[RESOLVED] Toshiba Laptop
Page 1 of 2 12 LastLast
Results 1 to 15 of 23

Thread: [RESOLVED] Toshiba Laptop

  1. #1
    Join Date
    Dec 2000
    Posts
    15

    Resolved [RESOLVED] Toshiba Laptop

    Got a warning virus screen with a phone number. Called it. Bought their 300 dollar 'super user plan'. They remoted the laptop and did something. Itsolutions LLC / efficientitsolutions.net
    Cancelled the order.

    thanks in advance!

    First.txt

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-09-2016
    Ran by steve (administrator) on STEVE-PC (29-09-2016 18:42:08)
    Running from C:\Users\steve\Desktop
    Loaded Profiles: steve (Available Profiles: steve)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Safe Mode (minimal)
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (Microsoft Corporation) C:\windows\System32\dllhost.exe


    ==================== Registry (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12452456 2012-02-22] (Realtek Semiconductor)
    HKLM\...\Run: [SRS Premium Sound HD] => C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe [2165120 2012-03-22] (SRS Labs, Inc.)
    HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2866960 2011-12-19] (Synaptics Incorporated)
    HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [590256 2011-09-23] (TOSHIBA Corporation)
    HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [989056 2012-02-13] (TOSHIBA Corporation)
    HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1562032 2012-02-09] (TOSHIBA Corporation)
    HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [712096 2011-12-14] (TOSHIBA Corporation)
    HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710560 2012-02-24] (TOSHIBA Corporation)
    HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
    HKLM\...\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597936 2011-07-27] (TOSHIBA Corporation)
    HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38824 2011-06-28] (TOSHIBA Corporation)
    HKLM\...\Run: [PwmConsole.exe] => C:\Program Files\Trend Micro\TMIDS\PwmConsole.exe [2047216 2015-06-29] (Trend Micro Inc.)
    HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [246264 2015-07-16] (Trend Micro Inc.)
    HKLM\...\Run: [Platinum] => C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe [1258496 2015-07-16] (Trend Micro Inc.)
    HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [630912 2012-02-13] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [TSleepSrv] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe [253312 2011-11-21] (TOSHIBA)
    HKLM-x32\...\Run: [NortonOnlineBackupReminder] => C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe [3218864 2011-06-22] (Toshiba)
    HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1298816 2011-07-11] (TOSHIBA Corporation)
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595992 2016-05-20] (Oracle Corporation)
    HKU\S-1-5-21-1354267143-4115596969-162612004-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2015-11-11] (Google Inc.)
    HKU\S-1-5-21-1354267143-4115596969-162612004-1000\...\Run: [PCKeeperLive] => "C:\Program Files\Essentware\PCKeeper\PCKeeper.exe" /autorun
    GroupPolicy: Restriction - Chrome <======= ATTENTION

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
    Tcpip\..\Interfaces\{8E7E69E6-2CAD-4767-8279-2BE14C938492}: [DhcpNameServer] 75.75.75.75 75.75.76.76

    Internet Explorer:
    ==================
    HKU\S-1-5-21-1354267143-4115596969-162612004-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://start.toshiba.com/?cid=C001B2Y
    SearchScopes: HKLM -> DefaultScope {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO
    SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM -> {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO
    SearchScopes: HKLM-x32 -> DefaultScope {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO
    SearchScopes: HKLM-x32 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKLM-x32 -> {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO
    SearchScopes: HKU\S-1-5-21-1354267143-4115596969-162612004-1000 -> DefaultScope {FFB5671D-7B31-484F-9215-BFD08D6A4115} URL = hxxp://www.google.com/search?sourceid=ie9&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO_enUS666
    SearchScopes: HKU\S-1-5-21-1354267143-4115596969-162612004-1000 -> {FFB5671D-7B31-484F-9215-BFD08D6A4115} URL = hxxp://www.google.com/search?sourceid=ie9&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO_enUS666
    SearchScopes: HKU\S-1-5-21-1354267143-4115596969-162612004-1000 -> {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO
    BHO: Trend Micro Password Manager BHO -> {3F019D1C-7EAA-4F25-A765-FBA635BD0AFF} -> C:\Program Files\Trend Micro\TMIDS\PwmIEBHO64.dll [2015-06-29] (Trend Micro Inc.)
    BHO: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
    BHO: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg.dll [2015-07-16] (Trend Micro Inc.)
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-01] (Google Inc.)
    BHO: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\TmBpIe64.dll [2016-06-15] (Trend Micro Inc.)
    BHO: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll [2012-08-24] (TOSHIBA Corporation)
    BHO-x32: Trend Micro Password Manager BHO -> {3F019D1C-7EAA-4F25-A765-FBA635BD0AFF} -> C:\Program Files\Trend Micro\TMIDS\PwmIEBHO32.dll [2015-06-29] (Trend Micro Inc.)
    BHO-x32: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-05-26] (Oracle Corporation)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
    BHO-x32: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg32.dll [2015-07-16] (Trend Micro Inc.)
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-01] (Google Inc.)
    BHO-x32: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\TmBpIe32.dll [2016-06-15] (Trend Micro Inc.)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-26] (Oracle Corporation)
    BHO-x32: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2012-08-24] (TOSHIBA Corporation)
    Toolbar: HKLM - Trend Micro Password Manager ToolBar - {9B4B91FC-EC4D-4018-9575-96FA5A3C03C5} - C:\Program Files\Trend Micro\TMIDS\PwmIEBHO64.dll [2015-06-29] (Trend Micro Inc.)
    Toolbar: HKLM - Trend Micro Security Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-01] (Google Inc.)
    Toolbar: HKLM-x32 - Trend Micro Password Manager ToolBar - {9B4B91FC-EC4D-4018-9575-96FA5A3C03C5} - C:\Program Files\Trend Micro\TMIDS\PwmIEBHO32.dll [2015-06-29] (Trend Micro Inc.)
    Toolbar: HKLM-x32 - Trend Micro Security Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-01] (Google Inc.)
    Toolbar: HKU\S-1-5-21-1354267143-4115596969-162612004-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    Toolbar: HKU\S-1-5-21-1354267143-4115596969-162612004-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-01] (Google Inc.)
    Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\TmBpIe64.dll [2016-06-15] (Trend Micro Inc.)
    Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\TmBpIe32.dll [2016-06-15] (Trend Micro Inc.)
    Handler: tmop - {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg.dll [2015-07-16] (Trend Micro Inc.)
    Handler-x32: tmop - {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg32.dll [2015-07-16] (Trend Micro Inc.)
    Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    Handler-x32: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ProToolbarIMRatingActiveX.dll [2015-07-16] (Trend Micro Inc.)
    Handler-x32: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll [2015-07-16] (Trend Micro Inc.)
    Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
    Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
    Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
    Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)

    FireFox:
    ========
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-26] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-26] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
    FF Plugin-x32: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 -> C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll [2011-09-28] ()
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-1354267143-4115596969-162612004-1000: @citrixonline.com/appdetectorplugin -> C:\Users\steve\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-09-27] (Citrix Online)
    FF HKLM\...\Firefox\Extensions: [tmbepff@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\firefoxextension
    FF Extension: (Trend Micro BEP Firefox Extension) - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\firefoxextension [2016-09-01]
    FF HKLM-x32\...\Firefox\Extensions: [tmbepff@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\firefoxextension
    FF HKLM-x32\...\Firefox\Extensions: [{22181a4d-af90-4ca3-a569-faed9118d6bc}] - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension
    FF Extension: (Trend Micro Toolbar) - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2016-03-08]
    FF HKLM-x32\...\Firefox\Extensions: [{BBB77B49-9FF4-4d5c-8FE2-92B1D6CD696C}] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension
    FF Extension: (Trend Micro Osprey Firefox Extension) - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension [2016-09-01]

    Chrome:
    =======
    CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.116\gcswf32.dll => No File
    CHR Plugin: (Java Deployment Toolkit 6.0.250.6) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll => No File
    CHR Plugin: (Java(TM) Platform SE 6 U25) - C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll => No File
    CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
    CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
    CHR Plugin: (Chrome NaCl) - C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.116\ppGoogleNaClPluginChrome.dll => No File
    CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\53.0.2785.116\pdf.dll => No File
    CHR Plugin: (Norton Confidential) - C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.1.0.30_0\npcoplgn.dll => No File
    CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.107\npGoogleUpdate3.dll => No File
    CHR Plugin: (WildTangent Games App Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
    CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    CHR Profile: C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default [2016-09-27]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-08]
    CHR Extension: (Trend Micro Toolbar) - C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohhcpmplhhiiaoiddkfboafbhiknefdf [2016-09-27]
    CHR Extension: (Trend Micro Password Manager) - C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\olmajmomenlhgihenlbjcfbopoghpckg [2016-06-08]
    CHR Extension: (Amazon Assistant for Chrome) - C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam [2016-09-27]
    CHR HKLM\...\Chrome\Extension: [olmajmomenlhgihenlbjcfbopoghpckg] - hxxps://clients2.google.com/service/update2/crx
    CHR HKU\S-1-5-21-1354267143-4115596969-162612004-1000\SOFTWARE\Google\Chrome\Extensions\...\Chrome\Extension: [pbjikboenpfhbbejgkoklgkhjpfogcam] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [ohhcpmplhhiiaoiddkfboafbhiknefdf] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [olmajmomenlhgihenlbjcfbopoghpckg] - hxxps://clients2.google.com/service/update2/crx

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    S2 Amazon 1Button App Service; C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe [436032 2016-02-17] (Amazon Inc.) [File not signed]
    S2 GFNEXSrv; C:\Windows\System32\GFNEXSrv.exe [162824 2010-09-09] ()
    S2 LMIRescue_82589000-4a13-45e8-9551-c7c3e8fc6c5d; C:\Users\steve\AppData\Local\LogMeIn Rescue Applet\LMIR0001.tmp\LMI_Rescue_srv.exe [4012024 2016-09-27] (LogMeIn, Inc.)
    S2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\SymcPCCULaunchSvc.exe [123320 2015-11-19] (Symantec Corporation)
    S2 PCCUJobMgr; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\ccSvcHst.exe [126392 2011-11-30] (Symantec Corporation)
    S2 Platinum Host Service; C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe [1137664 2015-07-16] (Trend Micro Inc.)
    S2 PwmSvc; C:\Program Files\Trend Micro\TMIDS\PwmSvc.exe [333856 2015-06-29] (Trend Micro Inc.)
    S2 rpcnetp; C:\Windows\System32\rpcnetp.exe [17920 2016-09-29] () [File not signed]
    S2 rpcnetp; C:\windows\SysWOW64\rpcnetp.exe [17920 2016-09-29] () [File not signed]
    S2 TosCoSrv; C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe [580608 2012-02-02] (TOSHIBA Corporation) [File not signed]
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
    S2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad -bt=0 [X]

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [31872 2012-02-01] (Advanced Micro Devices, Inc.)
    S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    S1 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [133424 2015-11-23] (Trend Micro Inc.)
    R0 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [324912 2015-11-23] (Trend Micro Inc.)
    R0 TMEBC; C:\Windows\System32\DRIVERS\TMEBC64.sys [59712 2015-06-11] (Trend Micro Inc.)
    S3 tmeevw; C:\Windows\System32\DRIVERS\tmeevw.sys [116576 2015-06-08] (Trend Micro Inc.)
    S1 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [99632 2015-11-23] (Trend Micro Inc.)
    S3 tmnciesc; C:\Windows\System32\DRIVERS\tmnciesc.sys [561952 2016-06-24] (Trend Micro Inc.)
    S1 tmumh; C:\Windows\System32\DRIVERS\TMUMH.sys [101600 2016-07-20] (Trend Micro Inc.)
    S2 tmusa; C:\Windows\System32\DRIVERS\tmusa.sys [124752 2015-12-09] (Trend Micro Inc.)
    S3 kbfilter; system32\DRIVERS\kbfilter.sys [X]

  2. #2
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Welcome aboard

    Please, observe following rules:

    • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
    • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
    • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
    • Never run more than one scan at a time.
    • Keep updating me regarding your computer behavior, good, or bad.
    • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
    • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
    • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.



    ====================================

    FRST log you posted is incomplete.
    FRST also produces another log. I need that one too.

  3. #3
    Join Date
    Dec 2000
    Posts
    15
    thanks!

    rest of logs:

