Jump to content

Featured Replies

  • Author
BTW, the removal process seems to be hanging at a point which is showing "Removing product VS", if that should be stuck there for another, what else can I try? I had told the owner he may need to reinstall OS but he says has some softwares on there which he can;t get back the license info for.
  • Author
McAfee is not showing up in the Remover list, only Mbam? Maybe I can try all of this safe mode?

Try in safe mode.

If still no joy let me have a fresh set of frst reports and we'll do it manually.

76c90dd0e79a714317a8daeecc1584d2.png

  • Author
I tried it again this time the MCR tool worked and can now go to the net, anything else needed to do here?

Just let me have a new set of frst reports and we'll see if there's any leftovers.

Won't be able to write a fix (If needed) until I'm home from work though.... a couple of hours.

76c90dd0e79a714317a8daeecc1584d2.png

  • Author

Sure thx but all is working fine.

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-10-2017 01

Ran by Webb (administrator) on WEBB-PC (19-10-2017 11:07:13)

Running from E:\

Loaded Profiles: Webb (Available Profiles: Webb)

Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: IE)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

() C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

() C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe

() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

() C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE

(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe

(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe

() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe

(Microsoft Corporation) C:\Windows\splwow64.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe

(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe

(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe

(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe

(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)

HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)

HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)

HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-09-01] (Apple Inc.)

HKLM-x32\...\Run: [TrayServer] => C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_14\TrayServer.exe

HKLM-x32\...\Run: [iSUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [324976 2010-05-21] (Flexera Software, Inc.)

HKLM-x32\...\Run: [] => [X]

HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatchTray14.exe [294032 2012-07-18] (Corel Corporation)

HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)

HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1637496 2011-08-04] (CANON INC.)

HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296520 2014-11-03] (RealNetworks, Inc.)

HKLM-x32\...\Run: [RealDownloader] => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [551488 2014-09-23] ()

HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2131344 2016-06-20] (Wondershare)

HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\AllMyTube\DelayPluginI.exe [1960336 2015-08-11] ()

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Amazon Music] => C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe [5908968 2016-06-16] ()

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Chromium] => "c:\users\webb\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-09-09] (Apple Inc.)

HKU\S-1-5-18\...\RunOnce: [sPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-07-18] (Microsoft Corporation)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2014-11-03]

ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-10-18]

ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{1BE97A3D-A7FB-498E-9B5F-075F5A5C3C67}: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{7BAF68A2-5E5E-4630-A2D4-91496139CC0F}: [DhcpNameServer] 192.168.1.1

 

Internet Explorer:

==================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKU\S-1-5-21-207249110-600702845-166796750-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/en-us/?ocid=U221DHP&pc=U221

SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-09-26] (RealDownloader)

BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

BHO-x32: Wondershare AllMyTube 4.3.0 -> {067DF9EC-26B7-40DC-8DB8-CD8BE85AE367} -> C:\ProgramData\Wondershare\AllMyTube\WSBrowserAppMgr.dll [2015-08-11] (Wondershare)

BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-09-26] (RealDownloader)

BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14] (CANON INC.)

BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14] (CANON INC.)

DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File

 

FireFox:

========

FF ProfilePath: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default [2017-10-18]

FF NewTab: Mozilla\Firefox\Profiles\t8ym71sf.default -> about:newtab

FF DefaultSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\t8ym71sf.default -> Bing

FF SelectedSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF Homepage: Mozilla\Firefox\Profiles\t8ym71sf.default -> user_pref("browser.startup.homepage", "hxxps://www.malwarebytes.org/restorebrowser/

FF Extension: (Transit) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\@Transit.xpi [2017-09-12]

FF Extension: (Bing Extension) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\bingsearch.full@microsoft.com [2017-10-18] [not signed]

FF SearchPlugin: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\searchplugins\bing-.xml [2015-03-28]

FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-11-03] [not signed]

FF HKLM-x32\...\Firefox\Extensions: [{4642CD99-8FDF-4550-94E1-63360972C326}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF HKLM-x32\...\Firefox\Extensions: [AllMyTube@Wondershare.com] - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com

FF Extension: (Wondershare AllMyTube) - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com [2016-02-10] [not signed]

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-13] ()

FF Plugin: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-13] ()

FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-21] (CANON INC.)

FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-09] (Nero AG)

FF Plugin-x32: @real.com/nppl3260;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2014-11-03] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.14 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-09-26] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprpplugin;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2014-11-03] (RealPlayer Cloud)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)

FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)

FF Plugin ProgramFiles/Appdata: C:\Users\Webb\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2009-09-25] (Microsoft Corporation)

 

Chrome:

=======

CHR DefaultProfile: Default

CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US1134D20170817&p={searchTerms}

CHR DefaultSearchKeyword: Default -> mcafee

CHR Profile: C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default [2017-10-19]

CHR Extension: (Chrome Web Store Payments) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-28]

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19]

CHR HKU\S-1-5-21-207249110-600702845-166796750-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx

 

==================== Services (Whitelisted) ====================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [457360 2012-06-20] ()

R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-17] (Adobe Systems Incorporated)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)

R2 BOT4Service; C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe [22160 2012-07-11] ()

R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]

S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]

R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-21] (Malwarebytes)

R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-09-26] ()

R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-11-03] (RealNetworks, Inc.)

R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31344 2014-09-26] ()

S3 RoxMediaDB14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxMediaDB14.exe [1096848 2012-07-18] (Corel Corporation)

S2 RoxWatch14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatch14.exe [341136 2012-07-18] (Corel Corporation)

S3 UPnPService; C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [548864 2008-10-21] (Magix AG) [File not signed]

S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

 

===================== Drivers (Whitelisted) ======================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [253888 2017-10-19] (Malwarebytes)

R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-07-10] (Corel Corporation)

S3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3741960 2015-06-19] (Realtek Semiconductor Corporation )

S1 RxFilter; C:\Windows\SysWOW64\DRIVERS\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)

R0 Sahdad64; C:\Windows\System32\Drivers\Sahdad64.sys [28304 2012-06-20] (Corel Corporation)

R0 Saibad64; C:\Windows\System32\Drivers\Saibad64.sys [20112 2012-06-20] (Corel Corporation)

R1 SaibVdAd64; C:\Windows\System32\Drivers\SaibVdAd64.sys [27792 2012-06-20] (Corel Corporation)

R3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-09-03] (Wondershare)

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-18 19:30 - 2017-10-18 19:30 - 000000000 ____D C:\Users\Webb\AppData\Roaming\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:29 - 000000000 ____D C:\Program Files (x86)\TP-LINK

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 000030472 _____ (Windows ® Server 2003 DDK provider) C:\Windows\system32\rtlCoInst.dll

2017-10-18 19:28 - 2015-06-19 02:53 - 000028467 _____ C:\Windows\system32\netrtwlanu.cat

2017-10-18 19:28 - 2015-02-16 15:19 - 000008320 _____ C:\Windows\system32\rtlCoInst.dat

2017-10-18 19:27 - 2017-10-18 19:29 - 000000000 ____D C:\ProgramData\TP-LINK

2017-10-18 15:14 - 2017-10-18 15:14 - 000004034 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse

2017-10-18 12:23 - 2017-10-19 11:07 - 000000000 ____D C:\FRST

2017-10-18 11:54 - 2017-10-18 12:21 - 000000000 ____D C:\AdwCleaner

2017-10-18 11:09 - 2017-10-18 11:18 - 000000258 __RSH C:\ProgramData\ntuser.pol

2017-10-18 10:51 - 2017-10-19 07:34 - 000003860 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse

2017-10-18 10:36 - 2017-10-19 10:16 - 000253888 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

2017-10-18 10:36 - 2017-10-18 11:17 - 000002016 _____ C:\Users\Public\Desktop\Malwarebytes.lnk

2017-10-18 10:36 - 2017-10-18 10:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes

2017-10-18 10:36 - 2017-10-18 10:36 - 000000000 ____D C:\Program Files\Malwarebytes

2017-10-18 10:36 - 2017-08-21 07:20 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys

2017-10-09 16:03 - 2017-10-09 16:03 - 000000000 ____D C:\FixMeStick Quarantine

2017-10-09 15:02 - 2017-10-12 23:07 - 000000000 ____D C:\FixMeStick

2017-10-01 00:01 - 2017-10-01 00:01 - 000245712 _____ (Mozilla) C:\Users\Webb\Downloads\Firefox Installer (4).exe

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-19 11:06 - 2014-03-31 21:02 - 053736246 _____ C:\Windows\ntbtlog.txt

2017-10-19 10:23 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2017-10-19 10:23 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2017-10-19 10:15 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT

2017-10-19 10:14 - 2009-07-14 00:45 - 000658640 _____ C:\Windows\system32\FNTCACHE.DAT

2017-10-19 09:47 - 2017-05-17 21:06 - 000000000 ____D C:\Program Files\Common Files\McAfee

2017-10-19 08:52 - 2017-08-17 20:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee

2017-10-19 08:48 - 2017-08-17 20:16 - 000000000 __RSD C:\Users\Webb\Documents\McAfee Vaults

2017-10-19 08:35 - 2017-08-16 16:27 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

2017-10-19 08:35 - 2017-08-16 16:27 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk

2017-10-19 07:47 - 2013-07-17 00:37 - 000000000 ____D C:\Users\Webb\AppData\Local\Adobe

2017-10-18 19:29 - 2013-07-26 11:51 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2017-10-18 19:29 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf

2017-10-18 19:01 - 2013-07-16 23:39 - 000000000 ____D C:\Users\Webb\AppData\LocalLow\Temp

2017-10-18 12:41 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\NDF

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\ProgramData\iolo

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\Program Files (x86)\iolo

2017-10-18 10:39 - 2009-07-14 01:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI

2017-10-18 10:36 - 2013-08-29 14:46 - 000000000 ____D C:\ProgramData\Malwarebytes

2017-10-12 15:35 - 2017-09-12 09:37 - 000003482 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Webb

2017-10-12 15:34 - 2013-07-28 15:18 - 000000576 _____ C:\Users\Webb\Desktop\Wintm.lnk

2017-10-12 12:38 - 2017-09-12 09:37 - 000003488 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Webb

2017-10-09 09:37 - 2009-07-14 01:08 - 000032618 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2017-10-05 21:24 - 2013-07-20 19:08 - 000000000 ____D C:\Users\Webb\AppData\Local\CrashDumps

2017-10-05 21:21 - 2017-08-18 10:48 - 000000000 ____D C:\Program Files\Mozilla Firefox

2017-10-05 21:08 - 2015-01-24 20:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2017-09-23 17:17 - 2017-06-04 15:39 - 000033280 _____ C:\Users\Webb\Desktop\jeans schedule octoberdec.xls

2017-09-23 17:09 - 2017-06-03 23:12 - 000033280 _____ C:\Users\Webb\Desktop\field service october to decenber.xls

 

==================== Files in the root of some directories =======

 

2014-10-07 20:18 - 2016-05-02 13:41 - 000000098 _____ () C:\Users\Webb\AppData\Roaming\WB.CFG

2014-12-21 16:06 - 2014-12-21 16:06 - 000001456 _____ () C:\Users\Webb\AppData\Local\Adobe Save for Web 12.0 Prefs

2013-07-26 19:36 - 2017-09-14 20:55 - 001592448 _____ () C:\Users\Webb\AppData\Local\rx_audio.Cache

2013-07-22 20:33 - 2017-09-14 20:55 - 000054072 _____ () C:\Users\Webb\AppData\Local\rx_image32.Cache

2013-07-16 17:13 - 2013-07-16 17:13 - 000000021 ____H () C:\ProgramData\.24554863501262644635642126105

2014-08-20 22:25 - 2014-09-08 15:45 - 000000848 ___SH () C:\ProgramData\KGyGaAvL.sys

2014-12-10 21:02 - 2014-12-10 21:02 - 000000085 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

2012-07-30 20:51 - 2012-07-30 20:51 - 000002454 _____ () C:\ProgramData\regid.2012-08.com.Corel,Roxio_76C7858E-078C-4C49-AB1A-2A7072664935.swidtag

 

==================== Bamital & volsnap ======================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

LastRegBack: 2016-05-20 20:45

 

==================== End of FRST.txt ============================

  • Author

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-10-2017 01

Ran by Webb (administrator) on WEBB-PC (19-10-2017 11:07:13)

Running from E:\

Loaded Profiles: Webb (Available Profiles: Webb)

Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: IE)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

() C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

() C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe

() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

() C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE

(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe

(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe

() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe

(Microsoft Corporation) C:\Windows\splwow64.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe

(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe

(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe

(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe

(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

(Microsoft Corporation) C:\Windows\System32\dllhost.exe

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)

HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)

HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)

HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-09-01] (Apple Inc.)

