\regid.2012-08.com.Corel,Roxio_76C7858E-078C-4C49-AB1A-2A7072664935.swidtag

 

==================== Bamital & volsnap ======================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

LastRegBack: 2016-05-20 20:45

 

==================== End of FRST.txt ============================

Posted

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-10-2017 01

Ran by Webb (administrator) on WEBB-PC (19-10-2017 14:10:01)

Running from E:\

Loaded Profiles: Webb (Available Profiles: Webb)

Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: IE)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

() C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

() C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe

() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

() C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE

(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe

(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe

() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe

(Microsoft Corporation) C:\Windows\splwow64.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe

(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe

(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe

(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)

HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)

HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)

HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-09-01] (Apple Inc.)

HKLM-x32\...\Run: [TrayServer] => C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_14\TrayServer.exe

HKLM-x32\...\Run: [iSUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [324976 2010-05-21] (Flexera Software, Inc.)

HKLM-x32\...\Run: [] => [X]

HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatchTray14.exe [294032 2012-07-18] (Corel Corporation)

HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)

HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1637496 2011-08-04] (CANON INC.)

HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296520 2014-11-03] (RealNetworks, Inc.)

HKLM-x32\...\Run: [RealDownloader] => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [551488 2014-09-23] ()

HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2131344 2016-06-20] (Wondershare)

HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\AllMyTube\DelayPluginI.exe [1960336 2015-08-11] ()

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Amazon Music] => C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe [5908968 2016-06-16] ()

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Chromium] => "c:\users\webb\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-09-09] (Apple Inc.)

HKU\S-1-5-18\...\RunOnce: [sPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-07-18] (Microsoft Corporation)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2014-11-03]

ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-10-18]

ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{1BE97A3D-A7FB-498E-9B5F-075F5A5C3C67}: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{7BAF68A2-5E5E-4630-A2D4-91496139CC0F}: [DhcpNameServer] 192.168.1.1

 

Internet Explorer:

==================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKU\S-1-5-21-207249110-600702845-166796750-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/en-us/?ocid=U221DHP&pc=U221

SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-09-26] (RealDownloader)

BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

BHO-x32: Wondershare AllMyTube 4.3.0 -> {067DF9EC-26B7-40DC-8DB8-CD8BE85AE367} -> C:\ProgramData\Wondershare\AllMyTube\WSBrowserAppMgr.dll [2015-08-11] (Wondershare)

BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-09-26] (RealDownloader)

BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14] (CANON INC.)

BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14] (CANON INC.)

DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File

 

FireFox:

========

FF ProfilePath: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default [2017-10-18]

FF NewTab: Mozilla\Firefox\Profiles\t8ym71sf.default -> about:newtab

FF DefaultSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\t8ym71sf.default -> Bing

FF SelectedSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF Homepage: Mozilla\Firefox\Profiles\t8ym71sf.default -> user_pref("browser.startup.homepage", "hxxps://www.malwarebytes.org/restorebrowser/

FF Extension: (Transit) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\@Transit.xpi [2017-09-12]

FF Extension: (Bing Extension) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\bingsearch.full@microsoft.com [2017-10-18] [not signed]

FF SearchPlugin: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\searchplugins\bing-.xml [2015-03-28]

FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-11-03] [not signed]

FF HKLM-x32\...\Firefox\Extensions: [{4642CD99-8FDF-4550-94E1-63360972C326}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF HKLM-x32\...\Firefox\Extensions: [AllMyTube@Wondershare.com] - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com

FF Extension: (Wondershare AllMyTube) - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com [2016-02-10] [not signed]

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_170.dll [2017-10-19] ()

FF Plugin: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_170.dll [2017-10-19] ()

FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-21] (CANON INC.)

FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-09] (Nero AG)

FF Plugin-x32: @real.com/nppl3260;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2014-11-03] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.14 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-09-26] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprpplugin;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2014-11-03] (RealPlayer Cloud)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)

FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)

FF Plugin ProgramFiles/Appdata: C:\Users\Webb\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2009-09-25] (Microsoft Corporation)

 

Chrome:

=======

CHR DefaultProfile: Default

CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US1134D20170817&p={searchTerms}

CHR DefaultSearchKeyword: Default -> mcafee

CHR Profile: C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default [2017-10-19]

CHR Extension: (Chrome Web Store Payments) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-28]

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19]

CHR HKU\S-1-5-21-207249110-600702845-166796750-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx

 

==================== Services (Whitelisted) ====================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [457360 2012-06-20] ()

R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-17] (Adobe Systems Incorporated)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)

R2 BOT4Service; C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe [22160 2012-07-11] ()

R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]

S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]

R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes)

R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-09-26] ()

R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-11-03] (RealNetworks, Inc.)

R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31344 2014-09-26] ()

S3 RoxMediaDB14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxMediaDB14.exe [1096848 2012-07-18] (Corel Corporation)

S2 RoxWatch14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatch14.exe [341136 2012-07-18] (Corel Corporation)

S3 UPnPService; C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [548864 2008-10-21] (Magix AG) [File not signed]

S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

 

===================== Drivers (Whitelisted) ======================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-10-04] ()

R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [192952 2017-10-19] (Malwarebytes)

R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2017-10-19] (Malwarebytes)

R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [45504 2017-10-19] (Malwarebytes)

R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [252232 2017-10-19] (Malwarebytes)

R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2017-10-19] (Malwarebytes)

R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-07-10] (Corel Corporation)

S3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3741960 2015-06-19] (Realtek Semiconductor Corporation )

S1 RxFilter; C:\Windows\SysWOW64\DRIVERS\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)

R0 Sahdad64; C:\Windows\System32\Drivers\Sahdad64.sys [28304 2012-06-20] (Corel Corporation)

R0 Saibad64; C:\Windows\System32\Drivers\Saibad64.sys [20112 2012-06-20] (Corel Corporation)

R1 SaibVdAd64; C:\Windows\System32\Drivers\SaibVdAd64.sys [27792 2012-06-20] (Corel Corporation)

R3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-09-03] (Wondershare)

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-19 11:41 - 2017-10-19 14:11 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys

2017-10-19 11:41 - 2017-10-19 11:41 - 000192952 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys

2017-10-19 11:41 - 2017-10-19 11:41 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys

2017-10-19 11:41 - 2017-10-19 11:41 - 000045504 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys

2017-10-19 11:40 - 2017-10-19 11:40 - 000252232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys

2017-10-19 11:40 - 2017-10-19 11:40 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk

2017-10-19 11:40 - 2017-10-19 11:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes

2017-10-19 11:40 - 2017-10-19 11:40 - 000000000 ____D C:\Program Files\Malwarebytes

2017-10-19 11:40 - 2017-10-04 13:15 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys

2017-10-19 11:34 - 2017-10-19 11:35 - 071535032 _____ (Malwarebytes ) C:\Users\Webb\Downloads\mb3-setup-consumer-3.2.2.2029-1.0.212-1.0.2951.exe

2017-10-18 19:30 - 2017-10-18 19:30 - 000000000 ____D C:\Users\Webb\AppData\Roaming\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:29 - 000000000 ____D C:\Program Files (x86)\TP-LINK

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 000030472 _____ (Windows ® Server 2003 DDK provider) C:\Windows\system32\rtlCoInst.dll

2017-10-18 19:28 - 2015-06-19 02:53 - 000028467 _____ C:\Windows\system32\netrtwlanu.cat

2017-10-18 19:28 - 2015-02-16 15:19 - 000008320 _____ C:\Windows\system32\rtlCoInst.dat

2017-10-18 19:27 - 2017-10-18 19:29 - 000000000 ____D C:\ProgramData\TP-LINK

2017-10-18 15:14 - 2017-10-18 15:14 - 000004034 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse

2017-10-18 12:23 - 2017-10-19 14:10 - 000000000 ____D C:\FRST

2017-10-18 11:54 - 2017-10-18 12:21 - 000000000 ____D C:\AdwCleaner

2017-10-18 11:09 - 2017-10-18 11:18 - 000000258 __RSH C:\ProgramData\ntuser.pol

2017-10-18 10:51 - 2017-10-19 07:34 - 000003860 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse

2017-10-09 16:03 - 2017-10-09 16:03 - 000000000 ____D C:\FixMeStick Quarantine

2017-10-09 15:02 - 2017-10-12 23:07 - 000000000 ____D C:\FixMeStick

2017-10-01 00:01 - 2017-10-01 00:01 - 000245712 _____ (Mozilla) C:\Users\Webb\Downloads\Firefox Installer (4).exe

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-19 14:11 - 2014-03-31 21:02 - 053737144 _____ C:\Windows\ntbtlog.txt

2017-10-19 12:36 - 2013-07-16 19:25 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2017-10-19 12:36 - 2013-07-16 19:25 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2017-10-19 12:36 - 2013-07-16 19:25 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

2017-10-19 12:35 - 2013-07-16 19:25 - 000000000 ____D C:\Windows\SysWOW64\Macromed

2017-10-19 12:35 - 2013-07-16 19:25 - 000000000 ____D C:\Windows\system32\Macromed

2017-10-19 12:18 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2017-10-19 12:18 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2017-10-19 11:40 - 2013-08-29 14:46 - 000000000 ____D C:\ProgramData\Malwarebytes

2017-10-19 10:15 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT

2017-10-19 10:14 - 2009-07-14 00:45 - 000658640 _____ C:\Windows\system32\FNTCACHE.DAT

2017-10-19 09:47 - 2017-05-17 21:06 - 000000000 ____D C:\Program Files\Common Files\McAfee

2017-10-19 08:52 - 2017-08-17 20:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee

2017-10-19 08:48 - 2017-08-17 20:16 - 000000000 __RSD C:\Users\Webb\Documents\McAfee Vaults

2017-10-19 08:35 - 2017-08-16 16:27 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

2017-10-19 08:35 - 2017-08-16 16:27 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk

2017-10-19 07:47 - 2013-07-17 00:37 - 000000000 ____D C:\Users\Webb\AppData\Local\Adobe

2017-10-18 19:29 - 2013-07-26 11:51 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2017-10-18 19:29 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf

2017-10-18 19:01 - 2013-07-16 23:39 - 000000000 ____D C:\Users\Webb\AppData\LocalLow\Temp

2017-10-18 12:41 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\NDF

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\ProgramData\iolo

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\Program Files (x86)\iolo

2017-10-18 10:39 - 2009-07-14 01:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI

2017-10-12 15:35 - 2017-09-12 09:37 - 000003482 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Webb

2017-10-12 15:34 - 2013-07-28 15:18 - 000000576 _____ C:\Users\Webb\Desktop\Wintm.lnk

2017-10-12 12:38 - 2017-09-12 09:37 - 000003488 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Webb

2017-10-09 09:37 - 2009-07-14 01:08 - 000032618 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2017-10-05 21:24 - 2013-07-20 19:08 - 000000000 ____D C:\Users\Webb\AppData\Local\CrashDumps

2017-10-05 21:21 - 2017-08-18 10:48 - 000000000 ____D C:\Program Files\Mozilla Firefox

2017-10-05 21:08 - 2015-01-24 20:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2017-09-23 17:17 - 2017-06-04 15:39 - 000033280 _____ C:\Users\Webb\Desktop\jeans schedule octoberdec.xls

2017-09-23 17:09 - 2017-06-03 23:12 - 000033280 _____ C:\Users\Webb\Desktop\field service october to decenber.xls

 

==================== Files in the root of some directories =======

 

2014-10-07 20:18 - 2016-05-02 13:41 - 000000098 _____ () C:\Users\Webb\AppData\Roaming\WB.CFG

2014-12-21 16:06 - 2014-12-21 16:06 - 000001456 _____ () C:\Users\Webb\AppData\Local\Adobe Save for Web 12.0 Prefs

2013-07-26 19:36 - 2017-09-14 20:55 - 001592448 _____ () C:\Users\Webb\AppData\Local\rx_audio.Cache

2013-07-22 20:33 - 2017-09-14 20:55 - 000054072 _____ () C:\Users\Webb\AppData\Local\rx_image32.Cache