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-09-29 18:42 - 2016-09-29 18:42 - 00021897 _____ C:\Users\steve\Desktop\FRST.txt
    2016-09-29 18:42 - 2016-09-29 18:42 - 00000000 ____D C:\FRST
    2016-09-29 18:41 - 2016-09-29 18:34 - 02404352 _____ (Farbar) C:\Users\steve\Desktop\FRST64.exe
    2016-09-27 12:55 - 2016-09-27 12:55 - 00012735 _____ C:\Users\steve\Desktop\Technical Support.pdf
    2016-09-27 12:54 - 2016-09-27 12:54 - 00123999 _____ C:\Users\steve\Desktop\Drl.jpeg
    2016-09-27 12:52 - 2016-09-27 12:54 - 00000000 ___RD C:\Users\steve\Documents\Scanned Documents
    2016-09-27 12:52 - 2016-09-27 12:52 - 00000000 ____D C:\Users\steve\Documents\Fax
    2016-09-27 11:42 - 2016-09-27 13:36 - 00000000 ____D C:\Program Files (x86)\Citrix
    2016-09-27 11:41 - 2016-09-27 11:42 - 00000000 ____D C:\Users\steve\AppData\Local\Citrix
    2016-09-27 11:39 - 2016-09-27 11:39 - 00000000 ____D C:\Users\steve\AppData\Local\LogMeIn Rescue Applet
    2016-09-22 17:21 - 2016-09-22 17:21 - 01051248 _____ C:\windows\Minidump\092216-25911-01.dmp
    2016-09-20 13:45 - 2016-08-05 11:30 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
    2016-09-20 13:45 - 2016-08-05 11:13 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
    2016-09-19 17:09 - 2016-09-01 15:26 - 00394440 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
    2016-09-19 17:09 - 2016-09-01 14:41 - 00346320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
    2016-09-19 17:09 - 2016-08-31 23:18 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
    2016-09-19 17:09 - 2016-08-31 23:08 - 20312064 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
    2016-09-19 17:09 - 2016-08-31 22:48 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
    2016-09-19 17:09 - 2016-08-31 22:46 - 00498688 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
    2016-09-19 17:09 - 2016-08-31 22:46 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
    2016-09-19 17:09 - 2016-08-31 22:46 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
    2016-09-19 17:09 - 2016-08-31 22:44 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
    2016-09-19 17:09 - 2016-08-31 22:34 - 02286592 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
    2016-09-19 17:09 - 2016-08-31 22:31 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
    2016-09-19 17:09 - 2016-08-31 22:31 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
    2016-09-19 17:09 - 2016-08-31 22:26 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
    2016-09-19 17:09 - 2016-08-31 22:24 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
    2016-09-19 17:09 - 2016-08-31 22:24 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
    2016-09-19 17:09 - 2016-08-31 22:23 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
    2016-09-19 17:09 - 2016-08-31 22:08 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
    2016-09-19 17:09 - 2016-08-31 21:59 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
    2016-09-19 17:09 - 2016-08-31 21:57 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
    2016-09-19 17:09 - 2016-08-31 21:53 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
    2016-09-19 17:09 - 2016-08-31 21:52 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
    2016-09-19 17:09 - 2016-08-31 21:48 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
    2016-09-19 17:09 - 2016-08-31 21:45 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
    2016-09-19 17:09 - 2016-08-31 21:34 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
    2016-09-19 17:09 - 2016-08-31 21:30 - 00692736 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
    2016-09-19 17:09 - 2016-08-31 21:29 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
    2016-09-19 17:09 - 2016-08-31 21:29 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
    2016-09-19 17:09 - 2016-08-31 21:27 - 13808128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
    2016-09-19 17:09 - 2016-08-31 21:24 - 04607488 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
    2016-09-19 17:09 - 2016-08-31 20:45 - 25770496 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
    2016-09-19 17:09 - 2016-08-31 20:43 - 02445824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
    2016-09-19 17:09 - 2016-08-31 20:42 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
    2016-09-19 17:09 - 2016-08-31 20:40 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
    2016-09-19 17:09 - 2016-08-31 20:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
    2016-09-19 17:09 - 2016-08-31 20:38 - 01316352 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
    2016-09-19 17:09 - 2016-08-31 20:25 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
    2016-09-19 17:09 - 2016-08-31 20:24 - 02894336 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
    2016-09-19 17:09 - 2016-08-31 20:24 - 00576000 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
    2016-09-19 17:09 - 2016-08-31 20:24 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
    2016-09-19 17:09 - 2016-08-31 20:24 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
    2016-09-19 17:09 - 2016-08-31 20:24 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
    2016-09-19 17:09 - 2016-08-31 20:16 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
    2016-09-19 17:09 - 2016-08-31 20:15 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
    2016-09-19 17:09 - 2016-08-31 20:12 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
    2016-09-19 17:09 - 2016-08-31 20:11 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
    2016-09-19 17:09 - 2016-08-31 20:11 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
    2016-09-19 17:09 - 2016-08-31 20:10 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
    2016-09-19 17:09 - 2016-08-31 20:10 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
    2016-09-19 17:09 - 2016-08-31 20:06 - 06047232 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
    2016-09-19 17:09 - 2016-08-31 20:03 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
    2016-09-19 17:09 - 2016-08-31 19:59 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
    2016-09-19 17:09 - 2016-08-31 19:51 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
    2016-09-19 17:09 - 2016-08-31 19:50 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
    2016-09-19 17:09 - 2016-08-31 19:47 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
    2016-09-19 17:09 - 2016-08-31 19:46 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
    2016-09-19 17:09 - 2016-08-31 19:44 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
    2016-09-19 17:09 - 2016-08-31 19:42 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
    2016-09-19 17:09 - 2016-08-31 19:31 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
    2016-09-19 17:09 - 2016-08-31 19:29 - 00724992 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
    2016-09-19 17:09 - 2016-08-31 19:28 - 00806400 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
    2016-09-19 17:09 - 2016-08-31 19:27 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
    2016-09-19 17:09 - 2016-08-31 19:26 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
    2016-09-19 17:09 - 2016-08-31 19:15 - 15411712 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
    2016-09-19 17:09 - 2016-08-31 19:10 - 02921472 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
    2016-09-19 17:09 - 2016-08-31 18:58 - 01550848 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
    2016-09-19 17:09 - 2016-08-31 18:47 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
    2016-09-19 17:09 - 2016-08-12 12:26 - 00464896 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
    2016-09-19 17:09 - 2016-08-12 12:26 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
    2016-09-19 17:09 - 2016-08-12 12:26 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
    2016-09-19 17:08 - 2016-09-02 11:40 - 00631176 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
    2016-09-19 17:08 - 2016-09-02 11:35 - 05548264 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
    2016-09-19 17:08 - 2016-09-02 11:35 - 00706280 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
    2016-09-19 17:08 - 2016-09-02 11:35 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
    2016-09-19 17:08 - 2016-09-02 11:35 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
    2016-09-19 17:08 - 2016-09-02 11:34 - 01732864 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 01464320 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00316416 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:21 - 04000488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
    2016-09-19 17:08 - 2016-09-02 11:21 - 03944680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
    2016-09-19 17:08 - 2016-09-02 11:18 - 01314112 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00260608 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:02 - 00148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
    2016-09-19 17:08 - 2016-09-02 11:02 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
    2016-09-19 17:08 - 2016-09-02 11:02 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
    2016-09-19 17:08 - 2016-09-02 10:58 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
    2016-09-19 17:08 - 2016-09-02 10:57 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
    2016-09-19 17:08 - 2016-09-02 10:55 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
    2016-09-19 17:08 - 2016-09-02 10:54 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
    2016-09-19 17:08 - 2016-09-02 10:54 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
    2016-09-19 17:08 - 2016-09-02 10:53 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
    2016-09-19 17:08 - 2016-09-02 10:49 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
    2016-09-19 17:08 - 2016-09-02 10:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
    2016-09-19 17:08 - 2016-09-02 10:49 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
    2016-09-19 17:08 - 2016-09-02 10:49 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
    2016-09-19 17:08 - 2016-09-02 10:48 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 10:48 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 10:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 10:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2016-09-19 17:08 - 2016-08-06 11:31 - 00877056 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
    2016-09-19 17:08 - 2016-08-06 11:15 - 00581632 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
    2016-09-19 17:08 - 2016-06-06 12:50 - 01483264 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
    2016-09-19 17:08 - 2016-06-06 12:50 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
    2016-09-19 17:08 - 2016-06-06 12:50 - 00190976 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
    2016-09-19 17:08 - 2016-06-06 12:50 - 00141824 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
    2016-09-19 17:08 - 2016-06-06 11:23 - 01176064 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
    2016-09-19 17:08 - 2016-06-06 11:23 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
    2016-09-19 17:08 - 2016-06-06 11:23 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
    2016-09-19 17:08 - 2016-06-06 11:23 - 00106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
    2016-09-19 17:08 - 2016-05-13 18:09 - 03156480 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
    2016-09-19 17:08 - 2016-05-13 18:09 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
    2016-09-19 17:08 - 2016-05-13 18:09 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
    2016-09-19 17:08 - 2016-05-13 18:07 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
    2016-09-19 17:08 - 2016-05-13 17:55 - 02607104 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
    2016-09-19 17:08 - 2016-05-13 17:53 - 00709120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
    2016-09-19 17:08 - 2016-05-13 17:53 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
    2016-09-19 17:08 - 2016-05-13 17:52 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
    2016-09-19 17:08 - 2016-05-13 17:52 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
    2016-09-19 17:08 - 2016-05-13 17:52 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
    2016-09-19 17:08 - 2016-05-13 17:52 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
    2016-09-19 17:08 - 2016-05-13 17:50 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
    2016-09-19 17:08 - 2016-05-13 17:38 - 00573440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
    2016-09-19 17:08 - 2016-05-13 17:38 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
    2016-09-19 17:08 - 2016-05-13 17:38 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
    2016-09-19 17:08 - 2016-05-13 17:38 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
    2016-09-19 17:08 - 2016-05-12 13:14 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
    2016-09-19 17:08 - 2016-05-12 11:18 - 00090624 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
    2016-09-19 17:08 - 2016-05-12 11:18 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
    2016-09-19 17:08 - 2016-05-04 13:21 - 00114408 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
    2016-09-19 17:08 - 2016-05-04 13:17 - 03244032 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
    2016-09-19 17:08 - 2016-05-04 13:17 - 02365440 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
    2016-09-19 17:08 - 2016-05-04 13:17 - 01806848 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
    2016-09-19 17:08 - 2016-05-04 13:17 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
    2016-09-19 17:08 - 2016-05-04 13:17 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
    2016-09-19 17:08 - 2016-05-04 13:16 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
    2016-09-19 17:08 - 2016-05-04 13:16 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
    2016-09-19 17:08 - 2016-05-04 11:04 - 00128512 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
    2016-09-19 17:08 - 2016-05-04 10:55 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
    2016-09-19 17:07 - 2016-09-02 11:31 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
    2016-09-19 17:07 - 2016-09-02 11:01 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
    2016-09-19 17:07 - 2016-09-02 10:53 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
    2016-09-19 17:07 - 2016-09-02 10:53 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
    2016-09-19 17:07 - 2016-09-02 10:49 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
    2016-09-19 17:07 - 2016-08-16 13:36 - 01009152 _____ (Microsoft Corporation) C:\windows\system32\user32.dll
    2016-09-19 17:07 - 2016-08-15 22:48 - 00833024 _____ (Microsoft Corporation) C:\windows\SysWOW64\user32.dll
    2016-09-19 17:07 - 2016-08-15 22:35 - 03218432 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
    2016-09-19 17:07 - 2016-07-07 11:36 - 01896168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
    2016-09-19 17:07 - 2016-07-07 11:36 - 00377576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
    2016-09-19 17:07 - 2016-07-07 11:36 - 00287976 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
    2016-09-19 17:07 - 2016-07-07 11:08 - 00046080 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
    2016-09-19 17:07 - 2016-07-01 11:31 - 00976896 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
    2016-09-19 17:07 - 2016-07-01 11:31 - 00084480 _____ (Microsoft Corporation) C:\windows\system32\INETRES.dll
    2016-09-19 17:07 - 2016-07-01 11:13 - 00741888 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
    2016-09-19 17:07 - 2016-07-01 11:13 - 00084480 _____ (Microsoft Corporation) C:\windows\SysWOW64\INETRES.dll
    2016-09-19 17:07 - 2016-05-04 13:17 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimsg.dll
    2016-09-19 17:07 - 2016-05-04 13:17 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\msimsg.dll
    2016-09-01 11:09 - 2016-09-01 22:03 - 00000000 ____D C:\windows\ELAMBKUP

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-09-29 18:41 - 2016-02-20 08:44 - 00295830 _____ C:\windows\ntbtlog.txt
    2016-09-29 18:41 - 2009-07-14 01:13 - 00782470 _____ C:\windows\system32\PerfStringBackup.INI
    2016-09-29 18:41 - 2009-07-13 23:20 - 00000000 ____D C:\windows\inf
    2016-09-29 18:37 - 2015-11-16 17:42 - 00017920 _____ C:\windows\SysWOW64\rpcnetp.exe
    2016-09-29 18:37 - 2015-11-16 17:42 - 00017920 _____ C:\windows\system32\rpcnetp.exe
    2016-09-27 13:40 - 2016-07-29 11:35 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA1d1e9aec697d400.job
    2016-09-27 12:02 - 2009-07-14 00:45 - 00024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2016-09-27 12:02 - 2009-07-14 00:45 - 00024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2016-09-27 11:42 - 2015-11-13 18:46 - 00000010 _____ C:\Users\steve\AppData\Local\sponge.last.runtime.cache
    2016-09-27 11:40 - 2016-07-29 11:35 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore1d1e9aec519f9f2.job
    2016-09-22 17:24 - 2016-06-03 16:28 - 00262144 _____ C:\windows\system32\config\ELAM
    2016-09-22 17:21 - 2015-11-22 19:15 - 336136806 _____ C:\windows\MEMORY.DMP
    2016-09-22 17:21 - 2015-11-22 19:15 - 00000000 ____D C:\windows\Minidump
    2016-09-22 17:21 - 2009-07-14 01:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
    2016-09-21 22:44 - 2015-11-22 18:56 - 00000000 ____D C:\Users\steve\AppData\Local\CrashDumps
    2016-09-21 22:14 - 2015-11-16 17:42 - 00017920 _____ C:\windows\SysWOW64\rpcnetp.dll
    2016-09-20 13:32 - 2009-07-14 00:45 - 00267672 _____ C:\windows\system32\FNTCACHE.DAT
    2016-09-20 13:08 - 2015-11-13 14:08 - 00000000 ____D C:\windows\system32\MRT
    2016-09-20 12:52 - 2015-11-13 14:08 - 144199024 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
    2016-09-19 12:05 - 2015-11-11 18:56 - 00002206 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2016-09-06 16:33 - 2015-11-13 15:22 - 00000000 ____D C:\Users\steve\AppData\Local\ElevatedDiagnostics
    2016-09-01 22:05 - 2015-11-13 10:17 - 00000000 ___SD C:\windows\system32\GWX
    2016-09-01 22:05 - 2009-07-13 23:20 - 00000000 ____D C:\windows\servicing
    2016-09-01 22:04 - 2015-11-13 14:52 - 00000000 ____D C:\ProgramData\Trend Micro
    2016-09-01 22:04 - 2010-11-21 03:16 - 00000000 ___RD C:\Users\Public\Recorded TV
    2016-09-01 22:02 - 2009-07-13 23:20 - 00000000 ____D C:\windows\registration
    2016-09-01 18:44 - 2015-11-11 21:00 - 00000000 ____D C:\Users\steve

    ==================== Files in the root of some directories =======

    2015-11-13 14:50 - 2015-11-13 14:50 - 0000036 _____ () C:\Users\steve\AppData\Local\housecall.guid.cache
    2015-11-13 18:46 - 2016-09-27 11:42 - 0000010 _____ () C:\Users\steve\AppData\Local\sponge.last.runtime.cache

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\windows\system32\winlogon.exe => File is digitally signed
    C:\windows\system32\wininit.exe => File is digitally signed
    C:\windows\SysWOW64\wininit.exe => File is digitally signed
    C:\windows\explorer.exe => File is digitally signed
    C:\windows\SysWOW64\explorer.exe => File is digitally signed
    C:\windows\system32\svchost.exe => File is digitally signed
    C:\windows\SysWOW64\svchost.exe => File is digitally signed
    C:\windows\system32\services.exe => File is digitally signed
    C:\windows\system32\User32.dll => File is digitally signed
    C:\windows\SysWOW64\User32.dll => File is digitally signed
    C:\windows\system32\userinit.exe => File is digitally signed
    C:\windows\SysWOW64\userinit.exe => File is digitally signed
    C:\windows\system32\rpcss.dll => File is digitally signed
    C:\windows\system32\dnsapi.dll => File is digitally signed
    C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2016-05-31 18:37

    ==================== End of FRST.txt ============================

  4. #4
    Join Date
    Dec 2000
    Posts
    15
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-09-2016
    Ran by steve (29-09-2016 18:43:07)
    Running from C:\Users\steve\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) (2015-11-12 01:00:05)
    Boot Mode: Safe Mode (minimal)
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-1354267143-4115596969-162612004-500 - Administrator - Disabled)
    Guest (S-1-5-21-1354267143-4115596969-162612004-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-1354267143-4115596969-162612004-1002 - Limited - Enabled)
    steve (S-1-5-21-1354267143-4115596969-162612004-1000 - Administrator - Enabled) => C:\Users\steve

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Trend Micro Internet Security (Disabled - Up to date) {8242D66F-41BD-4049-C2E6-E578E73B62A0}
    AS: Trend Micro Internet Security (Disabled - Up to date) {3923378B-6787-4FC7-F856-DE0A9CBC281D}
    AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
    Adobe Flash Player 22 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 22.0.0.192 - Adobe Systems Incorporated)
    Adobe Reader X (10.1.16) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)
    Amazon 1Button App (x32 Version: 2.3.4 - Amazon) Hidden <==== ATTENTION
    Amazon Assistant (HKLM-x32\...\Amazon Assistant) (Version: 2.3.4 - Amazon) <==== ATTENTION
    AMD Catalyst Install Manager (HKLM\...\{63F96D8F-D32B-AABF-4DE1-F51FF391FFD6}) (Version: 3.0.870.0 - Advanced Micro Devices, Inc.)
    Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    Bejeweled 3 (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Citrix Online Launcher (HKLM-x32\...\{09DA5EE2-7E46-4DC4-96F9-BFEE50D40659}) (Version: 1.0.408 - Citrix)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    FATE (x32 Version: 2.2.0.97 - WildTangent) Hidden
    FUJIFILM MyFinePix Studio 4.2 (HKLM-x32\...\MyFinePix Studio_is1) (Version: - )
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 53.0.2785.116 - Google Inc.)
    Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7619.1252 - Google Inc.)
    Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.21.107 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
    Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation)
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Letters from Nowhere 2 (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
    Penguins! (x32 Version: 2.2.0.98 - WildTangent) Hidden
    Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
    PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
    PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
    Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
    Premium Sound HD (HKLM\...\{3007FF9F-5B2C-41FF-8BFC-08BF25DB2681}) (Version: 1.12.1800 - SRS Labs, Inc.)
    QuickTime 7 (HKLM-x32\...\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6577 - Realtek Semiconductor Corp.)
    Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7601.30130 - Realtek Semiconductor Corp.)
    Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0016 - REALTEK Semiconductor Corp.)
    Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.38.2 - Synaptics Incorporated)
    TOSHIBA Application Installer (HKLM-x32\...\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.1.2 - TOSHIBA)
    TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.2.3.1 - TOSHIBA CORPORATION)
    TOSHIBA Battery Check Utility (HKLM-x32\...\{5468E297-7EF8-4CB3-A091-F8714147793F}) (Version: 1.00.01.01 - Toshiba Corporation)
    Toshiba Book Place (HKLM-x32\...\{C31337DE-0CDC-45A9-9A32-F099AC78D557}) (Version: 3.0.9490 - K-NFB Reading Technology, Inc.)
    TOSHIBA Bulletin Board (HKLM-x32\...\InstallShield_{1C8C049A-145F-4A6E-8290-B5C245EBE39D}) (Version: 1.6.11.64 - TOSHIBA Corporation)
    TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.11 for x64 - TOSHIBA Corporation)
    TOSHIBA eco Utility (HKLM\...\{C9C56642-9AAB-4267-9454-36FF1CC59168}) (Version: 1.3.11.64 - TOSHIBA Corporation)
    TOSHIBA Face Recognition (HKLM-x32\...\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.18.64 - TOSHIBA Corporation)
    TOSHIBA Hardware Setup (HKLM-x32\...\{2FD5D2C5-A7A1-4065-89BA-90542BF7CCD3}) (Version: 2.00.0020 - TOSHIBA)
    TOSHIBA HDD/SSD Alert (HKLM\...\{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.12 - TOSHIBA Corporation)
    Toshiba Laptop Checkup (HKLM-x32\...\NortonPCCheckup) (Version: 2.0.17.38 - Symantec Corporation)
    TOSHIBA Media Controller (HKLM-x32\...\{C7A4F26F-F9B0-41B2-8659-99181108CDE3}) (Version: 1.0.87.5 - TOSHIBA CORPORATION)
    TOSHIBA Media Controller Plug-in (HKLM-x32\...\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}) (Version: 1.0.8.0 - TOSHIBA CORPORATION)
    Toshiba Online Backup (HKLM-x32\...\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 2.0.0.31 - Toshiba)
    TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.7.15.64 - TOSHIBA Corporation)
    TOSHIBA Quality Application (HKLM-x32\...\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.4 - TOSHIBA)
    TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.6.52020009 - TOSHIBA CORPORATION)
    TOSHIBA ReelTime (HKLM-x32\...\InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}) (Version: 1.7.21.64 - TOSHIBA Corporation)
    TOSHIBA Resolution+ Plug-in for Windows Media Player (HKLM-x32\...\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}) (Version: 1.1.3.03 - TOSHIBA Corporation)
    Toshiba Security Dashboard (HKLM-x32\...\ToshibaSD) (Version: 1.0.0.48 - Symantec Corporation)
    TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.15.0 - TOSHIBA)
    TOSHIBA Sleep Utility (HKLM-x32\...\{654F7484-88C5-46DC-AB32-C66BCB0E2102}) (Version: 1.4.0022.000104 - TOSHIBA Corporation)
    TOSHIBA Supervisor Password (HKLM-x32\...\{119826A8-4EF6-4BE5-A88B-D2D81FA7CEE2}) (Version: 2.00.0009 - TOSHIBA)
    TOSHIBA User's Guide (HKLM-x32\...\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
    TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.6.0023.640204 - TOSHIBA Corporation)
    TOSHIBA Web Camera Application (HKLM-x32\...\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}) (Version: 2.0.3.33 - TOSHIBA Corporation)
    TOSHIBARegistration (HKLM-x32\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.0.9 - TOSHIBA)
    Trend Micro DirectPass (Version: 1.9.0.1094 - Trend Micro Inc.) Hidden
    Trend Micro Internet Security (HKLM\...\{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}) (Version: 10.0 - Trend Micro Inc.)
    Trend Micro Password Manager (HKLM\...\{3075404F-5657-4f31-A064-FEF98661BDD4}) (Version: 1.9.1189 - Trend Micro Inc.)
    Trend Micro Titanium (Version: 10.0 - Trend Micro Inc.) Hidden
    Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
    VCRT for DirectPass x64 (Version: 1.0.0.1000 - Trend Micro, Inc.) Hidden
    VCRT for DirectPass x86 (x32 Version: 1.0.0.1000 - Trend Micro, Inc.) Hidden
    WildTangent Games (HKLM-x32\...\WildTangent toshiba Master Uninstall) (Version: 1.0.3.0 - WildTangent)
    WildTangent Games App (Toshiba Games) (x32 Version: 4.0.5.36 - WildTangent) Hidden
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {00D05A3D-CEA0-437E-89BA-DF6984EA1B70} - System32\Tasks\DistromaticUpdater-logon => C:\Program Files (x86)\Amazon Browser Settings\updater.exe [2016-05-26] (Distromatic) <==== ATTENTION
    Task: {2546B30F-AB89-4B60-B9FD-F9BF6D29BE21} - System32\Tasks\DistromaticUpdater-periodic => C:\Program Files (x86)\Amazon Browser Settings\updater.exe [2016-05-26] (Distromatic) <==== ATTENTION
    Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
    Task: {36DA4BCC-27F7-4352-8765-61A86B0022D1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.)
    Task: {3F122AA9-B62F-4CBE-B298-FBC8ADA19A4E} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.2.0.29\SymErr.exe
    Task: {55A42844-DA6E-4C58-8D4C-9482151DEFD1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.)
    Task: {81743C56-CBD0-4A3D-8A00-E75AA4D17586} - System32\Tasks\DistromaticSearchProtect-hourly => C:\Program Files (x86)\Amazon Browser Settings\AmznSearchProtect.exe [2016-05-26] (Distromatic) <==== ATTENTION
    Task: {889FC228-6D8F-45AE-87CB-6F348987C0AE} - System32\Tasks\Trend Micro Inspect of Platinum => C:\Program Files\Trend Micro\Titanium\plugin\Pt\win32\Inspect\Inspect.exe [2015-08-19] (Trend Micro Inc.)
    Task: {902F6F3B-ABAD-45F5-9094-3DC80ED4DEA3} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
    Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe
    Task: {A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D} - System32\Tasks\Microsoft\Windows\Location\Notifications => C:\Windows\System32\LocationNotificationWindows.exe
    Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
    Task: {B709435B-2544-4F1A-85EB-1E9EA83057D4} - System32\Tasks\GoogleUpdateTaskMachineUA1d1e9aec697d400 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.)
    Task: {C2D6F654-729D-4AB1-B54B-E62C0AA1F241} - System32\Tasks\DistromaticSearchProtect-logon => C:\Program Files (x86)\Amazon Browser Settings\AmznSearchProtect.exe [2016-05-26] (Distromatic) <==== ATTENTION
    Task: {C768A65F-3D85-416C-B88F-2F450DFED72B} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
    Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
    Task: {D025A81F-507D-489C-A80D-4599ABF5B8BD} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.2.0.29\SymErr.exe
    Task: {D4631BFF-F122-4C8E-B65F-22826B983E05} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {E7BAEA7A-9D74-4B87-A537-8404E1B479E2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-06-24] (Adobe Systems Incorporated)
    Task: {F82EEEED-084D-47F9-A0D5-A6D98936C837} - System32\Tasks\GoogleUpdateTaskMachineCore1d1e9aec519f9f2 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.)
    Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d1e9aec519f9f2.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA1d1e9aec697d400.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============