HKLM-x32\...\Run: [TrayServer] => C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_14\TrayServer.exe

HKLM-x32\...\Run: [iSUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [324976 2010-05-21] (Flexera Software, Inc.)

HKLM-x32\...\Run: [] => [X]

HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatchTray14.exe [294032 2012-07-18] (Corel Corporation)

HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)

HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1637496 2011-08-04] (CANON INC.)

HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296520 2014-11-03] (RealNetworks, Inc.)

HKLM-x32\...\Run: [RealDownloader] => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [551488 2014-09-23] ()

HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2131344 2016-06-20] (Wondershare)

HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\AllMyTube\DelayPluginI.exe [1960336 2015-08-11] ()

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Amazon Music] => C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe [5908968 2016-06-16] ()

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Chromium] => "c:\users\webb\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-09-09] (Apple Inc.)

HKU\S-1-5-18\...\RunOnce: [sPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-07-18] (Microsoft Corporation)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2014-11-03]

ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-10-18]

ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{1BE97A3D-A7FB-498E-9B5F-075F5A5C3C67}: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{7BAF68A2-5E5E-4630-A2D4-91496139CC0F}: [DhcpNameServer] 192.168.1.1

 

Internet Explorer:

==================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKU\S-1-5-21-207249110-600702845-166796750-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/en-us/?ocid=U221DHP&pc=U221

SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-09-26] (RealDownloader)

BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

BHO-x32: Wondershare AllMyTube 4.3.0 -> {067DF9EC-26B7-40DC-8DB8-CD8BE85AE367} -> C:\ProgramData\Wondershare\AllMyTube\WSBrowserAppMgr.dll [2015-08-11] (Wondershare)

BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-09-26] (RealDownloader)

BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14] (CANON INC.)

BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14] (CANON INC.)

DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File

 

FireFox:

========

FF ProfilePath: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default [2017-10-18]

FF NewTab: Mozilla\Firefox\Profiles\t8ym71sf.default -> about:newtab

FF DefaultSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\t8ym71sf.default -> Bing

FF SelectedSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF Homepage: Mozilla\Firefox\Profiles\t8ym71sf.default -> user_pref("browser.startup.homepage", "hxxps://www.malwarebytes.org/restorebrowser/

FF Extension: (Transit) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\@Transit.xpi [2017-09-12]

FF Extension: (Bing Extension) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\bingsearch.full@microsoft.com [2017-10-18] [not signed]

FF SearchPlugin: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\searchplugins\bing-.xml [2015-03-28]

FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-11-03] [not signed]

FF HKLM-x32\...\Firefox\Extensions: [{4642CD99-8FDF-4550-94E1-63360972C326}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF HKLM-x32\...\Firefox\Extensions: [AllMyTube@Wondershare.com] - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com

FF Extension: (Wondershare AllMyTube) - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com [2016-02-10] [not signed]

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_130.dll [2017-09-13] ()

FF Plugin: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_130.dll [2017-09-13] ()

FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-21] (CANON INC.)

FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-09] (Nero AG)

FF Plugin-x32: @real.com/nppl3260;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2014-11-03] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.14 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-09-26] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprpplugin;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2014-11-03] (RealPlayer Cloud)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)

FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)

FF Plugin ProgramFiles/Appdata: C:\Users\Webb\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2009-09-25] (Microsoft Corporation)

 

Chrome:

=======

CHR DefaultProfile: Default

CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US1134D20170817&p={searchTerms}

CHR DefaultSearchKeyword: Default -> mcafee

CHR Profile: C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default [2017-10-19]

CHR Extension: (Chrome Web Store Payments) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-28]

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19]

CHR HKU\S-1-5-21-207249110-600702845-166796750-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx

 

==================== Services (Whitelisted) ====================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [457360 2012-06-20] ()

R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-17] (Adobe Systems Incorporated)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)

R2 BOT4Service; C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe [22160 2012-07-11] ()

R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]

S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]

R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-21] (Malwarebytes)

R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-09-26] ()

R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-11-03] (RealNetworks, Inc.)

R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31344 2014-09-26] ()

S3 RoxMediaDB14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxMediaDB14.exe [1096848 2012-07-18] (Corel Corporation)

S2 RoxWatch14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatch14.exe [341136 2012-07-18] (Corel Corporation)

S3 UPnPService; C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [548864 2008-10-21] (Magix AG) [File not signed]

S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

 

===================== Drivers (Whitelisted) ======================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [253888 2017-10-19] (Malwarebytes)

R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-07-10] (Corel Corporation)

S3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3741960 2015-06-19] (Realtek Semiconductor Corporation )

S1 RxFilter; C:\Windows\SysWOW64\DRIVERS\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)

R0 Sahdad64; C:\Windows\System32\Drivers\Sahdad64.sys [28304 2012-06-20] (Corel Corporation)

R0 Saibad64; C:\Windows\System32\Drivers\Saibad64.sys [20112 2012-06-20] (Corel Corporation)

R1 SaibVdAd64; C:\Windows\System32\Drivers\SaibVdAd64.sys [27792 2012-06-20] (Corel Corporation)

R3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-09-03] (Wondershare)

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-18 19:30 - 2017-10-18 19:30 - 000000000 ____D C:\Users\Webb\AppData\Roaming\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:29 - 000000000 ____D C:\Program Files (x86)\TP-LINK

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 000030472 _____ (Windows ® Server 2003 DDK provider) C:\Windows\system32\rtlCoInst.dll

2017-10-18 19:28 - 2015-06-19 02:53 - 000028467 _____ C:\Windows\system32\netrtwlanu.cat

2017-10-18 19:28 - 2015-02-16 15:19 - 000008320 _____ C:\Windows\system32\rtlCoInst.dat

2017-10-18 19:27 - 2017-10-18 19:29 - 000000000 ____D C:\ProgramData\TP-LINK

2017-10-18 15:14 - 2017-10-18 15:14 - 000004034 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse

2017-10-18 12:23 - 2017-10-19 11:07 - 000000000 ____D C:\FRST

2017-10-18 11:54 - 2017-10-18 12:21 - 000000000 ____D C:\AdwCleaner

2017-10-18 11:09 - 2017-10-18 11:18 - 000000258 __RSH C:\ProgramData\ntuser.pol

2017-10-18 10:51 - 2017-10-19 07:34 - 000003860 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse

2017-10-18 10:36 - 2017-10-19 10:16 - 000253888 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys

2017-10-18 10:36 - 2017-10-18 11:17 - 000002016 _____ C:\Users\Public\Desktop\Malwarebytes.lnk

2017-10-18 10:36 - 2017-10-18 10:36 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes

2017-10-18 10:36 - 2017-10-18 10:36 - 000000000 ____D C:\Program Files\Malwarebytes

2017-10-18 10:36 - 2017-08-21 07:20 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys

2017-10-09 16:03 - 2017-10-09 16:03 - 000000000 ____D C:\FixMeStick Quarantine

2017-10-09 15:02 - 2017-10-12 23:07 - 000000000 ____D C:\FixMeStick

2017-10-01 00:01 - 2017-10-01 00:01 - 000245712 _____ (Mozilla) C:\Users\Webb\Downloads\Firefox Installer (4).exe

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-19 11:06 - 2014-03-31 21:02 - 053736246 _____ C:\Windows\ntbtlog.txt

2017-10-19 10:23 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2017-10-19 10:23 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2017-10-19 10:15 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT

2017-10-19 10:14 - 2009-07-14 00:45 - 000658640 _____ C:\Windows\system32\FNTCACHE.DAT

2017-10-19 09:47 - 2017-05-17 21:06 - 000000000 ____D C:\Program Files\Common Files\McAfee

2017-10-19 08:52 - 2017-08-17 20:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee

2017-10-19 08:48 - 2017-08-17 20:16 - 000000000 __RSD C:\Users\Webb\Documents\McAfee Vaults

2017-10-19 08:35 - 2017-08-16 16:27 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

2017-10-19 08:35 - 2017-08-16 16:27 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk

2017-10-19 07:47 - 2013-07-17 00:37 - 000000000 ____D C:\Users\Webb\AppData\Local\Adobe

2017-10-18 19:29 - 2013-07-26 11:51 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2017-10-18 19:29 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf

2017-10-18 19:01 - 2013-07-16 23:39 - 000000000 ____D C:\Users\Webb\AppData\LocalLow\Temp

2017-10-18 12:41 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\NDF

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\ProgramData\iolo

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\Program Files (x86)\iolo

2017-10-18 10:39 - 2009-07-14 01:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI

2017-10-18 10:36 - 2013-08-29 14:46 - 000000000 ____D C:\ProgramData\Malwarebytes

2017-10-12 15:35 - 2017-09-12 09:37 - 000003482 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Webb

2017-10-12 15:34 - 2013-07-28 15:18 - 000000576 _____ C:\Users\Webb\Desktop\Wintm.lnk

2017-10-12 12:38 - 2017-09-12 09:37 - 000003488 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Webb

2017-10-09 09:37 - 2009-07-14 01:08 - 000032618 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2017-10-05 21:24 - 2013-07-20 19:08 - 000000000 ____D C:\Users\Webb\AppData\Local\CrashDumps

2017-10-05 21:21 - 2017-08-18 10:48 - 000000000 ____D C:\Program Files\Mozilla Firefox

2017-10-05 21:08 - 2015-01-24 20:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2017-09-23 17:17 - 2017-06-04 15:39 - 000033280 _____ C:\Users\Webb\Desktop\jeans schedule octoberdec.xls

2017-09-23 17:09 - 2017-06-03 23:12 - 000033280 _____ C:\Users\Webb\Desktop\field service october to decenber.xls

 

==================== Files in the root of some directories =======

 

2014-10-07 20:18 - 2016-05-02 13:41 - 000000098 _____ () C:\Users\Webb\AppData\Roaming\WB.CFG

2014-12-21 16:06 - 2014-12-21 16:06 - 000001456 _____ () C:\Users\Webb\AppData\Local\Adobe Save for Web 12.0 Prefs

2013-07-26 19:36 - 2017-09-14 20:55 - 001592448 _____ () C:\Users\Webb\AppData\Local\rx_audio.Cache

2013-07-22 20:33 - 2017-09-14 20:55 - 000054072 _____ () C:\Users\Webb\AppData\Local\rx_image32.Cache

2013-07-16 17:13 - 2013-07-16 17:13 - 000000021 ____H () C:\ProgramData\.24554863501262644635642126105

2014-08-20 22:25 - 2014-09-08 15:45 - 000000848 ___SH () C:\ProgramData\KGyGaAvL.sys

2014-12-10 21:02 - 2014-12-10 21:02 - 000000085 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

2012-07-30 20:51 - 2012-07-30 20:51 - 000002454 _____ () C:\ProgramData\regid.2012-08.com.Corel,Roxio_76C7858E-078C-4C49-AB1A-2A7072664935.swidtag

 

==================== Bamital & volsnap ======================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

LastRegBack: 2016-05-20 20:45

 

==================== End of FRST.txt ============================

Hi Mike,

 

Did you realise that you posted the main frst.txt twice.

Let me have the addition.txt and I can finish off the fixlist.

 

Thanks.

76c90dd0e79a714317a8daeecc1584d2.png

  • Author

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 18-10-2017 01

Ran by Webb (administrator) on WEBB-PC (19-10-2017 14:10:01)

Running from E:\

Loaded Profiles: Webb (Available Profiles: Webb)

Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)

Internet Explorer Version 11 (Default browser: IE)

Boot Mode: Normal

Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

 

==================== Processes (Whitelisted) =================

 

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

 

() C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler.exe

(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.5\GoogleCrashHandler64.exe

(Intel Corporation) C:\Windows\System32\hkcmd.exe

(Intel Corporation) C:\Windows\System32\igfxpers.exe

(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE

(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe

() C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe

() C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe

(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe

() C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe

(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE

(Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe

(Wondershare) C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe

() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

(RealNetworks, Inc.) C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin\rpdsvc.exe

() C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe

(Microsoft Corporation) C:\Windows\splwow64.exe

(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe

(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE

(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe

(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe

(MAGIX AG) C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe

(InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe

(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe

(Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe

(Microsoft Corporation) C:\Windows\System32\PrintIsolationHost.exe

 

==================== Registry (Whitelisted) ===========================

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

 

HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [444904 2012-09-20] (Adobe Systems Incorporated)

HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2779024 2011-03-14] (CANON INC.)

HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [176440 2016-09-09] (Apple Inc.)

HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [67384 2016-09-01] (Apple Inc.)

HKLM-x32\...\Run: [TrayServer] => C:\Program Files (x86)\MAGIX\Movie_Edit_Pro_14\TrayServer.exe

HKLM-x32\...\Run: [iSUSPM] => C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe [324976 2010-05-21] (Flexera Software, Inc.)

HKLM-x32\...\Run: [] => [X]

HKLM-x32\...\Run: [RoxWatchTray] => C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatchTray14.exe [294032 2012-07-18] (Corel Corporation)

HKLM-x32\...\Run: [PMBVolumeWatcher] => C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)

HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1637496 2011-08-04] (CANON INC.)

HKLM-x32\...\Run: [TkBellExe] => C:\Program Files (x86)\Real\RealPlayer\update\realsched.exe [296520 2014-11-03] (RealNetworks, Inc.)

HKLM-x32\...\Run: [RealDownloader] => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [551488 2014-09-23] ()

HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [2131344 2016-06-20] (Wondershare)

HKLM-x32\...\Run: [DelaypluginInstall] => C:\ProgramData\Wondershare\AllMyTube\DelayPluginI.exe [1960336 2015-08-11] ()

Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Amazon Music] => C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe [5908968 2016-06-16] ()

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [Chromium] => "c:\users\webb\appdata\local\chromium\application\chrome.exe" --auto-launch-at-startup --profile-directory="Default" --restore-last-session

HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Run: [iCloudServices] => C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe [67384 2016-09-09] (Apple Inc.)

HKU\S-1-5-18\...\RunOnce: [sPReview] => C:\Windows\System32\SPReview\SPReview.exe [301568 2013-07-18] (Microsoft Corporation)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\RealPlayer Cloud Service UI.lnk [2014-11-03]

ShortcutTarget: RealPlayer Cloud Service UI.lnk -> C:\Program Files (x86)\Real\RealPlayer\RPDS\Bin64\rpsystray.exe (RealNetworks, Inc.)

Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\TP-LINK Wireless Configuration Utility.lnk [2017-10-18]

ShortcutTarget: TP-LINK Wireless Configuration Utility.lnk -> C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe ()

 

==================== Internet (Whitelisted) ====================

 

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

 

Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{1BE97A3D-A7FB-498E-9B5F-075F5A5C3C67}: [DhcpNameServer] 192.168.1.1

Tcpip\..\Interfaces\{7BAF68A2-5E5E-4630-A2D4-91496139CC0F}: [DhcpNameServer] 192.168.1.1

 

Internet Explorer:

==================

HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com

HKU\S-1-5-21-207249110-600702845-166796750-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.msn.com/en-us/?ocid=U221DHP&pc=U221

SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

BHO: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin64.dll [2014-09-26] (RealDownloader)

BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

BHO-x32: Wondershare AllMyTube 4.3.0 -> {067DF9EC-26B7-40DC-8DB8-CD8BE85AE367} -> C:\ProgramData\Wondershare\AllMyTube\WSBrowserAppMgr.dll [2015-08-11] (Wondershare)

BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer -> {3049C3E9-B461-4BC5-8870-4C09146192CA} -> C:\Program Files (x86)\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll [2014-09-26] (RealDownloader)

BHO-x32: Canon Easy-WebPrint EX BHO -> {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} -> C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll [2012-06-14] (CANON INC.)

BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll [2012-06-14] (CANON INC.)

DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File

 

FireFox:

========

FF ProfilePath: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default [2017-10-18]

FF NewTab: Mozilla\Firefox\Profiles\t8ym71sf.default -> about:newtab

FF DefaultSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF DefaultSearchEngine.US: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF SearchEngineOrder.3: Mozilla\Firefox\Profiles\t8ym71sf.default -> Bing

FF SelectedSearchEngine: Mozilla\Firefox\Profiles\t8ym71sf.default -> Search Provided by Yahoo

FF Homepage: Mozilla\Firefox\Profiles\t8ym71sf.default -> user_pref("browser.startup.homepage", "hxxps://www.malwarebytes.org/restorebrowser/

FF Extension: (Transit) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\@Transit.xpi [2017-09-12]

FF Extension: (Bing Extension) - C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\Extensions\bingsearch.full@microsoft.com [2017-10-18] [not signed]

FF SearchPlugin: C:\Users\Webb\AppData\Roaming\Mozilla\Firefox\Profiles\t8ym71sf.default\searchplugins\bing-.xml [2015-03-28]

FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF Extension: (RealDownloader) - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2014-11-03] [not signed]

FF HKLM-x32\...\Firefox\Extensions: [{4642CD99-8FDF-4550-94E1-63360972C326}] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext

FF HKLM-x32\...\Firefox\Extensions: [AllMyTube@Wondershare.com] - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com

FF Extension: (Wondershare AllMyTube) - C:\ProgramData\Wondershare\AllMyTube\AllMyTube@Wondershare.com [2016-02-10] [not signed]

FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_27_0_0_170.dll [2017-10-19] ()

FF Plugin: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect64.dll [2012-09-20] (Adobe Systems)

FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_27_0_0_170.dll [2017-10-19] ()

FF Plugin-x32: @canon.com/EPPEX -> C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL [2011-04-21] (CANON INC.)

FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]

FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50428.0\npctrl.dll [2016-04-27] ( Microsoft Corporation)

FF Plugin-x32: @Nero.com/KM -> C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL [2012-08-09] (Nero AG)

FF Plugin-x32: @real.com/nppl3260;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll [2014-11-03] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=17.0.14 -> C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll [2014-09-26] (RealNetworks, Inc.)

FF Plugin-x32: @real.com/nprpplugin;version=17.0.14.69 -> c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll [2014-11-03] (RealPlayer Cloud)

FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-08-16] (Google Inc.)

FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.1 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: @videolan.org/vlc,version=2.2.6 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2017-05-24] (VideoLAN)

FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2017-07-31] (Adobe Systems Inc.)

FF Plugin-x32: adobe.com/AdobeAAMDetect -> C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\CCM\Utilities\npAdobeAAMDetect32.dll [2012-09-20] (Adobe Systems)

FF Plugin ProgramFiles/Appdata: C:\Users\Webb\AppData\Roaming\mozilla\plugins\np-mswmp.dll [2009-09-25] (Microsoft Corporation)

 

Chrome:

=======

CHR DefaultProfile: Default

CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US1134D20170817&p={searchTerms}

CHR DefaultSearchKeyword: Default -> mcafee

CHR Profile: C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default [2017-10-19]

CHR Extension: (Chrome Web Store Payments) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-09-28]

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19]

CHR HKU\S-1-5-21-207249110-600702845-166796750-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [bmkckgpgekmanipelfidlhmkfcjicion] - hxxps://clients2.google.com/service/update2/crx

 

==================== Services (Whitelisted) ====================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R2 9734BF6A-2DCD-40f0-BAB0-5AAFEEBE1269; C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe [457360 2012-06-20] ()

R2 AdobeActiveFileMonitor11.0; C:\Program Files (x86)\Adobe\Elements 11 Organizer\PhotoshopElementsFileAgent.exe [171600 2012-09-17] (Adobe Systems Incorporated)

R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-08-05] (Apple Inc.)

R2 BOT4Service; C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe [22160 2012-07-11] ()

R2 Fabs; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\FABS.exe [1858048 2012-01-23] (MAGIX AG) [File not signed]

S3 FirebirdServerMAGIXInstance; C:\Program Files (x86)\Common Files\MAGIX Services\Database\bin\fbserver.exe [2702848 2011-04-26] (MAGIX®) [File not signed]

R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6058960 2017-08-07] (Malwarebytes)

R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-09-26] ()

R2 RealPlayer Cloud Service; c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-11-03] (RealNetworks, Inc.)

R2 RealPlayerUpdateSvc; C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe [31344 2014-09-26] ()

S3 RoxMediaDB14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxMediaDB14.exe [1096848 2012-07-18] (Corel Corporation)

S2 RoxWatch14; C:\Program Files (x86)\Roxio Creator NXT\Common\RoxWatch14.exe [341136 2012-07-18] (Corel Corporation)

S3 UPnPService; C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [548864 2008-10-21] (Magix AG) [File not signed]

S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

 

===================== Drivers (Whitelisted) ======================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77440 2017-10-04] ()

R2 MBAMChameleon; C:\Windows\System32\Drivers\MbamChameleon.sys [192952 2017-10-19] (Malwarebytes)

R3 MBAMFarflt; C:\Windows\System32\DRIVERS\farflt.sys [110016 2017-10-19] (Malwarebytes)

R3 MBAMProtection; C:\Windows\System32\DRIVERS\mbam.sys [45504 2017-10-19] (Malwarebytes)

R3 MBAMSwissArmy; C:\Windows\System32\Drivers\mbamswissarmy.sys [252232 2017-10-19] (Malwarebytes)

R3 MBAMWebProtection; C:\Windows\System32\DRIVERS\mwac.sys [84256 2017-10-19] (Malwarebytes)

R0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-07-10] (Corel Corporation)

S3 RtlWlanu; C:\Windows\System32\DRIVERS\rtwlanu.sys [3741960 2015-06-19] (Realtek Semiconductor Corporation )

S1 RxFilter; C:\Windows\SysWOW64\DRIVERS\RxFilter.sys [65520 2009-06-26] (Sonic Solutions)

R0 Sahdad64; C:\Windows\System32\Drivers\Sahdad64.sys [28304 2012-06-20] (Corel Corporation)

R0 Saibad64; C:\Windows\System32\Drivers\Saibad64.sys [20112 2012-06-20] (Corel Corporation)

R1 SaibVdAd64; C:\Windows\System32\Drivers\SaibVdAd64.sys [27792 2012-06-20] (Corel Corporation)

R3 WsAudio_Device; C:\Windows\System32\drivers\VirtualAudio.sys [31080 2013-09-03] (Wondershare)

 

==================== NetSvcs (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

 

==================== One Month Created files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-19 11:41 - 2017-10-19 14:11 - 000084256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys

2017-10-19 11:41 - 2017-10-19 11:41 - 000192952 _____ (Malwarebytes) C:\Windows\system32\Drivers\MbamChameleon.sys

2017-10-19 11:41 - 2017-10-19 11:41 - 000110016 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys

2017-10-19 11:41 - 2017-10-19 11:41 - 000045504 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys

2017-10-19 11:40 - 2017-10-19 11:40 - 000252232 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamswissarmy.sys

2017-10-19 11:40 - 2017-10-19 11:40 - 000001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk

2017-10-19 11:40 - 2017-10-19 11:40 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes

2017-10-19 11:40 - 2017-10-19 11:40 - 000000000 ____D C:\Program Files\Malwarebytes

2017-10-19 11:40 - 2017-10-04 13:15 - 000077440 _____ C:\Windows\system32\Drivers\mbae64.sys

2017-10-19 11:34 - 2017-10-19 11:35 - 071535032 _____ (Malwarebytes ) C:\Users\Webb\Downloads\mb3-setup-consumer-3.2.2.2029-1.0.212-1.0.2951.exe

2017-10-18 19:30 - 2017-10-18 19:30 - 000000000 ____D C:\Users\Webb\AppData\Roaming\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:30 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TP-LINK

2017-10-18 19:29 - 2017-10-18 19:29 - 000000000 ____D C:\Program Files (x86)\TP-LINK

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 003741960 _____ (Realtek Semiconductor Corporation ) C:\Windows\system32\Drivers\rtwlanu.sys

2017-10-18 19:28 - 2015-06-19 02:54 - 000030472 _____ (Windows ® Server 2003 DDK provider) C:\Windows\system32\rtlCoInst.dll

2017-10-18 19:28 - 2015-06-19 02:53 - 000028467 _____ C:\Windows\system32\netrtwlanu.cat

2017-10-18 19:28 - 2015-02-16 15:19 - 000008320 _____ C:\Windows\system32\rtlCoInst.dat

2017-10-18 19:27 - 2017-10-18 19:29 - 000000000 ____D C:\ProgramData\TP-LINK

2017-10-18 15:14 - 2017-10-18 15:14 - 000004034 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse

2017-10-18 12:23 - 2017-10-19 14:10 - 000000000 ____D C:\FRST

2017-10-18 11:54 - 2017-10-18 12:21 - 000000000 ____D C:\AdwCleaner

2017-10-18 11:09 - 2017-10-18 11:18 - 000000258 __RSH C:\ProgramData\ntuser.pol

2017-10-18 10:51 - 2017-10-19 07:34 - 000003860 _____ C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse

2017-10-09 16:03 - 2017-10-09 16:03 - 000000000 ____D C:\FixMeStick Quarantine

2017-10-09 15:02 - 2017-10-12 23:07 - 000000000 ____D C:\FixMeStick

2017-10-01 00:01 - 2017-10-01 00:01 - 000245712 _____ (Mozilla) C:\Users\Webb\Downloads\Firefox Installer (4).exe

 

==================== One Month Modified files and folders ========

 

(If an entry is included in the fixlist, the file/folder will be moved.)

 

2017-10-19 14:11 - 2014-03-31 21:02 - 053737144 _____ C:\Windows\ntbtlog.txt

2017-10-19 12:36 - 2013-07-16 19:25 - 000803328 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe

2017-10-19 12:36 - 2013-07-16 19:25 - 000144896 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl

2017-10-19 12:36 - 2013-07-16 19:25 - 000004312 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater

2017-10-19 12:35 - 2013-07-16 19:25 - 000000000 ____D C:\Windows\SysWOW64\Macromed

2017-10-19 12:35 - 2013-07-16 19:25 - 000000000 ____D C:\Windows\system32\Macromed

2017-10-19 12:18 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

2017-10-19 12:18 - 2009-07-14 00:45 - 000022464 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

2017-10-19 11:40 - 2013-08-29 14:46 - 000000000 ____D C:\ProgramData\Malwarebytes

2017-10-19 10:15 - 2009-07-14 01:08 - 000000006 ____H C:\Windows\Tasks\SA.DAT

2017-10-19 10:14 - 2009-07-14 00:45 - 000658640 _____ C:\Windows\system32\FNTCACHE.DAT

2017-10-19 09:47 - 2017-05-17 21:06 - 000000000 ____D C:\Program Files\Common Files\McAfee

2017-10-19 08:52 - 2017-08-17 20:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee

2017-10-19 08:48 - 2017-08-17 20:16 - 000000000 __RSD C:\Users\Webb\Documents\McAfee Vaults

2017-10-19 08:35 - 2017-08-16 16:27 - 000002195 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk

2017-10-19 08:35 - 2017-08-16 16:27 - 000002183 _____ C:\Users\Public\Desktop\Google Chrome.lnk

2017-10-19 07:47 - 2013-07-17 00:37 - 000000000 ____D C:\Users\Webb\AppData\Local\Adobe

2017-10-18 19:29 - 2013-07-26 11:51 - 000000000 ___HD C:\Program Files (x86)\InstallShield Installation Information

2017-10-18 19:29 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\inf

2017-10-18 19:01 - 2013-07-16 23:39 - 000000000 ____D C:\Users\Webb\AppData\LocalLow\Temp

2017-10-18 12:41 - 2009-07-13 23:20 - 000000000 ____D C:\Windows\system32\NDF

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\ProgramData\iolo

2017-10-18 11:08 - 2013-08-29 13:05 - 000000000 ____D C:\Program Files (x86)\iolo

2017-10-18 10:39 - 2009-07-14 01:13 - 000782470 _____ C:\Windows\system32\PerfStringBackup.INI

2017-10-12 15:35 - 2017-09-12 09:37 - 000003482 _____ C:\Windows\System32\Tasks\ReclaimerUpdateXML_Webb

2017-10-12 15:34 - 2013-07-28 15:18 - 000000576 _____ C:\Users\Webb\Desktop\Wintm.lnk

2017-10-12 12:38 - 2017-09-12 09:37 - 000003488 _____ C:\Windows\System32\Tasks\ReclaimerUpdateFiles_Webb

2017-10-09 09:37 - 2009-07-14 01:08 - 000032618 _____ C:\Windows\Tasks\SCHEDLGU.TXT

2017-10-05 21:24 - 2013-07-20 19:08 - 000000000 ____D C:\Users\Webb\AppData\Local\CrashDumps

2017-10-05 21:21 - 2017-08-18 10:48 - 000000000 ____D C:\Program Files\Mozilla Firefox

2017-10-05 21:08 - 2015-01-24 20:54 - 000000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service

2017-09-23 17:17 - 2017-06-04 15:39 - 000033280 _____ C:\Users\Webb\Desktop\jeans schedule octoberdec.xls

2017-09-23 17:09 - 2017-06-03 23:12 - 000033280 _____ C:\Users\Webb\Desktop\field service october to decenber.xls

 

==================== Files in the root of some directories =======

 

2014-10-07 20:18 - 2016-05-02 13:41 - 000000098 _____ () C:\Users\Webb\AppData\Roaming\WB.CFG

2014-12-21 16:06 - 2014-12-21 16:06 - 000001456 _____ () C:\Users\Webb\AppData\Local\Adobe Save for Web 12.0 Prefs

2013-07-26 19:36 - 2017-09-14 20:55 - 001592448 _____ () C:\Users\Webb\AppData\Local\rx_audio.Cache

2013-07-22 20:33 - 2017-09-14 20:55 - 000054072 _____ () C:\Users\Webb\AppData\Local\rx_image32.Cache

2013-07-16 17:13 - 2013-07-16 17:13 - 000000021 ____H () C:\ProgramData\.24554863501262644635642126105

2014-08-20 22:25 - 2014-09-08 15:45 - 000000848 ___SH () C:\ProgramData\KGyGaAvL.sys

2014-12-10 21:02 - 2014-12-10 21:02 - 000000085 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.400.32.bc

2012-07-30 20:51 - 2012-07-30 20:51 - 000002454 _____ () C:\ProgramData\regid.2012-08.com.Corel,Roxio_76C7858E-078C-4C49-AB1A-2A7072664935.swidtag

 

==================== Bamital & volsnap ======================

 

(There is no automatic fix for files that do not pass verification.)

 

C:\Windows\system32\winlogon.exe => File is digitally signed

C:\Windows\system32\wininit.exe => File is digitally signed

C:\Windows\SysWOW64\wininit.exe => File is digitally signed

C:\Windows\explorer.exe => File is digitally signed

C:\Windows\SysWOW64\explorer.exe => File is digitally signed

C:\Windows\system32\svchost.exe => File is digitally signed

C:\Windows\SysWOW64\svchost.exe => File is digitally signed

C:\Windows\system32\services.exe => File is digitally signed

C:\Windows\system32\User32.dll => File is digitally signed

C:\Windows\SysWOW64\User32.dll => File is digitally signed

C:\Windows\system32\userinit.exe => File is digitally signed

C:\Windows\SysWOW64\userinit.exe => File is digitally signed

C:\Windows\system32\rpcss.dll => File is digitally signed

C:\Windows\system32\dnsapi.dll => File is digitally signed

C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed

C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed

 

LastRegBack: 2016-05-20 20:45

 

==================== End of FRST.txt ============================

  • Author

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-10-2017 01

Ran by Webb (19-10-2017 14:27:47)

Running from E:\

Windows 7 Home Premium Service Pack 1 (X64) (2013-07-16 14:41:32)

Boot Mode: Normal

==========================================================

 

 

==================== Accounts: =============================

 

Administrator (S-1-5-21-207249110-600702845-166796750-500 - Administrator - Disabled)

Guest (S-1-5-21-207249110-600702845-166796750-501 - Limited - Disabled)

HomeGroupUser$ (S-1-5-21-207249110-600702845-166796750-1002 - Limited - Enabled)

Webb (S-1-5-21-207249110-600702845-166796750-1000 - Administrator - Enabled) => C:\Users\Webb

 

==================== Security Center ========================

 

(If an entry is included in the fixlist, it will be removed.)

 

AV: Malwarebytes (Enabled - Up to date) {23007AD3-69FE-687C-2629-D584AFFAF72B}

AS: Malwarebytes (Enabled - Up to date) {98619B37-4FC4-67F2-1C99-EEF6D47DBD96}

AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

 

==================== Installed Programs ======================

 

(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 

Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 17.012.20098 - Adobe Systems Incorporated)

Adobe Flash Player 27 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 27.0.0.170 - Adobe Systems Incorporated)

Adobe Flash Player 27 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 27.0.0.170 - Adobe Systems Incorporated)

Adobe Photoshop Elements 11 (HKLM-x32\...\Adobe Photoshop Elements 11) (Version: 11.0 - Adobe Systems Incorporated)

Amazon Music (HKU\S-1-5-21-207249110-600702845-166796750-1000\...\Amazon Amazon Music) (Version: 4.3.2.1367 - Amazon Services LLC)

Apple Application Support (32-bit) (HKLM-x32\...\{29DB9165-5FC1-48F0-9188-26123F526848}) (Version: 5.0.1 - Apple Inc.)

Apple Application Support (32-bit) (HKLM-x32\...\{FE5C2FAA-118D-4509-B51D-3F71CC9E1B3E}) (Version: 4.3 - Apple Inc.)

Apple Application Support (64-bit) (HKLM\...\{5905C8CF-1C88-4478-A48E-4E458AD1BC7E}) (Version: 5.0.1 - Apple Inc.)

Apple Mobile Device Support (HKLM\...\{D4D86CB2-2370-4691-8272-3869EDED6C64}) (Version: 10.0.0.18 - Apple Inc.)

Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.)

Audacity 2.0.5 (HKLM-x32\...\Audacity_is1) (Version: 2.0.5 - Audacity Team)

Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)

Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - )

Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.3.5.0 - Canon Inc.)

Canon MG5300 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series) (Version: - )

Canon MG5300 series On-screen Manual (HKLM-x32\...\Canon MG5300 series On-screen Manual) (Version: - )

Canon MG5300 series User Registration (HKLM-x32\...\Canon MG5300 series User Registration) (Version: - )

Canon MP Navigator EX 5.0 (HKLM-x32\...\MP Navigator EX 5.0) (Version: - )

Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - )

Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - )

Citrix Online Launcher (HKLM-x32\...\{77463C86-BB3A-426E-A6C2-06B4D28C250F}) (Version: 1.0.223 - Citrix)

CLM Explorer (HKLM-x32\...\CLMExplorer) (Version: - Robert Hudson)

Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)

Corel WinDVD (HKLM-x32\...\{5C1F18D2-F6B7-4242-B803-B5A78648185D}) (Version: 10.8.0.201 - Corel Inc.) Hidden

Creator NXT Content (HKLM-x32\...\{9F717571-FEE8-45CD-8B03-5B2D06AD28F7}) (Version: 14.0.024 - Roxio) Hidden

DirectX 9 Runtime (HKLM-x32\...\{3A9527CF-4E91-4683-A03F-F1AD022126E5}) (Version: 1.00.0000 - Sonic Solutions) Hidden

Elements 11 Organizer (HKLM-x32\...\{D4D065E1-3ABF-41D0-B385-FC6F027F4D00}) (Version: 11.0 - Adobe Systems Incorporated) Hidden

EMC 10 Content (HKLM-x32\...\{FDB46DE7-9045-47BB-970A-3E4ED5369E03}) (Version: 1.0.035 - Roxo, Inc.) Hidden

EMCGadgets64 (HKLM\...\{02AD9D20-03D2-4DE0-8793-E8253026AD86}) (Version: 1.0.302 - Sonic) Hidden

Final Draft 7 (HKLM-x32\...\{78D62D17-D970-42DA-B8CF-5E5576293B33}) (Version: 7.1.3.42 - Final Draft, Inc.)

Firebird SQL Server - MAGIX Edition (HKLM-x32\...\{39AB2E37-1A55-4292-A5D3-971E9F70D0F8}) (Version: 2.1.32.0 - MAGIX AG)

Google Chrome (HKLM-x32\...\Google Chrome) (Version: 62.0.3202.62 - Google Inc.)

Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden

Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden

iCloud (HKLM\...\{CE29BC77-C5AE-49D8-A8C0-FDAF6ACF74DF}) (Version: 6.0.1.41 - Apple Inc.)

iTunes (HKLM\...\{9946A4F7-E0FD-4A33-82D1-06CBFFBBB9F9}) (Version: 12.5.1.21 - Apple Inc.)

Kingdom Hall Schedules (HKLM-x32\...\KHS_is1) (Version: 11.15 - Majestic Software)

K-Lite Codec Pack 10.7.1 Full (HKLM-x32\...\KLiteCodecPack_is1) (Version: 10.7.1 - )

K-Lite Codec Pack Packages (HKU\S-1-5-21-207249110-600702845-166796750-1000\...\K-Lite Codec Pack Packages) (Version: - ) <==== ATTENTION

MAGIX MP3 deluxe 19 (HKLM\...\{EA52DEA5-3A60-470C-BBDA-5B962BE45CED}) (Version: 19.0.0.30 - MAGIX Software GmbH) Hidden

MAGIX MP3 deluxe 19 (HKLM-x32\...\MX.{EA52DEA5-3A60-470C-BBDA-5B962BE45CED}) (Version: 19.0.0.30 - MAGIX Software GmbH)

MAGIX MP3 Maker 15 10.0.0.317 (UK) (HKLM-x32\...\MAGIX MP3 Maker 15 UK) (Version: 10.0.0.317 - MAGIX AG)

MAGIX Screenshare 4.3.6.1987 (UK) (HKLM-x32\...\MAGIX Screenshare UK) (Version: 4.3.6.1987 - MAGIX AG)

MAGIX Speed burnR (MSI) (HKLM\...\{7EE6ACF3-FED2-4B97-96CE-846CF1B84F39}) (Version: 7.0.1.27 - MAGIX Software GmbH) Hidden

MAGIX Speed burnR (MSI) (HKLM-x32\...\MX.{7EE6ACF3-FED2-4B97-96CE-846CF1B84F39}) (Version: 7.0.1.27 - MAGIX Software GmbH)

Malwarebytes version 3.2.2.2029 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.2.2.2029 - Malwarebytes)

Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)

Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft)

Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)

Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation)

Microsoft Office Standard Edition 2003 (HKLM-x32\...\{91120409-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)

Microsoft OneDrive (HKU\S-1-5-21-207249110-600702845-166796750-1000\...\OneDriveSetup.exe) (Version: 17.0.4041.0512 - Microsoft Corporation)

Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50428.0 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)

Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)

Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)

Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)

Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{4fcf070a-daac-45e9-a8b0-6850941f7ed8}) (Version: 12.0.21005.1 - Microsoft Corporation)

Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)

MP3 deluxe 19 Update (HKLM\...\{A50A6DA4-F139-419B-8C2B-6B81D96AEE20}) (Version: 19.0.1.48 - MAGIX Software GmbH) Hidden

MSXML 4.0 SP3 Parser (HKLM-x32\...\{196467F1-C11F-4F76-858B-5812ADC83B94}) (Version: 4.30.2100.0 - Microsoft Corporation)

MSXML 4.0 SP3 Parser (KB2758694) (HKLM-x32\...\{1D95BA90-F4F8-47EC-A882-441C99D30C1E}) (Version: 4.30.2117.0 - Microsoft Corporation)

nero12kwikburnexpressess (HKLM-x32\...\{57AB77BC-E70C-454B-BD0C-E543A7961912}) (Version: 12.0.00300 - Nero AG)

Office 15 Click-to-Run Extensibility Component (HKLM-x32\...\{90150000-008C-0000-0000-0000000FF1CE}) (Version: 15.0.4551.1512 - Microsoft Corporation) Hidden

Office 15 Click-to-Run Licensing Component (HKLM\...\{90150000-008F-0000-1000-0000000FF1CE}) (Version: 15.0.4551.1512 - Microsoft Corporation) Hidden

Office 15 Click-to-Run Localization Component (HKLM-x32\...\{90150000-008C-0409-0000-0000000FF1CE}) (Version: 15.0.4551.1512 - Microsoft Corporation) Hidden

Pinnacle Studio 12 (HKLM-x32\...\{D041EB9E-890A-4098-8F94-51DA194AC72A}) (Version: 12.0.0.6163 - Pinnacle Systems)

Pinnacle Video Driver (HKLM\...\{5EB90C06-964F-4195-B83E-BD7E55C88415}) (Version: 12.00.0017 - Pinnacle Systems)

PMB (HKLM-x32\...\{B6A98E5F-D6A7-46FB-9E9D-1F7BF443491C}) (Version: 5.5.02.12220 - Sony Corporation)

Prerequisite installer (HKLM-x32\...\{3AAB08A3-F129-4BD5-B409-AE674F93759D}) (Version: 12.0.0002 - Nero AG) Hidden

PSE11 STI Installer (HKLM-x32\...\{98CE8819-87AA-4814-8167-ADDDD513485F}) (Version: 11.0 - Adobe Systems Incorporated) Hidden

QuickTime 7 (HKLM-x32\...\{FF59BD75-466A-4D5A-AD23-AAD87C5FD44C}) (Version: 7.79.80.95 - Apple Inc.)

RBVirtualFolder64Inst (HKLM\...\{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}) (Version: 1.00.0000 - Roxio, Inc.) Hidden

RealDownloader (HKLM-x32\...\{0b2ba5b5-983a-4565-ace1-2e55014848d2}) (Version: 17.0.14.26 - RealNetworks) Hidden

RealDownloader (HKLM-x32\...\{0F44CC14-936F-4A6D-A4B4-4953AE174A2A}) (Version: 17.0.14.8 - RealNetworks, Inc.) Hidden

RealDownloader (HKLM-x32\...\{7D700940-82E4-4442-B8AF-EF6C9C509C06}) (Version: 17.0.14.26 - RealNetworks) Hidden

RealNetworks - Microsoft Visual C++ 2005 Runtime (HKLM-x32\...\{026C3D27-9BE1-46BE-BEAE-6DE38A0F4FBE}) (Version: 8.0 - RealNetworks) Hidden

RealNetworks - Microsoft Visual C++ 2008 Runtime (HKLM-x32\...\{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}) (Version: 9.0 - RealNetworks, Inc) Hidden

RealNetworks - Microsoft Visual C++ 2010 Runtime (HKLM\...\{21E47F47-C9A7-4454-BA48-388327B0EA00}) (Version: 10.0 - RealNetworks, Inc) Hidden

RealNetworks - Microsoft Visual C++ 2010 Runtime (HKLM-x32\...\{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}) (Version: 10.0 - RealNetworks, Inc) Hidden

RealPlayer Cloud (HKLM-x32\...\RealPlayer 17.0) (Version: 17.0.14 - RealNetworks)

RealUpgrade 1.1 (HKLM-x32\...\{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}) (Version: 1.1.0 - RealNetworks, Inc.) Hidden

Roxio Creator NXT (HKLM-x32\...\{CC915001-1639-4D1B-B0A1-A7AC70C99179}) (Version: 14.0.36.0 - Roxio)

Roxio Easy CD and DVD Burning (HKLM-x32\...\{537BF16E-7412-448C-95D8-846E85A1D817}) (Version: 10.3 - Roxio)

Roxio File Backup (HKLM\...\{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}) (Version: 1.3.0 - Roxio) Hidden

Roxio PhotoShow (HKLM-x32\...\Roxio PhotoShow) (Version: 6.0 - Sonic Solutions)

Roxio Virtual Drive x64 (HKLM\...\{632DCE79-2711-4B07-BB89-DA763E96840C}) (Version: 1.00.0000 - Roxio, Inc.) Hidden

SmartSound Common Data (HKLM-x32\...\{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.) Hidden

SmartSound Common Data (HKLM-x32\...\InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}) (Version: 1.1.0 - SmartSound Software Inc.)

SmartSound Quicktracks 5 (HKLM-x32\...\{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.7 - SmartSound Software Inc.) Hidden

SmartSound Quicktracks 5 (HKLM-x32\...\InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}) (Version: 5.1.7 - SmartSound Software Inc.)

SONAR LE (HKLM-x32\...\SONAR85LE_is1) (Version: 18.0 - Cakewalk Music Software)

Sonic CinePlayer Decoder Pack (HKLM-x32\...\{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}) (Version: 4.3.0 - Sonic Solutions) Hidden

TL-WN725N_WN723N Driver (HKLM-x32\...\{3C3F9CEB-2C5A-4A47-8EAA-DA76037546BA}) (Version: 1.3.1 - TP-LINK)

TMS2015 (HKLM-x32\...\{85E02722-AA60-47D6-BB40-9D9CCE181C13}) (Version: 20.15.1 - 2137378 Ontario Inc.)

TP-LINK Wireless Configuration Utility (HKLM-x32\...\{319D91C6-3D44-436C-9F79-36C0D22372DC}) (Version: 1.3.1 - TP-LINK)

Triple Scoop Music (HKLM-x32\...\{4CD51492-D68C-49AC-9692-29FCC19FBC26}) (Version: 1.0.019 - Roxio) Hidden

Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft)

UpdateService (HKLM-x32\...\{E3AE96D6-E196-45B4-AF62-2B41998B9E37}) (Version: 1.0.0 - RealNetworks, Inc.) Hidden

VD64Inst (HKLM\...\{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}) (Version: 1.00.0000 - Roxio, Inc.) Hidden

Video Downloader (HKLM-x32\...\{65257823-1757-44CF-B23A-D615D7CC460D}) (Version: 1.0.0 - RealNetworks) Hidden

Virtual DJ Broadcaster - Atomix Productions (HKLM-x32\...\Virtual DJ Broadcaster - Atomix Productions) (Version: - )

VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.6 - VideoLAN)

Watchtower Library - English (HKLM-x32\...\{1D72ED8E-EA0F-4AE3-BBC5-2EC55FA5649F}) (Version: 18.0 - Watchtower Bible and Tract Society of Pennsylvania, Inc.)

Watchtower Library 2015 - English (HKLM-x32\...\{F0D4F127-987D-4345-AA96-5699CF14AF35}) (Version: 17.0 - Watchtower Bible and Tract Society of Pennsylvania, Inc.)

Wondershare AllMyTube(Build 4.5.0.0) (HKLM-x32\...\Wondershare AllMyTube_is1) (Version: 4.5.0.0 - Wondershare Software)

Wondershare Helper Compact 2.5.0 (HKLM-x32\...\{5363CE84-5F09-48A1-8B6C-6BB590FFEDF2}_is1) (Version: 2.5.0 - Wondershare)

 

==================== Custom CLSID (Whitelisted): ==========================

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{0C3BA0B1-BC14-4B55-98DC-F1E913C1DA10}\InprocServer32 -> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\ActiveX64.ocx (TODO: <Company name>)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{6FFA7438-3E00-4176-9717-B3BBE2E704AB}\InprocServer32 -> C:\Program Files (x86)\Common Files\Roxio Shared\10.0\DLLShared\ActiveX64.ocx (TODO: <Company name>)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E}\InprocServer32 -> C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{A66FC8BB-7AFD-4FCF-BBA1-341AE079C7DF}\InprocServer32 -> C:\Program Files\Roxio Creator NXT\Virtual Drive 10\DC_ShellExt64.dll (Corel Corporation)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{BBACC218-34EA-4666-9D7A-C78F2274A524}\InprocServer32 -> C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{CB3D0F55-BC2C-4C1A-85ED-23ED75B5106B}\InprocServer32 -> C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{F241C880-6982-4CE5-8CF7-7085BA96DA5A}\InprocServer32 -> C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\SkyDriveShell64.dll (Microsoft Corporation)

CustomCLSID: HKU\S-1-5-21-207249110-600702845-166796750-1000_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\17.0.4041.0512\amd64\FileSyncApi64.dll (Microsoft Corporation)

ContextMenuHandlers1: [PhotoStreamsExt] -> {89D984B3-813B-406A-8298-118AFA3A22AE} => C:\Program Files\Common Files\Apple\Internet Services\ShellStreams64.dll [2016-09-09] (Apple Inc.)

ContextMenuHandlers1: [Roxio Burn] -> {E8CB9D53-A47A-42B5-9F5B-96B037C9DD4C} => C:\Program Files\Roxio\Roxio Burn\RB_ContextMenu64.dll [2012-07-05] ()

ContextMenuHandlers1: [RXDCExtSvr] -> {0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} => C:\Program Files\Roxio\Virtual Drive 10\DC_ShellExt64.dll [2009-06-26] (Sonic Solutions)

ContextMenuHandlers2: [RXDCExtSvr] -> {0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} => C:\Program Files\Roxio\Virtual Drive 10\DC_ShellExt64.dll [2009-06-26] (Sonic Solutions)

ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)

ContextMenuHandlers3: [{4A7C4306-57E0-4C0C-83A9-78C1528F618C}] -> {4A7C4306-57E0-4C0C-83A9-78C1528F618C} => c:\program files (x86)\real\realplayer\RPDS\Bin64\rpcloudview.dll [2014-11-03] (RealNetworks, Inc.)

ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\Windows\system32\igfxpph.dll [2011-02-11] (Intel Corporation)

ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2017-08-30] (Malwarebytes)

ContextMenuHandlers6: [RXDCExtSvr] -> {0FB82570-BB2D-23D3-8D3B-AC2F34F1FA3C} => C:\Program Files\Roxio\Virtual Drive 10\DC_ShellExt64.dll [2009-06-26] (Sonic Solutions)

ContextMenuHandlers1_S-1-5-21-207249110-600702845-166796750-1000: [RXDCExtSvr] -> {A66FC8BB-7AFD-4FCF-BBA1-341AE079C7DF} => C:\Program Files\Roxio Creator NXT\Virtual Drive 10\DC_ShellExt64.dll [2012-07-18] (Corel Corporation)

ContextMenuHandlers2_S-1-5-21-207249110-600702845-166796750-1000: [RXDCExtSvr] -> {A66FC8BB-7AFD-4FCF-BBA1-341AE079C7DF} => C:\Program Files\Roxio Creator NXT\Virtual Drive 10\DC_ShellExt64.dll [2012-07-18] (Corel Corporation)

ContextMenuHandlers6_S-1-5-21-207249110-600702845-166796750-1000: [RXDCExtSvr] -> {A66FC8BB-7AFD-4FCF-BBA1-341AE079C7DF} => C:\Program Files\Roxio Creator NXT\Virtual Drive 10\DC_ShellExt64.dll [2012-07-18] (Corel Corporation)

 

==================== Scheduled Tasks (Whitelisted) =============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

Task: {025FE179-4831-477F-8D1B-10F3F2E58528} - System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe

Task: {34902A79-56ED-4AE8-A16D-F946D1B8605A} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig

Task: {34902A79-56ED-4AE8-A16D-F946D1B8605A} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(2): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshContent

Task: {34902A79-56ED-4AE8-A16D-F946D1B8605A} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B => Command(3): C:\Windows\system32\GWX\GWXDetector.exe [2016-07-13] (Microsoft Corporation)

Task: {4074CE58-CFF1-41E3-96D4-EB0B438C3B61} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2017-10-19] (Adobe Systems Incorporated)

Task: {54628E3C-C21F-418D-82D5-F0E59766123E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-08-16] (Google Inc.)

Task: {5AAAB923-3E02-4118-AD39-9DD6D604F642} - System32\Tasks\ReclaimerUpdateFiles_Webb => C:\Users\Webb\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.08\agent\rnupgagent.exe [2017-09-11] (RealNetworks, Inc.)

Task: {63F0E1D7-725E-4837-AA71-DFC527DEEC6E} - System32\Tasks\RNUpgradeHelperResumePrompt_Webb => C:\Users\Webb\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.08\agent\rnupgagent.exe [2017-09-11] (RealNetworks, Inc.)

Task: {6675B259-962D-4653-9B41-1E6AF6094B86} - System32\Tasks\ReclaimerUpdateXML_Webb => C:\Users\Webb\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.08\agent\rnupgagent.exe [2017-09-11] (RealNetworks, Inc.)

Task: {6948C87B-F506-427A-A8AE-C446F7B68BB7} - System32\Tasks\AdobeAAMUpdater-1.0-Webb-PC-Webb => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2012-09-20] (Adobe Systems Incorporated)

Task: {7BB8588F-ACBD-436B-B5E6-8827C512F577} - System32\Tasks\RealDownloader Update Check => C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe [2014-09-23] ()

Task: {819D2C2C-B29C-46DE-960B-08B3FCA2B108} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(1): %windir%\system32\GWX\GWXUXWorker.exe -> /ScheduleUpgradeReminderTime

Task: {819D2C2C-B29C-46DE-960B-08B3FCA2B108} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\GWXTriggers\ScheduleUpgradeReminderTime => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2016-07-13] (Microsoft Corporation)

Task: {81A7BFC9-4CD6-4250-BB90-49F444A8B77C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2016-02-23] (Apple Inc.)

Task: {847EE0D9-7A49-4CF0-BA6B-597C7D453ECF} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfigAndContent

Task: {847EE0D9-7A49-4CF0-BA6B-597C7D453ECF} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfigandcontent => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2016-07-13] (Microsoft Corporation)

Task: {8D4F47D6-E0C6-4019-9351-87BC637BA492} - System32\Tasks\{5112F452-3CA7-4C49-8748-B938086E88AC} => C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe [2009-06-22] ()

Task: {9A446A7C-EA95-44CD-BD4D-44B94A6BB67F} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2017-07-19] (Adobe Systems Incorporated)

Task: {A85E2D96-C599-40FC-A310-DE1D19DE5743} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(1): %windir%\system32\GWX\GWXConfigManager.exe -> /RefreshConfig

Task: {A85E2D96-C599-40FC-A310-DE1D19DE5743} - C:\Windows\System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => Command(2): C:\Windows\system32\GWX\GWXDetector.exe [2016-07-13] (Microsoft Corporation)

Task: {ABEF6771-F264-4060-A12E-F85222041AD1} - System32\Tasks\RNUpgradeHelperLogonPrompt_Webb => C:\Users\Webb\AppData\Roaming\Real\Update\UpgradeHelper\RealPlayer\14.08\agent\rnupgagent.exe [2017-09-11] (RealNetworks, Inc.)

Task: {AF110201-E2DA-4AC4-85C3-26D842B61080} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2017-08-16] (Google Inc.)

Task: {B2A9E3B1-6839-477A-886D-0B9759CF622D} - System32\Tasks\{7F3A22C9-F476-4463-8930-56090A39A198} => C:\Program Files (x86)\Common Files\Roxio Shared\10.0\Roxio Central36\Main\Roxio_Central36.exe [2009-06-22] ()

Task: {CC6D1F03-AA20-4BE6-AC1F-9DE6CB0E142E} - System32\Tasks\klcp_update => C:\Program Files (x86)\K-Lite Codec Pack\Tools\CodecTweakTool.exe [2014-09-04] ()

Task: {D271CC90-ABFD-42D0-BE8C-78522C6AC001} - System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe

Task: {D2FA513E-DD71-4370-9C87-9753A8A45DAB} - System32\Tasks\{1A179B3C-3F33-4F86-BAE0-B036074283A2} => C:\Windows\system32\pcalua.exe -a C:\ProgramData\Uninstall\{537BF16E-7412-448C-95D8-846E85A1D817}\setup.exe -c /x {537BF16E-7412-448C-95D8-846E85A1D817}

Task: {D464CFBC-565F-4B20-902B-8B6A7869BD69} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-207249110-600702845-166796750-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\recordingmanager.exe [2014-09-26] (RealNetworks, Inc.)

Task: {E391135D-D6FD-449A-A7A7-4B9FEFEDC9EF} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-207249110-600702845-166796750-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-09-26] (RealNetworks, Inc.)

Task: {FAEE40A9-19C7-43C0-9848-C457D385C9F0} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-207249110-600702845-166796750-1000 => C:\Program Files (x86)\RealNetworks\RealDownloader\RealUpgrade.exe [2014-09-26] (RealNetworks, Inc.)

 

(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

 

 

==================== Shortcuts & WMI ========================

 

(The entries could be listed to be restored or removed.)

 

 

Shortcut: C:\Users\Webb\AppData\Roaming\Microsoft\Windows\Network Shortcuts\My Web Sites on MSN\target.lnk -> hxxp://www.msnusers.co

 

==================== Loaded Modules (Whitelisted) ==============

 

2012-06-20 15:48 - 2012-06-20 15:48 - 000457360 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\SaibSVC.exe

2012-07-05 19:47 - 2012-07-05 19:47 - 000185488 _____ () C:\Program Files\Roxio\Roxio Burn\RB_ContextMenu64.dll

2016-09-01 18:12 - 2016-09-01 18:12 - 000092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll

2016-09-01 18:12 - 2016-09-01 18:12 - 001353528 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll

2014-09-18 21:58 - 2016-06-16 16:05 - 005908968 _____ () C:\Users\Webb\AppData\Local\Amazon Music\Amazon Music Helper.exe

2017-10-18 19:29 - 2015-03-20 16:23 - 002206208 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\TWCU.exe

2012-07-11 01:04 - 2012-07-11 01:04 - 000022160 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\BService.exe

2014-09-23 15:54 - 2014-09-23 15:54 - 000551488 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\downloader2.exe

2014-09-26 11:18 - 2014-09-26 11:18 - 000039568 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe

2014-09-26 16:14 - 2014-09-26 16:14 - 000031344 _____ () C:\Program Files (x86)\Real\UpdateService\RealPlayerUpdateSvc.exe

2017-10-19 11:40 - 2017-10-04 13:15 - 002289096 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll

2017-10-19 11:40 - 2017-10-04 13:15 - 002358728 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll

2016-09-01 18:13 - 2016-09-01 18:13 - 001041720 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll

2016-09-01 18:13 - 2016-09-01 18:13 - 000080184 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll

2016-09-01 18:12 - 2016-09-01 18:12 - 000189752 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxslt.dll

2017-10-18 19:29 - 2015-03-23 17:33 - 001411072 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\nicLan.dll

2017-10-18 19:29 - 2015-03-20 16:16 - 000192000 _____ () C:\Program Files (x86)\TP-LINK\TP-LINK Wireless Configuration Utility\DC_WFF.dll

2012-07-11 01:04 - 2012-07-11 01:04 - 003306128 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\BEngine.dll

2012-07-11 01:04 - 2012-07-11 01:04 - 000523920 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\TRREngine.dll

2012-07-11 01:04 - 2012-07-11 01:04 - 000108176 _____ () C:\Program Files (x86)\Roxio\BackOnTrack\App\Logging.dll

2014-09-23 15:05 - 2014-09-23 15:05 - 001382048 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\cpprest100_1_2.dll

2016-06-24 10:35 - 2016-06-20 14:48 - 001506304 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\DAQExp.dll

2016-02-10 17:51 - 2014-05-19 17:19 - 000137728 _____ () C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\CBSCreateVC.dll

2014-11-03 19:53 - 2014-11-03 19:53 - 000865880 _____ () c:\program files (x86)\real\realplayer\RPDS\Plugins\cldplin.dll

2014-09-26 16:13 - 2014-09-26 16:13 - 000035464 _____ () C:\Program Files (x86)\Real\UpdateService\DL2UpdatePlugin.dll

2014-09-26 16:13 - 2014-09-26 16:13 - 000035976 _____ () C:\Program Files (x86)\Real\UpdateService\RealDownloaderUpdatePlugin.dll

2014-09-26 16:13 - 2014-09-26 16:13 - 000033400 _____ () C:\Program Files (x86)\Real\UpdateService\RPDSUpdatePlugin.dll

2014-09-26 16:13 - 2014-09-26 16:13 - 000034456 _____ () C:\Program Files (x86)\Real\UpdateService\VideoDLUpdatePlugin.dll

 

==================== Alternate Data Streams (Whitelisted) =========

 

(If an entry is included in the fixlist, only the ADS will be removed.)

 

AlternateDataStreams: C:\Users\Public\Documents\20130816_140212.jpg:com.dropbox.attributes [159]

AlternateDataStreams: C:\Users\Public\Documents\20130816_140235.jpg:com.dropbox.attributes [81]

AlternateDataStreams: C:\Users\Public\Documents\20130816_140242.jpg:com.dropbox.attributes [326]

AlternateDataStreams: C:\Users\Public\Documents\20130816_140311.jpg:com.dropbox.attributes [324]

AlternateDataStreams: C:\Users\Webb\Desktop\if you dont know me.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Desktop\my greatest demo.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Desktop\my greatest inspiration.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Desktop\SHE.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Desktop\teddy pendergrass tribute.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Documents\a song for you.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Documents\if you dont know me.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Documents\my greatest demo.mp3:Roxio EMC Stream [38]

AlternateDataStreams: C:\Users\Webb\Documents\my greatest inspiration.mp3:Roxio EMC Stream [38]

 

==================== Safe Mode (Whitelisted) ===================

 

(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

 

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SMPCHelper => ""=""

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\tvnserver => ""=""

 

==================== Association (Whitelisted) ===============

 

(If an entry is included in the fixlist, the registry item will be restored to default or removed.)

 

 

==================== Internet Explorer trusted/restricted ===============

 

(If an entry is included in the fixlist, it will be removed from the registry.)

 

 

==================== Hosts content: ===============================

 

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

 

2009-07-13 22:34 - 2017-10-18 18:59 - 000000035 _____ C:\Windows\system32\Drivers\etc\hosts

 

 

==================== Other Areas ============================

 

(Currently there is no automatic fix for this section.)

 

HKU\S-1-5-21-207249110-600702845-166796750-1000\Control Panel\Desktop\\Wallpaper ->

DNS Servers: 192.168.1.1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

Windows Firewall is enabled.

 

==================== MSCONFIG/TASK MANAGER disabled items ==

 

 

==================== FirewallRules (Whitelisted) ===============

 

(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

 

FirewallRules: [{6ADFDAB0-A444-46FA-B2B3-21B2A7D5B153}] => (Allow) C:\Users\Webb\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe

FirewallRules: [{20C65842-7DAC-4206-B55D-0582BB95DBF7}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe

FirewallRules: [{54B84CF2-9221-4FCF-A483-6CD115FB8A63}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\RM.exe

FirewallRules: [{5D25AC97-9A3B-43F9-B8F0-04E4A8035937}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe

FirewallRules: [{C97F8651-8B4B-4E22-9B60-8A6629567283}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\Studio.exe

FirewallRules: [{23A8420D-5748-474B-9C70-6155CDAF4022}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe

FirewallRules: [{FB272CE9-6AD8-4BC7-9078-C47F422799C8}] => (Allow) C:\Program Files (x86)\Pinnacle\Studio 12\Programs\umi.exe

FirewallRules: [{3B0184D1-1662-4AAC-9D20-AA7564AD1753}] => (Allow) LPort=0

FirewallRules: [{EB5AE450-47A4-4C36-9AEB-722516CBE492}] => (Allow) LPort=2869

FirewallRules: [{6F49D27B-EF99-455A-A12B-021D31F3F2DD}] => (Allow) LPort=1900

FirewallRules: [{ABF98727-69AC-4C61-B7F5-FEDFD3A58275}] => (Allow) C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe

FirewallRules: [{F630F497-A827-42CD-B425-E935924E56F4}] => (Allow) C:\Program Files (x86)\Common Files\MAGIX Shared\UPnPService\UPnPService.exe

FirewallRules: [{7ADE29D4-D538-46BC-8315-63A21316333D}] => (Allow) LPort=9000

FirewallRules: [{029705A6-237A-46E9-816C-6CAD9446256E}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe

FirewallRules: [{04F61DE6-4E0A-4B55-B70D-67FF2BFB60B5}] => (Allow) C:\Program Files (x86)\Nero\KM\KwikMedia.exe

FirewallRules: [{17276718-75C8-4614-B5B4-69C12CFF2D30}] => (Allow) c:\program files (x86)\real\realplayer\RPDS\Bin\rpdsvc.exe

FirewallRules: [{7B5FE7FB-EDC3-4C99-B87F-0D816237B457}] => (Allow) C:\Program Files (x86)\mystarttb\ToolbarCleaner.exe

FirewallRules: [{93DC9F0E-CF9D-4EB3-861B-C5B529656C7B}] => (Allow) C:\Program Files (x86)\mystarttb\ToolbarCleaner.exe

FirewallRules: [{94B5E611-A99C-4B2C-A2A6-066EC98B358D}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{C63465B1-7BBF-405D-BD58-E6E904040601}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe

FirewallRules: [{69975844-1968-4B78-A253-E2F52D353EFB}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [{C74B9F76-0BE7-4957-9621-3162E4AA67B5}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe

FirewallRules: [TCP Query User{9DEE37A6-0DFA-47E7-81F1-A0ABE706C59F}C:\program files (x86)\wondershare\allmytube\allmytube.exe] => (Allow) C:\program files (x86)\wondershare\allmytube\allmytube.exe

FirewallRules: [uDP Query User{F6316BA7-B001-42BC-8CD5-65C3DF9A6C05}C:\program files (x86)\wondershare\allmytube\allmytube.exe] => (Allow) C:\program files (x86)\wondershare\allmytube\allmytube.exe

FirewallRules: [{699E23B5-370E-46CD-B857-2D861C415A47}] => (Allow) C:\Program Files\iTunes\iTunes.exe

FirewallRules: [{1415D485-D8DC-40FD-A462-5671560DD9E8}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe

FirewallRules: [{D7717A97-9C28-47B3-AF12-844AA27D617B}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

 

==================== Restore Points =========================

 

09-10-2017 11:25:16 Windows Backup

09-10-2017 13:16:54 Windows Backup

09-10-2017 13:31:18 Windows Backup

18-10-2017 12:13:34 JRT Pre-Junkware Removal

18-10-2017 19:28:23 Installed TP-LINK Wireless Configuration Utility and Driver

18-10-2017 19:29:30 Installed TP-LINK Wireless Configuration Utility

 

==================== Faulty Device Manager Devices =============

 

Name: Microsoft Teredo Tunneling Adapter

Description: Microsoft Teredo Tunneling Adapter

Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}

Manufacturer: Microsoft

Service: tunnel

Problem: : This device cannot start. (Code10)

Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device.

On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard.

 

 

==================== Event log errors: =========================

 

Application errors:

==================

Error: (10/19/2017 12:43:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledSPRetry 9703

 

Error: (10/19/2017 12:43:28 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledEvent 9703

 

Error: (10/19/2017 12:43:27 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: Continuously busy for more than a second

 

Error: (10/19/2017 12:43:26 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledSPRetry 8627

 

Error: (10/19/2017 12:43:26 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledEvent 8627

 

Error: (10/19/2017 12:43:26 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: Continuously busy for more than a second

 

Error: (10/19/2017 12:43:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledSPRetry 7550

 

Error: (10/19/2017 12:43:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledEvent 7550

 

Error: (10/19/2017 12:43:25 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: Continuously busy for more than a second

 

Error: (10/19/2017 12:43:24 PM) (Source: Bonjour Service) (EventID: 100) (User: )

Description: Task Scheduling Error: m->NextScheduledSPRetry 6474

 

 

System errors:

=============

Error: (10/19/2017 02:08:48 PM) (Source: Service Control Manager) (EventID: 7011) (User: )

Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

 

Error: (10/19/2017 10:15:55 AM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load:

RxFilter

 

Error: (10/19/2017 10:15:48 AM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The Roxio Hard Drive Watcher 14 service terminated with the following error:

The class is configured to run as a security id different from the caller

 

Error: (10/19/2017 09:48:45 AM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load:

RxFilter

 

Error: (10/19/2017 09:48:31 AM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The Roxio Hard Drive Watcher 14 service terminated with the following error:

The class is configured to run as a security id different from the caller

 

Error: (10/19/2017 09:42:43 AM) (Source: DCOM) (EventID: 10010) (User: )

Description: The server {E782BE15-9936-4A7F-8DF9-9AB95D229DF1} did not register with DCOM within the required timeout.

 

Error: (10/19/2017 09:34:37 AM) (Source: Service Control Manager) (EventID: 7026) (User: )

Description: The following boot-start or system-start driver(s) failed to load:

RxFilter

 

Error: (10/19/2017 09:34:30 AM) (Source: Service Control Manager) (EventID: 7023) (User: )

Description: The Roxio Hard Drive Watcher 14 service terminated with the following error:

The class is configured to run as a security id different from the caller

 

Error: (10/19/2017 09:34:16 AM) (Source: Service Control Manager) (EventID: 7000) (User: )

Description: The McAfee Service Controller service failed to start due to the following error:

The system cannot find the file specified.

 

Error: (10/19/2017 09:34:16 AM) (Source: Service Control Manager) (EventID: 7003) (User: )

Description: The McAfee Boot Delay Start Service service depends the following service: mfevtp. This service might not be installed.

 

 

CodeIntegrity:

===================================

Date: 2015-08-02 08:54:49.135

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:49.129

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:49.082

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:49.064

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\x86_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_47662a2706182d6f\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.687

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.598

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.490

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.483

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingcore_31bf3856ad364e35_10.0.10074.1_none_a384c5aabe759ea5\wermgr.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.429

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

Date: 2015-08-02 08:54:48.423

Description: Windows is unable to verify the integrity of the file \Device\HarddiskVolume2\$Windows.~BT\Updates\Critical\8e08ca47-f6ba-409d-82de-698e324c0004\amd64_microsoft-windows-errorreportingfaults_31bf3856ad364e35_10.0.10074.1_none_f3153036f55ab3f5\werfault.exe because the signing certificate has been revoked. Check with the publisher to see if a new signed version of the kernel module is available.

 

 

==================== Memory info ===========================

 

Processor: Pentium® Dual-Core CPU E6700 @ 3.20GHz

Percentage of memory in use: 31%

Total physical RAM: 6108.99 MB

Available physical RAM: 4156.91 MB

Total Virtual: 12216.17 MB

Available Virtual: 7976.96 MB

 

==================== Drives ================================

 

Drive c: () (Fixed) (Total:931.41 GB) (Free:703.85 GB) NTFS

Drive e: (2G-3) (Removable) (Total:1.91 GB) (Free:1.56 GB) FAT

 

==================== MBR & Partition Table ==================

 

========================================================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 05AF9A15)

Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)

Partition 2: (Not Active) - (Size=931.4 GB) - (Type=07 NTFS)

 

========================================================

Disk: 5 (MBR Code: Windows XP) (Size: 1.9 GB) (Disk ID: C3072E18)

Partition 1: (Active) - (Size=1.9 GB) - (Type=06)

 

==================== End of Addition.txt ============================

Hi Mike,

 

Not a lot of McAfee left, the removal went quite well.

We'll clean out the rest of McAfee and a few orphan entries... then you'll be good to go.

 

Obviously you'll have to save the fixlist to the usb stick again as FRST was run from there.

fixlist.txt

76c90dd0e79a714317a8daeecc1584d2.png

  • Author

Ok, here's the report:

 

Fix result of Farbar Recovery Scan Tool (x64) Version: 18-10-2017 01

Ran by Webb (19-10-2017 15:08:02) Run:2

Running from E:\

Loaded Profiles: Webb (Available Profiles: Webb)

Boot Mode: Normal

==============================================

 

fixlist content:

*****************

CloseProcesses:

HKLM-x32\...\Run: [] => [X]

SearchScopes: HKLM -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

SearchScopes: HKLM-x32 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =

BHO: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

BHO-x32: No Name -> {B164E929-A1B6-4A06-B104-2CD0E90A88FF} -> No File

Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - No File

CHR DefaultSearchURL: Default -> hxxps://search.yahoo.com/search?fr=mcafee&type=C211US1134D20170817&p={searchTerms}

CHR DefaultSearchKeyword: Default -> mcafee

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19]

017-10-19 09:47 - 2017-05-17 21:06 - 000000000 ____D C:\Program Files\Common Files\McAfee

2017-10-19 08:52 - 2017-08-17 20:16 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee

2017-10-19 08:48 - 2017-08-17 20:16 - 000000000 __RSD C:\Users\Webb\Documents\McAfee Vaults

Task: {025FE179-4831-477F-8D1B-10F3F2E58528} - System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe

Task: {D271CC90-ABFD-42D0-BE8C-78522C6AC001} - System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => C:\Program Files\Common Files\McAfee\AMContent\scanners\x86_64\datrep\1.50.1291.1\mcdatrep.exe

Task: {D2FA513E-DD71-4370-9C87-9753A8A45DAB} - System32\Tasks\{1A179B3C-3F33-4F86-BAE0-B036074283A2} => C:\Windows\system32\pcalua.exe -a C:\ProgramData\Uninstall\{537BF16E-7412-448C-95D8-846E85A1D817}\setup.exe -c /x {537BF16E-7412-448C-95D8-846E85A1D817}

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcapexe => ""=""

FirewallRules: [{1415D485-D8DC-40FD-A462-5671560DD9E8}] => (Allow) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe

EmptyTemp:

 

*****************

 

Processes closed successfully.

HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value removed successfully

HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully

HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value restored successfully

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key removed successfully

HKLM\Software\Classes\CLSID\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key not found.

HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key removed successfully

HKLM\Software\Wow6432Node\Classes\CLSID\{B164E929-A1B6-4A06-B104-2CD0E90A88FF} => key not found.

HKLM\Software\Classes\PROTOCOLS\Filter\application/x-mfe-ipt => key removed successfully

HKLM\Software\Classes\CLSID\{3EF5086B-5478-4598-A054-786C45D75692} => key not found.

Chrome DefaultSearchURL => removed successfully

Chrome DefaultSearchKeyword => removed successfully

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19] => Error: No automatic fix found for this entry.

017-10-19 09:47 - 2017-05-17 21:06 - 000000000 ____D C:\Program Files\Common Files\McAfee => Error: No automatic fix found for this entry.

C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee => moved successfully

C:\Users\Webb\Documents\McAfee Vaults => moved successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{025FE179-4831-477F-8D1B-10F3F2E58528} => key removed successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{025FE179-4831-477F-8D1B-10F3F2E58528} => key removed successfully

C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => moved successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Intel Security DAT Reputation (AMCore) periodic endpoint safety pulse => key removed successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D271CC90-ABFD-42D0-BE8C-78522C6AC001} => key removed successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D271CC90-ABFD-42D0-BE8C-78522C6AC001} => key removed successfully

C:\Windows\System32\Tasks\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => moved successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Intel Security DAT Reputation (AMCore) Post DAT update endpoint safety pulse => key removed successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{D2FA513E-DD71-4370-9C87-9753A8A45DAB} => key removed successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D2FA513E-DD71-4370-9C87-9753A8A45DAB} => key removed successfully

C:\Windows\System32\Tasks\{1A179B3C-3F33-4F86-BAE0-B036074283A2} => moved successfully

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\{1A179B3C-3F33-4F86-BAE0-B036074283A2} => key removed successfully

HKLM\System\CurrentControlSet\Control\SafeBoot\Network\mcapexe => key removed successfully

HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Parameters\FirewallPolicy\FirewallRules\\{1415D485-D8DC-40FD-A462-5671560DD9E8} => value removed successfully

 

=========== EmptyTemp: ==========

 

BITS transfer queue => 8388608 B

DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 5879569 B

Java, Flash, Steam htmlcache => 0 B

Windows/system/drivers => 23826217 B

Edge => 0 B

Chrome => 140526815 B

Firefox => 0 B

Opera => 0 B

 

Temp, IE cache, history, cookies, recent:

Users => 0 B

Default => 0 B

Public => 0 B

ProgramData => 0 B

systemprofile => 128 B

systemprofile32 => 128 B

LocalService => 0 B

NetworkService => 0 B

Webb => 83684368 B

 

RecycleBin => 895767 B

EmptyTemp: => 251 MB temporary data Removed.

 

================================

 

 

The system needed a reboot.

 

==== End of Fixlog 15:08:20 ====

Hi Mike,

 

CHR Extension: (Chrome Media Router) - C:\Users\Webb\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-10-19] => Error: No automatic fix found for this entry.
Seems the only way to remove this would be to reset Chrome.

It's not a malicious entry... just a bit dubious.

Up to you if you want to reset Chrome.

 

Customer should be happy now.

 

Safe surfing. e551c0a6c62160eeac0c672f27ea97b9.gif

76c90dd0e79a714317a8daeecc1584d2.png

Guest
Reply to this topic...