2013-07-16 17:13 - 2013-07-16 17:13 - 000000021 ____H () C:\ProgramData\.24554863501262644635642126105

2014-08-20 22:25 - 2014-09-08 15:45 - 000000848 ___SH () C:\ProgramData\KGyGaAvL.sys

2014-12-10 21:02 - 2014-12-10 21:02 - 000000085 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

2012-07-30 20:51 - 2012-07-30 20:51 - 000002454 _____ () C:\ProgramData\regid.2012-08.com.Corel,Roxio_76C7858E-078C-4C49-AB1A-2A7072664935.swidtag

 

==================== Bamital & volsnap ======================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

LastRegBack: 2016-05-20 20:45

 

==================== End of FRST.txt ============================

Posted

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-10-2017 01

Ran by Webb (19-10-2017 14:27:47)

Running from E:\

Windows 7 Home Premium Service Pack 1 (X64) (2013-07-16 14:41:32)

Boot Mode: Normal

==========================================================

 

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-207249110-600702845-166796750-500 - Administrator - Disabled)

Guest (S-1-5-21-207249110-600702845-166796750-501 - Limited - Disabled)

HomeGroupUser$ (S-1-5-21-207249110-600702845-166796750-1002 - Limited - Enabled)

Webb (S-1-5-21-207249110-600702845-166796750-1000 - Administrator - Enabled) => C:\Users\Webb

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}

AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}

AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

 

==================== Installed Programs ======================

 

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated)

Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.170 - Adobe Systems Incorporated)

Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.170 - Adobe Systems Incorporated)

Adobe Photoshop Elements 11 (HKLM-x32\...\Adobe Photoshop Elements 11) (Version: 11.0 - Adobe Systems Incorporated)

Amazon Music (HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Amazon Amazon Music) (Version: 4.3.2.1367 - Amazon Services LLC)

Apple Application Support (32-bit) (HKLM-x32\...\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.)

Apple Application Support (32-bit) (HKLM-x32\...\{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}) (Version: 4.3 - Apple Inc.)

Apple Application Support (64-bit) (HKLM\...\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.)

Apple Mobile Device Support (HKLM\...\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.)

Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)

Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)

Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)

Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - )

Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.3.5.0 - Canon Inc.)

Canon MG5300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series) (Version: - )

Canon MG5300 series On-screen Manual (HKLM-x32\...\Canon MG5300 series On-screen Manual) (Version: - )

Canon MG5300 series User Registration (HKLM-x32\...\Canon MG5300 series User Registration) (Version: - )

Canon MP Navigator EX 5.0 (HKLM-x32\...\MP Navigator EX 5.0) (Version: - )

Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - )

Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - )

Citrix Online Launcher (HKLM-x32\...\{77463C86-BB3A-426E-A6C2-06B4D28C250F}) (Version: 1.0.223 - Citrix)

CLM Explorer (HKLM-x32\...\CLMExplorer) (Version: - Robert Hudson)

Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)

Corel WinDVD (HKLM-x32\...\{5C1F18D2-F6B7-4242-B803-B5A78648185D}) (Version: 10.8.0.201 - Corel Inc.) Hidden

Creator NXT Content (HKLM-x32\...\{9F717571-FEE8-45CD-8B03-5B2D06AD28F7}) (Version: 14.0.024 - Roxio) Hidden

DirectX 9 Runtime (HKLM-x32\...\{3A9527CF-4E91-4683-A03F-F1AD022126E5}) (Version: 1.00.0000 - Sonic Solutions) Hidden

Elements 11 Organizer (HKLM-x32\...\{D4D065E1-3ABF-41D0-B385-FC6F027F4D00}) (Version: 11.0 - Adobe Systems Incorporated) Hidden

EMC 10 Content (HKLM-x32\...\{FDB46DE7-9045-47BB-970A-3E4ED5369E03}) (Version: 1.0.035 - Roxo, Inc.) Hidden

EMCGadgets64 (HKLM\...\{02AD9D20-03D2-4DE0-8793-E8253026AD86}) (Version: 1.0.302 - Sonic) Hidden

Final Draft 7 (HKLM-x32\...\{78D62D17-D970-42DA-B8CF-5E5576293B33}) (Version: 7.1.3.42 - Final Draft, Inc.)

Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG)

Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.62 - Google Inc.)

Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden

Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden

iCloud (HKLM\...\{CE29BC77-C5AE-49D8-A8C0-FDAF6ACF74DF}) (Version: 6.0.1.41 - Apple Inc.)

iTunes (HKLM\...\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.)

Kingdom Hall Schedules (HKLM-x32\...\KHS_is1) (Version: 11.15 - Majestic Software)

K-Lite Codec Pack 10.7.1 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.7.1 - )

K-Lite Codec Pack Packages (HKU\S-1-5-21-207249110-600702845-166796750-1000\...\K-Lite Codec Pack Packages) (Version: - ) <==== ATTENTION

MAGIX MP3 deluxe 19 (HKLM\...\{EA52DEA5-3A60-470C-BBDA-5B962BE45CED}) (Version: 19.0.0.30 - MAGIX Software GmbH) Hidden

MAGIX MP3 deluxe 19 (HKLM-x32\...\MX.{EA52DEA5-3A60-470C-BBDA-5B962BE45CED}) (Version: 19.0.0.30 - MAGIX Software GmbH)

MAGIX MP3 Maker 15 10.0.0.317 (UK) (HKLM-x32\...\MAGIX MP3 Maker 15 UK) (Version: 10.0.0.317 - MAGIX AG)

MAGIX Screenshare 4.3.6.1987 (UK) (HKLM-x32\...\MAGIX Screenshare UK) (Version: 4.3.6.1987 - MAGIX AG)

MAGIX Speed burnR (MSI) (HKLM\...\{7EE6ACF3-FED2-4B97-96CE-846CF1B84F39}) (Version: 7.0.1.27 - MAGIX Software GmbH) Hidden

MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{7EE6ACF3-FED2-4B97-96CE-846CF1B84F39}) (Version: 7.0.1.27 - MAGIX Software GmbH)

Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes)

Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)

Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)

Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)

Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)

Microsoft Office Standard Edition 2003 (HKLM-x32\...\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)

Microsoft OneDrive (HKU\S-1-5-21-207249110-600702845-166796750-1000\...\OneDriveSetup.exe) (Version: 17.0.4041.0512 - Microsoft Corporation)

Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)

Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)

MP3 deluxe 19 Update (HKLM\...\{A50A6DA4-F139-419B-8C2B-6B81D96AEE20}) (Version: 19.0.1.48 - MAGIX Software GmbH) Hidden

MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)

MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)

nero12kwikburnexpressess (HKLM-x32\...\{57AB77BC-E70C-454B-BD0C-E543A7961912}) (Version: 12.0.00300 - Nero AG)

Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.4551.1512 - Microsoft Corporation) Hidden

Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.4551.1512 - Microsoft Corporation) Hidden

Office 15 Click-to-Run Localization Component (HKLM-x32\...\{90150000-008C-0409-0000-0000000FF1CE}) (Version: 15.0.4551.1512 - Microsoft Corporation) Hidden

Pinnacle Studio 12 (HKLM-x32\...\{D041EB9E-890A-4098-8F94-51DA194AC72A}) (Version: 12.0.0.6163 - Pinnacle Systems)

Pinnacle Video Driver (HKLM\...\{5EB90C06-964F-4195-B83E-BD7E55C88415}) (Version: 12.00.0017 - Pinnacle Systems)

PMB (HKLM-x32\...\{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}) (Version: 5.5.02.12220 - Sony Corporation)

Prerequisite installer (HKLM-x32\...\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0002 - Nero AG) Hidden

PSE11 STI Installer (HKLM-x32\...\{98CE8819-87AA-4814-8167-ADDDD513485F}) (Version: 11.0 - Adobe Systems Incorporated) Hidden

QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)

RBVirtualFolder64Inst (HKLM\...\{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}) (Version: 1.00.0000 - Roxio, Inc.) Hidden

RealDownloader (HKLM-x32\...\{0b2ba5b5-983a-4565-ace1-2e55014848d2}) (Version: 17.0.14.26 - RealNetworks) Hidden

RealDownloader (HKLM-x32\...\{0F44CC14-936F-4A6D-A4B4-4953AE174A2A}) (Version: 17.0.14.8 - RealNetworks, Inc.) Hidden

RealDownloader (HKLM-x32\...\{7D700940-82E4-4442-B8AF-EF6C9C509C06}) (Version: 17.0.14.26 - RealNetworks) Hidden

RealNetworks - Microsoft Visual C++ 2005 Runtime (HKLM-x32\...\{026C3D27-9BE1-46BE-BEAE-6DE38A0F4FBE}) (Version: 8.0 - RealNetworks) Hidden

RealNetworks - Microsoft Visual C++ 2008 Runtime (HKLM-x32\...\{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}) (Version: 9.0 - RealNetworks, Inc) Hidden

RealNetworks - Microsoft Visual C++ 2010 Runtime (HKLM\...\{21E47F47-C9A7-4454-BA48-388327B0EA00}) (Version: 10.0 - RealNetworks, Inc) Hidden

RealNetworks - Microsoft Visual C++ 2010 Runtime (HKLM-x32\...\{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}) (Version: 10.0 - RealNetworks, Inc) Hidden

RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.14 - RealNetworks)

RealUpgrade 1.1 (HKLM-x32\...\{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}) (Version: 1.1.0 - RealNetworks, Inc.) Hidden

Roxio Creator NXT (HKLM-x32\...\{CC915001-1639-4D1B-B0A1-A7AC70C99179}) (Version: 14.0.36.0 - Roxio)

Roxio Easy CD and DVD Burning (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3 - Roxio)

Roxio File Backup (HKLM\...\{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}) (Version: 1.3.0 - Roxio) Hidden

Roxio PhotoShow (HKLM-x32\...\Roxio PhotoShow) (Version: 6.0 - Sonic Solutions)

Roxio Virtual Drive x64 (HKLM\...\{632DCE79-2711-4B07-BB89-DA763E96840C}) (Version: 1.00.0000 - Roxio, Inc.) Hidden

SmartSound Common Data (HKLM-x32\...\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.) Hidden

SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)

SmartSound Quicktracks 5 (HKLM-x32\...\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.7 - SmartSound Software Inc.) Hidden

SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.7 - SmartSound Software Inc.)

SONAR LE (HKLM-x32\...\SONAR85LE_is1) (Version: 18.0 - Cakewalk Music Software)

Sonic CinePlayer Decoder Pack (HKLM-x32\...\{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}) (Version: 4.3.0 - Sonic Solutions) Hidden

TL-WN725N_WN723N Driver (HKLM-x32\...\{3C3F9CEB-2C5A-4A47-8EAA-DA76037546BA}) (Version: 1.3.1 - TP-LINK)

TMS2015 (HKLM-x32\...\{85E02722-AA60-47D6-BB40-9D9CCE181C13}) (Version: 20.15.1 - 2137378 Ontario Inc.)

TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)

Triple Scoop Music (HKLM-x32\...\{4CD51492-D68C-49AC-9692-29FCC19FBC26}) (Version: 1.0.019 - Roxio) Hidden

Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)

UpdateService (HKLM-x32\...\{E3AE96D6-E196-45B4-AF62-2B41998B9E37}) (Version: 1.0.0 - RealNetworks, Inc.) Hidden

VD64Inst (HKLM\...\{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}) (Version: 1.00.0000 - Roxio, Inc.) Hidden

Video Downloader (HKLM-x32\...\{65257823-1757-44CF-B23A-D615D7CC460D}) (Version: 1.0.0 - RealNetworks) Hidden

Virtual DJ Broadcaster - Atomix Productions (HKLM-x32\...\Virtual DJ Broadcaster - Atomix Productions) (Version: - )

VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)

Watchtower Library - English (HKLM-x32\...\{1D72ED8E-EA0F-4AE3-BBC5-2EC55FA5649F}) (Version: 18.0 - Watchtower Bible and Tract Society of Pennsylvania, Inc.)

Watchtower Library 2015 - English (HKLM-x32\...\{F0D4F127-987D-4345-AA96-5699CF14AF35}) (Version: 17.0 - Watchtower Bible and Tract Society of Pennsylvania, Inc.)

Wondershare AllMyTube(Build 4.5.0.0) (HKLM-x32\...\Wondershare AllMyTube_is1) (Version: 4.5.0.0 - Wondershare Software)

Wondershare Helper Compact 2.5.0 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.0 - Wondershare)

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{0C3BA0B1-BC14-4B55-98DC-F1E913C1DA10}\InprocServer32 -> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\ActiveX64.ocx (TODO: <Company name>)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{6FFA7438-3E00-4176-9717-B3BBE2E704AB}\InprocServer32 -> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\ActiveX64.ocx (TODO: <Company name>)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{A66FC8BB-7AFD-4FCF-BBA1-341AE079C7DF}\InprocServer32 -> C:\Program Files\Roxio Creator NXT\Virtual Drive 10\DC_ShellExt64.dll (Corel Corporation)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\FileSyncApi64.dll (Microsoft Corporation)

ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2016-09-09] (Apple Inc.)

ContextMenuHandlers1: [Roxio Burn] -> {E8CB9D53-A47A-42B5-9F5B-96B037C9DD4C} => C:\Program Files\Roxio\Roxio Burn\RB_ContextMenu64.dll [2012-07-05] ()

ContextMenuHandlers1: [RXDCExtSvr] -> {0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} => C:\Program Files\Roxio\Virtual Drive 10\DC_ShellExt64.dll [2009-06-26] (Sonic Solutions)

ContextMenuHandlers2: [RXDCExtSvr] -> {0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} => C:\Program Files\Roxio\Virtual Drive 10\DC_ShellExt64.dll [2009-06-26] (Sonic Solutions)

ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)

ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => c:\program files (x86)\real\realplayer\RPDS\Bin64\rpcloudview.dll [2014-11-03] (RealNetworks, Inc.)

ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-02-11] (Intel Corporation)

ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)

ContextMenuHandlers6: [RXDCExtSvr] -> {0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} => C:\Program Files\Roxio\Virtual Drive 10\DC_ShellExt64.dll [2009-06-26] (Sonic Solutions)

ContextMenuHandlers1_S-1-5-21-207249110-600702845-166796750-1000: [RXDCExtSvr] -> {A66FC8BB-7AFD-4FCF-BBA1-341AE079C7DF} => C:\Program Files\Roxio Creator NXT\Virtual Drive 10\DC_ShellExt64.dll [2012-07-18] (Corel Corporation)

ContextMenuHandlers2_S-1-5-21-207249110-600702845-166796750-1000: [RXDCExtSvr] -> {A66FC8BB-7AFD-4FCF-BBA1-341AE079C7DF} => C:\Program Files\Roxio Creator NXT\Virtual Drive 10\DC_ShellExt64.dll [2012-07-18] (Corel Corporation)

ContextMenuHandlers6_S-1-5-21-207249110-600702845-166796750-1000: [RXDCExtSvr] -> {A66FC8BB-7AFD-4FCF-BBA1-341AE079C7DF} => C:\Program Files\Roxio Creator NXT\Virtual Drive 10\DC_ShellExt64.dll [2012-07-18] (Corel Corporation)

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {025FE179-4831-477F-8D1B-10F3F2E58528} - System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe

Task: {34902A79-56ED-4AE8-A16D-F946D1B8605A} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig

Task: {34902A79-56ED-4AE8-A16D-F946D1B8605A} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(2): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshContent

Task: {34902A79-56ED-4AE8-A16D-F946D1B8605A} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(3): C:\Windows\system32\GWX\GWXDetector.exe [2016-07-13] (Microsoft Corporation)

Task: {4074CE58-CFF1-41E3-96D4-EB0B438C3B61} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-19] (Adobe Systems Incorporated)

Task: {54628E3C-C21F-418D-82D5-F0E59766123E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-08-16] (Google Inc.)

Task: {5AAAB923-3E02-4118-AD39-9DD6D604F642} - System32\Tasks\ReclaimerUpdateFiles_Webb => C:\Users\Webb\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.08\agent\rnupgagent.exe [2017-09-11] (RealNetworks, Inc.)

Task: {63F0E1D7-725E-4837-AA71-DFC527DEEC6E} - System32\Tasks\RNUpgradeHelperResumePrompt_Webb => C:\Users\Webb\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.08\agent\rnupgagent.exe [2017-09-11] (RealNetworks, Inc.)

Task: {6675B259-962D-4653-9B41-1E6AF6094B86} - System32\Tasks\ReclaimerUpdateXML_Webb => C:\Users\Webb\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.08\agent\rnupgagent.exe [2017-09-11] (RealNetworks, Inc.)

Task: {6948C87B-F506-427A-A8AE-C446F7B68BB7} - System32\Tasks\AdobeAAMUpdater-1.0-Webb-PC-Webb => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20] (Adobe Systems Incorporated)

Task: {7BB8588F-ACBD-436B-B5E6-8827C512F577} - System32\Tasks\RealDownloader Update Check => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [2014-09-23] ()

Task: {819D2C2C-B29C-46DE-960B-08B3FCA2B108} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(1): %windir%\system32\GWX\GWXUXWorker.exe -> /ScheduleUpgradeReminderTime

Task: {819D2C2C-B29C-46DE-960B-08B3FCA2B108} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2016-07-13] (Microsoft Corporation)

Task: {81A7BFC9-4CD6-4250-BB90-49F444A8B77C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)

Task: {847EE0D9-7A49-4CF0-BA6B-597C7D453ECF} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfigAndContent

Task: {847EE0D9-7A49-4CF0-BA6B-597C7D453ECF} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2016-07-13] (Microsoft Corporation)

Task: {8D4F47D6-E0C6-4019-9351-87BC637BA492} - System32\Tasks\{5112F452-3CA7-4C49-8748-B938086E88AC} => C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe [2009-06-22] ()

Task: {9A446A7C-EA95-44CD-BD4D-44B94A6BB67F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)

Task: {A85E2D96-C599-40FC-A310-DE1D19DE5743} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig

Task: {A85E2D96-C599-40FC-A310-DE1D19DE5743} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2016-07-13] (Microsoft Corporation)

Task: {ABEF6771-F264-4060-A12E-F85222041AD1} - System32\Tasks\RNUpgradeHelperLogonPrompt_Webb => C:\Users\Webb\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.08\agent\rnupgagent.exe [2017-09-11] (RealNetworks, Inc.)

Task: {AF110201-E2DA-4AC4-85C3-26D842B61080} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-08-16] (Google Inc.)

Task: {B2A9E3B1-6839-477A-886D-0B9759CF622D} - System32\Tasks\{7F3A22C9-F476-4463-8930-56090A39A198} => C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe [2009-06-22] ()

Task: {CC6D1F03-AA20-4BE6-AC1F-9DE6CB0E142E} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-09-04] ()

Task: {D271CC90-ABFD-42D0-BE8C-78522C6AC001} - System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe

Task: {D2FA513E-DD71-4370-9C87-9753A8A45DAB} - System32\Tasks\{1A179B3C-3F33-4F86-BAE0-B036074283A2} => C:\Windows\system32\pcalua.exe -a C:\ProgramData\Uninstall\{537BF16E-7412-448C-95D8-846E85A1D817}\setup.exe -c /x {537BF16E-7412-448C-95D8-846E85A1D817}

Task: {D464CFBC-565F-4B20-902B-8B6A7869BD69} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-207249110-600702845-166796750-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-09-26] (RealNetworks, Inc.)

Task: {E391135D-D6FD-449A-A7A7-4B9FEFEDC9EF} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-207249110-600702845-166796750-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-09-26] (RealNetworks, Inc.)

Task: {FAEE40A9-19C7-43C0-9848-C457D385C9F0} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-207249110-600702845-166796750-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-09-26] (RealNetworks, Inc.)

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

 

==================== Shortcuts & WMI ========================

 

(The entries could be listed to be restored or removed.)

 

 

Shortcut: C:\Users\Webb\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.co

 

==================== Loaded Modules (Whitelisted) ==============

 

2012-06-20 15:48 - 2012-06-20 15:48 - 000457360 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe

2012-07-05 19:47 - 2012-07-05 19:47 - 000185488 _____ () C:\Program Files\Roxio\Roxio Burn\RB_ContextMenu64.dll

2016-09-01 18:12 - 2016-09-01 18:12 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll

2016-09-01 18:12 - 2016-09-01 18:12 - 001353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll

2014-09-18 21:58 - 2016-06-16 16:05 - 005908968 _____ () C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe

2017-10-18 19:29 - 2015-03-20 16:23 - 002206208 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe

2012-07-11 01:04 - 2012-07-11 01:04 - 000022160 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe

2014-09-23 15:54 - 2014-09-23 15:54 - 000551488 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe

2014-09-26 11:18 - 2014-09-26 11:18 - 000039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

2014-09-26 16:14 - 2014-09-26 16:14 - 000031344 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe

2017-10-19 11:40 - 2017-10-04 13:15 - 002289096 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll

2017-10-19 11:40 - 2017-10-04 13:15 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll

2016-09-01 18:13 - 2016-09-01 18:13 - 001041720 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll

2016-09-01 18:13 - 2016-09-01 18:13 - 000080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

2016-09-01 18:12 - 2016-09-01 18:12 - 000189752 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll

2017-10-18 19:29 - 2015-03-23 17:33 - 001411072 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\nicLan.dll

2017-10-18 19:29 - 2015-03-20 16:16 - 000192000 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\DC_WFF.dll

2012-07-11 01:04 - 2012-07-11 01:04 - 003306128 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\BEngine.dll

2012-07-11 01:04 - 2012-07-11 01:04 - 000523920 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\TRREngine.dll

2012-07-11 01:04 - 2012-07-11 01:04 - 000108176 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\Logging.dll

2014-09-23 15:05 - 2014-09-23 15:05 - 001382048 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\cpprest100_1_2.dll

2016-06-24 10:35 - 2016-06-20 14:48 - 001506304 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll

2016-02-10 17:51 - 2014-05-19 17:19 - 000137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll

2014-11-03 19:53 - 2014-11-03 19:53 - 000865880 _____ () c:\program files (x86)\real\realplayer\RPDS\Plugins\cldplin.dll

2014-09-26 16:13 - 2014-09-26 16:13 - 000035464 _____ () C:\Program Files (x86)\Real\UpdateService\DL2UpdatePlugin.dll

2014-09-26 16:13 - 2014-09-26 16:13 - 000035976 _____ () C:\Program Files (x86)\Real\UpdateService\RealDownloaderUpdatePlugin.dll

2014-09-26 16:13 - 2014-09-26 16:13 - 000033400 _____ () C:\Program Files (x86)\Real\UpdateService\RPDSUpdatePlugin.dll

2014-09-26 16:13 - 2014-09-26 16:13 - 000034456 _____ () C:\Program Files (x86)\Real\UpdateService\VideoDLUpdatePlugin.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

AlternateDataStreams: C:\Users\Public\Documents\20130816_140212.jpg:com.dropbox.attributes [159]

AlternateDataStreams: C:\Users\Public\Documents\20130816_140235.jpg:com.dropbox.attributes [81]

AlternateDataStreams: C:\Users\Public\Documents\20130816_140242.jpg:com.dropbox.attributes [326]

AlternateDataStreams: C:\Users\Public\Documents\20130816_140311.jpg:com.dropbox.attributes [324]

AlternateDataStreams: C:\Users\Webb\Desktop\if you dont know me.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Desktop\my greatest demo.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Desktop\my greatest inspiration.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Desktop\SHE.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Desktop\teddy pendergrass tribute.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Documents\a song for you.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Documents\if you dont know me.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Documents\my greatest demo.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Documents\my greatest inspiration.mp3:Roxio EMC Stream [38]

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

 

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMPCHelper => ""=""

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tvnserver => ""=""

 

==================== Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

 

==================== Hosts content: ===============================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2009-07-13 22:34 - 2017-10-18 18:59 - 000000035 _____ C:\Windows\system32\Drivers\etc\hosts

 

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-21-207249110-600702845-166796750-1000\Control Panel\Desktop\\Wallpaper ->

DNS Servers: 192.168.1.1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

Windows Firewall is enabled.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [{6ADFDAB0-A444-46FA-B2B3-21B2A7D5B153}] => (Allow) C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe

FirewallRules: [{20C65842-7DAC-4206-B55D-0582BB95DBF7}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe

FirewallRules: [{54B84CF2-9221-4FCF-A483-6CD115FB8A63}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe

FirewallRules: [{5D25AC97-9A3B-43F9-B8F0-04E4A8035937}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe

FirewallRules: [{C97F8651-8B4B-4E22-9B60-8A6629567283}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe

FirewallRules: [{23A8420D-5748-474B-9C70-6155CDAF4022}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe

FirewallRules: [{FB272CE9-6AD8-4BC7-9078-C47F422799C8}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe

FirewallRules: [{3B0184D1-1662-4AAC-9D20-AA7564AD1753}] => (Allow) LPort=0

FirewallRules: [{EB5AE450-47A4-4C36-9AEB-722516CBE492}] => (Allow) LPort=2869

FirewallRules: [{6F49D27B-EF99-455A-A12B-021D31F3F2DD}] => (Allow) LPort=1900

FirewallRules: [{ABF98727-69AC-4C61-B7F5-FEDFD3A58275}] => (Allow) C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe

FirewallRules: [{F630F497-A827-42CD-B425-E935924E56F4}] => (Allow) C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe

FirewallRules: [{7ADE29D4-D538-46BC-8315-63A21316333D}] => (Allow) LPort=9000

FirewallRules: [{029705A6-237A-46E9-816C-6CAD9446256E}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe

FirewallRules: [{04F61DE6-4E0A-4B55-B70D-67FF2BFB60B5}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe

FirewallRules: [{17276718-75C8-4614-B5B4-69C12CFF2D30}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe

FirewallRules: [{7B5FE7FB-EDC3-4C99-B87F-0D816237B457}] => (Allow) C:\Program Files (x86)\mystarttb\ToolbarCleaner.exe

FirewallRules: [{93DC9F0E-CF9D-4EB3-861B-C5B529656C7B}] => (Allow) C:\Program Files (x86)\mystarttb\ToolbarCleaner.exe

FirewallRules: [{94B5E611-A99C-4B2C-A2A6-066EC98B358D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{C63465B1-7BBF-405D-BD58-E6E904040601}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{69975844-1968-4B78-A253-E2F52D353EFB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{C74B9F76-0BE7-4957-9621-3162E4AA67B5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [TCP Query User{9DEE37A6-0DFA-47E7-81F1-A0ABE706C59F}C:\program files (x86)\wondershare\allmytube\allmytube.exe] => (Allow) C:\program files (x86)\wondershare\allmytube\allmytube.exe

FirewallRules: [uDP Query User{F6316BA7-B001-42BC-8CD5-65C3DF9A6C05}C:\program files (x86)\wondershare\allmytube\allmytube.exe] => (Allow) C:\program files (x86)\wondershare\allmytube\allmytube.exe

FirewallRules: [{699E23B5-370E-46CD-B857-2D861C415A47}] => (Allow) C:\Program Files\iTunes\iTunes.exe

FirewallRules: [{1415D485-D8DC-40FD-A462-5671560DD9E8}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe

FirewallRules: [{D7717A97-9C28-47B3-AF12-844AA27D617B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

 

==================== Restore Points =========================

 

09-10-2017 11:25:16 Windows Backup

09-10-2017 13:16:54 Windows Backup

09-10-2017 13:31:18 Windows Backup

18-10-2017 12:13:34 JRT Pre-Junkware Removal

18-10-2017 19:28:23 Installed TP-LINK Wireless Configuration Utility and Driver

18-10-2017 19:29:30 Installed TP-LINK Wireless Configuration Utility

 

==================== Faulty Device Manager Devices =============

 

Name: Microsoft Teredo Tunneling Adapter

Description: Microsoft Teredo Tunneling Adapter

Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}

Manufacturer: Microsoft

Service: tunnel

Problem: : This device cannot start. (Code10)

Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.

On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

 

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (10/19/2017 12:43:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledSPRetry 9703

 

Error: (10/19/2017 12:43:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledEvent 9703

 

Error: (10/19/2017 12:43:27 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: Continuously busy for more than a second

 

Error: (10/19/2017 12:43:26 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledSPRetry 8627

 

Error: (10/19/2017 12:43:26 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledEvent 8627

 

Error: (10/19/2017 12:43:26 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: Continuously busy for more than a second

 

Error: (10/19/2017 12:43:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledSPRetry 7550

 

Error: (10/19/2017 12:43:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledEvent 7550

 

Error: (10/19/2017 12:43:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: Continuously busy for more than a second

 

Error: (10/19/2017 12:43:24 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledSPRetry 6474

 

 

System errors:

=============

Error: (10/19/2017 02:08:48 PM) (Source: Service Control Manager) (EventID: 7011) (User: )

Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

 

Error: (10/19/2017 10:15:55 AM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load:

RxFilter

 

Error: (10/19/2017 10:15:48 AM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The Roxio Hard Drive Watcher 14 service terminated with the following error:

The class is configured to run as a security id different from the caller

 

Error: (10/19/2017 09:48:45 AM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load:

RxFilter

 

Error: (10/19/2017 09:48:31 AM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The Roxio Hard Drive Watcher 14 service terminated with the following error:

The class is configured to run as a security id different from the caller

 

Error: (10/19/2017 09:42:43 AM) (Source: DCOM) (EventID: 10010) (User: )

Description: The server {E782BE15-9936-4A7F-8DF9-9AB95D229DF1} did not register with DCOM within the required timeout.

 

Error: (10/19/2017 09:34:37 AM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load:

RxFilter

 

Error: (10/19/2017 09:34:30 AM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The Roxio Hard Drive Watcher 14 service terminated with the following error:

The class is configured to run as a security id different from the caller

 

Error: (10/19/2017 09:34:16 AM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The McAfee Service Controller service failed to start due to the following error:

The system cannot find the file specified.

 

Error: (10/19/2017 09:34:16 AM) (Source: Service Control Manager) (EventID: 7003) (User: )

Description: The McAfee Boot Delay Start Service service depends the following service: mfevtp. This service might not be installed.

 

 

CodeIntegrity:

===================================

Date: 2015-08-02 08:54:49.135

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:49.129

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:49.082

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:49.064

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.687

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.598

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.490

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.483

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.429

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.423

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

 

==================== Memory info ===========================

 

Processor: Pentium® Dual-Core CPU E6700 @ 3.20GHz

Percentage of memory in use: 31%

Total physical RAM: 6108.99 MB

Available physical RAM: 4156.91 MB

Total Virtual: 12216.17 MB

Available Virtual: 7976.96 MB

 

==================== Drives ================================

 

Drive c: () (Fixed) (Total:931.41 GB) (Free:703.85 GB) NTFS

Drive e: (2G-3) (Removable) (Total:1.91 GB) (Free:1.56 GB) FAT

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 05AF9A15)

Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

 

========================================================

Disk: 5 (MBR Code: Windows XP) (Size: 1.9 GB) (Disk ID: C3072E18)

Partition 1: (Active) - (Size=1.9 GB) - (Type=06)

 

==================== End of Addition.txt ============================

Posted

Hi Mike,

 

Not a lot of McAfee left, the removal went quite well.

We'll clean out the rest of McAfee and a few orphan entries... then you'll be good to go.

 

Obviously you'll have to save the fixlist to the usb stick again as FRST was run from there.

fixlist.txt

76c90dd0e79a714317a8daeecc1584d2.png

Posted

Ok, here's the report:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 18-10-2017 01

Ran by Webb (19-10-2017 15:08:02) Run:2

Running from E:\

Loaded Profiles: Webb (Available Profiles: Webb)

Boot Mode: Normal

==============================================

 

fixlist content:

*****************

CloseProcesses:

HKLM-x32\...\Run: [] => [X]

SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File

CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US1134D20170817&p={searchTerms}

CHR DefaultSearchKeyword: Default -> mcafee

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19]

017-10-19 09:47 - 2017-05-17 21:06 - 000000000 ____D C:\Program Files\Common Files\McAfee

2017-10-19 08:52 - 2017-08-17 20:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee

2017-10-19 08:48 - 2017-08-17 20:16 - 000000000 __RSD C:\Users\Webb\Documents\McAfee Vaults

Task: {025FE179-4831-477F-8D1B-10F3F2E58528} - System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe

Task: {D271CC90-ABFD-42D0-BE8C-78522C6AC001} - System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe

Task: {D2FA513E-DD71-4370-9C87-9753A8A45DAB} - System32\Tasks\{1A179B3C-3F33-4F86-BAE0-B036074283A2} => C:\Windows\system32\pcalua.exe -a C:\ProgramData\Uninstall\{537BF16E-7412-448C-95D8-846E85A1D817}\setup.exe -c /x {537BF16E-7412-448C-95D8-846E85A1D817}

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""

FirewallRules: [{1415D485-D8DC-40FD-A462-5671560DD9E8}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe

EmptyTemp:

 

*****************

 

Processes closed successfully.

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully

HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully

HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key removed successfully

HKLM\Software\Classes\CLSID\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key not found.

HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key removed successfully

HKLM\Software\Wow6432Node\Classes\CLSID\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key not found.

HKLM\Software\Classes\PROTOCOLS\Filter\application/x-mfe-ipt => key removed successfully

HKLM\Software\Classes\CLSID\{3EF5086B-5478-4598-A054-786C45D75692} => key not found.

Chrome DefaultSearchURL => removed successfully

Chrome DefaultSearchKeyword => removed successfully

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19] => Error: No automatic fix found for this entry.

017-10-19 09:47 - 2017-05-17 21:06 - 000000000 ____D C:\Program Files\Common Files\McAfee => Error: No automatic fix found for this entry.

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee => moved successfully

C:\Users\Webb\Documents\McAfee Vaults => moved successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{025FE179-4831-477F-8D1B-10F3F2E58528} => key removed successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{025FE179-4831-477F-8D1B-10F3F2E58528} => key removed successfully

C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => moved successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => key removed successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D271CC90-ABFD-42D0-BE8C-78522C6AC001} => key removed successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D271CC90-ABFD-42D0-BE8C-78522C6AC001} => key removed successfully

C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => moved successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => key removed successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D2FA513E-DD71-4370-9C87-9753A8A45DAB} => key removed successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D2FA513E-DD71-4370-9C87-9753A8A45DAB} => key removed successfully

C:\Windows\System32\Tasks\{1A179B3C-3F33-4F86-BAE0-B036074283A2} => moved successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1A179B3C-3F33-4F86-BAE0-B036074283A2} => key removed successfully

HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcapexe => key removed successfully

HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1415D485-D8DC-40FD-A462-5671560DD9E8} => value removed successfully

 

=========== EmptyTemp: ==========

 

BITS transfer queue => 8388608 B

DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5879569 B

Java, Flash, Steam htmlcache => 0 B

Windows/system/drivers => 23826217 B

Edge => 0 B

Chrome => 140526815 B

Firefox => 0 B

Opera => 0 B

 

Temp, IE cache, history, cookies, recent:

Users => 0 B

Default => 0 B

Public => 0 B

ProgramData => 0 B

systemprofile => 128 B

systemprofile32 => 128 B

LocalService => 0 B

NetworkService => 0 B

Webb => 83684368 B

 

RecycleBin => 895767 B

EmptyTemp: => 251 MB temporary data Removed.

 

================================

 

 

The system needed a reboot.

 

==== End of Fixlog 15:08:20 ====

Posted

Hi Mike,

 

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19] => Error: No automatic fix found for this entry.
Seems the only way to remove this would be to reset Chrome.

It's not a malicious entry... just a bit dubious.

Up to you if you want to reset Chrome.

 

Customer should be happy now.

 

Safe surfing. e551c0a6c62160eeac0c672f27ea97b9.gif

76c90dd0e79a714317a8daeecc1584d2.png

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...