    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\Users\steve\Desktop\Drl.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
    AlternateDataStreams: C:\Users\steve\Desktop\Drl.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\LMIRescue_82589000-4a13-45e8-9551-c7c3e8fc6c5d => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Option => "OptionValue"="1"

    ==================== Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE trusted site: HKU\S-1-5-21-1354267143-4115596969-162612004-1000\...\amazon.com -> hxxps://amazon.com

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-13 22:34 - 2009-06-10 17:00 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1354267143-4115596969-162612004-1000\Control Panel\Desktop\\Wallpaper ->
    DNS Servers: Media is not connected to internet.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)

    ==================== MSCONFIG/TASK MANAGER disabled items ==


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{CEF4FAEE-9D20-4057-9DD5-53AF1ACA796C}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    FirewallRules: [{931D5A93-CF43-4158-88E5-CD67B746D8D0}] => (Allow) LPort=2869
    FirewallRules: [{179F11AF-215F-4318-952E-8703BDAF36F1}] => (Allow) LPort=1900
    FirewallRules: [{BB6DA4A1-99F8-4F31-B9A9-AC7A0E900F91}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    FirewallRules: [{454DD60F-646C-458D-85FE-7986983ED794}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
    FirewallRules: [{E003F557-41F3-4947-A6F4-0251FAB63764}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
    FirewallRules: [{8B76C25D-DA5C-4D94-BE3E-A0E833DAE7EF}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    ==================== Restore Points =========================

    15-07-2016 11:04:32 Windows Update
    20-07-2016 11:23:40 Windows Update
    13-08-2016 11:30:17 Windows Update
    18-08-2016 11:21:58 Windows Update
    02-09-2016 12:51:45 Windows Update
    20-09-2016 12:48:41 Windows Update
    21-09-2016 12:01:31 Windows Update

    ==================== Faulty Device Manager Devices =============

    Name: Security Processor Loader Driver
    Description: Security Processor Loader Driver
    Class Guid: {8ECC055D-047F-11D1-A537-0000F8753ED1}
    Manufacturer:
    Service: spldr
    Problem: : This device is not present, is not working properly, or does not have all its drivers installed. (Code 24)
    Resolution: The device is installed incorrectly. The problem could be a hardware failure, or a new driver might be needed.
    Devices stay in this state if they have been prepared for removal.
    After you remove the device, this error disappears.Remove the device, and this error should be resolved.


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (09/29/2016 06:39:04 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (09/27/2016 01:30:44 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program iexplore.exe version 11.0.9600.18450 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 1164

    Start Time: 01d2153811edd416

    Termination Time: 0

    Application Path: C:\Program Files\Internet Explorer\iexplore.exe

    Report Id:

    Error: (09/26/2016 04:34:36 PM) (Source: Application Hang) (EventID: 1002) (User: )
    Description: The program IEXPLORE.EXE version 11.0.9600.18450 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

    Process ID: 16e0

    Start Time: 01d21538124f6c82

    Termination Time: 4326

    Application Path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE

    Report Id:

    Error: (09/22/2016 05:21:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (09/21/2016 10:43:55 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: IEXPLORE.EXE, version: 11.0.9600.18450, time stamp: 0x57c77728
    Faulting module name: atidxx32.dll, version: 8.17.10.418, time stamp: 0x4f3981b2
    Exception code: 0xc0000005
    Fault offset: 0x00089863
    Faulting process id: 0x1fa0
    Faulting application start time: 0x01d2147b24028e34
    Faulting application path: C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE
    Faulting module path: C:\windows\system32\atidxx32.dll
    Report Id: 674d66a9-806e-11e6-9e45-4c72b932a5a4

    Error: (09/21/2016 10:15:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (09/21/2016 09:57:04 PM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
    Description: The Desktop Window Manager has encountered a fatal error (0x88980406)

    Error: (09/21/2016 09:56:46 PM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
    Description: The Desktop Window Manager has encountered a fatal error (0x88980406)

    Error: (09/21/2016 09:54:50 PM) (Source: Desktop Window Manager) (EventID: 9020) (User: )
    Description: The Desktop Window Manager has encountered a fatal error (0x88980406)

    Error: (09/20/2016 01:33:09 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.


    System errors:
    =============
    Error: (09/29/2016 06:37:46 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    The dependency service or group failed to start.

    Error: (09/29/2016 06:37:46 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    The dependency service or group failed to start.

    Error: (09/29/2016 06:37:46 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    The dependency service or group failed to start.

    Error: (09/29/2016 06:37:46 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    The dependency service or group failed to start.

    Error: (09/29/2016 06:37:46 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    The dependency service or group failed to start.

    Error: (09/29/2016 06:37:46 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    The dependency service or group failed to start.

    Error: (09/29/2016 06:37:46 PM) (Source: DCOM) (EventID: 10005) (User: )
    Description: DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server:
    {9E175B6D-F52A-11D8-B9A5-505054503030}

    Error: (09/29/2016 06:37:39 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    The dependency service or group failed to start.

    Error: (09/29/2016 06:37:39 PM) (Source: Service Control Manager) (EventID: 7001) (User: )
    Description: The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error:
    The dependency service or group failed to start.

    Error: (09/29/2016 06:37:39 PM) (Source: DCOM) (EventID: 10005) (User: )
    Description: DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server:
    {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}


    ==================== Memory info ===========================

    Processor: AMD A6-4400M APU with Radeon(tm) HD Graphics
    Percentage of memory in use: 14%
    Total physical RAM: 3558.37 MB
    Available physical RAM: 3029.11 MB
    Total Virtual: 7114.92 MB
    Available Virtual: 6624.36 MB

    ==================== Drives ================================

    Drive c: (TI106426W0A) (Fixed) (Total:581.16 GB) (Free:508.16 GB) NTFS ==>[system with boot components (obtained from drive)]
    Drive e: () (Removable) (Total:57.87 GB) (Free:43.57 GB) FAT32

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 596.2 GB) (Disk ID: E36266CE)
    Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
    Partition 2: (Not Active) - (Size=581.2 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=13.5 GB) - (Type=17)

    ========================================================
    Disk: 1 (Size: 57.9 GB) (Disk ID: 00000000)

    Partition: GPT.

    ==================== End of Addition.txt ============================

  5. #5
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Uninstall following unwanted programs:

    Amazon Assistant
    Amazon 1Button App

    Download RogueKiller from one of the following links and save it to your Desktop:

    Link 1
    Link 2


    • Close all the running programs
    • Double click on downloaded setup.exe file to install the program.
    • Click on Start Scan button.
    • Click on another Start Scan button.
    • Wait until the Status box shows Scan Finished
    • Click on Delete.
    • Wait until the Status box shows Deleting Finished.
    • Click on Report and copy/paste the content of the Notepad into your next reply.
    • RKreport.txt could also be found on your desktop.
    • If more than one log is produced post all logs.


    Please download Malwarebytes Anti-Malware (MBAM) to your desktop.
    NOTE. If you already have MBAM 2.0 installed scroll down.
    • Double-click mbam-setup-2.0.0.1000.exe and follow the prompts to install the program.
    • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
    • Click Finish.
    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.

    If you already have MBAM 2.0 installed:
    • On the Dashboard, click the 'Update Now >>' link
    • After the update completes, click the 'Scan Now >>' button.
    • Or, on the Dashboard, click the Scan Now >> button.
    • If an update is available, click the Update Now button.
    • A Threat Scan will begin.
    • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
    • In most cases, a restart will be required.
    • Wait for the prompt to restart the computer to appear, then click on Yes.

    How to get logs:
    (Export log to save as txt)

    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Export'.
    • Click 'Text file (*.txt)'
    • In the Save File dialog box which appears, click on Desktop.
    • In the File name: box type a name for your scan log.
    • A message box named 'File Saved' should appear stating "Your file has been successfully exported".
    • Click Ok
    • Attach that saved log to your next reply.

    (Copy to clipboard for pasting into forum replies or tickets)
    • After the restart once you are back at your desktop, open MBAM once more.
    • Click on the History tab > Application Logs.
    • Double click on the Scan Log which shows the Date and time of the scan just performed.
    • Click 'Copy to Clipboard'
    • Paste the contents of the clipboard into your reply.

    Please download AdwCleaner by Xplode onto your desktop.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Scan button.
    • When the scan has finished click on Clean button.
    • Your computer will be rebooted automatically. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.

    Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Post the contents of JRT.txt into your next message.

  6. #6
    Join Date
    Dec 2000
    Posts
    15
    RogueKiller

    RogueKiller V12.6.4.0 (x64) [Sep 26 2016] (Free) by Adlice Software
    mail : http://www.adlice.com/contact/
    Feedback : http://forum.adlice.com
    Website : http://www.adlice.com/download/roguekiller/
    Blog : http://www.adlice.com

    Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Normal mode
    User : steve [Administrator]
    Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
    Mode : Delete -- Date : 09/30/2016 08:08:27 (Duration : 00:25:00)

    ¤¤¤ Processes : 0 ¤¤¤

    ¤¤¤ Registry : 11 ¤¤¤
    [PUP] (X64) HKEY_CLASSES_ROOT\CLSID\{990F7D4F-09EF-47DF-9ABE-BAF2DCCF5C4B} ("C:\Program Files\Essentware\Common\AccountService.exe") -> Deleted
    [PUP] (X64) HKEY_LOCAL_MACHINE\Software\Essentware -> Deleted
    [PUP] (X64) HKEY_USERS\S-1-5-21-1354267143-4115596969-162612004-1000\Software\Distromatic -> Deleted
    [PUP] (X64) HKEY_USERS\S-1-5-21-1354267143-4115596969-162612004-1000\Software\Essentware -> Deleted
    [PUP] (X86) HKEY_USERS\S-1-5-21-1354267143-4115596969-162612004-1000\Software\Distromatic -> Deleted
    [PUP] (X86) HKEY_USERS\S-1-5-21-1354267143-4115596969-162612004-1000\Software\Essentware -> Deleted
    [PUP] (X64) HKEY_USERS\S-1-5-21-1354267143-4115596969-162612004-1000\Software\Microsoft\Windows\CurrentVersion\Run | PCKeeperLive : "C:\Program Files\Essentware\PCKeeper\PCKeeper.exe" /autorun [x] -> Deleted
    [PUP] (X86) HKEY_USERS\S-1-5-21-1354267143-4115596969-162612004-1000\Software\Microsoft\Windows\CurrentVersion\Run | PCKeeperLive : "C:\Program Files\Essentware\PCKeeper\PCKeeper.exe" /autorun [x] -> ERROR [2]
    [PUP] (X64) HKEY_LOCAL_MACHINE\System\ControlSet002\Services\Amazon 1Button App Service ("C:\Program Files (x86)\Amazon\Amazon1ButtonApp\Amazon1ButtonService64.Exe") -> Deleted
    [PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-1354267143-4115596969-162612004-1000\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://start.toshiba.com/?cid=C001B2Y -> Replaced (http://www.microsoft.com/isapi/redir...r=6&ar=msnhome)
    [PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-1354267143-4115596969-162612004-1000\Software\Microsoft\Internet Explorer\Main | Default_Page_URL : http://start.toshiba.com/?cid=C001B2Y -> Replaced (http://www.microsoft.com/isapi/redir...r=6&ar=msnhome)

    ¤¤¤ Tasks : 0 ¤¤¤

    ¤¤¤ Files : 2 ¤¤¤
    [PUP][Folder] C:\Users\steve\AppData\Local\Essentware -> Deleted
    [PUP][File] C:\Users\steve\AppData\Local\Essentware\DefaultDomain_Path_xseuterajdw5fywvmojz5uax4dukfyo4\2.2.2030.0\user.config -> Deleted
    [PUP][Folder] C:\Users\steve\AppData\Local\Essentware\DefaultDomain_Path_xseuterajdw5fywvmojz5uax4dukfyo4\2.2.2030.0 -> Deleted
    [PUP][Folder] C:\Users\steve\AppData\Local\Essentware\DefaultDomain_Path_xseuterajdw5fywvmojz5uax4dukfyo4 -> Deleted
    [PUP][Folder] C:\ProgramData\Essentware -> Deleted
    [PUP][File] C:\ProgramData\Essentware\AccountService\AccountService.exe0.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\AccountService\AccountService.exe1.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\AccountService\AccountService.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\AccountService\CrashReportSender.llog -> Deleted
    [PUP][Folder] C:\ProgramData\Essentware\AccountService -> Deleted
    [PUP][File] C:\ProgramData\Essentware\Installer\AccSvc.log -> Deleted
    [PUP][File] C:\ProgramData\Essentware\Installer\installer.exe0.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\Installer\installer.exe1.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\Installer\installer.exe2.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\Installer\installer0.exe0.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\Installer\PCKeeper Installer.exe0.llog -> Deleted
    [PUP][Folder] C:\ProgramData\Essentware\Installer -> Deleted
    [PUP][File] C:\ProgramData\Essentware\installer.exe -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\CrashReportSender.llog -> Deleted
    [PUP][Folder] C:\ProgramData\Essentware\PCKeeper\Minidumps -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\OneClickFixService.exe0.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\PCKeeper.exe0.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\PCKeeper.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\PCKeeperService.exe0.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\PCKeeperService.exe1.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\PCKeeperService.exe2.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\PCKeeperService.llog -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\ProblemFinder\RegistryScan.xml -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\ProblemFinder\ScanReport.xml -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\ProblemFinder\SystemScan.xml -> Deleted
    [PUP][Folder] C:\ProgramData\Essentware\PCKeeper\ProblemFinder -> Deleted
    [PUP][File] C:\ProgramData\Essentware\PCKeeper\RegistryCleanerComponent.dll0.llog -> Deleted
    [PUP][Folder] C:\ProgramData\Essentware\PCKeeper -> Deleted

    ¤¤¤ WMI : 0 ¤¤¤

    ¤¤¤ Hosts File : 0 ¤¤¤

    ¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

    ¤¤¤ Web browsers : 1 ¤¤¤
    [PUP][CHROME:Addon] Default : Amazon Assistant for Chrome [pbjikboenpfhbbejgkoklgkhjpfogcam] -> Deleted

    ¤¤¤ MBR Check : ¤¤¤
    +++++ PhysicalDrive0: Hitachi HTS547564A9E384 ATA Device +++++
    --- User ---
    [MBR] ea0000d05cfa6c0cb5298137312f30e3
    [BSP] db94bb477ca213da87283327a4790f81 : HP MBR Code
    Partition table:
    0 - [ACTIVE] ACER (0x27) [VISIBLE] Offset (sectors): 2048 | Size: 1500 MB
    1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 3074048 | Size: 595108 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    2 - [XXXXXX] NTFS (0x17) [HIDDEN!] Offset (sectors): 1221855232 | Size: 13871 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader]
    User = LL1 ... OK
    User = LL2 ... OK

    +++++ PhysicalDrive1: SanDisk Ultra USB Device +++++
    --- User ---
    [MBR] b2a5207711aaeee8437ff9e9e721809e
    [BSP] df4f83c1f72e36823a12b0dfc7617313 : Empty MBR Code
    Partition table:
    0 - [XXXXXX] FAT32-LBA (0xc) [VISIBLE] Offset (sectors): 21952 | Size: 59285 MB
    User = LL1 ... OK
    Error reading LL2 MBR! ([32] The request is not supported. )



    _______________________________________________
    Malwarebytes Anti-Malware

    Malwarebytes Anti-Malware
    www.malwarebytes.org

    Scan Date: 9/30/2016
    Scan Time: 8:40 AM
    Logfile: mbam log.txt
    Administrator: Yes

    Version: 2.2.1.1043
    Malware Database: v2016.09.22.13
    Rootkit Database: v2016.08.15.01
    License: Free
    Malware Protection: Disabled
    Malicious Website Protection: Disabled
    Self-protection: Disabled

    OS: Windows 7 Service Pack 1
    CPU: x64
    File System: NTFS
    User: steve

    Scan Type: Threat Scan
    Result: Completed
    Objects Scanned: 290919
    Time Elapsed: 18 min, 22 sec

    Memory: Enabled
    Startup: Enabled
    Filesystem: Enabled
    Archives: Enabled
    Rootkits: Disabled
    Heuristics: Enabled
    PUP: Enabled
    PUM: Enabled

    Processes: 0
    (No malicious items detected)

    Modules: 0
    (No malicious items detected)

    Registry Keys: 3
    PUP.Optional.PCKeeper, HKLM\SOFTWARE\MICROSOFT\TRACING\PCKeeper_RASAPI32, Quarantined, [161f4b2a8d0deb4bfaf61797ee15857b],
    PUP.Optional.PCKeeper, HKLM\SOFTWARE\MICROSOFT\TRACING\PCKeeper_RASMANCS, Quarantined, [1520de97a8f269cd965abfefa75cfc04],
    PUP.Optional.PCKeeper, HKU\S-1-5-21-1354267143-4115596969-162612004-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\19612210_0, Quarantined, [c075dc997e1c979fa2bbf800cb3844bc],

    Registry Values: 1
    PUP.Optional.PCKeeper, HKU\S-1-5-21-1354267143-4115596969-162612004-1000\SOFTWARE\MICROSOFT\INTERNET EXPLORER\LOWREGISTRY\AUDIO\POLICYCONFIG\PROPERTYSTORE\19612210_0, {0.0.0.00000000}.{2bf14d81-43d1-4dcf-99a7-2d1e5008f733}|\Device\HarddiskVolume2\Program Files\Essentware\PCKeeper\PCKeeper.exe%b{00000000-0000-0000-0000-000000000000}, Quarantined, [c075dc997e1c979fa2bbf800cb3844bc]

    Registry Data: 0
    (No malicious items detected)

    Folders: 0
    (No malicious items detected)

    Files: 2
    PUP.Optional.PCKeeper, C:\ProgramData\RogueKiller\Quarantine\486D63BFA4F821AB.vir, Quarantined, [c075f97c1189b5814334335f996b16ea],
    PUP.Optional.PCKeeper, C:\Users\steve\Downloads\PCKeeper Installer.exe, Quarantined, [5cd92d48bcde49ed680fbad8719312ee],

    Physical Sectors: 0
    (No malicious items detected)


    (end)

    _______________________________________________
    AdwCleaner
    I got this message:

    http://general-changelog-team.fr/fr/...e/2-adwcleaner
    This site can’t be reached general-changelog-team.fr’s server DNS address could not be found.
    DNS_PROBE_FINISHED_NXDOMAIN


    _______________________________________________
    Junkware Removal Tool

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Malwarebytes
    Version: 8.0.8 (09.20.2016)
    Operating System: Windows 7 Home Premium x64
    Ran by steve (Administrator) on Fri 09/30/2016 at 12:10:41.53
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    File System: 27

    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8929H80R (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9RY7FCT0 (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WO2Z69X (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B9BDEK08 (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DJMZ85UN (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IJMX2QNE (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KJL1U62C (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
    Successfully deleted: C:\Users\steve\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YKRBKZBR (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\prefetch\GOOGLETOOLBARMANAGER_F3B2E431-434BCC1B.pf (File)
    Successfully deleted: C:\windows\prefetch\GOOGLETOOLBARNOTIFIER.EXE-7AE0A20E.pf (File)
    Successfully deleted: C:\windows\prefetch\GOOGLETOOLBARUSER_32.EXE-34B1B1C5.pf (File)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\0PS72R2M (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\62AXOPQ5 (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8929H80R (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9RY7FCT0 (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\9WO2Z69X (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B9BDEK08 (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\DJMZ85UN (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FZG8CKJ5 (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\IJMX2QNE (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\KJL1U62C (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LIXMVQOA (Temporary Internet Files Folder)
    Successfully deleted: C:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\YKRBKZBR (Temporary Internet Files Folder)



    Registry: 0





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on Fri 09/30/2016 at 12:17:51.20
    End of JRT log
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  7. #7
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550

  8. #8
    Join Date
    Dec 2000
    Posts
    15
    # AdwCleaner v6.020 - Logfile created 30/09/2016 at 23:36:52
    # Updated on 14/09/2016 by ToolsLib
    # Database : 2016-09-14.2 [Local]
    # Operating System : Windows 7 Home Premium Service Pack 1 (X64)
    # Username : steve - STEVE-PC
    # Running from : C:\Users\steve\Desktop\AdwCleaner current.exe
    # Mode: Scan
    # Support : https://toolslib.net/forum



    ***** [ Services ] *****

    No malicious services found.


    ***** [ Folders ] *****

    No malicious folders found.


    ***** [ Files ] *****

    No malicious files found.


    ***** [ DLL ] *****

    No malicious DLLs found.


    ***** [ WMI ] *****

    No malicious keys found.


    ***** [ Shortcuts ] *****

    No infected shortcut found.


    ***** [ Scheduled Tasks ] *****

    No malicious task found.


    ***** [ Registry ] *****

    Key Found: HKLM\SOFTWARE\Classes\protector_dll.Protector
    Key Found: HKLM\SOFTWARE\Classes\protector_dll.Protector.1
    Key Found: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
    Key Found: HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
    Key Found: [x64] HKLM\SOFTWARE\Classes\protector_dll.Protector
    Key Found: [x64] HKLM\SOFTWARE\Classes\protector_dll.Protector.1
    Key Found: [x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib
    Key Found: [x64] HKLM\SOFTWARE\Classes\protector_dll.ProtectorLib.1
    Key Found: HKLM\SOFTWARE\Classes\AppID\{56AD7EEE-D6C0-410E-8A7B-811DEA764554}
    Key Found: HKLM\SOFTWARE\Classes\AppID\{E8EB2F1F-661E-4A7F-8F9A-77DEB757A906}
    Key Found: HKLM\SOFTWARE\Classes\AppID\{AF85DB83-06F2-4ECF-97CF-C46EDB06BE29}
    Key Found: HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{BD6ECB00-7C4A-4F97-B425-44117F2A7AAE}


    ***** [ Web browsers ] *****

    No malicious Firefox based browser items found.
    Chrome pref Found: [C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Secure Preferences ] - pbjikboenpfhbbejgkoklgkhjpfogcam

    *************************

    C:\AdwCleaner\AdwCleaner[R0].txt - [1428 Bytes] - [30/09/2016 12:06:53]
    C:\AdwCleaner\AdwCleaner[S0].txt - [1504 Bytes] - [30/09/2016 12:08:38]
    C:\AdwCleaner\AdwCleaner[S1].txt - [2044 Bytes] - [30/09/2016 23:36:52]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S1].txt - [2117 Bytes] ##########

  9. #9
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Please download ComboFix from Here, Here or Here to your Desktop.

    **Note: In the event you already have Combofix, this is a new version that I need you to download. It is important that it is saved directly to your desktop**

    • Never rename Combofix unless instructed.
    • Close any open browsers.
    • Very Important! Temporarily disable your anti-virus and any anti-malware real-time protection before performing a scan. They can interfere with ComboFix or remove some of its embedded files which may cause "unpredictable results".
    • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
    • Close any open browsers.
    • WARNING: Combofix will disconnect your machine from the Internet as soon as it starts
    • Please do not attempt to re-connect your machine back to the Internet until Combofix has completely finished.
    • If there is no internet connection after running Combofix, then restart your computer to restore back your connection.
      If the connection is not there use restore point you created prior to running Combofix.
    • Double click on combofix.exe & follow the prompts.



    • NOTE1. If Combofix asks you to install Recovery Console, please allow it.
      NOTE 2. If Combofix asks you to update the program, always do so.



    • When finished, it will produce a report for you.
    • Please post the "C:\ComboFix.txt"


    **Note 1: Do not mouseclick combofix's window while it's running. That may cause it to stall
    **Note 2 for AVG and CA Internet Security (Total Defense Internet Security) users: ComboFix will not run until AVG/CA Internet Security is uninstalled as a protective measure against the anti-virus. This is because AVG/CA Internet Security "falsely" detects ComboFix (or its embedded files) as a threat and may remove them resulting in the tool not working correctly which in turn can cause "unpredictable results". Since AVG/CA Internet Security cannot be effectively disabled before running ComboFix, the author recommends you to uninstall AVG/CA Internet Security first.
    Use AppRemover to uninstall it: http://www.appremover.com/
    We can reinstall it when we're done with CF.
    **Note 3: If you receive an error Illegal operation attempted on a registery key that has been marked for deletion, restart computer to fix the issue.
    **Note 4: Some infections may take some significant time to be cured. As long as your computer clock is running Combofix is still working. Be patient.


    Make sure, you re-enable your security programs, when you're done with Combofix.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    NOTE.
    If, for some reason, Combofix refuses to run, try the following...

    Delete Combofix file, download fresh one, but rename combofix.exe to your_name.exe BEFORE saving it to your desktop.
    Do NOT run it yet.
    Download Rkill (courtesy of BleepingComputer.com) to your desktop.
    There are 2 different versions. If one of them won't run then download and try to run the other one.
    You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    rKill.exe: http://www.bleepingcomputer.com/download/rkill/dl/10/
    iExplore.exe (renamed rKill.exe): http://www.bleepingcomputer.com/download/rkill/dl/11/

    Restart computer in safe mode


    • Double-click on the Rkill desktop icon to run the tool.
    • If using Windows Vista, 7 or 8 right-click on it and choose Run As Administrator.
    • A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    • If not, delete the file, then download and use the one provided in Link 2.
    • Do not reboot until instructed.
    • If the tool does not run from any of the links provided, please let me know.



    When the scan is done Notepad will open with rKill.txt log.
    NOTE. rKill.txt log will also be present on your desktop.

    Once you've gotten one of them to run, immediately run your_name.exe by double clicking on it.

    IF you had to run rKill post BOTH logs, rKill.txt and Combofix.txt.

  10. #10
    Join Date
    Dec 2000
    Posts
    15
    ComboFix 16-09-28.01 - steve 10/02/2016 8:36.1.2 - x64
    Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.3558.2328 [GMT -4:00]
    Running from: c:\users\steve\Desktop\ComboFix.exe
    AV: Trend Micro Internet Security *Disabled/Updated* {8242D66F-41BD-4049-C2E6-E578E73B62A0}
    SP: Trend Micro Internet Security *Disabled/Updated* {3923378B-6787-4FC7-F856-DE0A9CBC281D}
    SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    * Created a new restore point
    .
    .
    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    c:\programdata\ntuser.pol
    c:\windows\msdownld.tmp
    .
    .
    ((((((((((((((((((((((((( Files Created from 2016-09-02 to 2016-10-02 )))))))))))))))))))))))))))))))
    .
    .
    2016-10-02 12:46 . 2016-10-02 12:46 -------- d-----w- c:\users\Default\AppData\Local\temp
    2016-09-30 16:06 . 2016-10-01 12:03 -------- d-----w- C:\AdwCleaner
    2016-09-30 12:38 . 2016-09-30 16:04 192216 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
    2016-09-30 12:38 . 2016-09-30 12:38 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
    2016-09-30 12:38 . 2016-09-30 12:38 -------- d-----w- c:\programdata\Malwarebytes
    2016-09-30 12:38 . 2016-03-10 18:09 64896 ----a-w- c:\windows\system32\drivers\mwac.sys
    2016-09-30 12:38 . 2016-03-10 18:08 140672 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
    2016-09-30 12:38 . 2016-03-10 18:08 27008 ----a-w- c:\windows\system32\drivers\mbam.sys
    2016-09-30 12:08 . 2016-09-30 12:08 28272 ----a-w- c:\windows\system32\drivers\TrueSight.sys
    2016-09-30 12:07 . 2016-09-30 12:07 -------- d-----w- c:\program files\RogueKiller
    2016-09-30 12:03 . 2016-09-30 12:03 -------- d-----w- c:\programdata\RogueKiller
    2016-09-30 12:03 . 2016-09-30 12:03 -------- d-----w- c:\users\steve\AppData\Local\Programs
    2016-09-29 22:42 . 2016-09-29 22:43 -------- d-----w- C:\FRST
    2016-09-27 15:42 . 2016-09-27 17:36 -------- d-----w- c:\program files (x86)\Citrix
    2016-09-27 15:41 . 2016-09-30 12:07 -------- d-----w- c:\users\steve\AppData\Local\Citrix
    2016-09-27 15:39 . 2016-09-27 15:39 -------- d-----w- c:\users\steve\AppData\Local\LogMeIn Rescue Applet
    2016-09-20 17:45 . 2016-08-05 15:30 2048 ----a-w- c:\windows\system32\tzres.dll
    2016-09-20 17:45 . 2016-08-05 15:13 2048 ----a-w- c:\windows\SysWow64\tzres.dll
    2016-09-19 21:08 . 2016-08-06 15:31 877056 ----a-w- c:\windows\system32\oleaut32.dll
    2016-09-19 21:07 . 2016-09-02 15:31 28672 ----a-w- c:\windows\system32\sspisrv.dll
    .
    .
    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2016-10-01 12:05 . 2015-11-16 21:42 17920 ----a-w- c:\windows\SysWow64\rpcnetp.dll
    2016-10-01 12:05 . 2015-11-16 21:42 17920 ----a-w- c:\windows\SysWow64\rpcnetp.exe
    2016-10-01 12:05 . 2015-11-16 21:42 17920 ----a-w- c:\windows\system32\rpcnetp.exe
    2016-09-20 16:52 . 2015-11-13 18:08 144199024 -c--a-w- c:\windows\system32\MRT.exe
    2016-09-02 15:16 . 2016-09-19 21:08 44032 ----a-w- c:\windows\apppatch\acwow64.dll
    2016-07-20 22:53 . 2016-01-07 19:25 101600 ----a-w- c:\windows\system32\drivers\TMUMH.sys
    2016-07-15 19:54 . 2011-03-29 01:36 24800 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
    .
    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4
    .
    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2015-11-11 39408]
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
    "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-02-14 630912]
    "NortonOnlineBackupReminder"="c:\program files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe" [2011-06-22 3218864]
    "ToshibaServiceStation"="c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" [2011-07-12 1298816]
    "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2013-09-14 59720]
    "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2015-08-06 421888]
    "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2016-05-20 595992]
    .
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "ConsentPromptBehaviorAdmin"= 5 (0x5)
    "ConsentPromptBehaviorUser"= 3 (0x3)
    "EnableUIADesktopToggle"= 0 (0x0)
    .
    R2 Amsp;Trend Micro Solution Platform;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe;c:\program files\Trend Micro\AMSP\coreServiceShell.exe coreFrameworkHost.exe [x]
    R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
    R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
    R3 kbfilter;kbfilter;c:\windows\system32\DRIVERS\kbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\kbfilter.sys [x]
    R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
    R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
    R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x]
    R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
    S0 amdkmpfd;AMD PCI Root Bus Lower Filter;c:\windows\system32\DRIVERS\amdkmpfd.sys;c:\windows\SYSNATIVE\DRIVERS\amdkmpfd.sys [x]
    S0 TMEBC;TMEBC;c:\windows\system32\DRIVERS\TMEBC64.sys;c:\windows\SYSNATIVE\DRIVERS\TMEBC64.sys [x]
    S1 tmevtmgr;tmevtmgr;c:\windows\system32\DRIVERS\tmevtmgr.sys;c:\windows\SYSNATIVE\DRIVERS\tmevtmgr.sys [x]
    S1 tmumh;tmumh;c:\windows\system32\DRIVERS\TMUMH.sys;c:\windows\SYSNATIVE\DRIVERS\TMUMH.sys [x]
    S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
    S2 DiagTrack;Diagnostics Tracking Service;c:\windows\System32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x]
    S2 GFNEXSrv;GFNEX Service;c:\windows\System32\GFNEXSrv.exe;c:\windows\SYSNATIVE\GFNEXSrv.exe [x]
    S2 Norton PC Checkup Application Launcher;Toshiba Laptop Checkup Application Launcher;c:\program files (x86)\Norton PC Checkup\Engine\2.0.17.38\SymcPCCULaunchSvc.exe;c:\program files (x86)\Norton PC Checkup\Engine\2.0.17.38\SymcPCCULaunchSvc.exe [x]
    S2 PCCUJobMgr;Common Client Job Manager Service;c:\program files (x86)\Norton PC Checkup\Engine\2.0.17.38\ccSvcHst.exe;c:\program files (x86)\Norton PC Checkup\Engine\2.0.17.38\ccSvcHst.exe [x]
    S2 Platinum Host Service;Platinum Host Service;c:\program files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe;c:\program files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe [x]
    S2 PwmSvc;Trend Micro Password Manager Central Control Service;c:\program files\Trend Micro\TMIDS\PwmSvc.exe;c:\program files\Trend Micro\TMIDS\PwmSvc.exe [x]
    S2 tmusa;Trend Micro Osprey Driver;c:\windows\system32\DRIVERS\tmusa.sys;c:\windows\SYSNATIVE\DRIVERS\tmusa.sys [x]
    S2 TOSHIBA eco Utility Service;TOSHIBA eco Utility Service;c:\program files\TOSHIBA\TECO\TecoService.exe;c:\program files\TOSHIBA\TECO\TecoService.exe [x]
    S2 TVALZFL;TOSHIBA ACPI-Based Value Added Logical and General Purpose Device Filter Driver;c:\windows\system32\DRIVERS\TVALZFL.sys;c:\windows\SYSNATIVE\DRIVERS\TVALZFL.sys [x]
    S3 amdhub30;AMD USB 3.0 Hub Driver;c:\windows\system32\DRIVERS\amdhub30.sys;c:\windows\SYSNATIVE\DRIVERS\amdhub30.sys [x]
    S3 amdxhc;AMD USB 3.0 Host Controller Driver;c:\windows\system32\DRIVERS\amdxhc.sys;c:\windows\SYSNATIVE\DRIVERS\amdxhc.sys [x]
    S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
    S3 PGEffect;Pangu effect driver;c:\windows\system32\DRIVERS\pgeffect.sys;c:\windows\SYSNATIVE\DRIVERS\pgeffect.sys [x]
    S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys;c:\windows\SYSNATIVE\Drivers\RtsUStor.sys [x]
    S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
    S3 RTL8192Ce;Realtek Wireless LAN 802.11n PCI-E NIC Driver;c:\windows\system32\DRIVERS\rtl8192Ce.sys;c:\windows\SYSNATIVE\DRIVERS\rtl8192Ce.sys [x]
    S3 TMachInfo;TMachInfo;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe;c:\program files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [x]
    S3 tmeevw;tmeevw;c:\windows\system32\DRIVERS\tmeevw.sys;c:\windows\SYSNATIVE\DRIVERS\tmeevw.sys [x]
    S3 tmnciesc;tmnciesc;c:\windows\system32\DRIVERS\tmnciesc.sys;c:\windows\SYSNATIVE\DRIVERS\tmnciesc.sys [x]
    S3 TOSHIBA HDD SSD Alert Service;TOSHIBA HDD SSD Alert Service;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe;c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [x]
    S3 TPCHSrv;TPCH Service;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe;c:\program files\TOSHIBA\TPHM\TPCHSrv.exe [x]
    S3 usbfilter;AMD USB Filter Driver;c:\windows\system32\DRIVERS\usbfilter.sys;c:\windows\SYSNATIVE\DRIVERS\usbfilter.sys [x]
    .
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]
    LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr QWAVE wcncsvc
    .
    [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
    2016-09-19 15:50 1267528 ----a-w- c:\program files (x86)\Google\Chrome\Application\53.0.2785.116\Installer\chrmstp.exe
    .
    Contents of the 'Scheduled Tasks' folder
    .
    2016-06-05 c:\windows\Tasks\Adobe Flash Player Updater.job
    - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-18 20:00]
    .
    2016-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-11-11 23:04]
    .
    2016-10-01 c:\windows\Tasks\GoogleUpdateTaskMachineCore1d1e9aec519f9f2.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-11-11 23:04]
    .
    2016-08-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-11-11 23:04]
    .
    2016-10-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA1d1e9aec697d400.job
    - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2015-11-11 23:04]
    .
    .
    --------- X64 Entries -----------
    .
    .
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2012-02-22 12452456]
    "SRS Premium Sound HD"="c:\program files\SRS Labs\SRS Control Panel\SRSPanel_64.exe" [2012-03-22 2165120]
    "TosSENotify"="c:\program files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe" [2012-02-24 710560]
    "TosVolRegulator"="c:\program files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe" [2009-11-11 24376]
    "PwmConsole.exe"="c:\program files\Trend Micro\TMIDS\PwmConsole.exe" [2015-06-29 2047216]
    "Trend Micro Client Framework"="c:\program files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe" [2015-07-16 246264]
    "Platinum"="c:\program files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe" [2015-07-16 1258496]
    .
    ------- Supplementary Scan -------
    .
    uLocal Page = c:\windows\system32\blank.htm
    uStart Page = hxxp://www.google.com/
    mLocal Page = c:\windows\SysWOW64\blank.htm
    Trusted Zone: amazon.com
    TCP: DhcpNameServer = 75.75.75.75 75.75.76.76
    Handler: tmop - {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - c:\program files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg32.dll
    .
    - - - - ORPHANS REMOVED - - - -
    .
    Toolbar-Locked - (no file)
    Wow6432Node-HKLM-Run-TSleepSrv - %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
    HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
    Toolbar-Locked - (no file)
    HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
    HKLM-Run-TPwrMain - c:\program files (x86)\TOSHIBA\Power Saver\TPwrMain.EXE
    HKLM-Run-TCrdMain - c:\program files (x86)\TOSHIBA\FlashCards\TCrdMain.exe
    HKLM-Run-Teco - c:\program files (x86)\TOSHIBA\TECO\Teco.exe
    HKLM-Run-TosWaitSrv - c:\program files (x86)\TOSHIBA\TPHM\TosWaitSrv.exe
    HKLM-Run-TosNC - c:\program files (x86)\Toshiba\BulletinBoard\TosNcCore.exe
    HKLM-Run-TosReelTimeMonitor - c:\program files (x86)\TOSHIBA\ReelTime\TosReelTimeMonitor.exe
    .
    .
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\services\PCCUJobMgr]
    "ImagePath"="\"c:\program files (x86)\Norton PC Checkup\Engine\2.0.17.38\ccSvcHst.exe\" /s \"PCCUJobMgr\" /m \"c:\program files (x86)\Norton PC Checkup\Engine\2.0.17.38\diMaster.dll\" /prefetch:1"
    .
    --------------------- LOCKED REGISTRY KEYS ---------------------
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_22_0_0_192_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
    @="c:\\windows\\system32\\Macromed\\Flash\\FlashUtil64_22_0_0_192_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker6"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}]
    @Denied: (A 2) (Everyone)
    @="FlashBroker"
    "LocalizedString"="@c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_22_0_0_192_ActiveX.exe,-101"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation]
    "Enabled"=dword:00000001
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_22_0_0_192_ActiveX.exe"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Shockwave Flash Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_22_0_0_192.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
    @="0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
    @="ShockwaveFlash.ShockwaveFlash.22"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_22_0_0_192.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="ShockwaveFlash.ShockwaveFlash"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
    @Denied: (A 2) (Everyone)
    @="Macromedia Flash Factory Object"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_22_0_0_192.ocx"
    "ThreadingModel"="Apartment"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
    @="FlashFactory.FlashFactory.1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
    @="c:\\windows\\SysWOW64\\Macromed\\Flash\\Flash32_22_0_0_192.ocx, 1"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
    @="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
    @="1.0"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
    @="FlashFactory.FlashFactory"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}]
    @Denied: (A 2) (Everyone)
    @="IFlashBroker6"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32]
    @="{00020424-0000-0000-C000-000000000046}"
    .
    [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib]
    @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
    "Version"="1.0"
    .
    [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]
    @Denied: (Full) (Everyone)
    .
    Completion time: 2016-10-02 09:01:29
    ComboFix-quarantined-files.txt 2016-10-02 13:01
    .
    Pre-Run: 549,348,823,040 bytes free
    Post-Run: 549,917,732,864 bytes free
    .
    - - End Of File - - 040C38D3FCC8A0366781BA8884373810
    5B5E648D12FCADC244C1EC30318E1EB9

  11. #11
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Re-run Farbar Recovery Scan Tool (FRST/FRST64) you ran at the very beginning of this topic.


    • Double click to run it.
    • Make sure you checkmark Addition.txt box.
    • Press Scan button.
    • Scan will create two logs, FRST.txt and Addition.txt in the same directory the tool is run. Please copy and paste them to your reply.

  12. #12
    Join Date
    Dec 2000
    Posts
    15
    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 28-09-2016
    Ran by steve (administrator) on STEVE-PC (02-10-2016 22:47:17)
    Running from C:\Users\steve\Desktop
    Loaded Profiles: steve (Available Profiles: steve)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (AMD) C:\windows\System32\atiesrxx.exe
    () C:\windows\System32\GFNEXSrv.exe
    (AMD) C:\windows\System32\atieclxx.exe
    (Trend Micro Inc.) C:\Program Files\Trend Micro\UniClient\UiFrmwrk\uiWatchDog.exe
    (Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\ccSvcHst.exe
    (Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe
    (Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtWatchDog.exe
    (Trend Micro Inc.) C:\Program Files\Trend Micro\TMIDS\PwmSvc.exe
    (TOSHIBA Corporation) C:\windows\System32\TODDSrv.exe
    (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    (TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoService.exe
    (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
    (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
    (SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TPwrMain.exe
    (TOSHIBA Corporation) C:\Program Files\Toshiba\FlashCards\TCrdMain.exe
    (TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\Teco.exe
    (TOSHIBA Corporation) C:\Program Files\Toshiba\ReelTime\TosReelTimeMonitor.exe
    (Trend Micro Inc.) C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe
    (TOSHIBA Corporation) C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe
    (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
    (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
    (Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\ccSvcHst.exe
    (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    (Microsoft Corporation) C:\windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
    (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSENotify.exe
    (TOSHIBA Corporation) C:\Program Files (x86)\Toshiba\TOSHIBA Service Station\TMachInfo.exe
    (TOSHIBA Corporation) C:\Program Files\Toshiba\TPHM\TPCHWMsg.exe
    (Microsoft Corporation) C:\windows\System32\dllhost.exe
    (Symantec Corporation) C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\SymcPCCULaunchSvc.exe
    (TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoHook.exe


    ==================== Registry (Whitelisted) ====================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12452456 2012-02-22] (Realtek Semiconductor)
    HKLM\...\Run: [SRS Premium Sound HD] => C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe [2165120 2012-03-22] (SRS Labs, Inc.)
    HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2866960 2011-12-19] (Synaptics Incorporated)
    HKLM\...\Run: [TPwrMain] => C:\Program Files\TOSHIBA\Power Saver\TPwrMain.EXE [590256 2011-09-23] (TOSHIBA Corporation)
    HKLM\...\Run: [TCrdMain] => C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe [989056 2012-02-13] (TOSHIBA Corporation)
    HKLM\...\Run: [Teco] => C:\Program Files\TOSHIBA\TECO\Teco.exe [1562032 2012-02-09] (TOSHIBA Corporation)
    HKLM\...\Run: [TosWaitSrv] => C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe [712096 2011-12-14] (TOSHIBA Corporation)
    HKLM\...\Run: [TosSENotify] => C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe [710560 2012-02-24] (TOSHIBA Corporation)
    HKLM\...\Run: [TosVolRegulator] => C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe [24376 2009-11-11] (TOSHIBA Corporation)
    HKLM\...\Run: [TosNC] => C:\Program Files\Toshiba\BulletinBoard\TosNcCore.exe [597936 2011-07-27] (TOSHIBA Corporation)
    HKLM\...\Run: [TosReelTimeMonitor] => C:\Program Files\TOSHIBA\ReelTime\TosReelTimeMonitor.exe [38824 2011-06-28] (TOSHIBA Corporation)
    HKLM\...\Run: [PwmConsole.exe] => C:\Program Files\Trend Micro\TMIDS\PwmConsole.exe [2047216 2015-06-29] (Trend Micro Inc.)
    HKLM\...\Run: [Trend Micro Client Framework] => C:\Program Files\Trend Micro\UniClient\UiFrmWrk\UIWatchDog.exe [246264 2015-07-16] (Trend Micro Inc.)
    HKLM\...\Run: [Platinum] => C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSessionAgent.exe [1258496 2015-07-16] (Trend Micro Inc.)
    HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [630912 2012-02-13] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [NortonOnlineBackupReminder] => C:\Program Files (x86)\Toshiba\Toshiba Online Backup\Activation\TOBuActivation.exe [3218864 2011-06-22] (Toshiba)
    HKLM-x32\...\Run: [ToshibaServiceStation] => C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1298816 2011-07-11] (TOSHIBA Corporation)
    HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
    HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2015-08-06] (Apple Inc.)
    HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [595992 2016-05-20] (Oracle Corporation)
    HKU\S-1-5-21-1354267143-4115596969-162612004-1000\...\Run: [swg] => C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2015-11-11] (Google Inc.)
    GroupPolicy: Restriction - Chrome <======= ATTENTION

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 75.75.75.75 75.75.76.76
    Tcpip\..\Interfaces\{8E7E69E6-2CAD-4767-8279-2BE14C938492}: [DhcpNameServer] 75.75.75.75 75.75.76.76

    Internet Explorer:
    ==================
    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\S-1-5-21-1354267143-4115596969-162612004-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Restriction <======= ATTENTION
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome
    HKU\S-1-5-21-1354267143-4115596969-162612004-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
    SearchScopes: HKLM -> {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO
    SearchScopes: HKLM-x32 -> {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO
    SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    SearchScopes: HKU\S-1-5-21-1354267143-4115596969-162612004-1000 -> {FFB5671D-7B31-484F-9215-BFD08D6A4115} URL = hxxp://www.google.com/search?sourceid=ie9&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO_enUS666
    SearchScopes: HKU\S-1-5-21-1354267143-4115596969-162612004-1000 -> {{67A2568C-7A0A-4EED-AECC-B5405DE63B64}} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNO
    BHO: Trend Micro Password Manager BHO -> {3F019D1C-7EAA-4F25-A765-FBA635BD0AFF} -> C:\Program Files\Trend Micro\TMIDS\PwmIEBHO64.dll [2015-06-29] (Trend Micro Inc.)
    BHO: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    BHO: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
    BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-29] (Microsoft Corp.)
    BHO: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg.dll [2015-07-16] (Trend Micro Inc.)
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-01] (Google Inc.)
    BHO: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\TmBpIe64.dll [2016-06-15] (Trend Micro Inc.)
    BHO: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\x64\TOSHIBAMediaControllerIE.dll [2012-08-24] (TOSHIBA Corporation)
    BHO-x32: Trend Micro Password Manager BHO -> {3F019D1C-7EAA-4F25-A765-FBA635BD0AFF} -> C:\Program Files\Trend Micro\TMIDS\PwmIEBHO32.dll [2015-06-29] (Trend Micro Inc.)
    BHO-x32: Trend Micro Security Toolbar Helper -> {43C6D902-A1C5-45c9-91F6-FD9E90337E18} -> C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    BHO-x32: SteadyVideoBHO Class -> {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} -> C:\Program Files (x86)\amd\SteadyVideo\SteadyVideo.dll [2011-06-08] (Advanced Micro Devices)
    BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\ssv.dll [2016-05-26] (Oracle Corporation)
    BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2011-03-28] (Microsoft Corp.)
    BHO-x32: Trend Micro Network Filter Plugin -> {959A5673-7971-48e6-AF54-58F745AC4ABC} -> C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg32.dll [2015-07-16] (Trend Micro Inc.)
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-01] (Google Inc.)
    BHO-x32: Trend Micro IE Protection -> {BBACBAFD-FA5E-4079-8B33-00EB9F13D4AC} -> C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\TmBpIe32.dll [2016-06-15] (Trend Micro Inc.)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\jp2ssv.dll [2016-05-26] (Oracle Corporation)
    BHO-x32: TOSHIBA Media Controller Plug-in -> {F3C88694-EFFA-4d78-B409-54B7B2535B14} -> C:\Program Files (x86)\TOSHIBA\TOSHIBA Media Controller Plug-in\TOSHIBAMediaControllerIE.dll [2012-08-24] (TOSHIBA Corporation)
    Toolbar: HKLM - Trend Micro Password Manager ToolBar - {9B4B91FC-EC4D-4018-9575-96FA5A3C03C5} - C:\Program Files\Trend Micro\TMIDS\PwmIEBHO64.dll [2015-06-29] (Trend Micro Inc.)
    Toolbar: HKLM - Trend Micro Security Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-01] (Google Inc.)
    Toolbar: HKLM-x32 - Trend Micro Password Manager ToolBar - {9B4B91FC-EC4D-4018-9575-96FA5A3C03C5} - C:\Program Files\Trend Micro\TMIDS\PwmIEBHO32.dll [2015-06-29] (Trend Micro Inc.)
    Toolbar: HKLM-x32 - Trend Micro Security Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2016-05-01] (Google Inc.)
    Toolbar: HKU\S-1-5-21-1354267143-4115596969-162612004-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
    Toolbar: HKU\S-1-5-21-1354267143-4115596969-162612004-1000 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2016-05-01] (Google Inc.)
    Handler: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\TmBpIe64.dll [2016-06-15] (Trend Micro Inc.)
    Handler-x32: tmbp - {1A77E7DC-C9A0-4110-8A37-2F36BAE71ECF} - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\TmBpIe32.dll [2016-06-15] (Trend Micro Inc.)
    Handler: tmop - {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg.dll [2015-07-16] (Trend Micro Inc.)
    Handler-x32: tmop - {69FD7CE3-4604-4fe6-967C-49B9735CEE70} - C:\Program Files\Trend Micro\AMSP\module\20013\3.8.1222\2.0.1084\TmopIEPlg32.dll [2015-07-16] (Trend Micro Inc.)
    Handler: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    Handler-x32: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\Titanium\UIFramework\ToolbarIE.dll [2015-12-21] (Trend Micro Inc.)
    Handler: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\plugin\ToolbarIE64\ProToolbarIMRatingActiveX.dll [2015-07-16] (Trend Micro Inc.)
    Handler-x32: tmtbim - {0B37915C-8B98-4B9E-80D4-464D2C830D10} - C:\Program Files\Trend Micro\Titanium\UIFramework\ProToolbarIMRatingActiveX.dll [2015-07-16] (Trend Micro Inc.)
    Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
    Filter-x32: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
    Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)
    Filter-x32: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\amd\SteadyVideo\VideoMIMEFilter.dll [2011-06-08] (Advanced Micro Devices)

    FireFox:
    ========
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @java.com/DTPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\dtplugin\npDeployJava1.dll [2016-05-26] (Oracle Corporation)
    FF Plugin-x32: @java.com/JavaPlugin,version=11.91.2 -> C:\Program Files (x86)\Java\jre1.8.0_91\bin\plugin2\npjp2.dll [2016-05-26] (Oracle Corporation)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.31.5\npGoogleUpdate3.dll [2016-07-29] (Google Inc.)
    FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll [2015-09-24] (Adobe Systems Inc.)
    FF Plugin HKU\S-1-5-21-1354267143-4115596969-162612004-1000: @citrixonline.com/appdetectorplugin -> C:\Users\steve\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2016-09-27] (Citrix Online)
    FF HKLM\...\Firefox\Extensions: [tmbepff@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\firefoxextension
    FF Extension: (Trend Micro BEP Firefox Extension) - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\firefoxextension [2016-09-01]
    FF HKLM-x32\...\Firefox\Extensions: [tmbepff@trendmicro.com] - C:\Program Files\Trend Micro\AMSP\module\20002\9.1.1089\9.1.1089\firefoxextension
    FF HKLM-x32\...\Firefox\Extensions: [{22181a4d-af90-4ca3-a569-faed9118d6bc}] - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension
    FF Extension: (Trend Micro Toolbar) - C:\Program Files\Trend Micro\Titanium\UIFramework\Toolbar\firefoxextension [2016-03-08]
    FF HKLM-x32\...\Firefox\Extensions: [{BBB77B49-9FF4-4d5c-8FE2-92B1D6CD696C}] - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension
    FF Extension: (Trend Micro Osprey Firefox Extension) - C:\Program Files\Trend Micro\AMSP\module\20013\FxExt\firefoxextension [2016-09-01]

    Chrome:
    =======
    CHR Profile: C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default [2016-09-30]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2016-06-08]
    CHR Extension: (Trend Micro Toolbar) - C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohhcpmplhhiiaoiddkfboafbhiknefdf [2016-09-27]
    CHR Extension: (Trend Micro Password Manager) - C:\Users\steve\AppData\Local\Google\Chrome\User Data\Default\Extensions\olmajmomenlhgihenlbjcfbopoghpckg [2016-06-08]
    CHR HKLM\...\Chrome\Extension: [olmajmomenlhgihenlbjcfbopoghpckg] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [ohhcpmplhhiiaoiddkfboafbhiknefdf] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [olmajmomenlhgihenlbjcfbopoghpckg] - hxxps://clients2.google.com/service/update2/crx

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 GFNEXSrv; C:\Windows\System32\GFNEXSrv.exe [162824 2010-09-09] ()
    R2 Norton PC Checkup Application Launcher; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\SymcPCCULaunchSvc.exe [123320 2015-11-19] (Symantec Corporation)
    R2 PCCUJobMgr; C:\Program Files (x86)\Norton PC Checkup\Engine\2.0.17.38\ccSvcHst.exe [126392 2011-11-30] (Symantec Corporation)
    R2 Platinum Host Service; C:\Program Files\Trend Micro\Titanium\plugin\Pt\PtSvcHost.exe [1137664 2015-07-16] (Trend Micro Inc.)
    R2 PwmSvc; C:\Program Files\Trend Micro\TMIDS\PwmSvc.exe [333856 2015-06-29] (Trend Micro Inc.)
    R2 TosCoSrv; C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe [580608 2012-02-02] (TOSHIBA Corporation) [File not signed]
    S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)
    S2 Amsp; "C:\Program Files\Trend Micro\AMSP\coreServiceShell.exe" coreFrameworkHost.exe -m=rb -dt=60000 -ad -bt=0 [X]

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [31872 2012-02-01] (Advanced Micro Devices, Inc.)
    U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation)
    S3 ebdrv; C:\Windows\system32\drivers\evbda.sys [3286016 2009-06-10] (Broadcom Corporation)
    R1 tmactmon; C:\Windows\System32\DRIVERS\tmactmon.sys [133424 2015-11-23] (Trend Micro Inc.)
    R0 tmcomm; C:\Windows\System32\DRIVERS\tmcomm.sys [324912 2015-11-23] (Trend Micro Inc.)
    R0 TMEBC; C:\Windows\System32\DRIVERS\TMEBC64.sys [59712 2015-06-11] (Trend Micro Inc.)
    R3 tmeevw; C:\Windows\System32\DRIVERS\tmeevw.sys [116576 2015-06-08] (Trend Micro Inc.)
    R1 tmevtmgr; C:\Windows\System32\DRIVERS\tmevtmgr.sys [99632 2015-11-23] (Trend Micro Inc.)
    R3 tmnciesc; C:\Windows\System32\DRIVERS\tmnciesc.sys [561952 2016-06-24] (Trend Micro Inc.)
    R1 tmumh; C:\Windows\System32\DRIVERS\TMUMH.sys [101600 2016-07-20] (Trend Micro Inc.)
    R2 tmusa; C:\Windows\System32\DRIVERS\tmusa.sys [124752 2015-12-09] (Trend Micro Inc.)
    U3 TrueSight; C:\windows\System32\drivers\TrueSight.sys [28272 2016-09-30] ()
    U3 catchme; \??\C:\ComboFix\catchme.sys [X]
    S3 kbfilter; system32\DRIVERS\kbfilter.sys [X]

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

  13. #13
    Join Date
    Dec 2000
    Posts
    15
    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-10-02 09:01 - 2016-10-02 09:01 - 00018177 _____ C:\ComboFix.txt
    2016-10-02 08:35 - 2011-06-26 02:45 - 00256000 _____ C:\windows\PEV.exe
    2016-10-02 08:35 - 2010-11-07 13:20 - 00208896 _____ C:\windows\MBR.exe
    2016-10-02 08:35 - 2009-04-20 00:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
    2016-10-02 08:35 - 2000-08-30 20:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
    2016-10-02 08:35 - 2000-08-30 20:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
    2016-10-02 08:35 - 2000-08-30 20:00 - 00098816 _____ C:\windows\sed.exe
    2016-10-02 08:35 - 2000-08-30 20:00 - 00080412 _____ C:\windows\grep.exe
    2016-10-02 08:35 - 2000-08-30 20:00 - 00068096 _____ C:\windows\zip.exe
    2016-10-02 08:34 - 2016-10-02 09:02 - 00000000 ____D C:\Qoobox
    2016-10-02 08:34 - 2016-10-02 08:57 - 00000000 ____D C:\windows\erdnt
    2016-10-02 08:34 - 2016-10-02 08:26 - 05659993 ____R (Swearware) C:\Users\steve\Desktop\ComboFix.exe
    2016-09-30 23:35 - 2016-09-30 23:28 - 03861056 _____ C:\Users\steve\Desktop\AdwCleaner current.exe
    2016-09-30 12:17 - 2016-09-30 12:17 - 00004769 _____ C:\Users\steve\Desktop\JRT.txt
    2016-09-30 12:06 - 2016-10-01 08:03 - 00000000 ____D C:\AdwCleaner
    2016-09-30 08:38 - 2016-09-30 12:04 - 00192216 _____ (Malwarebytes) C:\windows\system32\Drivers\MBAMSwissArmy.sys
    2016-09-30 08:38 - 2016-09-30 08:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes Anti-Malware
    2016-09-30 08:38 - 2016-09-30 08:38 - 00000000 ____D C:\ProgramData\Malwarebytes
    2016-09-30 08:38 - 2016-09-30 08:38 - 00000000 ____D C:\Program Files (x86)\Malwarebytes Anti-Malware
    2016-09-30 08:38 - 2016-03-10 14:09 - 00064896 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
    2016-09-30 08:38 - 2016-03-10 14:08 - 00140672 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamchameleon.sys
    2016-09-30 08:38 - 2016-03-10 14:08 - 00027008 _____ (Malwarebytes) C:\windows\system32\Drivers\mbam.sys
    2016-09-30 08:37 - 2016-09-29 19:01 - 22851472 _____ (Malwarebytes ) C:\Users\steve\Desktop\mbam-setup-2.2.1.1043.exe
    2016-09-30 08:08 - 2016-09-30 08:08 - 00028272 _____ C:\windows\system32\Drivers\TrueSight.sys
    2016-09-30 08:07 - 2016-09-30 08:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
    2016-09-30 08:07 - 2016-09-30 08:07 - 00000000 ____D C:\Program Files\RogueKiller
    2016-09-30 08:03 - 2016-09-30 08:03 - 00000000 ____D C:\ProgramData\RogueKiller
    2016-09-30 08:03 - 2016-09-29 19:02 - 33579072 _____ (Adlice Software ) C:\Users\steve\Desktop\1RogueKiller current.exe
    2016-09-29 18:43 - 2016-09-29 18:43 - 00026926 _____ C:\Users\steve\Desktop\Addition.txt
    2016-09-29 18:42 - 2016-10-02 22:47 - 00021761 _____ C:\Users\steve\Desktop\FRST.txt
    2016-09-29 18:42 - 2016-10-02 22:47 - 00000000 ____D C:\FRST
    2016-09-29 18:41 - 2016-09-29 18:34 - 02404352 _____ (Farbar) C:\Users\steve\Desktop\FRST64.exe
    2016-09-27 12:55 - 2016-09-27 12:55 - 00012735 _____ C:\Users\steve\Desktop\Technical Support.pdf
    2016-09-27 12:54 - 2016-09-27 12:54 - 00123999 _____ C:\Users\steve\Desktop\Drl.jpeg
    2016-09-27 12:52 - 2016-09-27 12:54 - 00000000 ___RD C:\Users\steve\Documents\Scanned Documents
    2016-09-27 12:52 - 2016-09-27 12:52 - 00000000 ____D C:\Users\steve\Documents\Fax
    2016-09-27 11:42 - 2016-09-27 13:36 - 00000000 ____D C:\Program Files (x86)\Citrix
    2016-09-27 11:41 - 2016-09-30 08:07 - 00000000 ____D C:\Users\steve\AppData\Local\Citrix
    2016-09-27 11:39 - 2016-09-27 11:39 - 00000000 ____D C:\Users\steve\AppData\Local\LogMeIn Rescue Applet
    2016-09-22 17:21 - 2016-09-22 17:21 - 01051248 _____ C:\windows\Minidump\092216-25911-01.dmp
    2016-09-20 13:45 - 2016-08-05 11:30 - 00002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
    2016-09-20 13:45 - 2016-08-05 11:13 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
    2016-09-19 17:09 - 2016-09-01 15:26 - 00394440 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
    2016-09-19 17:09 - 2016-09-01 14:41 - 00346320 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
    2016-09-19 17:09 - 2016-08-31 23:18 - 02724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
    2016-09-19 17:09 - 2016-08-31 23:08 - 20312064 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
    2016-09-19 17:09 - 2016-08-31 22:48 - 00062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
    2016-09-19 17:09 - 2016-08-31 22:46 - 00498688 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
    2016-09-19 17:09 - 2016-08-31 22:46 - 00341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
    2016-09-19 17:09 - 2016-08-31 22:46 - 00047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
    2016-09-19 17:09 - 2016-08-31 22:44 - 00064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
    2016-09-19 17:09 - 2016-08-31 22:34 - 02286592 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
    2016-09-19 17:09 - 2016-08-31 22:31 - 00047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
    2016-09-19 17:09 - 2016-08-31 22:31 - 00030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
    2016-09-19 17:09 - 2016-08-31 22:26 - 00476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
    2016-09-19 17:09 - 2016-08-31 22:24 - 00663552 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
    2016-09-19 17:09 - 2016-08-31 22:24 - 00115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
    2016-09-19 17:09 - 2016-08-31 22:23 - 00620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
    2016-09-19 17:09 - 2016-08-31 22:08 - 00416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
    2016-09-19 17:09 - 2016-08-31 21:59 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
    2016-09-19 17:09 - 2016-08-31 21:57 - 00091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
    2016-09-19 17:09 - 2016-08-31 21:53 - 00168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
    2016-09-19 17:09 - 2016-08-31 21:52 - 00076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
    2016-09-19 17:09 - 2016-08-31 21:48 - 00279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
    2016-09-19 17:09 - 2016-08-31 21:45 - 00130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
    2016-09-19 17:09 - 2016-08-31 21:34 - 00230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
    2016-09-19 17:09 - 2016-08-31 21:30 - 00692736 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
    2016-09-19 17:09 - 2016-08-31 21:29 - 02055680 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
    2016-09-19 17:09 - 2016-08-31 21:29 - 01155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
    2016-09-19 17:09 - 2016-08-31 21:27 - 13808128 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
    2016-09-19 17:09 - 2016-08-31 21:24 - 04607488 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
    2016-09-19 17:09 - 2016-08-31 20:45 - 25770496 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
    2016-09-19 17:09 - 2016-08-31 20:43 - 02445824 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
    2016-09-19 17:09 - 2016-08-31 20:42 - 00710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
    2016-09-19 17:09 - 2016-08-31 20:40 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
    2016-09-19 17:09 - 2016-08-31 20:40 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
    2016-09-19 17:09 - 2016-08-31 20:38 - 01316352 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
    2016-09-19 17:09 - 2016-08-31 20:25 - 00066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
    2016-09-19 17:09 - 2016-08-31 20:24 - 02894336 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
    2016-09-19 17:09 - 2016-08-31 20:24 - 00576000 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
    2016-09-19 17:09 - 2016-08-31 20:24 - 00417792 _____ (Microsoft Corporation) C:\windows\system32\html.iec
    2016-09-19 17:09 - 2016-08-31 20:24 - 00088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
    2016-09-19 17:09 - 2016-08-31 20:24 - 00048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
    2016-09-19 17:09 - 2016-08-31 20:16 - 00054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
    2016-09-19 17:09 - 2016-08-31 20:15 - 00034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
    2016-09-19 17:09 - 2016-08-31 20:12 - 00615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
    2016-09-19 17:09 - 2016-08-31 20:11 - 00144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
    2016-09-19 17:09 - 2016-08-31 20:11 - 00114688 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
    2016-09-19 17:09 - 2016-08-31 20:10 - 00817664 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
    2016-09-19 17:09 - 2016-08-31 20:10 - 00814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
    2016-09-19 17:09 - 2016-08-31 20:06 - 06047232 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
    2016-09-19 17:09 - 2016-08-31 20:03 - 00968704 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
    2016-09-19 17:09 - 2016-08-31 19:59 - 00489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
    2016-09-19 17:09 - 2016-08-31 19:51 - 00077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
    2016-09-19 17:09 - 2016-08-31 19:50 - 00107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
    2016-09-19 17:09 - 2016-08-31 19:47 - 00199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
    2016-09-19 17:09 - 2016-08-31 19:46 - 00092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
    2016-09-19 17:09 - 2016-08-31 19:44 - 00315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
    2016-09-19 17:09 - 2016-08-31 19:42 - 00152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
    2016-09-19 17:09 - 2016-08-31 19:31 - 00262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
    2016-09-19 17:09 - 2016-08-31 19:29 - 00724992 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
    2016-09-19 17:09 - 2016-08-31 19:28 - 00806400 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
    2016-09-19 17:09 - 2016-08-31 19:27 - 01359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
    2016-09-19 17:09 - 2016-08-31 19:26 - 02131456 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
    2016-09-19 17:09 - 2016-08-31 19:15 - 15411712 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
    2016-09-19 17:09 - 2016-08-31 19:10 - 02921472 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
    2016-09-19 17:09 - 2016-08-31 18:58 - 01550848 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
    2016-09-19 17:09 - 2016-08-31 18:47 - 00800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
    2016-09-19 17:09 - 2016-08-12 12:26 - 00464896 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv.sys
    2016-09-19 17:09 - 2016-08-12 12:26 - 00405504 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srv2.sys
    2016-09-19 17:09 - 2016-08-12 12:26 - 00168960 _____ (Microsoft Corporation) C:\windows\system32\Drivers\srvnet.sys
    2016-09-19 17:08 - 2016-09-02 11:40 - 00631176 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
    2016-09-19 17:08 - 2016-09-02 11:35 - 05548264 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
    2016-09-19 17:08 - 2016-09-02 11:35 - 00706280 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
    2016-09-19 17:08 - 2016-09-02 11:35 - 00154856 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
    2016-09-19 17:08 - 2016-09-02 11:35 - 00095464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
    2016-09-19 17:08 - 2016-09-02 11:34 - 01732864 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00362496 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00086528 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
    2016-09-19 17:08 - 2016-09-02 11:31 - 00013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 01464320 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 01212928 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 01163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00730624 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00316416 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00006656 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:30 - 00003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:21 - 04000488 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
    2016-09-19 17:08 - 2016-09-02 11:21 - 03944680 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
    2016-09-19 17:08 - 2016-09-02 11:18 - 01314112 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 01114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00553472 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00260608 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00006656 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:16 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 11:02 - 00148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
    2016-09-19 17:08 - 2016-09-02 11:02 - 00062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
    2016-09-19 17:08 - 2016-09-02 11:02 - 00017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe
    2016-09-19 17:08 - 2016-09-02 10:58 - 00338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
    2016-09-19 17:08 - 2016-09-02 10:57 - 00296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
    2016-09-19 17:08 - 2016-09-02 10:55 - 00159744 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
    2016-09-19 17:08 - 2016-09-02 10:54 - 00291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
    2016-09-19 17:08 - 2016-09-02 10:54 - 00129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
    2016-09-19 17:08 - 2016-09-02 10:53 - 00112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
    2016-09-19 17:08 - 2016-09-02 10:49 - 00025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
    2016-09-19 17:08 - 2016-09-02 10:49 - 00014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
    2016-09-19 17:08 - 2016-09-02 10:49 - 00007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
    2016-09-19 17:08 - 2016-09-02 10:49 - 00002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
    2016-09-19 17:08 - 2016-09-02 10:48 - 00006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 10:48 - 00004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 10:48 - 00003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2016-09-19 17:08 - 2016-09-02 10:48 - 00003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2016-09-19 17:08 - 2016-08-06 11:31 - 00877056 _____ (Microsoft Corporation) C:\windows\system32\oleaut32.dll
    2016-09-19 17:08 - 2016-08-06 11:15 - 00581632 _____ (Microsoft Corporation) C:\windows\SysWOW64\oleaut32.dll
    2016-09-19 17:08 - 2016-06-06 12:50 - 01483264 _____ (Microsoft Corporation) C:\windows\system32\crypt32.dll
    2016-09-19 17:08 - 2016-06-06 12:50 - 00228864 _____ (Microsoft Corporation) C:\windows\system32\wintrust.dll
    2016-09-19 17:08 - 2016-06-06 12:50 - 00190976 _____ (Microsoft Corporation) C:\windows\system32\cryptsvc.dll
    2016-09-19 17:08 - 2016-06-06 12:50 - 00141824 _____ (Microsoft Corporation) C:\windows\system32\cryptnet.dll
    2016-09-19 17:08 - 2016-06-06 11:23 - 01176064 _____ (Microsoft Corporation) C:\windows\SysWOW64\crypt32.dll
    2016-09-19 17:08 - 2016-06-06 11:23 - 00179200 _____ (Microsoft Corporation) C:\windows\SysWOW64\wintrust.dll
    2016-09-19 17:08 - 2016-06-06 11:23 - 00145920 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptsvc.dll
    2016-09-19 17:08 - 2016-06-06 11:23 - 00106496 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptnet.dll
    2016-09-19 17:08 - 2016-05-13 18:09 - 03156480 _____ (Microsoft Corporation) C:\windows\system32\wucltux.dll
    2016-09-19 17:08 - 2016-05-13 18:09 - 00192512 _____ (Microsoft Corporation) C:\windows\system32\wuwebv.dll
    2016-09-19 17:08 - 2016-05-13 18:09 - 00098816 _____ (Microsoft Corporation) C:\windows\system32\wudriver.dll
    2016-09-19 17:08 - 2016-05-13 18:07 - 00091136 _____ (Microsoft Corporation) C:\windows\system32\WinSetupUI.dll
    2016-09-19 17:08 - 2016-05-13 17:55 - 02607104 _____ (Microsoft Corporation) C:\windows\system32\wuaueng.dll
    2016-09-19 17:08 - 2016-05-13 17:53 - 00709120 _____ (Microsoft Corporation) C:\windows\system32\wuapi.dll
    2016-09-19 17:08 - 2016-05-13 17:53 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wuapp.exe
    2016-09-19 17:08 - 2016-05-13 17:52 - 00140288 _____ (Microsoft Corporation) C:\windows\system32\wuauclt.exe
    2016-09-19 17:08 - 2016-05-13 17:52 - 00037888 _____ (Microsoft Corporation) C:\windows\system32\wups2.dll
    2016-09-19 17:08 - 2016-05-13 17:52 - 00036864 _____ (Microsoft Corporation) C:\windows\system32\wups.dll
    2016-09-19 17:08 - 2016-05-13 17:52 - 00012288 _____ (Microsoft Corporation) C:\windows\system32\wu.upgrade.ps.dll
    2016-09-19 17:08 - 2016-05-13 17:50 - 00174080 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuwebv.dll
    2016-09-19 17:08 - 2016-05-13 17:38 - 00573440 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapi.dll
    2016-09-19 17:08 - 2016-05-13 17:38 - 00093696 _____ (Microsoft Corporation) C:\windows\SysWOW64\wudriver.dll
    2016-09-19 17:08 - 2016-05-13 17:38 - 00035328 _____ (Microsoft Corporation) C:\windows\SysWOW64\wuapp.exe
    2016-09-19 17:08 - 2016-05-13 17:38 - 00030208 _____ (Microsoft Corporation) C:\windows\SysWOW64\wups.dll
    2016-09-19 17:08 - 2016-05-12 13:14 - 00084992 _____ (Microsoft Corporation) C:\windows\system32\asycfilt.dll
    2016-09-19 17:08 - 2016-05-12 11:18 - 00090624 _____ (Microsoft Corporation) C:\windows\SysWOW64\olepro32.dll
    2016-09-19 17:08 - 2016-05-12 11:18 - 00067584 _____ (Microsoft Corporation) C:\windows\SysWOW64\asycfilt.dll
    2016-09-19 17:08 - 2016-05-04 13:21 - 00114408 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
    2016-09-19 17:08 - 2016-05-04 13:17 - 03244032 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
    2016-09-19 17:08 - 2016-05-04 13:17 - 02365440 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
    2016-09-19 17:08 - 2016-05-04 13:17 - 01806848 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
    2016-09-19 17:08 - 2016-05-04 13:17 - 00504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
    2016-09-19 17:08 - 2016-05-04 13:17 - 00337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
    2016-09-19 17:08 - 2016-05-04 13:16 - 01941504 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
    2016-09-19 17:08 - 2016-05-04 13:16 - 00070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
    2016-09-19 17:08 - 2016-05-04 11:04 - 00128512 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
    2016-09-19 17:08 - 2016-05-04 10:55 - 00073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
    2016-09-19 17:07 - 2016-09-02 11:31 - 00028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
    2016-09-19 17:07 - 2016-09-02 11:30 - 00022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00065536 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
    2016-09-19 17:07 - 2016-09-02 11:16 - 00017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
    2016-09-19 17:07 - 2016-09-02 11:01 - 00064000 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
    2016-09-19 17:07 - 2016-09-02 10:53 - 00050176 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
    2016-09-19 17:07 - 2016-09-02 10:53 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
    2016-09-19 17:07 - 2016-09-02 10:49 - 00036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
    2016-09-19 17:07 - 2016-08-16 13:36 - 01009152 _____ (Microsoft Corporation) C:\windows\system32\user32.dll
    2016-09-19 17:07 - 2016-08-15 22:48 - 00833024 _____ (Microsoft Corporation) C:\windows\SysWOW64\user32.dll
    2016-09-19 17:07 - 2016-08-15 22:35 - 03218432 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
    2016-09-19 17:07 - 2016-07-07 11:36 - 01896168 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
    2016-09-19 17:07 - 2016-07-07 11:36 - 00377576 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
    2016-09-19 17:07 - 2016-07-07 11:36 - 00287976 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
    2016-09-19 17:07 - 2016-07-07 11:08 - 00046080 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpipreg.sys
    2016-09-19 17:07 - 2016-07-01 11:31 - 00976896 _____ (Microsoft Corporation) C:\windows\system32\inetcomm.dll
    2016-09-19 17:07 - 2016-07-01 11:31 - 00084480 _____ (Microsoft Corporation) C:\windows\system32\INETRES.dll
    2016-09-19 17:07 - 2016-07-01 11:13 - 00741888 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcomm.dll
    2016-09-19 17:07 - 2016-07-01 11:13 - 00084480 _____ (Microsoft Corporation) C:\windows\SysWOW64\INETRES.dll
    2016-09-19 17:07 - 2016-05-04 13:17 - 00025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimsg.dll
    2016-09-19 17:07 - 2016-05-04 13:17 - 00025088 _____ (Microsoft Corporation) C:\windows\system32\msimsg.dll

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2016-10-02 22:47 - 2016-07-29 11:35 - 00000898 _____ C:\windows\Tasks\GoogleUpdateTaskMachineUA1d1e9aec697d400.job
    2016-10-02 15:18 - 2016-07-29 11:35 - 00000894 _____ C:\windows\Tasks\GoogleUpdateTaskMachineCore1d1e9aec519f9f2.job
    2016-10-02 08:47 - 2009-07-13 22:34 - 00000215 _____ C:\windows\system.ini
    2016-10-02 08:36 - 2009-07-14 00:45 - 00024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2016-10-02 08:36 - 2009-07-14 00:45 - 00024608 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2016-10-02 08:35 - 2009-07-14 01:13 - 00782470 _____ C:\windows\system32\PerfStringBackup.INI
    2016-10-02 08:35 - 2009-07-13 23:20 - 00000000 ____D C:\windows\inf
    2016-10-02 08:30 - 2016-06-03 16:28 - 00262144 _____ C:\windows\system32\config\ELAM
    2016-10-01 19:43 - 2009-07-14 01:08 - 00000006 ____H C:\windows\Tasks\SA.DAT
    2016-10-01 08:05 - 2015-11-16 17:42 - 00017920 _____ C:\windows\SysWOW64\rpcnetp.exe
    2016-10-01 08:05 - 2015-11-16 17:42 - 00017920 _____ C:\windows\SysWOW64\rpcnetp.dll
    2016-10-01 08:05 - 2015-11-16 17:42 - 00017920 _____ C:\windows\system32\rpcnetp.exe
    2016-09-30 10:02 - 2009-07-13 23:20 - 00000000 ____D C:\windows\ModemLogs
    2016-09-30 08:06 - 2015-11-11 19:15 - 00000000 ____D C:\ProgramData\WildTangent
    2016-09-30 08:06 - 2015-11-11 19:15 - 00000000 ____D C:\Program Files (x86)\TOSHIBA Games
    2016-09-30 08:06 - 2009-07-14 01:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
    2016-09-29 18:41 - 2016-02-20 08:44 - 00295830 _____ C:\windows\ntbtlog.txt
    2016-09-27 11:42 - 2015-11-13 18:46 - 00000010 _____ C:\Users\steve\AppData\Local\sponge.last.runtime.cache
    2016-09-22 17:21 - 2015-11-22 19:15 - 336136806 _____ C:\windows\MEMORY.DMP
    2016-09-22 17:21 - 2015-11-22 19:15 - 00000000 ____D C:\windows\Minidump
    2016-09-21 22:44 - 2015-11-22 18:56 - 00000000 ____D C:\Users\steve\AppData\Local\CrashDumps
    2016-09-20 13:32 - 2009-07-14 00:45 - 00267672 _____ C:\windows\system32\FNTCACHE.DAT
    2016-09-20 13:08 - 2015-11-13 14:08 - 00000000 ____D C:\windows\system32\MRT
    2016-09-20 12:52 - 2015-11-13 14:08 - 144199024 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
    2016-09-19 12:05 - 2015-11-11 18:56 - 00002206 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2016-09-06 16:33 - 2015-11-13 15:22 - 00000000 ____D C:\Users\steve\AppData\Local\ElevatedDiagnostics

    ==================== Files in the root of some directories =======

    2015-11-13 14:50 - 2015-11-13 14:50 - 0000036 _____ () C:\Users\steve\AppData\Local\housecall.guid.cache
    2015-11-13 18:46 - 2016-09-27 11:42 - 0000010 _____ () C:\Users\steve\AppData\Local\sponge.last.runtime.cache

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\windows\system32\winlogon.exe => File is digitally signed
    C:\windows\system32\wininit.exe => File is digitally signed
    C:\windows\SysWOW64\wininit.exe => File is digitally signed
    C:\windows\explorer.exe => File is digitally signed
    C:\windows\SysWOW64\explorer.exe => File is digitally signed
    C:\windows\system32\svchost.exe => File is digitally signed
    C:\windows\SysWOW64\svchost.exe => File is digitally signed
    C:\windows\system32\services.exe => File is digitally signed
    C:\windows\system32\User32.dll => File is digitally signed
    C:\windows\SysWOW64\User32.dll => File is digitally signed
    C:\windows\system32\userinit.exe => File is digitally signed
    C:\windows\SysWOW64\userinit.exe => File is digitally signed
    C:\windows\system32\rpcss.dll => File is digitally signed
    C:\windows\system32\dnsapi.dll => File is digitally signed
    C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2016-05-31 18:37

    ==================== End of FRST.txt ============================

  14. #14
    Join Date
    Dec 2000
    Posts
    15
    Additional scan result of Farbar Recovery Scan Tool (x64) Version: 28-09-2016
    Ran by steve (02-10-2016 22:48:03)
    Running from C:\Users\steve\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) (2015-11-12 01:00:05)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-1354267143-4115596969-162612004-500 - Administrator - Disabled)
    Guest (S-1-5-21-1354267143-4115596969-162612004-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-1354267143-4115596969-162612004-1002 - Limited - Enabled)
    steve (S-1-5-21-1354267143-4115596969-162612004-1000 - Administrator - Enabled) => C:\Users\steve

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Trend Micro Internet Security (Disabled - Up to date) {8242D66F-41BD-4049-C2E6-E578E73B62A0}
    AS: Trend Micro Internet Security (Disabled - Up to date) {3923378B-6787-4FC7-F856-DE0A9CBC281D}
    AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 3.1.0.4880 - Adobe Systems Incorporated)
    Adobe Flash Player 22 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 22.0.0.192 - Adobe Systems Incorporated)
    Adobe Reader X (10.1.16) MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.1.16 - Adobe Systems Incorporated)
    AMD Catalyst Install Manager (HKLM\...\{63F96D8F-D32B-AABF-4DE1-F51FF391FFD6}) (Version: 3.0.870.0 - Advanced Micro Devices, Inc.)
    Apple Application Support (HKLM-x32\...\{46F044A5-CE8B-4196-984E-5BD6525E361D}) (Version: 2.3.6 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
    D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
    FUJIFILM MyFinePix Studio 4.2 (HKLM-x32\...\MyFinePix Studio_is1) (Version: - )
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 53.0.2785.116 - Google Inc.)
    Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.7619.1252 - Google Inc.)
    Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.21.107 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.31.5 - Google Inc.) Hidden
    Java 8 Update 91 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218091F0}) (Version: 8.0.910.15 - Oracle Corporation)
    Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
    Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes)
    Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
    Microsoft .NET Framework 4.6.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.6.01055 - Microsoft Corporation)
    Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
    Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
    Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
    PlayReady PC Runtime amd64 (HKLM\...\{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}) (Version: 1.3.0 - Microsoft Corporation)
    PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
    Premium Sound HD (HKLM\...\{3007FF9F-5B2C-41FF-8BFC-08BF25DB2681}) (Version: 1.12.1800 - SRS Labs, Inc.)
    QuickTime 7 (HKLM-x32\...\{80CEEB1E-0A6C-45B9-A312-37A1D25FDEBC}) (Version: 7.78.80.95 - Apple Inc.)
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.48.823.2011 - Realtek)
    Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6577 - Realtek Semiconductor Corp.)
    Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7601.30130 - Realtek Semiconductor Corp.)
    Realtek WLAN Driver (HKLM-x32\...\{9D3D8C60-A55F-4fed-B2B9-173001290E16}) (Version: 2.00.0016 - REALTEK Semiconductor Corp.)
    RogueKiller version 12 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12 - Adlice Software)
    Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.3.38.2 - Synaptics Incorporated)
    TOSHIBA Application Installer (HKLM-x32\...\{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}) (Version: 9.0.1.2 - TOSHIBA)
    TOSHIBA Assist (HKLM-x32\...\{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}) (Version: 4.2.3.1 - TOSHIBA CORPORATION)
    TOSHIBA Battery Check Utility (HKLM-x32\...\{5468E297-7EF8-4CB3-A091-F8714147793F}) (Version: 1.00.01.01 - Toshiba Corporation)
    Toshiba Book Place (HKLM-x32\...\{C31337DE-0CDC-45A9-9A32-F099AC78D557}) (Version: 3.0.9490 - K-NFB Reading Technology, Inc.)
    TOSHIBA Bulletin Board (HKLM-x32\...\InstallShield_{1C8C049A-145F-4A6E-8290-B5C245EBE39D}) (Version: 1.6.11.64 - TOSHIBA Corporation)
    TOSHIBA Disc Creator (HKLM\...\{5DA0E02F-970B-424B-BF41-513A5018E4C0}) (Version: 2.1.0.11 for x64 - TOSHIBA Corporation)
    TOSHIBA eco Utility (HKLM\...\{C9C56642-9AAB-4267-9454-36FF1CC59168}) (Version: 1.3.11.64 - TOSHIBA Corporation)
    TOSHIBA Face Recognition (HKLM-x32\...\InstallShield_{F67FA545-D8E5-4209-86B1-AEE045D1003F}) (Version: 3.1.18.64 - TOSHIBA Corporation)
    TOSHIBA Hardware Setup (HKLM-x32\...\{2FD5D2C5-A7A1-4065-89BA-90542BF7CCD3}) (Version: 2.00.0020 - TOSHIBA)
    TOSHIBA HDD/SSD Alert (HKLM\...\{D4322448-B6AF-4316-B859-D8A0E84DCB38}) (Version: 3.1.64.12 - TOSHIBA Corporation)
    Toshiba Laptop Checkup (HKLM-x32\...\NortonPCCheckup) (Version: 2.0.17.38 - Symantec Corporation)
    TOSHIBA Media Controller (HKLM-x32\...\{C7A4F26F-F9B0-41B2-8659-99181108CDE3}) (Version: 1.0.87.5 - TOSHIBA CORPORATION)
    TOSHIBA Media Controller Plug-in (HKLM-x32\...\{F26FDF57-483E-42C8-A9C9-EEE1EDB256E0}) (Version: 1.0.8.0 - TOSHIBA CORPORATION)
    Toshiba Online Backup (HKLM-x32\...\{C57BCDE1-7CB9-467D-B3BA-7E119916CDC1}) (Version: 2.0.0.31 - Toshiba)
    TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.7.15.64 - TOSHIBA Corporation)
    TOSHIBA Quality Application (HKLM-x32\...\{E69992ED-A7F6-406C-9280-1C156417BC49}) (Version: 1.0.4 - TOSHIBA)
    TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 2.1.6.52020009 - TOSHIBA CORPORATION)
    TOSHIBA ReelTime (HKLM-x32\...\InstallShield_{24811C12-F4A9-4D0F-8494-A7B8FE46123C}) (Version: 1.7.21.64 - TOSHIBA Corporation)
    TOSHIBA Resolution+ Plug-in for Windows Media Player (HKLM-x32\...\{6CB76C9D-80C2-4CB3-A4CD-D96B239E3F94}) (Version: 1.1.3.03 - TOSHIBA Corporation)
    Toshiba Security Dashboard (HKLM-x32\...\ToshibaSD) (Version: 1.0.0.48 - Symantec Corporation)
    TOSHIBA Service Station (HKLM-x32\...\{AC6569FA-6919-442A-8552-073BE69E247A}) (Version: 2.2.15.0 - TOSHIBA)
    TOSHIBA Sleep Utility (HKLM-x32\...\{654F7484-88C5-46DC-AB32-C66BCB0E2102}) (Version: 1.4.0022.000104 - TOSHIBA Corporation)
    TOSHIBA Supervisor Password (HKLM-x32\...\{119826A8-4EF6-4BE5-A88B-D2D81FA7CEE2}) (Version: 2.00.0009 - TOSHIBA)
    TOSHIBA User's Guide (HKLM-x32\...\{3384E1D9-3F18-4A98-8655-180FEF0DFC02}) (Version: 1.00.02 - TOSHIBA)
    TOSHIBA Value Added Package (HKLM-x32\...\InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}) (Version: 1.6.0023.640204 - TOSHIBA Corporation)
    TOSHIBA Web Camera Application (HKLM-x32\...\InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}) (Version: 2.0.3.33 - TOSHIBA Corporation)
    TOSHIBARegistration (HKLM-x32\...\{5AF550B4-BB67-4E7E-82F1-2C4300279050}) (Version: 1.0.9 - TOSHIBA)
    Trend Micro DirectPass (Version: 1.9.0.1094 - Trend Micro Inc.) Hidden
    Trend Micro Internet Security (HKLM\...\{ABBD4BA8-6703-40D2-AB1E-5BB1F7DB49A4}) (Version: 10.0 - Trend Micro Inc.)
    Trend Micro Password Manager (HKLM\...\{3075404F-5657-4f31-A064-FEF98661BDD4}) (Version: 1.9.1189 - Trend Micro Inc.)
    Trend Micro Titanium (Version: 10.0 - Trend Micro Inc.) Hidden
    VCRT for DirectPass x64 (Version: 1.0.0.1000 - Trend Micro, Inc.) Hidden
    VCRT for DirectPass x86 (x32 Version: 1.0.0.1000 - Trend Micro, Inc.) Hidden
    Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation)
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {2F57269B-1E09-4E2D-AB1E-B0FDAC7D279C} - \Microsoft\Windows\WindowsBackup\ConfigNotification -> No File <==== ATTENTION
    Task: {36DA4BCC-27F7-4352-8765-61A86B0022D1} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.)
    Task: {3F122AA9-B62F-4CBE-B298-FBC8ADA19A4E} - System32\Tasks\Norton Anti-Theft\Norton Error Processor => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.2.0.29\SymErr.exe
    Task: {55A42844-DA6E-4C58-8D4C-9482151DEFD1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.)
    Task: {889FC228-6D8F-45AE-87CB-6F348987C0AE} - System32\Tasks\Trend Micro Inspect of Platinum => C:\Program Files\Trend Micro\Titanium\plugin\Pt\win32\Inspect\Inspect.exe [2015-08-19] (Trend Micro Inc.)
    Task: {902F6F3B-ABAD-45F5-9094-3DC80ED4DEA3} - \Microsoft\Windows\Windows Activation Technologies\ValidationTaskDeadline -> No File <==== ATTENTION
    Task: {994C86AD-A929-4B2C-88A0-4E25A107A029} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe
    Task: {A6AF9377-77CE-47AB-AD7D-EC32CAD0C82D} - System32\Tasks\Microsoft\Windows\Location\Notifications => C:\Windows\System32\LocationNotificationWindows.exe
    Task: {AC4E5ACF-89F7-4220-BA21-81EE183975E2} - \Microsoft\Windows\Application Experience\AitAgent -> No File <==== ATTENTION
    Task: {B709435B-2544-4F1A-85EB-1E9EA83057D4} - System32\Tasks\GoogleUpdateTaskMachineUA1d1e9aec697d400 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.)
    Task: {C768A65F-3D85-416C-B88F-2F450DFED72B} - \Microsoft\Windows\Windows Activation Technologies\ValidationTask -> No File <==== ATTENTION
    Task: {CEE64558-E1A7-4D9D-80A7-2001912BE5B5} - \Microsoft\Windows\MemoryDiagnostic\CorruptionDetector -> No File <==== ATTENTION
    Task: {D025A81F-507D-489C-A80D-4599ABF5B8BD} - System32\Tasks\Norton Anti-Theft\Norton Error Analyzer => C:\Program Files (x86)\Norton Anti-Theft\Engine\1.2.0.29\SymErr.exe
    Task: {D4631BFF-F122-4C8E-B65F-22826B983E05} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
    Task: {E7BAEA7A-9D74-4B87-A537-8404E1B479E2} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-06-24] (Adobe Systems Incorporated)
    Task: {F82EEEED-084D-47F9-A0D5-A6D98936C837} - System32\Tasks\GoogleUpdateTaskMachineCore1d1e9aec519f9f2 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-11-14] (Google Inc.)
    Task: {FA2BC0A6-8D4B-458A-85C8-2B8C72487513} - \Microsoft\Windows\MemoryDiagnostic\DecompressionFailureDetector -> No File <==== ATTENTION

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore1d1e9aec519f9f2.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA1d1e9aec697d400.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2015-11-11 18:33 - 2010-09-09 21:26 - 00162824 _____ () C:\Windows\System32\GFNEXSrv.exe
    2016-01-07 15:24 - 2015-07-16 14:31 - 00089088 _____ () C:\Program Files\Trend Micro\Titanium\plugin\Pt\boost_thread-vc110-mt-1_52.dll
    2016-01-07 15:24 - 2015-07-16 14:31 - 00018944 _____ () C:\Program Files\Trend Micro\Titanium\plugin\Pt\boost_system-vc110-mt-1_52.dll
    2016-01-07 15:24 - 2015-07-16 14:31 - 00049664 _____ () C:\Program Files\Trend Micro\Titanium\plugin\Pt\boost_date_time-vc110-mt-1_52.dll
    2016-01-07 15:24 - 2015-07-16 14:31 - 00761856 _____ () C:\Program Files\Trend Micro\Titanium\plugin\Pt\boost_regex-vc110-mt-1_52.dll
    2011-08-22 19:19 - 2011-08-22 19:19 - 11204992 _____ () C:\Program Files\Toshiba\FlashCards\BlackPng.dll
    2010-12-15 19:19 - 2010-12-15 19:19 - 00124320 _____ () C:\Program Files\Toshiba\TECO\MUIHelp.dll
    2012-02-13 20:39 - 2012-02-13 20:39 - 00369152 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
    2012-02-03 17:33 - 2012-02-03 17:33 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
    2012-02-24 18:35 - 2012-02-24 18:35 - 00079784 _____ () C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)

    AlternateDataStreams: C:\Users\steve\Desktop\Drl.jpeg:3or4kl4x13tuuug3Byamue2s4b [83]
    AlternateDataStreams: C:\Users\steve\Desktop\Drl.jpeg:{4c8cc155-6c1e-11d1-8e41-00c04fb9386d} [0]

    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)

    IE trusted site: HKU\S-1-5-21-1354267143-4115596969-162612004-1000\...\amazon.com -> hxxps://amazon.com

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-13 22:34 - 2016-10-02 08:46 - 00000027 ____A C:\windows\system32\Drivers\etc\hosts

    127.0.0.1 localhost

    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-1354267143-4115596969-162612004-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\steve\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: Media is not connected to internet.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{CEF4FAEE-9D20-4057-9DD5-53AF1ACA796C}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
    FirewallRules: [{931D5A93-CF43-4158-88E5-CD67B746D8D0}] => (Allow) LPort=2869
    FirewallRules: [{179F11AF-215F-4318-952E-8703BDAF36F1}] => (Allow) LPort=1900
    FirewallRules: [{BB6DA4A1-99F8-4F31-B9A9-AC7A0E900F91}] => (Allow) C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
    FirewallRules: [{454DD60F-646C-458D-85FE-7986983ED794}] => (Allow) C:\Program Files (x86)\Windows Live\Mesh\MOE.exe
    FirewallRules: [{E003F557-41F3-4947-A6F4-0251FAB63764}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\WebKit2WebProcess.exe
    FirewallRules: [{8B76C25D-DA5C-4D94-BE3E-A0E833DAE7EF}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

    ==================== Restore Points =========================

    13-08-2016 11:30:17 Windows Update
    18-08-2016 11:21:58 Windows Update
    02-09-2016 12:51:45 Windows Update
    20-09-2016 12:48:41 Windows Update
    21-09-2016 12:01:31 Windows Update
    30-09-2016 12:10:50 JRT Pre-Junkware Removal
    02-10-2016 08:35:30 ComboFix created restore point

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (10/02/2016 03:18:22 PM) (Source: Application Error) (EventID: 1000) (User: )
    Description: Faulting application name: TPCHSrv.exe, version: 1.0.0.17, time stamp: 0x4ee83cbe
    Faulting module name: ntdll.dll, version: 6.1.7601.23539, time stamp: 0x57c99b8f
    Exception code: 0xc0000374
    Fault offset: 0x00000000000bf262
    Faulting process id: 0x136c
    Faulting application start time: 0x01d21c70018d25d4
    Faulting application path: C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
    Faulting module path: C:\windows\SYSTEM32\ntdll.dll
    Report Id: fb40e131-88d4-11e6-9c2a-4c72b932a5a4

    Error: (10/01/2016 07:43:26 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (10/01/2016 08:05:22 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (10/01/2016 08:04:16 AM) (Source: TOSHIBA Service Station) (EventID: 0) (User: )
    Description: The following module failed to stop processing: PC Health Info Connection. Error: Operation failed.

    Error: (10/01/2016 08:04:16 AM) (Source: TOSHIBA Service Station) (EventID: 0) (User: )
    Description: The following module failed to stop processing: Alerts. Error: Operation failed.

    Error: (10/01/2016 08:04:16 AM) (Source: TOSHIBA Service Station) (EventID: 0) (User: )
    Description: The following module failed to stop processing: Software Updates. Error: Operation failed.

    Error: (09/30/2016 03:31:10 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (09/30/2016 12:11:16 PM) (Source: Microsoft-Windows-CAPI2) (EventID: 513) (User: )
    Description: Cryptographic Services failed while processing the OnIdentity() call in the System Writer Object.

    Details:
    AddWin32ServiceFiles: Unable to back up image of service rpcnetp since QueryServiceConfig API failed

    System Error:
    The system cannot find the file specified.
    .

    Error: (09/30/2016 12:09:55 PM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (09/30/2016 10:03:09 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.


    System errors:
    =============
    Error: (10/02/2016 03:18:23 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The TPCH Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (10/02/2016 09:03:38 AM) (Source: DCOM) (EventID: 10010) (User: )
    Description: The server {995C996E-D918-4A8C-A302-45719A6F4EA7} did not register with DCOM within the required timeout.

    Error: (10/02/2016 08:46:51 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (10/02/2016 08:42:20 AM) (Source: Application Popup) (EventID: 1060) (User: )
    Description: \??\C:\ComboFix\catchme.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.

    Error: (10/02/2016 08:39:22 AM) (Source: Service Control Manager) (EventID: 7030) (User: )
    Description: The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

    Error: (10/01/2016 08:03:08 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
    Description: The Windows Media Player Network Sharing Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 30000 milliseconds: Restart the service.

    Error: (10/01/2016 08:03:08 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Toshiba Laptop Checkup Application Launcher service terminated unexpectedly. It has done this 1 time(s).

    Error: (10/01/2016 08:03:08 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The TOSHIBA HDD SSD Alert Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (10/01/2016 08:03:08 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The TPCH Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (10/01/2016 08:03:08 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Adobe Acrobat Update Service service terminated unexpectedly. It has done this 1 time(s).


    CodeIntegrity:
    ===================================
    Date: 2016-10-02 08:42:20.560
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

    Date: 2016-10-02 08:42:20.497
    Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


    ==================== Memory info ===========================

    Processor: AMD A6-4400M APU with Radeon(tm) HD Graphics
    Percentage of memory in use: 35%
    Total physical RAM: 3558.37 MB
    Available physical RAM: 2309.74 MB
    Total Virtual: 7114.92 MB
    Available Virtual: 5609.11 MB

    ==================== Drives ================================

    Drive c: (TI106426W0A) (Fixed) (Total:581.16 GB) (Free:512.23 GB) NTFS ==>[system with boot components (obtained from drive)]

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 596.2 GB) (Disk ID: E36266CE)
    Partition 1: (Active) - (Size=1.5 GB) - (Type=27)
    Partition 2: (Not Active) - (Size=581.2 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=13.5 GB) - (Type=17)

    ==================== End of Addition.txt ============================

  15. #15
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,550
    Download attached fixlist.txt file and save it to the Desktop.
    NOTE. It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Run FRST(FRST64) and press the Fix button just once and wait.
    The tool will make a log on the Desktop (Fixlog.txt). Please post it to your reply.
    Attached Files Attached Files

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •