[RESOLVED] Disabled Antivirus
Results 1 to 7 of 7

Thread: [RESOLVED] Disabled Antivirus

  1. #1
    Join Date
    Mar 2014
    Posts
    491

    Resolved [RESOLVED] Disabled Antivirus

    Today my action center on my Windows 7 told me that my Windows Defender and Avast were not turned on. (I didn't know Windows Defender was on here.) When I clicked to turn Avast on it wouldn't let me. I tried the same with Windows Defender and got the same result. I restarted my computer and everything turned on okay, but I'm still concerned. I'll post my FRST scan results shortly.

  2. #2
    Join Date
    Mar 2014
    Posts
    491
    FRST Part 1:Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 19.08.2018 02
    Ran by Angela (administrator) on ANGELA-PC (21-08-2018 12:58:24)
    Running from C:\Users\Angela\Desktop
    Loaded Profiles: Angela (Available Profiles: Angela)
    Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States)
    Internet Explorer Version 11 (Default browser: Chrome)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic...ery-scan-tool/

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
    (Microsoft Corporation) C:\WINDOWS\System32\wlanext.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    (Andrea Electronics Corporation) C:\Program Files\IDT\WDM\AESTSr64.exe
    (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
    (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
    (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
    (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
    (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler.exe
    (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.33.17\GoogleCrashHandler64.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
    (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe
    (Dell Inc.) C:\Program Files\Dell\QuickSet\quickset.exe
    (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
    (Microsoft Corporation) C:\WINDOWS\System32\rundll32.exe
    (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe
    (Intel Corporation) C:\WINDOWS\System32\igfxtray.exe
    (Intel Corporation) C:\WINDOWS\System32\hkcmd.exe
    (Intel Corporation) C:\WINDOWS\System32\igfxpers.exe
    (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
    () C:\Program Files\Earth Networks\WeatherBug\WeatherBug.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
    (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe
    (Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\btplayerctrl.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe
    (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe
    (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe
    (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
    (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
    (Microsoft Corporation) C:\WINDOWS\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
    (Microsoft Corporation) C:\WINDOWS\System32\dllhost.exe

    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM\...\Run: [Apoint] => C:\Program Files\DellTPad\Apoint.exe [609144 2011-04-12] (Alps Electric Co., Ltd.)
    HKLM\...\Run: [QuickSet] => C:\Program Files\Dell\QuickSet\QuickSet.exe [3668336 2011-03-24] (Dell Inc.)
    HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-09-15] (Intel(R) Corporation)
    HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp
    HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [525312 2011-01-25] (IDT, Inc.)
    HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [242392 2018-08-21] (AVAST Software)
    HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [298296 2018-07-06] (Apple Inc.)
    HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [503942 2011-04-13] (Creative Technology Ltd)
    HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-11-05] (Intel Corporation)
    HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-17] (Renesas Electronics Corporation)
    HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-15] (Adobe Systems Incorporated)
    HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [932288 2010-11-15] (Adobe Systems Incorporated)
    Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation)
    HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
    HKU\S-1-5-21-3674130756-1144773717-1238336968-1000\...\Run: [WeatherBug] => C:\Program Files\Earth Networks\WeatherBug\WeatherBug.exe [108456 2016-05-05] ()

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 24.116.0.53 24.116.2.50 192.168.1.1
    Tcpip\..\Interfaces\{7DE346BF-6AF2-495C-B05C-3121B7F13499}: [DhcpNameServer] 24.116.0.53 24.116.2.50 192.168.1.1

    Internet Explorer:
    ==================
    HKU\S-1-5-21-3674130756-1144773717-1238336968-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/USCON/1
    SearchScopes: HKLM -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
    SearchScopes: HKLM-x32 -> {2F1E335A-858A-4BE9-8F6B-D0AF1D018B53} URL = hxxp://www.bing.com/search?q={searchTerms}&form=DLCDF8&pc=MDDC&src=IE-SearchBox
    SearchScopes: HKU\S-1-5-21-3674130756-1144773717-1238336968-1000 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
    BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll [2012-01-05] (Sun Microsystems, Inc.)
    BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-11-15] (Adobe Systems Incorporated)
    BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll [2012-01-05] (Sun Microsystems, Inc.)

    FireFox:
    ========
    FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll [2012-01-05] (Sun Microsystems, Inc.)
    FF Plugin: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll [2012-01-05] (Sun Microsystems, Inc.)
    FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File]
    FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll [2010-04-01] ( Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [No File]
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-06-02] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.17\npGoogleUpdate3.dll [2018-06-02] (Google Inc.)

    Chrome:
    =======
    CHR HomePage: Default -> hxxps://www.google.as/
    CHR StartupUrls: Default -> "hxxps://www.google.com/","hxxps://encrypted.google.com"
    CHR DefaultSearchKeyword: Default -> google.com_
    CHR Profile: C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default [2018-08-21]
    CHR Extension: (Slides) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-06-02]
    CHR Extension: (Docs) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-06-02]
    CHR Extension: (Google Drive) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-06-02]
    CHR Extension: (WOT Web of Trust, Website Reputation Ratings) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp [2018-07-23]
    CHR Extension: (YouTube) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-06-02]
    CHR Extension: (Sheets) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-06-02]
    CHR Extension: (Google Docs Offline) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-08-13]
    CHR Extension: (AdBlock) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2018-07-25]
    CHR Extension: (Avast Online Security) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2018-06-03]
    CHR Extension: (Chrome Web Store Payments) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-06-02]
    CHR Extension: (Gmail) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-06-02]
    CHR Extension: (Chrome Media Router) - C:\Users\Angela\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-08-04]
    CHR HKLM-x32\...\Chrome\Extension: [eofcbnmajmjmplflapaojjnihcjkigck] - hxxps://clients2.google.com/service/update2/crx
    CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - hxxps://clients2.google.com/service/update2/crx

    ==================== Services (Whitelisted) ====================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2018-07-05] (Apple Inc.)
    R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe [7994520 2018-08-21] (AVAST Software)
    R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [322464 2018-08-21] (AVAST Software)
    R2 Bluetooth Device Monitor; C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe [921664 2011-05-19] (Intel Corporation) [File not signed]
    R3 Bluetooth Media Service; C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe [1335360 2011-05-19] (Intel Corporation) [File not signed]
    R2 Bluetooth OBEX Service; C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe [995392 2011-05-19] (Intel Corporation) [File not signed]
    S2 DellDigitalDelivery; C:\Program Files (x86)\Dell Digital Delivery\DeliveryService.exe [162816 2011-10-26] (Dell Products, LP.) [File not signed]
    R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [6541008 2018-05-09] (Malwarebytes)
    S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-09-15] ()
    S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ======================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R1 aswArPot; C:\windows\System32\drivers\aswArPot.sys [199712 2018-08-21] (AVAST Software)
    R1 aswbidsdriver; C:\windows\System32\drivers\aswbidsdrivera.sys [229384 2018-08-21] (AVAST Software)
    R0 aswbidsh; C:\windows\System32\drivers\aswbidsha.sys [201320 2018-08-21] (AVAST Software)
    R0 aswblog; C:\windows\System32\drivers\aswbloga.sys [346664 2018-08-21] (AVAST Software)
    R0 aswbuniv; C:\windows\System32\drivers\aswbuniva.sys [59568 2018-08-21] (AVAST Software)
    R1 aswHdsKe; C:\windows\System32\drivers\aswHdsKe.sys [249016 2018-08-21] (AVAST Software)
    S3 aswHwid; C:\windows\System32\drivers\aswHwid.sys [46968 2018-08-21] (AVAST Software)
    R2 aswMonFlt; C:\windows\System32\drivers\aswMonFlt.sys [163272 2018-08-21] (AVAST Software)
    R1 aswRdr; C:\windows\System32\drivers\aswRdr2.sys [111864 2018-08-21] (AVAST Software)
    R0 aswRvrt; C:\windows\System32\drivers\aswRvrt.sys [85968 2018-08-21] (AVAST Software)
    R1 aswSnx; C:\windows\System32\drivers\aswSnx.sys [1027720 2018-08-21] (AVAST Software)
    R1 aswSP; C:\windows\System32\drivers\aswSP.sys [467232 2018-08-21] (AVAST Software)
    R2 aswStm; C:\windows\System32\drivers\aswStm.sys [214800 2018-08-21] (AVAST Software)
    R0 aswVmm; C:\windows\System32\drivers\aswVmm.sys [381560 2018-08-21] (AVAST Software)
    R3 MBAMSwissArmy; C:\windows\System32\Drivers\mbamswissarmy.sys [253664 2018-08-21] (Malwarebytes)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2018-08-21 12:58 - 2018-08-21 12:58 - 000014078 _____ C:\Users\Angela\Desktop\FRST.txt
    2018-08-21 12:09 - 2018-08-21 12:09 - 002413056 _____ (Farbar) C:\Users\Angela\Desktop\FRST64.exe
    2018-08-21 11:07 - 2018-08-21 11:07 - 000379608 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
    2018-08-14 13:19 - 2018-08-03 10:55 - 000109568 _____ (Microsoft Corporation) C:\windows\system32\hlink.dll
    2018-08-14 13:19 - 2018-08-03 10:39 - 000084992 _____ (Microsoft Corporation) C:\windows\SysWOW64\hlink.dll
    2018-08-14 13:19 - 2018-08-01 22:20 - 000708272 _____ (Microsoft Corporation) C:\windows\system32\winload.efi
    2018-08-14 13:19 - 2018-08-01 22:18 - 000096864 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecdd.sys
    2018-08-14 13:19 - 2018-08-01 22:07 - 000263776 _____ (Microsoft Corporation) C:\windows\system32\hal.dll
    2018-08-14 13:19 - 2018-08-01 22:06 - 000156256 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ksecpkg.sys
    2018-08-14 13:19 - 2018-08-01 22:05 - 005553760 _____ (Microsoft Corporation) C:\windows\system32\ntoskrnl.exe
    2018-08-14 13:19 - 2018-08-01 22:02 - 001665320 _____ (Microsoft Corporation) C:\windows\system32\ntdll.dll
    2018-08-14 13:19 - 2018-08-01 22:00 - 000633080 _____ (Microsoft Corporation) C:\windows\system32\winresume.efi
    2018-08-14 13:19 - 2018-08-01 21:59 - 001211904 _____ (Microsoft Corporation) C:\windows\system32\rpcrt4.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000503808 _____ (Microsoft Corporation) C:\windows\system32\srcore.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000361984 _____ (Microsoft Corporation) C:\windows\system32\wow64win.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000345600 _____ (Microsoft Corporation) C:\windows\system32\schannel.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000316928 _____ (Microsoft Corporation) C:\windows\system32\msv1_0.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000312320 _____ (Microsoft Corporation) C:\windows\system32\ncrypt.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000243712 _____ (Microsoft Corporation) C:\windows\system32\wow64.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000215552 _____ (Microsoft Corporation) C:\windows\system32\winsrv.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000210432 _____ (Microsoft Corporation) C:\windows\system32\wdigest.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000190464 _____ (Microsoft Corporation) C:\windows\system32\rpchttp.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000146432 _____ (Microsoft Corporation) C:\windows\system32\msaudite.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000135680 _____ (Microsoft Corporation) C:\windows\system32\sspicli.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000094208 _____ (Microsoft Corporation) C:\windows\system32\TSpkg.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000063488 _____ (Microsoft Corporation) C:\windows\system32\setbcdlocale.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000060416 _____ (Microsoft Corporation) C:\windows\system32\msobjs.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000050176 _____ (Microsoft Corporation) C:\windows\system32\srclient.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000028672 _____ (Microsoft Corporation) C:\windows\system32\sspisrv.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000028160 _____ (Microsoft Corporation) C:\windows\system32\secur32.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000016384 _____ (Microsoft Corporation) C:\windows\system32\ntvdm64.dll
    2018-08-14 13:19 - 2018-08-01 21:59 - 000013312 _____ (Microsoft Corporation) C:\windows\system32\wow64cpu.dll
    2018-08-14 13:19 - 2018-08-01 21:58 - 001461760 _____ (Microsoft Corporation) C:\windows\system32\lsasrv.dll
    2018-08-14 13:19 - 2018-08-01 21:58 - 001163264 _____ (Microsoft Corporation) C:\windows\system32\kernel32.dll
    2018-08-14 13:19 - 2018-08-01 21:58 - 000731648 _____ (Microsoft Corporation) C:\windows\system32\kerberos.dll
    2018-08-14 13:19 - 2018-08-01 21:58 - 000463872 _____ (Microsoft Corporation) C:\windows\system32\certcli.dll
    2018-08-14 13:19 - 2018-08-01 21:58 - 000419840 _____ (Microsoft Corporation) C:\windows\system32\KernelBase.dll
    2018-08-14 13:19 - 2018-08-01 21:58 - 000044032 _____ (Microsoft Corporation) C:\windows\system32\csrsrv.dll
    2018-08-14 13:19 - 2018-08-01 21:58 - 000043520 _____ (Microsoft Corporation) C:\windows\system32\cryptbase.dll
    2018-08-14 13:19 - 2018-08-01 21:58 - 000022016 _____ (Microsoft Corporation) C:\windows\system32\credssp.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000880640 _____ (Microsoft Corporation) C:\windows\system32\advapi32.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000690688 _____ (Microsoft Corporation) C:\windows\system32\adtschema.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000123904 _____ (Microsoft Corporation) C:\windows\system32\bcrypt.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000059904 _____ (Microsoft Corporation) C:\windows\system32\appidapi.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000034816 _____ (Microsoft Corporation) C:\windows\system32\appidsvc.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000007168 _____ (Microsoft Corporation) C:\windows\system32\apisetschema.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000006144 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-security-base-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000005120 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-file-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-threadpool-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000004608 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processthreads-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-sysinfo-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-synch-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localregistry-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000004096 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-rtlsupport-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-processenvironment-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-namedpipe-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-misc-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-memory-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-libraryloader-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003584 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-heap-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-xstate-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-util-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-string-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-profile-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-io-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-interlocked-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-handle-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-fibers-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-errorhandling-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-delayload-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-debug-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-datetime-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:57 - 000003072 ____H (Microsoft Corporation) C:\windows\system32\api-ms-win-core-console-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:45 - 004054192 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntkrnlpa.exe
    2018-08-14 13:19 - 2018-08-01 21:45 - 003959984 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntoskrnl.exe
    2018-08-14 13:19 - 2018-08-01 21:43 - 001315512 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntdll.dll
    2018-08-14 13:19 - 2018-08-01 21:42 - 001114112 _____ (Microsoft Corporation) C:\windows\SysWOW64\kernel32.dll
    2018-08-14 13:19 - 2018-08-01 21:42 - 000666112 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpcrt4.dll
    2018-08-14 13:19 - 2018-08-01 21:42 - 000275456 _____ (Microsoft Corporation) C:\windows\SysWOW64\KernelBase.dll
    2018-08-14 13:19 - 2018-08-01 21:42 - 000096768 _____ (Microsoft Corporation) C:\windows\SysWOW64\sspicli.dll
    2018-08-14 13:19 - 2018-08-01 21:42 - 000082944 _____ (Microsoft Corporation) C:\windows\SysWOW64\bcrypt.dll
    2018-08-14 13:19 - 2018-08-01 21:42 - 000005120 _____ (Microsoft Corporation) C:\windows\SysWOW64\wow32.dll
    2018-08-14 13:19 - 2018-08-01 21:41 - 000554496 _____ (Microsoft Corporation) C:\windows\SysWOW64\kerberos.dll
    2018-08-14 13:19 - 2018-08-01 21:41 - 000261120 _____ (Microsoft Corporation) C:\windows\SysWOW64\msv1_0.dll
    2018-08-14 13:19 - 2018-08-01 21:41 - 000254464 _____ (Microsoft Corporation) C:\windows\SysWOW64\schannel.dll
    2018-08-14 13:19 - 2018-08-01 21:41 - 000223232 _____ (Microsoft Corporation) C:\windows\SysWOW64\ncrypt.dll
    2018-08-14 13:19 - 2018-08-01 21:41 - 000172032 _____ (Microsoft Corporation) C:\windows\SysWOW64\wdigest.dll
    2018-08-14 13:19 - 2018-08-01 21:41 - 000146432 _____ (Microsoft Corporation) C:\windows\SysWOW64\msaudite.dll
    2018-08-14 13:19 - 2018-08-01 21:41 - 000141312 _____ (Microsoft Corporation) C:\windows\SysWOW64\rpchttp.dll
    2018-08-14 13:19 - 2018-08-01 21:41 - 000070144 _____ (Microsoft Corporation) C:\windows\SysWOW64\TSpkg.dll
    2018-08-14 13:19 - 2018-08-01 21:41 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\msobjs.dll
    2018-08-14 13:19 - 2018-08-01 21:41 - 000043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\srclient.dll
    2018-08-14 13:19 - 2018-08-01 21:41 - 000022016 _____ (Microsoft Corporation) C:\windows\SysWOW64\secur32.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000690688 _____ (Microsoft Corporation) C:\windows\SysWOW64\adtschema.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000644096 _____ (Microsoft Corporation) C:\windows\SysWOW64\advapi32.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000342528 _____ (Microsoft Corporation) C:\windows\SysWOW64\certcli.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\appidapi.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000017408 _____ (Microsoft Corporation) C:\windows\SysWOW64\credssp.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000007168 _____ (Microsoft Corporation) C:\windows\SysWOW64\apisetschema.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000005120 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-file-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processthreads-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-sysinfo-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-synch-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-misc-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localregistry-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000004096 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-localization-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-processenvironment-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-namedpipe-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-memory-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-libraryloader-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-interlocked-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-heap-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-string-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-rtlsupport-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-profile-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-io-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-handle-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-fibers-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-errorhandling-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-delayload-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-debug-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-datetime-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:40 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-console-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:26 - 000148480 _____ (Microsoft Corporation) C:\windows\system32\appidpolicyconverter.exe
    2018-08-14 13:19 - 2018-08-01 21:26 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\appid.sys
    2018-08-14 13:19 - 2018-08-01 21:26 - 000017920 _____ (Microsoft Corporation) C:\windows\system32\appidcertstorecheck.exe

  3. #3
    Join Date
    Mar 2014
    Posts
    491
    FRST Part 2:2018-08-14 13:19 - 2018-08-01 21:25 - 000064512 _____ (Microsoft Corporation) C:\windows\system32\auditpol.exe
    2018-08-14 13:19 - 2018-08-01 21:22 - 000338432 _____ (Microsoft Corporation) C:\windows\system32\conhost.exe
    2018-08-14 13:19 - 2018-08-01 21:21 - 000296960 _____ (Microsoft Corporation) C:\windows\system32\rstrui.exe
    2018-08-14 13:19 - 2018-08-01 21:21 - 000129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\videoprt.sys
    2018-08-14 13:19 - 2018-08-01 21:17 - 000291328 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb10.sys
    2018-08-14 13:19 - 2018-08-01 21:17 - 000160256 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb.sys
    2018-08-14 13:19 - 2018-08-01 21:17 - 000129536 _____ (Microsoft Corporation) C:\windows\system32\Drivers\mrxsmb20.sys
    2018-08-14 13:19 - 2018-08-01 21:16 - 000112640 _____ (Microsoft Corporation) C:\windows\system32\smss.exe
    2018-08-14 13:19 - 2018-08-01 21:16 - 000064512 _____ (Microsoft Corporation) C:\windows\system32\Drivers\amdk8.sys
    2018-08-14 13:19 - 2018-08-01 21:16 - 000062464 _____ (Microsoft Corporation) C:\windows\system32\Drivers\intelppm.sys
    2018-08-14 13:19 - 2018-08-01 21:16 - 000060928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\processr.sys
    2018-08-14 13:19 - 2018-08-01 21:16 - 000060928 _____ (Microsoft Corporation) C:\windows\system32\Drivers\amdppm.sys
    2018-08-14 13:19 - 2018-08-01 21:16 - 000050688 _____ (Microsoft Corporation) C:\windows\SysWOW64\auditpol.exe
    2018-08-14 13:19 - 2018-08-01 21:16 - 000030720 _____ (Microsoft Corporation) C:\windows\system32\lsass.exe
    2018-08-14 13:19 - 2018-08-01 21:11 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\setup16.exe
    2018-08-14 13:19 - 2018-08-01 21:11 - 000014336 _____ (Microsoft Corporation) C:\windows\SysWOW64\ntvdm64.dll
    2018-08-14 13:19 - 2018-08-01 21:11 - 000007680 _____ (Microsoft Corporation) C:\windows\SysWOW64\instnm.exe
    2018-08-14 13:19 - 2018-08-01 21:11 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\user.exe
    2018-08-14 13:19 - 2018-08-01 21:10 - 000036352 _____ (Microsoft Corporation) C:\windows\SysWOW64\cryptbase.dll
    2018-08-14 13:19 - 2018-08-01 21:10 - 000006144 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-security-base-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:10 - 000004608 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-threadpool-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:10 - 000003584 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-xstate-l1-1-0.dll
    2018-08-14 13:19 - 2018-08-01 21:10 - 000003072 ____H (Microsoft Corporation) C:\windows\SysWOW64\api-ms-win-core-util-l1-1-0.dll
    2018-08-14 13:19 - 2018-07-19 18:53 - 000396936 _____ (Microsoft Corporation) C:\windows\system32\iedkcs32.dll
    2018-08-14 13:19 - 2018-07-19 17:58 - 000350272 _____ (Microsoft Corporation) C:\windows\SysWOW64\iedkcs32.dll
    2018-08-14 13:19 - 2018-07-19 01:15 - 025745408 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
    2018-08-14 13:19 - 2018-07-18 23:48 - 002724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
    2018-08-14 13:19 - 2018-07-18 23:47 - 000004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
    2018-08-14 13:19 - 2018-07-18 23:35 - 002902016 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
    2018-08-14 13:19 - 2018-07-18 23:34 - 000066560 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
    2018-08-14 13:19 - 2018-07-18 23:33 - 000576512 _____ (Microsoft Corporation) C:\windows\system32\vbscript.dll
    2018-08-14 13:19 - 2018-07-18 23:33 - 000417280 _____ (Microsoft Corporation) C:\windows\system32\html.iec
    2018-08-14 13:19 - 2018-07-18 23:33 - 000048640 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
    2018-08-14 13:19 - 2018-07-18 23:32 - 000088064 _____ (Microsoft Corporation) C:\windows\system32\MshtmlDac.dll
    2018-08-14 13:19 - 2018-07-18 23:30 - 005778432 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
    2018-08-14 13:19 - 2018-07-18 23:26 - 000054784 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
    2018-08-14 13:19 - 2018-07-18 23:25 - 000034304 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
    2018-08-14 13:19 - 2018-07-18 23:23 - 000615936 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
    2018-08-14 13:19 - 2018-07-18 23:22 - 020286464 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.dll
    2018-08-14 13:19 - 2018-07-18 23:22 - 000794624 _____ (Microsoft Corporation) C:\windows\system32\jscript.dll
    2018-08-14 13:19 - 2018-07-18 23:22 - 000144384 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
    2018-08-14 13:19 - 2018-07-18 23:22 - 000116224 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
    2018-08-14 13:19 - 2018-07-18 23:21 - 000814080 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
    2018-08-14 13:19 - 2018-07-18 23:16 - 002724864 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtml.tlb
    2018-08-14 13:19 - 2018-07-18 23:14 - 000969216 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
    2018-08-14 13:19 - 2018-07-18 23:11 - 000489984 _____ (Microsoft Corporation) C:\windows\system32\dxtmsft.dll
    2018-08-14 13:19 - 2018-07-18 23:05 - 000497664 _____ (Microsoft Corporation) C:\windows\SysWOW64\vbscript.dll
    2018-08-14 13:19 - 2018-07-18 23:05 - 000077824 _____ (Microsoft Corporation) C:\windows\system32\JavaScriptCollectionAgent.dll
    2018-08-14 13:19 - 2018-07-18 23:04 - 000341504 _____ (Microsoft Corporation) C:\windows\SysWOW64\html.iec
    2018-08-14 13:19 - 2018-07-18 23:04 - 000087552 _____ (Microsoft Corporation) C:\windows\system32\tdc.ocx
    2018-08-14 13:19 - 2018-07-18 23:04 - 000062464 _____ (Microsoft Corporation) C:\windows\SysWOW64\iesetup.dll
    2018-08-14 13:19 - 2018-07-18 23:04 - 000047616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieetwproxystub.dll
    2018-08-14 13:19 - 2018-07-18 23:03 - 000107520 _____ (Microsoft Corporation) C:\windows\system32\inseng.dll
    2018-08-14 13:19 - 2018-07-18 23:03 - 000064000 _____ (Microsoft Corporation) C:\windows\SysWOW64\MshtmlDac.dll
    2018-08-14 13:19 - 2018-07-18 23:01 - 002295808 _____ (Microsoft Corporation) C:\windows\SysWOW64\iertutil.dll
    2018-08-14 13:19 - 2018-07-18 23:00 - 000199680 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
    2018-08-14 13:19 - 2018-07-18 23:00 - 000092160 _____ (Microsoft Corporation) C:\windows\system32\mshtmled.dll
    2018-08-14 13:19 - 2018-07-18 22:58 - 000315392 _____ (Microsoft Corporation) C:\windows\system32\dxtrans.dll
    2018-08-14 13:19 - 2018-07-18 22:58 - 000047104 _____ (Microsoft Corporation) C:\windows\SysWOW64\jsproxy.dll
    2018-08-14 13:19 - 2018-07-18 22:57 - 000030720 _____ (Microsoft Corporation) C:\windows\SysWOW64\iernonce.dll
    2018-08-14 13:19 - 2018-07-18 22:56 - 000476160 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieui.dll
    2018-08-14 13:19 - 2018-07-18 22:56 - 000152064 _____ (Microsoft Corporation) C:\windows\system32\occache.dll
    2018-08-14 13:19 - 2018-07-18 22:55 - 000662016 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript.dll
    2018-08-14 13:19 - 2018-07-18 22:55 - 000115712 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieUnatt.exe
    2018-08-14 13:19 - 2018-07-18 22:54 - 000620032 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9diag.dll
    2018-08-14 13:19 - 2018-07-18 22:47 - 000262144 _____ (Microsoft Corporation) C:\windows\system32\webcheck.dll
    2018-08-14 13:19 - 2018-07-18 22:46 - 015283712 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
    2018-08-14 13:19 - 2018-07-18 22:46 - 000416256 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtmsft.dll
    2018-08-14 13:19 - 2018-07-18 22:45 - 000809472 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
    2018-08-14 13:19 - 2018-07-18 22:45 - 000728064 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
    2018-08-14 13:19 - 2018-07-18 22:43 - 002136064 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
    2018-08-14 13:19 - 2018-07-18 22:43 - 001359360 _____ (Microsoft Corporation) C:\windows\system32\mshtmlmedia.dll
    2018-08-14 13:19 - 2018-07-18 22:42 - 000060416 _____ (Microsoft Corporation) C:\windows\SysWOW64\JavaScriptCollectionAgent.dll
    2018-08-14 13:19 - 2018-07-18 22:41 - 000091136 _____ (Microsoft Corporation) C:\windows\SysWOW64\inseng.dll
    2018-08-14 13:19 - 2018-07-18 22:41 - 000073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\tdc.ocx
    2018-08-14 13:19 - 2018-07-18 22:39 - 000168960 _____ (Microsoft Corporation) C:\windows\SysWOW64\msrating.dll
    2018-08-14 13:19 - 2018-07-18 22:38 - 000076288 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmled.dll
    2018-08-14 13:19 - 2018-07-18 22:37 - 000279040 _____ (Microsoft Corporation) C:\windows\SysWOW64\dxtrans.dll
    2018-08-14 13:19 - 2018-07-18 22:35 - 000130048 _____ (Microsoft Corporation) C:\windows\SysWOW64\occache.dll
    2018-08-14 13:19 - 2018-07-18 22:32 - 004494848 _____ (Microsoft Corporation) C:\windows\SysWOW64\jscript9.dll
    2018-08-14 13:19 - 2018-07-18 22:31 - 004510720 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
    2018-08-14 13:19 - 2018-07-18 22:30 - 000230400 _____ (Microsoft Corporation) C:\windows\SysWOW64\webcheck.dll
    2018-08-14 13:19 - 2018-07-18 22:28 - 013679616 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieframe.dll
    2018-08-14 13:19 - 2018-07-18 22:28 - 002059776 _____ (Microsoft Corporation) C:\windows\SysWOW64\inetcpl.cpl
    2018-08-14 13:19 - 2018-07-18 22:28 - 000696320 _____ (Microsoft Corporation) C:\windows\SysWOW64\msfeeds.dll
    2018-08-14 13:19 - 2018-07-18 22:27 - 001155072 _____ (Microsoft Corporation) C:\windows\SysWOW64\mshtmlmedia.dll
    2018-08-14 13:19 - 2018-07-18 22:20 - 001554944 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
    2018-08-14 13:19 - 2018-07-18 22:09 - 004037632 _____ (Microsoft Corporation) C:\windows\SysWOW64\wininet.dll
    2018-08-14 13:19 - 2018-07-18 22:09 - 000800768 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
    2018-08-14 13:19 - 2018-07-18 22:06 - 001329152 _____ (Microsoft Corporation) C:\windows\SysWOW64\urlmon.dll
    2018-08-14 13:19 - 2018-07-18 22:04 - 000710144 _____ (Microsoft Corporation) C:\windows\SysWOW64\ieapfltr.dll
    2018-08-14 13:19 - 2018-07-13 14:19 - 001894080 _____ (Microsoft Corporation) C:\windows\system32\Drivers\tcpip.sys
    2018-08-14 13:19 - 2018-07-13 14:19 - 000377024 _____ (Microsoft Corporation) C:\windows\system32\Drivers\netio.sys
    2018-08-14 13:19 - 2018-07-13 14:19 - 000287936 _____ (Microsoft Corporation) C:\windows\system32\Drivers\FWPKCLNT.SYS
    2018-08-14 13:19 - 2018-07-08 11:08 - 000383680 _____ (Adobe Systems Incorporated) C:\windows\system32\atmfd.dll
    2018-08-14 13:19 - 2018-07-08 11:02 - 000152064 _____ (Microsoft Corporation) C:\windows\system32\t2embed.dll
    2018-08-14 13:19 - 2018-07-08 11:02 - 000100864 _____ (Microsoft Corporation) C:\windows\system32\fontsub.dll
    2018-08-14 13:19 - 2018-07-08 11:02 - 000041472 _____ (Microsoft Corporation) C:\windows\system32\lpk.dll
    2018-08-14 13:19 - 2018-07-08 11:01 - 000046080 _____ (Adobe Systems) C:\windows\system32\atmlib.dll
    2018-08-14 13:19 - 2018-07-08 11:01 - 000014336 _____ (Microsoft Corporation) C:\windows\system32\dciman32.dll
    2018-08-14 13:19 - 2018-07-08 10:47 - 000309440 _____ (Adobe Systems Incorporated) C:\windows\SysWOW64\atmfd.dll
    2018-08-14 13:19 - 2018-07-08 10:42 - 000111616 _____ (Microsoft Corporation) C:\windows\SysWOW64\t2embed.dll
    2018-08-14 13:19 - 2018-07-08 10:42 - 000025600 _____ (Microsoft Corporation) C:\windows\SysWOW64\lpk.dll
    2018-08-14 13:19 - 2018-07-08 10:41 - 000071680 _____ (Microsoft Corporation) C:\windows\SysWOW64\fontsub.dll
    2018-08-14 13:19 - 2018-07-08 10:41 - 000010240 _____ (Microsoft Corporation) C:\windows\SysWOW64\dciman32.dll
    2018-08-14 13:19 - 2018-07-08 10:13 - 000034304 _____ (Adobe Systems) C:\windows\SysWOW64\atmlib.dll
    2018-08-14 13:19 - 2018-07-07 10:24 - 003226112 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
    2018-08-14 13:19 - 2018-07-06 11:09 - 000947904 _____ (Microsoft Corporation) C:\windows\system32\Drivers\ndis.sys
    2018-08-14 13:19 - 2018-07-06 11:03 - 000056832 _____ (Microsoft Corporation) C:\windows\system32\mf3216.dll
    2018-08-14 13:19 - 2018-07-06 11:03 - 000008192 _____ (Microsoft Corporation) C:\windows\system32\msimg32.dll
    2018-08-14 13:19 - 2018-07-06 10:48 - 000043008 _____ (Microsoft Corporation) C:\windows\SysWOW64\mf3216.dll
    2018-08-14 13:19 - 2018-07-06 10:48 - 000004608 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimg32.dll
    2018-08-14 13:19 - 2018-06-29 10:55 - 000045568 _____ (Microsoft Corporation) C:\windows\system32\cscapi.dll
    2018-08-14 13:19 - 2018-06-29 10:55 - 000030208 _____ (Microsoft Corporation) C:\windows\system32\cscdll.dll
    2018-08-14 13:19 - 2018-06-29 10:40 - 000023040 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscdll.dll
    2018-08-14 13:19 - 2018-06-29 10:09 - 000034304 _____ (Microsoft Corporation) C:\windows\SysWOW64\cscapi.dll
    2018-08-14 13:19 - 2018-06-27 11:01 - 000114368 _____ (Microsoft Corporation) C:\windows\system32\consent.exe
    2018-08-14 13:19 - 2018-06-27 10:55 - 003246592 _____ (Microsoft Corporation) C:\windows\system32\msi.dll
    2018-08-14 13:19 - 2018-06-27 10:55 - 000504320 _____ (Microsoft Corporation) C:\windows\system32\msihnd.dll
    2018-08-14 13:19 - 2018-06-27 10:55 - 000484864 _____ (Microsoft Corporation) C:\windows\system32\StructuredQuery.dll
    2018-08-14 13:19 - 2018-06-27 10:55 - 000025088 _____ (Microsoft Corporation) C:\windows\system32\msimsg.dll
    2018-08-14 13:19 - 2018-06-27 10:54 - 001942016 _____ (Microsoft Corporation) C:\windows\system32\authui.dll
    2018-08-14 13:19 - 2018-06-27 10:54 - 000070144 _____ (Microsoft Corporation) C:\windows\system32\appinfo.dll
    2018-08-14 13:19 - 2018-06-27 10:43 - 000363520 _____ (Microsoft Corporation) C:\windows\SysWOW64\StructuredQuery.dll
    2018-08-14 13:19 - 2018-06-27 10:42 - 002366464 _____ (Microsoft Corporation) C:\windows\SysWOW64\msi.dll
    2018-08-14 13:19 - 2018-06-27 10:42 - 000337408 _____ (Microsoft Corporation) C:\windows\SysWOW64\msihnd.dll
    2018-08-14 13:19 - 2018-06-27 10:42 - 000025088 _____ (Microsoft Corporation) C:\windows\SysWOW64\msimsg.dll
    2018-08-14 13:19 - 2018-06-27 10:41 - 001806848 _____ (Microsoft Corporation) C:\windows\SysWOW64\authui.dll
    2018-08-14 13:19 - 2018-06-27 10:21 - 000128512 _____ (Microsoft Corporation) C:\windows\system32\msiexec.exe
    2018-08-14 13:19 - 2018-06-27 10:16 - 000073216 _____ (Microsoft Corporation) C:\windows\SysWOW64\msiexec.exe
    2018-08-14 13:19 - 2018-06-20 22:33 - 000002048 _____ (Microsoft Corporation) C:\windows\system32\tzres.dll
    2018-08-14 13:19 - 2018-06-20 22:09 - 000002048 _____ (Microsoft Corporation) C:\windows\SysWOW64\tzres.dll
    2018-08-09 19:35 - 2018-08-09 19:35 - 000009713 _____ C:\Users\Angela\Documents\Go, Go, Go.odt
    2018-07-27 17:17 - 2018-07-27 17:17 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
    2018-07-27 17:17 - 2018-07-27 17:17 - 000000000 ____D C:\Program Files\iPod
    2018-07-27 17:16 - 2018-07-27 17:17 - 000000000 ____D C:\Program Files\iTunes
    2018-07-27 17:09 - 2018-07-27 17:09 - 000000000 ____D C:\Program Files\Bonjour
    2018-07-27 17:09 - 2018-07-27 17:09 - 000000000 ____D C:\Program Files (x86)\Bonjour

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2018-08-21 12:58 - 2018-07-18 08:46 - 000000000 ____D C:\FRST
    2018-08-21 11:31 - 2018-06-02 20:26 - 000000422 _____ C:\windows\Tasks\SystemToolsDailyTest.job
    2018-08-21 11:30 - 2018-06-12 16:00 - 000003488 _____ C:\windows\System32\Tasks\PCDEventLauncher
    2018-08-21 11:30 - 2018-06-02 20:26 - 000003452 _____ C:\windows\System32\Tasks\SystemToolsDailyTest
    2018-08-21 11:17 - 2009-07-13 23:45 - 000020928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    2018-08-21 11:17 - 2009-07-13 23:45 - 000020928 ____H C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    2018-08-21 11:16 - 2009-07-14 00:13 - 000778834 _____ C:\windows\system32\PerfStringBackup.INI
    2018-08-21 11:16 - 2009-07-13 22:20 - 000000000 ____D C:\windows\inf
    2018-08-21 11:10 - 2018-06-23 17:05 - 000253664 _____ (Malwarebytes) C:\windows\system32\Drivers\mbamswissarmy.sys
    2018-08-21 11:09 - 2009-07-14 00:08 - 000000006 ____H C:\windows\Tasks\SA.DAT
    2018-08-21 11:07 - 2018-06-02 21:28 - 001027720 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000467232 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000381560 _____ (AVAST Software) C:\windows\system32\Drivers\aswVmm.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000346664 _____ (AVAST Software) C:\windows\system32\Drivers\aswbloga.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000249016 _____ (AVAST Software) C:\windows\system32\Drivers\aswHdsKe.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000229384 _____ (AVAST Software) C:\windows\system32\Drivers\aswbidsdrivera.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000214800 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000201320 _____ (AVAST Software) C:\windows\system32\Drivers\aswbidsha.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000199712 _____ (AVAST Software) C:\windows\system32\Drivers\aswArPot.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000163272 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000111864 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000085968 _____ (AVAST Software) C:\windows\system32\Drivers\aswRvrt.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000059568 _____ (AVAST Software) C:\windows\system32\Drivers\aswbuniva.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000046968 _____ (AVAST Software) C:\windows\system32\Drivers\aswHwid.sys
    2018-08-21 11:07 - 2018-06-02 21:28 - 000003910 _____ C:\windows\System32\Tasks\Avast Emergency Update
    2018-08-19 17:26 - 2009-07-13 22:20 - 000000000 ____D C:\windows\rescache
    2018-08-15 10:50 - 2009-07-13 23:45 - 000294512 _____ C:\windows\system32\FNTCACHE.DAT
    2018-08-15 10:46 - 2018-06-03 19:04 - 000000000 ____D C:\windows\system32\MRT
    2018-08-15 10:28 - 2018-06-03 19:03 - 137343192 ____C (Microsoft Corporation) C:\windows\system32\MRT.exe
    2018-08-09 19:28 - 2018-06-23 11:05 - 000000000 ____D C:\Users\Angela\Documents\Food
    2018-08-08 18:12 - 2018-06-02 21:06 - 000002226 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
    2018-07-30 11:17 - 2018-06-04 18:24 - 000000000 ____D C:\Users\Angela\Documents\Media
    2018-07-30 10:18 - 2009-07-14 00:08 - 000032638 _____ C:\windows\Tasks\SCHEDLGU.TXT
    2018-07-24 08:04 - 2018-06-04 18:24 - 000000000 ____D C:\Users\Angela\Documents\Must Save's

    Some files in TEMP:
    ====================
    2018-07-11 15:16 - 2018-07-11 15:16 - 019408800 _____ (Ellora Assets Corporation ) C:\Users\Angela\AppData\Local\Temp\FreemakeAudioConverterFull.exe
    2018-06-04 16:25 - 2010-08-14 02:19 - 000468232 _____ (Microsoft Corporation) C:\Users\Angela\AppData\Local\Temp\MSN56BB.exe
    2006-05-24 00:10 - 2006-05-24 00:10 - 000455600 ____R (Macrovision Corporation) C:\Users\Angela\AppData\Local\Temp\_is66BD.exe
    2006-05-24 00:10 - 2006-05-24 00:10 - 000455600 ____R (Macrovision Corporation) C:\Users\Angela\AppData\Local\Temp\_is8CC4.exe
    2006-05-23 22:10 - 2006-05-23 22:10 - 000455600 ____R (Macrovision Corporation) C:\Users\Angela\AppData\Local\Temp\_isA2F2.exe

    ==================== Bamital & volsnap ======================

    (There is no automatic fix for files that do not pass verification.)

    C:\windows\system32\winlogon.exe => File is digitally signed
    C:\windows\system32\wininit.exe => File is digitally signed
    C:\windows\SysWOW64\wininit.exe => File is digitally signed
    C:\windows\explorer.exe => File is digitally signed
    C:\windows\SysWOW64\explorer.exe => File is digitally signed
    C:\windows\system32\svchost.exe => File is digitally signed
    C:\windows\SysWOW64\svchost.exe => File is digitally signed
    C:\windows\system32\services.exe => File is digitally signed
    C:\windows\system32\User32.dll => File is digitally signed
    C:\windows\SysWOW64\User32.dll => File is digitally signed
    C:\windows\system32\userinit.exe => File is digitally signed
    C:\windows\SysWOW64\userinit.exe => File is digitally signed
    C:\windows\system32\rpcss.dll => File is digitally signed
    C:\windows\system32\dnsapi.dll => File is digitally signed
    C:\windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\windows\system32\Drivers\volsnap.sys => File is digitally signed

    LastRegBack: 2018-08-19 17:19

    ==================== End of FRST.txt ============================

  4. #4
    Join Date
    Mar 2014
    Posts
    491
    Addition:Additional scan result of Farbar Recovery Scan Tool (x64) Version: 19.08.2018 02
    Ran by Angela (21-08-2018 12:59:29)
    Running from C:\Users\Angela\Desktop
    Windows 7 Home Premium Service Pack 1 (X64) (2018-06-03 01:24:07)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-3674130756-1144773717-1238336968-500 - Administrator - Disabled)
    Angela (S-1-5-21-3674130756-1144773717-1238336968-1000 - Administrator - Enabled) => C:\Users\Angela
    Guest (S-1-5-21-3674130756-1144773717-1238336968-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-3674130756-1144773717-1238336968-1002 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Accidental Damage Services Agreement (HKLM-x32\...\{EF85FEF4-EB92-4075-A6D2-5F519BB30A2C}) (Version: 2.0.0 - Dell Inc.)
    Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 18.0.0.144 - Adobe Systems Incorporated)
    Adobe Flash Player 11 ActiveX 64-bit (HKLM\...\Adobe Flash Player ActiveX) (Version: 11.0.1.152 - Adobe Systems Incorporated)
    Adobe Reader X MUI (HKLM-x32\...\{AC76BA86-7AD7-FFFF-7B44-AA0000000001}) (Version: 10.0.0 - Adobe Systems Incorporated)
    Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version: 1.12.05 - Creative Technology Ltd)
    Apple Application Support (32-bit) (HKLM-x32\...\{E5347310-C82F-4833-AA36-8D11E5A8A86A}) (Version: 6.6 - Apple Inc.)
    Apple Application Support (64-bit) (HKLM\...\{D745E014-74DD-43A3-98DF-E7D38164B681}) (Version: 6.6 - Apple Inc.)
    Apple Mobile Device Support (HKLM\...\{C29B636B-9015-4ED1-A12F-6375A337F23B}) (Version: 11.4.1.46 - Apple Inc.)
    Apple Software Update (HKLM-x32\...\{A30EA700-5515-48F0-88B0-9E99DC356B88}) (Version: 2.6.0.1 - Apple Inc.)
    Avast Free Antivirus (HKLM-x32\...\Avast Antivirus) (Version: 18.6.2349 - AVAST Software)
    Banctec Service Agreement (HKLM-x32\...\{42D68A86-DB1C-4256-B8C9-5D0D92919AF5}) (Version: 2.0.0 - Dell Inc.)
    Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.)
    Complete Care Business Service Agreement (HKLM-x32\...\{0ECFCB07-9BFE-4970-ACA1-D568D982760B}) (Version: 2.0.0 - Dell Inc.)
    Consumer In-Home Service Agreement (HKLM-x32\...\{F47C37A4-7189-430A-B81D-739FF8A7A554}) (Version: 2.0.0 - Dell Inc.)
    Dell Digital Delivery (HKLM-x32\...\{AFC08A81-D3C5-46F4-8F08-876E4BA606EA}) (Version: 1.7.4502.0 - Dell Products, LP)
    Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
    Dell Home Systems Service Agreement (HKLM-x32\...\{AB2FDE4F-6BED-4E9E-B676-3DCCEBB1FBFE}) (Version: 2.0.0 - Dell Inc.)
    Dell Resource CD (HKLM-x32\...\{42929F0F-CE14-47AF-9FC7-FF297A603021}) (Version: 1.00.0000 - Dell Inc.)
    Dell Support Center (HKLM\...\{0090A87C-3E0E-43D4-AA71-A71B06563A4A}) (Version: 3.1.5803.11 - PC-Doctor, Inc.) Hidden
    Dell Support Center (HKLM\...\Dell Support Center) (Version: 3.1.5803.11 - Dell Inc.)
    Dell Touchpad (HKLM\...\{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}) (Version: 7.1209.101.204 - ALPS ELECTRIC CO., LTD.)
    Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 2.00.44 - Creative Technology Ltd)
    Google Chrome (HKLM-x32\...\Google Chrome) (Version: 68.0.3440.106 - Google Inc.)
    Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.17 - Google Inc.) Hidden
    IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6324.0 - IDT)
    Intel PROSet Wireless (HKLM-x32\...\ProInst) (Version: - ) Hidden
    Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation)
    Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
    Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2361 - Intel Corporation)
    Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{7CE8BE79-ABC3-4B2C-9543-28ED2B0A9EA8}) (Version: 1.2.0.0587 - Intel Corporation)
    Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{295AEB79-B53A-4F1B-860F-7800BB7E3681}) (Version: 14.2.1000 - Intel Corporation)
    Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 10.1.0.1008 - Intel Corporation)
    Intel(R) WiDi (HKLM-x32\...\{781A93CD-1608-427D-B7F0-D05C07795B25}) (Version: 2.1.41.0 - Intel Corporation)
    Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - )
    iTunes (HKLM\...\{36F365B3-05C2-455D-9D96-B73829DE046D}) (Version: 12.8.0.150 - Apple Inc.)
    Java(TM) 6 Update 27 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86416027FF}) (Version: 6.0.270 - Oracle)
    Java(TM) 6 Update 27 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83216027FF}) (Version: 6.0.270 - Oracle)
    Malwarebytes version 3.5.1.2522 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.5.1.2522 - Malwarebytes)
    Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
    Microsoft Silverlight (HKLM-x32\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 4.0.50401.0 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{052bac4a-6f79-46d4-a024-1ce1b4f73cd4}) (Version: 8.0.58299 - Microsoft Corporation)
    Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
    Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
    OpenOffice 4.1.5 (HKLM-x32\...\{ABCAD346-4F4B-49E9-9AA1-28EF8C26059D}) (Version: 4.15.9789 - Apache Software Foundation)
    PhotoScape (HKLM-x32\...\PhotoScape) (Version: - )
    PlayReady PC Runtime x86 (HKLM-x32\...\{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}) (Version: 1.3.0 - Microsoft Corporation)
    Premium Service Agreement (HKLM-x32\...\{C33AA6D6-F5EC-48F3-AFDC-8141345D473A}) (Version: 2.0.0 - Dell Inc.)
    QualxServ Service Agreement (HKLM-x32\...\{903679E8-44C8-4C07-9600-05C92654FC50}) (Version: 2.0.0 - Dell Inc.)
    Quickset64 (HKLM\...\{87CF757E-C1F1-4D22-865C-00C6950B5258}) (Version: 10.09.25 - Dell Inc.)
    Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.31.1025.2010 - Realtek)
    Realtek USB 2.0 Card Reader (HKLM-x32\...\{96AE7E41-E34E-47D0-AC07-1091A8127911}) (Version: 6.1.7600.30126 - Realtek Semiconductor Corp.)
    Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation) Hidden
    Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.32.0 - Renesas Electronics Corporation)
    Revo Uninstaller 2.0.5 (HKLM\...\{A28DBDA2-3CC7-4ADC-8BFE-66D7743C6C97}_is1) (Version: 2.0.5 - VS Revo Group, Ltd.)
    WeatherBugŪ (HKLM-x32\...\WeatherBugŪ) (Version: 10.0.7.4 - Earth Networks, Inc.)
    Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-08-21] (AVAST Software)
    ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-08-21] (AVAST Software)
    ContextMenuHandlers1: [BTMSentToExt] -> {0A7D34C2-E9DA-48A1-9E34-0CDFC2DE3B44} => C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll [2011-05-19] (Intel Corporation)
    ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-08-21] (AVAST Software)
    ContextMenuHandlers3: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)
    ContextMenuHandlers5: [igfxcui] -> {3AB1675A-CCFF-11D2-8B20-00A0C93CB1F4} => C:\windows\system32\igfxpph.dll [2011-04-10] (Intel Corporation)
    ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2018-08-21] (AVAST Software)
    ContextMenuHandlers6: [MBAMShlExt] -> {57CE581A-0CB6-4266-9CA0-19364C90A0B3} => C:\Program Files\Malwarebytes\Anti-Malware\mbshlext.dll [2018-05-09] (Malwarebytes)

    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {29E04578-3291-4FCA-AC1B-3DD22ABE76D7} - System32\Tasks\SystemToolsDailyTest => c:\Program Files\Dell Support Center\pcdrcui.exe [2011-03-22] (PC-Doctor, Inc.)
    Task: {383BCAC8-607F-4841-A1AB-AB0176037B90} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-06-02] (Google Inc.)
    Task: {3F1F9A40-F8C2-4B48-9D84-C1E83DDE5B6F} - System32\Tasks\PCDEventLauncher => c:\Program Files\Dell Support Center\sessionchecker.exe [2011-03-22] (PC-Doctor, Inc.)
    Task: {6D96B09C-DFBC-415F-9B57-DCB572F82299} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2018-06-02] (Google Inc.)
    Task: {7CAF3759-B8EC-470F-AAB7-0E8075040F10} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2018-01-08] (Apple Inc.)
    Task: {C44AB9CA-B92B-4F64-B463-EE5B832DC9B7} - System32\Tasks\PCDoctorBackgroundMonitorTask => c:\Program Files\Dell Support Center\uaclauncher.exe [2011-03-22] (PC-Doctor, Inc.)
    Task: {E4B4C484-07F3-4F07-A519-7A208B8A148B} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-08-21] (AVAST Software)
    Task: {FC497220-3BB6-4661-B6E6-C2F17165E37F} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe [2018-08-17] (AVAST Software)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\windows\Tasks\PCDoctorBackgroundMonitorTask.job => c:\Program Files\Dell Support Center\uaclauncher.exeo-backgroundmon scripts\defaultscan.xml
    Task: C:\windows\Tasks\SystemToolsDailyTest.job => c:\Program Files\Dell Support Center\pcdrcui.exe

    ==================== Shortcuts & WMI ========================

    (The entries could be listed to be restored or removed.)


    ==================== Loaded Modules (Whitelisted) ==============

    2011-09-15 18:46 - 2011-09-15 18:46 - 001501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
    2018-06-23 06:56 - 2018-06-23 06:56 - 001356088 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
    2018-05-15 18:59 - 2018-05-15 18:59 - 000088888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
    2018-06-23 17:05 - 2018-07-19 21:54 - 002433744 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\SelfProtectionSdk.dll
    2012-01-05 09:10 - 2011-04-10 13:40 - 000094208 _____ () C:\WINDOWS\System32\IccLibDll_x64.dll
    2018-07-06 02:00 - 2018-07-06 02:00 - 001356088 _____ () C:\Program Files\iTunes\libxml2.dll
    2018-07-06 02:00 - 2018-07-06 02:00 - 000088888 _____ () C:\Program Files\iTunes\zlib1.dll
    2018-06-04 19:02 - 2016-05-05 10:41 - 000108456 ____N () C:\Program Files\Earth Networks\WeatherBug\WeatherBug.exe
    2018-08-21 11:07 - 2018-08-21 11:07 - 000703192 _____ () c:\Program Files\AVAST Software\Avast\x64\StreamBack.dll
    2018-08-21 11:07 - 2018-08-21 11:07 - 000575704 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
    2018-08-21 10:36 - 2018-08-21 10:36 - 005666448 _____ () C:\Program Files\AVAST Software\Avast\defs\18082104\algo.dll
    2018-08-21 11:07 - 2018-08-21 11:07 - 000896216 _____ () C:\Program Files\AVAST Software\Avast\anen.dll
    2018-08-21 11:07 - 2018-08-21 11:07 - 000541400 _____ () C:\Program Files\AVAST Software\Avast\gui_cache.dll
    2018-08-21 11:07 - 2018-08-21 11:07 - 000151768 _____ () C:\Program Files\AVAST Software\Avast\hns_tools.dll
    2018-08-21 11:07 - 2018-08-21 11:07 - 000986840 _____ () C:\Program Files\AVAST Software\Avast\shepherdsync.dll
    2018-06-02 21:29 - 2018-06-02 21:29 - 067126928 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
    2018-08-17 11:51 - 2018-08-17 11:51 - 000169984 _____ () C:\windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\3da12de5df10f134ae5e99dfa5a17f56\IsdiInterop.ni.dll
    2012-01-05 07:39 - 2010-11-05 23:50 - 000058880 _____ () C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service"
    HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"

    ==================== Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2009-07-13 21:34 - 2018-07-27 16:27 - 000000825 _____ C:\windows\system32\Drivers\etc\hosts


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-3674130756-1144773717-1238336968-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Angela\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
    DNS Servers: 24.116.0.53 - 24.116.2.50
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [{A322352A-BB91-45F1-8E4F-69DF5A05D987}] => (Allow) C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
    FirewallRules: [{D122B53C-55EB-482A-BFE3-751AAE9DD699}] => (Allow) C:\Program Files (x86)\Intel Corporation\Intel WiDi\WiDiApp.exe
    FirewallRules: [{15D8110C-BA18-465A-9BF5-D54703105AA6}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{1D7370A9-4B2E-4F88-860A-049D5DAAC927}] => (Allow) C:\Program Files\Common Files\mcafee\mcsvchost\McSvHost.exe
    FirewallRules: [{7696917B-5B84-459E-919D-D09CAE3F6FEA}] => (Allow) C:\Program Files\dell stage\dell stage\accuweather\accuweather.exe
    FirewallRules: [{EBD3EA01-FE7C-453D-9E0F-70F1D4017A8E}] => (Allow) C:\Program Files\dell stage\musicstage\musicstageengine.exe
    FirewallRules: [{AF7132C7-8313-4DD2-963D-E2E5D9C7ED28}] => (Allow) C:\Program Files\dell stage\dell stage\stage_primary.exe
    FirewallRules: [{2672C880-8F4C-439D-A397-ACFE395CE51C}] => (Allow) C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
    FirewallRules: [{8D08F0F3-9A76-4F38-AFF3-D017B5718D86}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{27097632-4F7D-4A78-9182-1059B0B508B0}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
    FirewallRules: [{027C6BD6-B316-45FF-BBCD-5A50FE0F3156}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{74F63D5F-7E5D-4A36-A187-EB86AF32EC26}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
    FirewallRules: [{0C685378-DB73-4D10-9A84-F9ED8BCC39C8}] => (Allow) C:\Program Files\iTunes\iTunes.exe
    FirewallRules: [{A929F43C-38B7-4D3A-9803-6BA153E542D3}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    FirewallRules: [{016FBA95-246B-4676-B8D9-69E5F2725E7B}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe
    FirewallRules: [{FC57E768-36AF-4678-8190-96C89D5742B0}] => (Allow) C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe

    ==================== Restore Points =========================


    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (08/21/2018 11:09:52 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (08/21/2018 11:03:34 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (08/21/2018 10:36:25 AM) (Source: WinMgmt) (EventID: 10) (User: )
    Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.

    Error: (08/20/2018 02:05:59 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 5554

    Error: (08/20/2018 02:05:59 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 5554

    Error: (08/20/2018 02:05:59 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: Continuously busy for more than a second

    Error: (08/20/2018 02:05:57 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledSPRetry 3432

    Error: (08/20/2018 02:05:57 PM) (Source: Bonjour Service) (EventID: 100) (User: )
    Description: Task Scheduling Error: m->NextScheduledEvent 3432


    System errors:
    =============
    Error: (08/21/2018 11:11:55 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Dell Digital Delivery Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (08/21/2018 11:05:42 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Dell Digital Delivery Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (08/21/2018 10:38:24 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Dell Digital Delivery Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (08/21/2018 10:35:45 AM) (Source: EventLog) (EventID: 6008) (User: )
    Description: The previous system shutdown at 7:27:25 PM on ‎8/‎20/‎2018 was unexpected.

    Error: (08/20/2018 07:49:38 AM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Dell Digital Delivery Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (08/19/2018 03:38:44 PM) (Source: Service Control Manager) (EventID: 7034) (User: )
    Description: The Dell Digital Delivery Service service terminated unexpectedly. It has done this 1 time(s).

    Error: (08/19/2018 03:35:48 PM) (Source: EventLog) (EventID: 6008) (User: )
    Description: The previous system shutdown at 3:33:07 PM on ‎8/‎19/‎2018 was unexpected.

    Error: (08/19/2018 03:01:21 PM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
    Description: The following fatal alert was received: 20.


    ==================== Memory info ===========================

    Processor: Intel(R) Core(TM) i3-2350M CPU @ 2.30GHz
    Percentage of memory in use: 40%
    Total physical RAM: 6051.18 MB
    Available physical RAM: 3573.82 MB
    Total Virtual: 12100.5 MB
    Available Virtual: 9671.57 MB

    ==================== Drives ================================

    Drive c: (OS) (Fixed) (Total:451.01 GB) (Free:276.26 GB) NTFS

    \\?\Volume{f9488d98-66dc-11e8-a1d7-806e6f6e6963}\ (Recovery) (Fixed) (Total:14.65 GB) (Free:6.4 GB) NTFS

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7/8/10) (Size: 465.8 GB) (Disk ID: 821CAA44)
    Partition 1: (Not Active) - (Size=94 MB) - (Type=DE)
    Partition 2: (Active) - (Size=14.6 GB) - (Type=07 NTFS)
    Partition 3: (Not Active) - (Size=451 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt ============================

  5. #5
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,359
    I don't see anything malicious there.
    Since all is working after restart I'm assuming it was a temporary glitch.

  6. #6
    Join Date
    Mar 2014
    Posts
    491
    Great! Thank you!

  7. #7
    Join Date
    Dec 2007
    Location
    Daly City, CA
    Posts
    22,359
    You're very welcome

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •